Most ICO data breach reports late and incomplete prior to GDPR
A Freedom of Information (FOI) request from the Information Commissioner’s Office (ICO) was released today revealing the amount of late and incomplete data breach reports prior to GDPR.
It found that businesses routinely delayed data breach disclosure and failed to provide important details to the ICO in the year prior to the GDPR’s enactment.
On average, businesses waited three weeks after discovery to report a breach to the ICO, while the worst offending organisation waited 142 days. The vast majority (91%) of reports to the ICO failed to include important information such as the impact of the breach, recovery process and dates.
Source: Most ICO data breach reports late and incomplete prior to GDPR, reveals FOI