Data Breach Notifications
Increased and hefty penalties are part of new upcoming revisions of U.S. and E.U. international data protection laws, applicable whenever a Company does not properly capture and disclose data breaches.
We therefore ask you to speak up and report promptly on any confirmed or suspected breach.
The IS team has reviewed and re-enforced PMI’s current internal practice to:
• Formally capture and manage any real or suspected data breach.
• Manage the disclosure to outside stakeholders, when applicable.
A “Breach” is defined as an event where Personal or sensitive Company information is exposed to parties otherwise not relevant to normal or desired course of business. Breaches can be internal or external. Both need to be managed.
This reviewed practice is valid as of March 2015.