By Lawfox | Algemeen | 24 February 2022 | 3 min. reading time
I was reviewed by De Telegraaf about the data breach that occurred at Porsche.
Data breach due to theft of a USB stick
The Dutch Porsche seller Pon Luxury & Performance Cars had a USB stick stolen, containing data from people who had bought a Porsche between 2009 and 2017. The USB stick contained billing information, including name and address details, telephone numbers and e-mail addresses. The USB stick was stolen from a secure area in one of the Pon offices. Pon also did not let us know whether account data, driving license data and / or other data have also been captured. Pon also does not comment on whether the USB stick was encrypted or not.
Possible consequences of the data breach
As a result of the data breach, malicious parties can know where people who have managed to get a Porsche car live. It can also lead to identity fraud, phising and extortion.
Data breach notification obligation
Porsche has notified the breach to the Personal Authority, and that has made it to the police.
Interview De Telegraaf
De Telegraaf asked me whether it is customary for such information to be stored on a USB stick. Customary or not, I don’t think it’s convenient:
‘Not very useful’
usualICT lawyer at Lawfox Wouter Dammers says that it is not uncommon for sensitive data to be stored on USB sticks. “I don’t find that very useful,” he says. “A USB stick is not that big, you can easily lose it. And especially if the information it contains is not encrypted, it is not ideal. You can hope from companies that handle personal information that they give a computer good security and that also applies to USB sticks. Certainly if it is not encrypted, this is not useful. ”
Practical tips for a data breach
However, an accident is of course alway possible. No matter how well you have things in order. A data breach can happen to any company or organization. However, it is important to act quickly to limit the consequences of the data breach. This includes consequences for the privacy of the person concerned, but also, for example, damage to reputation.
It is therefore important for every company and organization to have a step-by-step plan ready, in case there is a data breach. The The Dutch Data Protection Authority is taking a step in the right direction. Everyone in the organization may encounter a data breach. Everyone in the organization must therefore have the knowledge and skills to identify a (possible) data breach and report it internally. With an internal working process at hand, the organization can determine whether there is a data breach and provide guidance for follow-up actions.
Do you want to know more about such an action plan, or are you dealing with a data breach yourself? Please call me (+31132077107) or email me W.Dammers@lawfox.nl.