Share

Digital

book

Promoting comparability in personal data breach notification reporting

This report provides the key findings of an OECD survey on comparability in personal data breach notification (PDBN) reporting that was implemented from June 2019 to February 2020. The main findings show a general trend towards mandatory PDBN regulation and identify internationally comparable data metrics used by privacy enforcement authorities (PEAs). The metrics include the number of reported PDBNs, data on the nature of causes, specific causes, and the types of data breached. In addition, the survey identified the types of questions suitable for internationally comparable data collections by PEAs. These include questions on sectoral application of mandatory PDBN, thresholds and timeframes for notifications to the designated authorities and data subjects, and the use of collected data for enforcement collaboration. The survey also sheds light on some of the possible challenges in improving international comparability such as lack of common standards in the industrial classifications used by PEAs.

Available from December 21, 2021

In series:OECD Digital Economy Papersview more titles