How To Prevent a Potential Data Breach?

ECOVIS ProventusLaw keeps you up-to-date with recent news and legislative changes relevant to the business. This time, ECOVIS ProventusLaw’s Data Protection team has prepared a summary on how to prevent potential data breaches and what to do in case of a personal data breach.

Firstly, ECOVIS ProventusLaw pays attention that organizations are required to carry out a risk assessment in all cases. Depending on the identified risks, nature, scope, context as well as the purpose of processing, appropriate technical and organizational measures ensuring the security of the processed data must be implemented. The list of which is available on the Lithuanian Data Protection Authority’s website.

When implementing / developing security measures, financial institutions are also required to comply with the Resolution of the Board of the Bank of Lithuania No 03-174 on the approval of the Description of Requirements for Information and Communication Technology and Security Risk.

GDPR principle of accountability requires every company to not only ensure compliance with the principles and rules of the GDPR, but also to demonstrate that they are being followed within the company.

Implementing the responsibilities arising from the principle of accountability is an ongoing process, therefore it is essential to ensure and maintain the necessary procedures and policies, to train and enforce staff and to establish appropriate internal governance and control.

What to do in the event of a personal data security breach

The most urgent

  • Upon becoming aware of a possible security breach, inform the responsible persons: IT and security specialists and the data protection officer (consult with him/her to investigate and control the incident, submitting a report to VDAI and data subjects).
  • Isolation of compromised devices during a cyber-attack.
  • Each security incident must be investigated in detail and its causes determined.
  • Inform the responsible authorities.
  • Inform customers and other data subjects.

  • Taking into account the data security incident and its consequences, implement additional security measures that would prevent such security breaches in the future, update available documents, procedures and plans.

We hope the information was useful. If you have additional questions or need professional assistance, please do not hesitate to contact us.

More information on introductory GDPR training.

Related news

Knowledge without experience is of little use. Therefore we are proud of having our own valuable experience to share with you.

Frequently Asked Questions

Postponement of the auditor’s visit during a tax audit

My company has just received a notice of accounting audit. I would like to change the date of the controller’s first visit to our premises. Is this possible?

Absolutely. You can indeed request the postponement of this first on-site intervention. But to do this, you must quickly formulate your request in writing. And be careful, the tax authorities are not obliged to accept it. Your request can only be accepted if the reasons you invoke seem serious. This may be the case, for example, if your accountant is absent or if your company is closed due to holidays. Generally, if it accepts your request, the administration informs you of the new date by registered letter with acknowledgement of receipt, and not by a corrected verification notice.

Contact person

+370 5 212 40 84

[email protected]

Loreta Andziulytė

Partner & Attorney at Law | Head of Data Protection, Employment & Corporate Law | CIPP/E

Contact person

+370 5 212 40 84

[email protected]

    Newsletter SubscriptionGet in touch