Jon Baines, Senior Data Protection Specialist at Mishcon de Reya, spoke to Fast Company about the potential data protection implications for CrowdStrike following a major system malfunction. The incident, which is said to have caused 8.5 million Windows computers to crash, could have ramifications under the UK General Data Protection Regulation (UK GDPR) in the UK and under the EU's own GDPR in Europe.
Jon suggests that organisations affected by the CrowdStrike outage might face scrutiny regarding UK GDPR and GDPR compliance, particularly if the incident caused issues with access to their personal data. The debate among data experts focuses on the responsibility for the outage and the extent to which UK GDPR and GDPR might apply.
While the full legal consequences are yet to be determined, Jon highlights the complex interplay between the concept of a "personal data breach", UK GDPR reporting requirements and the responsibilities of data controllers and processors.
Read in full.