Data Privacy Laws Response to Ransomware Attacks: A Multi-Jurisdictional Analysis

  • Brewczyńska M
  • Dunn S
  • Elijahu A
N/ACitations
Citations of this article
11Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In recent years thousands of organisations have fallen victim to ran- somware attacks. This malicious software disables access to users’ data and demands payment of a ransom for its restoration. Cyberattacks like these are usually thought of in the context of cybercrime, but because the data affected by ran- somware is often personal data, such attacks also raise pertinent questions that need to be examined under the light of data privacy laws. Considering that security has always been central to the protection of personal data, this chapter proposes an analysis of ransomware attacks through the lens of the well-established information security model, i.e. the CIA (confidentiality, integrity, and availability) triad. Using these three basic security principles, we examine whether ransomware will be considered a data breach under data privacy laws and what the legal implications of such breaches are. In order to illustrate these points, we will focus on ransomware attacks that target organisations that process personal data and highlight three examples of jurisdictions, namely the European Union (EU), Canada and Israel.

Cite

CITATION STYLE

APA

Brewczyńska, M., Dunn, S., & Elijahu, A. (2019). Data Privacy Laws Response to Ransomware Attacks: A Multi-Jurisdictional Analysis (pp. 281–305). https://doi.org/10.1007/978-94-6265-279-8_15

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free