A parks department discovers a contractor exfiltrated membership PII. Beyond internal policy, what must leadership recognize?
Select an answer to reveal the explanation.
Short Explanation
Catching a contractor stealing membership PII is not just an HR write-up. Depending on the jurisdiction, you may face breach notices, cybercrime reporting, and contractual remedies. Treating it as 'policy only' leaves the city exposed twice.
Full Explanation
Data exfiltration of personally identifiable information implicates internal policy, contractual remedies, and often statutory breach-notification and cybercrime frameworks. Municipal entities remain subject to applicable legal and regulatory obligations even when the actor is a contractor. Leadership must evaluate notification, evidence preservation, and law-enforcement or regulatory engagement — not merely revoke access and close an internal ticket.