So just to answer a few questions.
I was on holiday all last week, and was catching up on my emails over the weekend, which is why I didn’t know about this sooner, and also Ruth could not have reported the breach to me, because I wasn’t around.
It turns out that Nicola reported the breach herself, but didn’t get the process quite right. Ruth could very easily have helped her with this, she has experience with GDPR, but chose to escalate the matter instead. We all have GDPR training, but the last session was over a year ago and Nicola had obviously forgotten the details.
I don’t participate in cover-ups, thankfully this sort of thing doesn’t happen very often. But if something does go wrong, the onus is on sorting it out properly and discretely, and re-educating those that need it.
I would never use the terms ‘snitch’ and ‘grass’ in a work setting, but on an anonymous forum like MN I feel comfortable sharing my gut feelings about something, even though I would not articulate those thoughts.
So our department is gong to have a further session on GDPR, and I’ve spoken to both Nicola and Ruth separately. Nicola was mortified and Ruth “was just trying to help” by letting our most senior staff know, instead of helping Nicola report it in the correct way to the correct department. Interestingly I was given the heads-up about all this, by someone who isn’t really involved, and it became clear that many people know about Ruth’s “help”. My initial thoughts about Ruth haven’t changed.
And by the way, just to reiterate that both Nicola and Ruth are made up names, so I’m sorry if any real life people were alarmed!!!