GDPR

Knowledge Base | GDPR | What is a personal data breach?

What is a personal data breach?

A personal data breach is a security incident that causes personal data to be accidentally or unlawfully destroyed, lost, altered, disclosed or accessed without authorisation. It can affect digital information or paper records and does not have to involve a cyberattack.

Breaches can affect:

  • Confidentiality: Sending customer information to the wrong recipient.

  • Integrity: Unauthorised changes to someone’s records.

  • Availability: Ransomware preventing access to personal data.

Under GDPR breach notification requirements, controllers must notify the relevant authority without undue delay and, where feasible, within 72 hours of becoming aware, unless a risk to individuals’ rights and freedoms is unlikely. Breaches likely to create a high risk generally also require informing affected individuals without undue delay.

Every breach must be documented, including its effects and the action taken. A data breach response plan helps organisations assess incidents and meet these obligations.