Privacy
Glossary

Personal data breach

A personal data breach is a security breach that accidentally or unlawfully destroys, loses, alters, discloses or gives unauthorised access to personal data.

In brief

Under Article 4(12) GDPR, a personal data breach occurs when a security breach leads to the accidental or unlawful destruction, loss or alteration of personal data, or to its unauthorised disclosure or access. Examples include sending an email to the wrong recipient, losing a device, a ransomware attack or access by a person without permission.

Breaches are commonly described as confidentiality, integrity or availability breaches. Disclosure to an unauthorised person concerns confidentiality, an unauthorised change concerns integrity, and loss of access to or destruction of data concerns availability. Not every IT security incident is therefore a personal data breach. The key question is whether personal data has been affected.

After an incident, controllers should promptly establish which data and people are affected, what consequences are possible and which safeguards are in place. The breach must be documented. Where it is likely to result in a risk to people’s rights and freedoms, the supervisory authority must be notified without undue delay and, where feasible, within 72 hours. Where a high risk is likely, the affected people may also have to be informed. The topic on data breaches and notification duties, the data breach initial check and the data breach documentation checklist support an initial assessment.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich