Personal data breach
Definition
Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Most other frameworks use a similar functional definition, though some US state laws limit the trigger to specific categories of sensitive data such as Social Security numbers or financial account details.
Related terms
- Covered Entity / Business Associate
- Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
- Data fiduciary
- The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing...
- Notification trigger
- The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk...
- Safe harbour (encryption)
- A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...
- Supervisory authority
- The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...
Explained in
- Breach Notification Laws and ObligationsUnder GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. M...