Skip to content

Personal Data Breach

Definition

Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Most other frameworks use a similar functional definition, though some US state laws limit the trigger to specific categories of sensitive data such as Social Security numbers or financial account details.

Governing law
GDPR Article 4(12), EU/UK
Trigger
Accidental or unlawful loss, alteration, disclosure or access
US variant
Many state laws trigger only on specific data categories
Obligation
Time-bound notification to a supervisory authority

Common questions

Does a breach have to be caused by an attacker to count under GDPR?+

No. The GDPR definition covers accidental events such as a misconfigured server or a misdirected email, as well as deliberate intrusion, because the trigger is the security failure and its effect on the data, not the actor's intent.

How do US state breach laws typically differ from the GDPR approach?+

Most US state statutes only require notification when specific sensitive categories, such as Social Security numbers or financial account credentials, are involved, rather than treating any personal data exposure as reportable.

Related terms

Covered Entity / Business Associate
Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
Data Fiduciary
The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing...
Notification Trigger
The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk...
Safe Harbour (Encryption)
A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...
Supervisory Authority
The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.