Skip to content

Safe Harbour (Encryption)

Definition

A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the decryption key was not also compromised. GDPR Recital 83 and Article 34(3)(a) codify this; many US state laws include equivalent provisions.

Effect
Exempts encrypted data from breach notification
Condition
Decryption key not also compromised
GDPR reference
Recital 83, Article 34(3)(a)
Also found in
Many US state breach laws

Common questions

Why does the safe harbour condition require the key to be uncompromised too?+

Encrypted data that was breached alongside its decryption key offers no real protection to the individuals affected, so the exemption only applies when the data remains genuinely unreadable to whoever obtained it, which is why key security is assessed separately from the fact of encryption itself.

Does safe harbour encryption remove all breach-related obligations?+

No. It typically exempts an organisation from individual notification duties, but regulatory reporting obligations, internal incident documentation, and remediation steps often still apply, so the exemption narrows one specific requirement rather than the whole response.

Related terms

Covered Entity / Business Associate
Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
Data Fiduciary
The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing...
Notification Trigger
The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk...
Personal Data Breach
Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...
Supervisory Authority
The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.