Question

What counts as a data breach, and when must it be reported?

Vault Verified
Curated Intelligence
Definitive Source
Answer

A personal data breach is any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data — which is considerably broader than "we were hacked".

The three types, all of which count:

Confidentiality breach — unauthorised disclosure or access. The obvious case.

Integrity breach — unauthorised alteration.

Availability breach — accidental or unlawful loss of access, including destruction. This surprises people: a ransomware attack that encrypts data without exfiltrating it is a breach, and so is losing the only copy of something.

The commonplace incidents that qualify: an email sent to the wrong recipient; using cc instead of bcc on a mailing, which is among the most frequently reported breaches of all; a lost or stolen unencrypted laptop, phone or USB stick; papers left somewhere; a misconfigured system exposing records; data sent to the wrong supplier; and inadequate redaction in a released document.

When it must be reported to the regulator. To the ICO without undue delay and where feasible within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people's rights and freedoms.

The 72 hours runs from awareness, not from discovery of the full facts. You report what you know and supply the rest afterwards — waiting until the investigation is complete is the common and incorrect instinct.

When affected individuals must be told. Where the breach is likely to result in a high risk to their rights and freedoms — a higher threshold than for regulator reporting. The communication must be in clear plain language and describe the likely consequences and the measures taken.

Encryption matters legally, not just practically: if data is rendered unintelligible to anyone unauthorised, notification to individuals may not be required.

What must happen regardless of reportability: every breach must be recorded internally, including those not reported, with the facts, effects and remedial action. Regulators ask for this log.

Processors must notify their controller without undue delay; the controller reports onward.

General information, not legal advice.

Related Questions