Data breach
Also known as: data leak, personal data breach
An event where private information is seen, taken, changed or lost by people who should not have it.
Draft - this entry has not been reviewed yet.
Formal
A security incident that leads to the accidental or unlawful loss, change, disclosure of, or access to protected data, breaking its confidentiality, integrity or availability.
In plain English
Like a lost folder of patient records turning up on a train seat - whoever finds it can read it.
In practice
A clerk at a municipal job centre emails a file with 2,000 citizens' CPR numbers to the wrong outside recipient; the municipality must report it to Datatilsynet within 72 hours of finding out.
Why it matters
The people whose data escapes can face fraud or worse, and the organisation faces a duty to report, possible fines and lost trust.
Technical deep dive
In EU law the precise term is "personal data breach", defined in GDPR Article 4(12) as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. The definition is broader than the everyday "leak": the EDPB's Guidelines 9/2022 on personal data breach notification classify breaches as confidentiality breaches (unauthorised disclosure or access), integrity breaches (unauthorised alteration) and availability breaches (loss of access or destruction). Ransomware that encrypts personal data is therefore at least an availability breach even when nothing is exfiltrated, and a misdirected email is a confidentiality breach even when no attacker is involved. Data breaches involving only non-personal data, such as trade secrets, fall outside the GDPR but may still be significant incidents under NIS2.
The GDPR obligations are risk-graded. Article 33(1) requires the controller to notify the supervisory authority, in Denmark Datatilsynet, without undue delay and where feasible within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 33(2) requires a processor to notify the controller without undue delay, which is why data processing agreements specify short internal deadlines. Article 33(4) allows information to be provided in phases, and Article 33(5) requires every breach to be documented internally, including those that are not notified. Article 34 adds communication to the data subjects when the risk is high, with exemptions in 34(3), for example where the data was encrypted with a key that was not compromised.
The EDPB considers a controller "aware" when it has a reasonable degree of certainty that a security incident has compromised personal data, not when the investigation is finished; a short initial investigation is acceptable, but delaying it to avoid the clock is not. Risk assessment weighs the type and sensitivity of the data (special categories under Article 9, CPR numbers, financial data), volume, ease of identification, severity and permanence of consequences, vulnerable data subjects and whether the data is in the hands of a trusted or malicious recipient.
Failure to notify is itself sanctionable: breaches of Articles 33 and 34 fall under the Article 83(4) tier of up to EUR 10 million or 2 % of worldwide annual turnover, separate from any fine for the inadequate security that caused the breach. As a rule, Danish fines are set by the courts after Datatilsynet reports the case to the police, and notification is made through Virk.dk. A breach may trigger several regimes at once, such as GDPR, NIS2 and DORA, each with its own recipient, threshold and timeline.
What to learn first
Everything this builds on, foundations first.
- Confidentiality
- →Data breach
Relationships
Sources & further reading
Standards & official texts
- GDPR (Regulation (EU) 2016/679), Articles 4(12), 33 and 34
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…