Skip to content
Säkerhet

What is Data Breach?

When the wrong person gets access to the right data. Like someone unauthorised walking into your archive — except you never hear the door.

A data breach is when someone unauthorised accesses, steals, changes or destroys information they should not have. Picture someone getting into your locked archive and browsing your customer files — except it happens digitally and often completely silently. Many breaches are only discovered long after they occur.

A breach can happen in many ways: a stolen password, a security flaw in software, an employee clicking a phishing email or even a lost laptop. The result is the same — information that should be protected has ended up in the wrong hands.

It is important to distinguish a data breach from a personal data breach under GDPR. If the leaked information relates to identifiable individuals (names, national ID numbers, health data and so on), it also becomes a data protection issue, and you may be required to notify your supervisory authority within 72 hours.

Why do data breaches matter for your business?

A data breach can cost you on several fronts at once: lost customer trust, fines if personal data was involved and the expense of cleaning up and recovering. For a smaller business, reputational damage can hurt most over the long term.

That is why building in protection upfront and having a plan for if it still happens pays off. A company that handles an incident quickly and openly often fares better than one that tries to sweep it under the carpet.

Data breach in practice

Imagine an online shop where an old, unpatched part of the site has a security hole. An attacker exploits it and accesses the customer database with names, addresses and orders. The business notices nothing until customers start complaining about strange marketing emails.

A prepared company instead detects the breach quickly through monitoring, closes the hole, informs affected customers and reports the incident on time. The difference between those two outcomes almost always comes down to preparation.

Common questions about Data Breach

What is a data breach?

A data breach is when someone unauthorised accesses, steals, changes or destroys information they should not have. It can happen via stolen passwords, security flaws or human error, and can affect anything from customer data to internal documents.

Do you have to report a data breach?

If the breach involves personal data, GDPR may require you to notify your supervisory authority within 72 hours, and in some cases inform the affected individuals. Failing to report can lead to fines.

What is the difference between a data breach and a personal data breach?

A data breach covers unauthorised access to any data. A personal data breach specifically involves personal data about identifiable individuals. If personal data is involved, it is both.

Related terms

← Full glossary