Skip to content
GDPR

What is Personal Data Breach?

A data leak or unauthorised access to personal data. Under GDPR Article 33, many must be reported to the supervisory authority within 72 hours.

A personal data breach is when something goes wrong with the protection of personal data, so that it leaks, is destroyed, altered, or ends up in the wrong hands. Imagine dropping your keys in the street. Maybe a kind person finds them, maybe a thief — but the point is that control is lost. In the same way, it is a breach as soon as you no longer have full control over who can access the data.

It is not only about spectacular hacker attacks. A personal data breach can just as easily be an email with a customer list sent to the wrong person, a lost laptop without encryption, or an employee accidentally deleting a database. What they share is that protection fails in a way that can harm the people whose data is involved.

What makes the concept especially important is the time pressure. Under GDPR Article 33, many breaches must be reported to the supervisory authority within 72 hours of discovery. If the risk to those affected is high, you must also inform them directly. That is why you need to know in advance what to do — not start searching when the alarm is already sounding.

Why are personal data breaches important for your business?

A breach handled poorly can cost more than the leak itself. Miss the 72-hour deadline or cover up what happened, and you risk fines on top of the trust you have already lost with customers.

Handle it quickly and openly, however, and you show the business takes responsibility. Customers often forgive a mistake, but rarely being left in the dark. A thought-through incident procedure is both a legal and a trust insurance policy.

Personal data breach in practice

Say an employee at your business sends an Excel file with payroll data to the wrong recipient. That is a personal data breach. You document immediately what happened, assess the risk to the employees, and report to the supervisory authority if required, while asking the recipient to delete the file.

At ZORC we build systems with logging and access control so breaches are both fewer and easier to detect and investigate when they do occur.

Common questions about Personal Data Breach

What does personal data breach mean?

A personal data breach is a security failure that leads to personal data being leaked, destroyed, altered, or made available to unauthorised parties. It can be anything from a hacker attack to a misdirected email.

Must all personal data breaches be reported to the supervisory authority?

No — only those likely to pose a risk to the rights and freedoms of those affected need to be reported, and then within 72 hours. All breaches should still be documented internally, including those that are not reported.

How quickly must a personal data breach be reported?

Under GDPR Article 33, notification to the supervisory authority must happen without undue delay and no later than 72 hours after discovery. If the risk to individuals is high, they must also be informed.

Related terms

← Full glossary