People often labour under the impression that a data breach is some form of external malicious action or an IT or technical failure exposing people’s data. In fact a data breach under the GDPR is much broader than that. Article 4(12) of the GDPR defines it as:
a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
Most people do not know how broad this is. Sending an email containing personal data to the wrong recipient is a data breach – although a relatively minor one.

A much more serious one, as reported recently, is the inappropriate access of a person’s medical records.
People may think what they are doing is allowed. Perhaps because they happen to also work in the NHS, or that it is harmless. Far from it. People value their privacy and this kind of behaviour:
- Causes real distress to the individuals affected
- Reduces trust generally in public services and their ability to manage sensitive data
I have come across this scenario before. The financial, operational and reputational impact takes a lot of time and effort to address.
How To Prevent An Inappropriate Access Data Breach
To prevent this kind of breach occurring organisations must:
- Have clear policies setting out both what a data breach is
- Tell people who to talk to for help if they are unsure. This could be their line manager, data protection officer, Caldicott guardian etc.
- Tell people what to do if they think a data breach as occurred
- Set out the consequences for breaching the policy (I’m genuinely surprised how often organisations neglect this part)
They must also provide role specific training that sets out:
- what a data breach is in terms that relate to what people do within an organisation e.g. accessing patient records they have no reason to
- what the real world consequences of a data breach can be in terms of damage and distress
- emphasising the fair and transparent part of the first data privacy principle: only do what you said you would and behave as people would expect
This is why generic one-size-fits-all mandatory training a lot of organisations go for simply doesn’t cut it.
If a data breach still occurs after this organisations must ensure they take the appropriate action, which sadly really ought to include disciplinary action of at least a written warning. That might appear harsh, but organisations react much more robustly for even the most minor financial transgressions and the same value must be put on data. Also, a failure to act robustly (or have the right training and policies in place) make it much more likely the ICO will take action against you.
Interested in GDPR Training?
Our GDPR training courses will help you and your team develop the practical applicable skills needed to ensure GDPR compliance, retain stakeholder confident and avoid data breaches.
Find out more about training here.

- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: