What is a Data Breach under GDPR?

Safeguarding personal data is paramount for GDPR compliance. Under the General Data Protection Regulation (GDPR), organisations that fail to do so face hefty fines and reputational damage. But, what exactly constitutes a data breach under the GDPR? Let’s delve into the specifics and explore what it means for you.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

 

 

Defining a Data Breach

A data breach under the GDPR can be defined as “the accidental or deliberate destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.”

What Does This Mean?

At its core a data breach is any event that compromises the security of personal data, because something has happened that should not.

  • Accidental or deliberate: The GDPR differentiates between unintentional mistakes and deliberate misuse. Both types of incidents are data breaches and can trigger reporting obligations. Accidental mistakes must also be taken seriously when it comes to data protection.

  • Destruction, loss, alteration, unauthorised disclosure, or access: These terms make clear a data breach doesn’t occur only when someone acts maliciously, or only when data are lost or stolen. Inappropriate access to data or data changes even within your organisation are data breaches.

  • Personal data: This refers to any information relating to an identified or identifiable individual, such as name, address, email address, health records, and financial data. You can explore the definition of data and data processing here.

  • Transmitted, stored or otherwise processed: The breach could occur at any stage of the data lifecycle, from the moment it’s collected to when it’s transmitted, stored, or destroyed.

Examples of a Data Breach

Examples of a data breach include:

  • A hacker breaches your database and steals customer credit card information.

  • An employee accidentally sends sensitive customer data to the wrong email address.

  • A lost or stolen laptop contains unencrypted patient records.

  • A disgruntled employee maliciously alters employee salary records.

  • An unpatched security vulnerability allows unauthorised access to customer accounts.

The Information Commissioner (ICO), who administers the Data Protection Act in the UK, has taken action several times for data breaches including these recent (at the time of writing) examples. You can click on the bold text to read the full ICO report:

  • The ICO issued a reprimand to NHS Fife, after an unauthorised individual was able to enter a ward and access the personal information of 14 patients

  • The Police Service of Northern Ireland (PSNI) failed to have appropriate measures in place to prevent unlawful sharing of personal data

  • The family intervention officer at St Helens Borough Council who was prosecuted for viewing records on the council’s case management system without having a business need to do so.

As these cases show a GDPR breach can result in both organisations and individuals can be prosecuted and fined. You should also bear in mind that this can happen even if you are the victim of deliberate malicious action.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Data Breach: Your GDPR Obligations

If you experience a breach under the GDPR, you have specific obligations. You can find out more about how to handle a data breach here.

However, for the most serious data breaches you must:

  • Report the breach to the relevant supervisory authority within 72 hours.

  • Inform affected individuals as soon as possible.

  • Take appropriate measures to mitigate the risks arising from the breach.

  • Document the breach and your response actions.

Mitigating the Risks

Preventing data breaches in the first place is crucial. Implement robust security measures like encryption, access controls, and regular security assessments. Employee training on data protection best practices and incident response procedures is also essential.

You can learn more about how to prevent a breach here.

However, the data privacy principles will help you minimise the risk of a data breach, not least because one of them rests on data security. The others ensure that you will:

  • only have the minimum necessary data

  • keep personal data for no longer than necessary

  • understand and maintain an overview of your data processing activity

    Learn About the GDPR

    Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

    Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

    Five star training testimonial

 

Conclusion

Data breaches can be costly and damaging. Understanding the GDPR’s definition and your obligations as an organization is crucial for navigating this complex landscape. By prioritizing data security and adhering to legal requirements, you can minimize the risks of breaches and safeguard the personal information entrusted to you.