Not only hacking
The GDPR definition covers any loss of confidentiality, integrity or availability of personal data. An email sent to the wrong recipient, a lost unencrypted laptop, a cloud folder shared publicly or a ransomware attack that makes customer records unavailable can all be breaches.
Notification under the GDPR
Article 33 of the GDPR requires the data controller to notify the supervisory authority within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people. In Spain this is the AEPD. If the risk to individuals is high, Article 34 also requires informing the people affected. Every breach, notified or not, must be documented.
Data breach vs security incident
Every data breach is a security incident, but not every incident is a data breach. An attack blocked before any data is touched is an incident without a breach. Under NIS2 and DORA, significant incidents must also be reported to cybersecurity or financial authorities, sometimes in parallel with the GDPR notification. See our guide to incident reporting deadlines.
Being ready
Meeting a 72 hour deadline requires knowing in advance what personal data you hold, where it is, who decides on notification and how to assess the risk. That preparation belongs in the incident response plan.




