GlossaryCompliance operations

Data breach

Short answer

A data breach is a security incident in which data is accidentally or unlawfully destroyed, lost, altered, disclosed or accessed without authorisation. When personal data is involved, the GDPR requires companies to assess the risk and, in most cases, notify the authority within 72 hours.

Not only hacking

The GDPR definition covers any loss of confidentiality, integrity or availability of personal data. An email sent to the wrong recipient, a lost unencrypted laptop, a cloud folder shared publicly or a ransomware attack that makes customer records unavailable can all be breaches.

Notification under the GDPR

Article 33 of the GDPR requires the data controller to notify the supervisory authority within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people. In Spain this is the AEPD. If the risk to individuals is high, Article 34 also requires informing the people affected. Every breach, notified or not, must be documented.

Data breach vs security incident

Every data breach is a security incident, but not every incident is a data breach. An attack blocked before any data is touched is an incident without a breach. Under NIS2 and DORA, significant incidents must also be reported to cybersecurity or financial authorities, sometimes in parallel with the GDPR notification. See our guide to incident reporting deadlines.

Being ready

Meeting a 72 hour deadline requires knowing in advance what personal data you hold, where it is, who decides on notification and how to assess the risk. That preparation belongs in the incident response plan.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub