Skip to content

What Is a Personal Data Breach? EU GDPR Explained Clearly

What is a personal data breach under EU GDPR? Recognise confidentiality, integrity and availability failures, then take the right first-hour steps.

A present-day warehouse worker pauses with packing tape above two open parcels as a blank document bridges the wrong box and a supervisor approaches with an olive incident folder.
By AI Priority Map Editorial

The accounts team notices that a spreadsheet went to an old supplier contact. Nothing was hacked, the file is not online, and the recipient says it has been deleted. The event can still be a personal data breach because the legal definition is about what happened to personal data, not who caused it or how dramatic it looked 1,2.

Quick Answer. Under EU GDPR, a personal data breach is a security failure leading accidentally or unlawfully to the destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It covers confidentiality, integrity and availability. A hacker is not required, and not every breach requires notification to the supervisory authority 1,2.

The definition covers three kinds of failure

A personal data breach is a breach of security affecting personal data. Article 4(12) of EU GDPR (Regulation (EU) 2016/679) includes accidental or unlawful destruction, loss or alteration, as well as unauthorised disclosure or access 1. EDPB guidance groups the effects into three properties that ordinary incident language often separates 2.

The classification should be recorded.

PropertyWhat failedOrdinary example
ConfidentialitySomeone received or viewed personal data without authority.A payslip attachment goes to the wrong employee.
IntegrityPersonal data was changed incorrectly or without authority.A faulty import overwrites customers' bank details.
AvailabilityPersonal data became inaccessible or was destroyed when it was needed.Ransomware locks care records, or a backup cannot restore deleted files.

A single service failure may cross every column. An attacker can copy records, corrupt the live database and prevent restoration, leaving the organisation to investigate one event whose confidentiality, integrity and availability consequences differ for each affected person.

This wider definition matters because “data leak” describes only one branch. A database can remain private while corrupted values cause decisions about the wrong person. A lost service can harm someone who needs an appointment or payment record restored. The organisation should ask what happened to the information, not whether the event resembles a news headline.

The cause can be ordinary

Many breaches begin with routine work. An address is copied into the wrong email field. A paper file stays on a train. A staff account retains access after a role change. A shared folder is opened to more people than intended. A laptop is stolen from a car. Each event may meet the definition if personal data is exposed, changed, lost or unavailable 2,3.

The same event can affect more than one property. Ransomware may encrypt a database, make it unavailable and copy it to an attacker. An administrator may restore a backup but overwrite a week of accurate records. The incident record should not force the facts into one category when several effects occurred.

Intent is irrelevant to the definition. A deliberate insider disclosure and an accidental misaddressed email can both be breaches. Intent, scale, sensitivity and safeguards matter greatly to the later risk assessment, but an innocent mistake does not fall outside EU GDPR merely because nobody meant harm 1,2.

Processors have a related but different first duty. Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. The controller then owns the regulatory risk assessment and any notification to the competent supervisory authority 1.

Four breaches and two near-misses

Examples are useful only when the deciding fact is visible. The same lost device may be high risk without effective access protection and low risk when strongly encrypted. The same email error may be contained quickly or may expose information to a hostile recipient 3.

EventBreach?Why
A payroll spreadsheet reaches the wrong external address.Yes.Personal data was disclosed without authority, even if recall is attempted.
Ransomware prevents access to customer records for two days.Yes.Availability was lost, and confidentiality may also be affected.
A migration changes dates of birth in active records.Yes.Personal data lost integrity and may drive wrong decisions.
An unencrypted work phone containing customer messages is lost.Yes.Loss and possible unauthorised access require assessment.
A phishing email reaches staff but nobody opens it or enters information.Not yet a personal data breach.It is a cyber-security incident, but no personal data is shown to have been affected.
A laptop is misplaced in a locked office and recovered unopened minutes later.Possibly not.Investigate access evidence and controls; physical misplacement alone does not prove a personal-data outcome.

“Near-miss” does not mean “ignore”. It means the investigation did not establish destruction, loss, alteration, disclosure, unauthorised access or loss of availability. Recording that conclusion helps the organisation distinguish a genuine non-breach from a breach that was simply inconvenient to recognise.

A breach is not the same as a cyber incident

A cyber incident concerns systems or networks, while a personal data breach concerns personal data. The categories overlap but neither contains the other. Malware stopped before touching personal data may be a cyber incident without being a personal data breach. A paper envelope handed to the wrong customer can be a personal data breach without any cyber event.

A personal data breach is also not automatically reportable. First identify the security failure and affected personal data, then assess the likelihood and severity of consequences for people's rights and freedoms. The EDPB treats a controller as aware when it has a reasonable degree of certainty that a security incident has compromised personal data. Initial suspicion calls for prompt investigation; it is not permission to delay establishing whether that certainty exists 2. Article 33 requires notification to the competent supervisory authority unless the breach is unlikely to result in a risk. Where notification is required, it must be made without undue delay and, where feasible, within 72 hours after awareness. A notification made later must give reasons for the delay, and missing details may follow in phases without further undue delay 1.

Communicating with affected people has a separate threshold. Article 34 applies where the breach is likely to result in a high risk to their rights and freedoms, subject to the Article's conditions and exceptions 1,2. Keeping these decisions separate prevents both over-notification and the dismissal of a serious human error as merely “not cyber”.

The first hour is for facts and containment

The first task is to stop continuing harm without erasing evidence. Access to an exposed link can be removed, a compromised account disabled, a mistaken recipient asked to secure the material, or an affected device isolated. The times, screenshots and system records needed to reconstruct the event should be preserved because a planned response supports both containment and a defensible risk assessment 2,3.

The working record should capture when the controller became aware that personal data was probably compromised, identify one person to coordinate the response, and establish which data, how many people, which protections and which likely consequences are involved. Its first version can contain unknowns, provided it clearly distinguishes them from established facts instead of waiting for a perfect technical report.

A practical way to organise that record is to mirror the useful field groups in the EDPB's common notification template. These are preparation headings, not a claim that every listed field is mandatory in the competent authority's current route:

FieldFirst-hour entry
Route and statusCompetent authority's current route; new or follow-up, complete or incomplete, or withdrawal
Controller and contactsController details, reporting contact and a monitored response route
ChronologyEvent, discovery, awareness, containment and next update times
BreachNature, cause, affected systems and whether exposure continues
People and recordsCategories and approximate numbers, including relevant vulnerability
Risk and safeguardsProtections, likely consequences, current risk and uncertainties
Response and evidenceMitigation, prevention, communication to people, cross-border processing and attachments

The EDPB adopted template version 1.0 on 8 June 2026 for public consultation. The consultation ran from 10 June to 5 August 2026 and is now closed, but practical implementation across DPAs is still to be decided. The template is therefore not a universal live filing route: use it to prepare the record, then submit through the competent supervisory authority's current route 4.

The Article 33 clock does not require every fact to be settled before notification. EU GDPR permits information to be provided in phases where necessary, so long as further information follows without undue delay 1. A short early record therefore supports action; it is not a reason to wait until the investigation is complete.

The next question is risk, not vocabulary

Once the event meets the definition, the controller decides what follows. The competent supervisory authority receives a notification unless the breach is unlikely to result in a risk to people's rights and freedoms. Affected people face the separate high-risk threshold 1,2. Those tests belong in the decision article; this definition page supplies the stable first step.

Every personal data breach still needs documentation. Article 33(5) requires the controller to record the facts, effects and remedial action in a way that enables the supervisory authority to verify compliance 1. The record should also preserve the reasoning behind notification, delayed notification, phased information, or a decision that reporting was not required.

A small event with a strong record is more defensible than a large event reconstructed weeks later from inbox messages. The immediate discipline is consistent: identify the personal-data outcome, contain continuing harm, establish awareness time, assess risk and make each notification decision against the correct threshold.

Last updated: 26 August 2026.

Frequently Asked Questions

What is a personal data breach under EU GDPR?
A personal data breach is a security failure leading accidentally or unlawfully to the destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It includes failures of confidentiality, integrity and availability. A breach can be caused by a person, process or technology; it does not require a hacker, public leak or deliberate wrongdoing [1][2].
Is sending an email to the wrong person a data breach?
Usually yes, if the email or attachment contains personal data and an unintended recipient receives it. That is an unauthorised disclosure even if the recipient is trusted and deletes the message. The organisation should contain the incident, establish what was exposed, assess risks to people and document the notification decision [1][2][3].
Is a lost laptop always a personal data breach?
A lost laptop is a security incident, but whether personal data has been breached depends on the facts. Strong encryption, effective access controls and reliable remote wiping may make access to the data unlikely. The loss still needs investigation and documentation; encryption affects the risk assessment, not the need to establish what happened [2][3].
Does unavailable data count as a breach?
Yes. A personal data breach includes loss of availability, not only unauthorised disclosure. Ransomware, failed restoration or accidental deletion can therefore be a breach when personal data cannot be accessed as needed. The impact, duration, recoverability and possible consequences for individuals belong in the risk assessment [1][2].
Are all personal data breaches reportable to an authority?
No. A controller notifies the competent supervisory authority unless the breach is unlikely to result in a risk to people's rights and freedoms. A separate, higher threshold applies to communicating with affected people. Every breach still needs a record describing the facts, effects and remedial action, including the reasoning where notification is not made [1][2].
What should we do in the first hour after a breach?
Contain the incident without destroying evidence, preserve the time of awareness, identify affected systems, data and people, and give one named person control of the assessment. Start a written incident record immediately. Do not wait for perfect technical certainty before collecting the facts needed to assess risk and manage the 72-hour notification period [1][2][3].

Sources

  1. 1.Regulation (EU) 2016/679 (General Data Protection Regulation)Official Journal of the European Union · 2016
  2. 2.Guidelines 9/2022 on personal data breach notification under GDPREuropean Data Protection Board · 2023
  3. 3.Guidelines 01/2021 on Examples regarding Personal Data Breach NotificationEuropean Data Protection Board · 2022
  4. 4.Template for personal data breach notificationEuropean Data Protection Board · 2026

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.