Data Breach Register
A data breach register is an internal record in which an organization documents the data breaches it experiences, including details about what happened and how it responded. It serves as a log that helps organizations track incidents and demonstrate that they have met their obligations to record and, where required, report breaches. The specific contents and legal requirement to maintain such a register depend on the jurisdiction and the type of data involved.
A data breach register (also described as data breach documentation) is a maintained record in which an organization documents personal data breaches, where a personal data breach is generally understood as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Under the UK and EU data protection frameworks referenced in the evidence, controllers are generally required to document all such breaches by adding relevant information to this record, irrespective of whether the breach itself must be notified to a supervisory authority; the register supports the accountability principle by enabling authorities such as the ICO or EDPB-aligned supervisory bodies to verify compliance. The precise scope, required fields, and retention expectations are not fully specified in the evidence provided and differ across jurisdictions and sectors (for example, the U.S. HHS/OCR regime for protected health information and FTC breach-response guidance operate under distinct legal bases from the UK/EU personal data regime). Readers should verify current requirements against the applicable authoritative source, as these obligations are jurisdiction-specific and subject to amendment.
Why it matters
A data breach register is a cornerstone of the accountability principle in data protection compliance. Under the UK and EU frameworks, controllers are generally required to document personal data breaches regardless of whether a given breach must be notified to a supervisory authority. This distinction matters: the duty to record is broader than the duty to report. An organization may correctly conclude that a particular incident does not meet the threshold for notification, but it is still expected to log the incident, its effects, and the remedial action taken. The register is the evidence that this assessment happened and was reasoned.
The register also serves an evidentiary function during regulatory scrutiny. It enables authorities such as the UK's Information Commissioner's Office (ICO) or EDPB-aligned supervisory bodies to verify that an organization has met its recording and, where applicable, reporting obligations. Without a maintained record, an organization may find it difficult to demonstrate compliance even where its underlying handling of an incident was sound. In practice, the absence or inadequacy of breach documentation can itself become a point of regulatory concern, separate from the breach that triggered it.
It is important not to treat the register as a single universal obligation. The requirement to maintain such a record, and its precise contents, depend on the jurisdiction and the category of data involved. The U.S. regime for protected health information administered by HHS/OCR, and the FTC's breach-response guidance for businesses, operate under distinct legal bases from the UK/EU personal data regime. Organizations operating across territories should not assume that a register designed for one framework satisfies the obligations of another, and should verify current requirements against the applicable authoritative source.
Who it's relevant to
Inside Data Breach Register
Common questions
Answers to the questions practitioners most commonly ask about Data Breach Register.

