Personal Data Breach
A personal data breach is a security failure that leads to personal information being accidentally or unlawfully destroyed, lost, altered, disclosed to, or accessed by people who should not have it. It covers more than just data being stolen; losing data or accidentally changing or deleting it can also count. What organizations must do in response depends on where they operate and the nature of the information affected.
Under the EU GDPR, and correspondingly under the UK GDPR as interpreted by the ICO, a personal data breach is defined as 'a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.' The concept therefore encompasses three broad categories of impact: confidentiality breaches (unauthorised or accidental disclosure of, or access to, personal data), integrity breaches (unauthorised or accidental alteration of personal data), and availability breaches (accidental or unlawful loss of access to, or destruction of, personal data). It is important to note that this is a security incident specifically affecting personal data; not every security incident constitutes a personal data breach, and not every personal data breach triggers the same downstream obligations, which under the GDPR framework generally turn on the assessed risk to the rights and freedoms of affected individuals. This EU/UK statutory definition should be distinguished from the varied and non-uniform definitions of 'data breach' used across United States law, where terminology is often narrower and framed in terms of the unauthorized acquisition of personal information, and where obligations arise principally under sector-specific and state-level statutes rather than a single omnibus regime. Because notification thresholds, timelines, and the precise scope of covered data differ substantially by jurisdiction and sector, and because official guidance is periodically updated, readers should verify obligations against the current authoritative text applicable to their circumstances.
Why it matters
A personal data breach is one of the few compliance events that can trigger legally binding, time-sensitive obligations rather than discretionary action. Under the EU GDPR and, correspondingly, the UK GDPR as interpreted by the ICO, an incident that meets the statutory definition can create duties to assess risk, document the event, and in many cases notify a supervisory authority and affected individuals. Getting the classification wrong in either direction carries consequences: treating a reportable breach as a routine IT incident may expose an organization to enforcement, while over-reporting can consume resources and erode credibility with regulators.
The term matters precisely because it is broader than the everyday notion of data being "stolen." The GDPR definition captures accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access, which means an employee accidentally deleting records or emailing personal data to the wrong recipient can qualify just as a malicious external attack would. This breadth means organizations need internal processes capable of recognizing confidentiality, integrity, and availability incidents alike, not only headline-grabbing cyberattacks.
Equally important is that the concept does not carry a single, universal meaning. The EU/UK statutory definition differs from the varied approaches across United States law, where the term is often framed more narrowly around the unauthorized acquisition of personal information and where obligations arise under sector-specific and state-level statutes rather than one omnibus regime. Because notification thresholds, timelines, and covered-data definitions differ substantially by jurisdiction and sector, and because official guidance is periodically updated, the same underlying event can produce materially different obligations depending on where an organization operates.
Who it's relevant to
Inside Personal Data Breach
Common questions
Answers to the questions practitioners most commonly ask about Personal Data Breach.

