1. What counts as a breach
What the law means by a personal data breach
Under UK GDPR, a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That definition is worth reading twice, because it is much broader than most people assume.
Notice what it does not say. It does not say "hacking". It does not say "cyber attack". It does not require a criminal, a ransom note, or anyone acting in bad faith. An honest mistake by a well-meaning colleague can be a personal data breach just as much as a deliberate intrusion by an outsider.
Notice also the word "accidental". Sending a spreadsheet of client details to the wrong recipient is accidental, and it is still a breach. Deleting the only copy of someone's records by mistake is accidental, and it is still a breach.
The two ingredients
Every personal data breach has two ingredients:
- A security incident: something went wrong with how data was protected, handled, or controlled.
- Personal data was affected: the incident touched information about identifiable living individuals.
If a security incident affects only anonymised statistics, system configuration files, or commercial data with no personal element, it may still be a serious security matter, but it is not a personal data breach in the legal sense.
Why the broad definition matters to you
Because the definition is broad, the judgement about whether something "counts" should never rest with the person who caused or spotted the incident. Your job is to recognise that something might be a breach and report it. Deciding whether it legally is one, how serious it is, and whether regulators need to know is a job for the people in your organisation who own breach response.
If you take one thing from this section, take this: when in doubt, treat it as a potential breach and report it. Nobody was ever criticised for reporting something that turned out to be harmless. Plenty of organisations have been criticised for the opposite.
› Course contents
What counts as a breach
First response
Assessing and notifying
Learning and prevention