Skip to content
Amrani Academy

1. What counts as a breach

Confidentiality, integrity and availability breaches

The ICO groups personal data breaches into three types, borrowed from classic information security thinking. A single incident can involve one, two, or all three at once.

Confidentiality breaches

There is an unauthorised or accidental disclosure of, or access to, personal data. Someone saw data they should not have seen. Examples include an email sent to the wrong person, a file shared with the wrong permissions, an attacker reading customer records, or a colleague looking up a record they have no business reason to view.

Integrity breaches

There is an unauthorised or accidental alteration of personal data. The data still exists and may still be accessible, but it is no longer accurate or trustworthy. Examples include an attacker modifying records, a faulty import overwriting correct values, or someone editing a record they should not have touched.

Availability breaches

There is an accidental or unlawful destruction of, or loss of access to, personal data. People who need the data cannot get to it, temporarily or permanently. Examples include ransomware encrypting your files, a database being deleted without a usable backup, or the only copy of paper records being destroyed in a flood.

Why availability surprises people

Availability breaches are the type people most often fail to recognise. It feels wrong that "we lost access to our own data" could be a reportable breach, but think about the impact on individuals: if a hospital cannot access patient records, or a payroll provider cannot access salary data, real people can suffer real harm even though nobody outside the organisation ever saw a single record.

Ransomware is the clearest modern example. Even if you are confident the attacker only encrypted data and never copied it, the loss of access is itself a breach, and if the attacker did copy data, you have a confidentiality breach on top. This is why ransomware incidents almost always need proper breach assessment rather than being treated as a purely technical outage.

Course contents