Data breach

Data protection glossary · 1 minute read

A data breach is a breach of the security of personal data, for example through loss, unauthorised access or accidental disclosure.

Notifying and responding

Notifiable data breaches must be reported to the supervisory authority within 72 hours. A well-practised internal reporting chain is essential if the deadline is to be met at all.

Typical cases

  • email containing personal data sent to the wrong recipient
  • loss of an unencrypted laptop or USB stick
  • ransomware attack with encryption or exfiltration of data
  • databases openly accessible on the internet

A distinction is made between breaches of confidentiality, integrity and availability.

Documentation

Every data breach must be documented internally, even if it is not notifiable. The documentation covers the facts, the effects and the remedial action taken.

Art. 4(12) GDPR
Definition of a personal data breach.
Art. 33 GDPR
Notification to the supervisory authority and documentation obligation.
Art. 34 GDPR
Communication to data subjects where there is a high risk.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.