A GDPR personal data breach happens when personal data is lost, changed, destroyed or accessed by someone who should not have it. Sometimes the breach is a cyberattack. Times it is much less dramatic. A laptop may be left on a train. An email may be sent to the person. A file may be shared with the account.

What Counts as Personal Data?

Personal data is information that can identify a person, either directly or by connecting it with information. A name is an example. An email address can also count.

Gdpr covers more than the details people usually think about. Customer records can contain information that looks harmless alone but becomes identifying when combined with details. That is where things get tricky.

The Data Doesn’t Have to Be Stolen

Imagine an employee sends a spreadsheet to the customer. No one hacked anything. No password was cracked. Still if that spreadsheet contains someone Personal data there has been a loss of control over that data.

Common Ways a Breach Happens

– A laptop or phone especially if it contains customer records and nobody knows where it went.

– An email sent to the person can be enough even when the sender notices the mistake almost immediately.

– Weak account security sometimes opens the door to someone who should never have seen the data in the first place.

– A paper file left somewhere it should not be. Boring perhaps. Still a real security problem.

What GDPR Expects After a Breach

Once an organisation knows about a data breach it must assess what happened and how serious the risk is to the people affected. If the breach is likely to create a risk to people’s rights and freedoms the organisation generally must notify the data protection authority without undue delay and where required, within 72 hours of becoming aware of it.

If the risk to individuals is high affected people may also need to be told. The clock matters here. Waiting for an explanation is not a sensible strategy.

Why the Details Matter

Not every incident is treated in the same way. Losing a brochure is not remotely the same, as exposing someone’s financial information. The nature of the data matters. So does what happened to it and the possible harm.

Honestly this is where GDPR becomes more practical than people expect. You do not need to panic over every click but you do need a process to spot what happened and judge the risk.