A personal data breach happens when personal information is lost, stolen, exposed or accessed by someone who should not have it. That is simple enough right? Well the hard part is that a breach does not always look like a hacker breaking into a system.

What Counts as Personal Data?

Personal data is information that identifies a person or can help identify them. Your name alone might not always be enough. Add information that clearly points to you though. The situation changes.

It Can Be More Than a Password

Think about the information businesses collect every day. Your contact details can count. So can information about your account or details connected to your identity. Even something not obvious can be data if it can be linked back to you.

When Does It Become a Breach?

A breach usually happens when personal data is handled in a way that was not allowed or expected. That includes exposure, not just deliberate stealing.

• A spreadsheet sent to the wrong customer especially if it contains someone elses account details is a breach that needs to be reported.

• A stolen work laptop becomes a problem if the files on it contain personal information and are not properly protected.

• Someone looking at customer records without permission counts even if they never download anything. The act of accessing is the problem.

What About Lost or Deleted Data?

Losing data can also be a breach. Imagine a paper file left in a taxi.. A database that gets deleted and can’t be recovered. The situation depends on what happened and what information was involved.

Don’t think that only permanent loss matters. Temporary exposure can be enough. If personal information was seen by the person for a short time the incident still needs to be taken seriously.

Why the Details Matter

Not every security mistake has the effect. A company needs to look at what data was involved who could see it and what actually happened. The risk, to the people affected is important too.

That evaluation is where things get complicated. A misplaced document containing contact information isn’t the same situation as exposed financial or very sensitive information. Treating every incident the way is not a good idea.