Data Breach: Your Obligations

About this module

A data breach is a legal event as well as a security problem. This lesson defines breaches broadly: personal data accessed, disclosed, changed, lost, or destroyed accidentally or unlawfully. That includes wrong-recipient emails, lost laptops, and ransomware. Learners see when the 72-hour GDPR notification clock starts, when regulators or affected individuals must be told, and why even low-risk breaches still belong in the breach register. Employee action is deliberately simple: stop further access, do not delete evidence, document what happened, and report it right away.

Key takeaways

  • A breach includes accidental or unlawful access, disclosure, alteration, loss, or destruction of personal data
  • The GDPR 72-hour clock starts when the organization has reasonable certainty of a reportable breach
  • Containment, risk assessment, and notification decisions need to happen in order
  • Even low-risk breaches should be recorded in the breach register

Full Transcript

A data breach is not just a technology problem. It is a legal event — and when one happens, your organisation has clear obligations under G.D.P.R. and similar frameworks.

A data breach is any incident where personal data is accidentally or unlawfully accessed, disclosed, altered, lost, or destroyed. That includes a mislaid laptop, an email sent to the wrong person, or a ransomware attack.

The cause does not matter — the exposure does. Seventy-two hours.

That is how long G.D.P.R. gives you to notify the relevant supervisory authority once you become aware of a reportable breach. The clock starts the moment your organisation has reasonable certainty a breach has occurred.

You must report to the authority when the breach is likely to result in a high risk to the rights and freedoms of individuals. Think identity theft, financial loss, or significant reputational harm to those affected.

Not every breach requires regulator notification. If the data was properly encrypted, or the risk to individuals is genuinely low, you may document and close internally.

But you must still record it in your breach register. When a breach is discovered, your response must be swift and structured.

Three steps: contain the breach to stop further loss, assess the scope and risk level, then notify the right people at the right time. Containment means stopping the bleeding.

Isolate affected systems, revoke compromised credentials, and prevent further data from being accessed or exfiltrated. Document every action you take from this moment forward.

Assess the full scope of the incident. What personal data was involved?

How many individuals? Is the data sensitive — health records, financial details, or passwords?

The answers determine whether you must notify the regulator and affected people. If the breach meets the threshold, notify your supervisory authority within 72 hours.

If individuals face high risk, notify them too — without undue delay. Be clear about what happened, what data was involved, and what steps you are taking.

When a breach poses a high risk to individuals, you must contact them directly. The communication must be clear and practical — explain what happened, what personal data was affected, what the consequences might be, and exactly what the individual should do now to protect themselves.

Do not be tempted to stay quiet. Deliberately concealing a reportable breach, or delaying notification beyond what is reasonable, is itself a breach of the law.

Regulators treat cover-ups far more seriously than the original incident. Individuals can face personal criminal liability.

As an employee, your job on discovering a breach is straightforward. Stop any further access.

Do not try to fix it yourself or delete anything — you may be destroying evidence. Report it immediately to your manager or data protection officer.

Record everything you saw, and when. Speed and accuracy are critical.

Even breaches that do not require regulator notification must be documented. G.D.P.R. mandates that you maintain a register of all personal data breaches. Regulators can request this register at any time.

An incomplete or missing register is itself a violation. Industry research consistently shows it takes organisations an average of two hundred and seven days to identify a data breach.

The longer a breach goes undetected, the greater the harm — and the harder it is to meet the 72-hour notification window. Before any notification goes out, run through this checklist.

Your breach register must be updated. The risk assessment must be complete.

Notify the supervisory authority within 72 hours. Contact affected individuals if the risk threshold is met.

Coordinate with I.T. and legal before any external communication is sent. A data breach is a serious legal event.

Contain it fast, assess the risk carefully, and notify the right people within the required timeframe. Your actions in the first hours determine the outcome.