Definition

    What Is a Data Breach?

    A data breach is a security incident in which personal data is accessed, disclosed, altered, lost, or destroyed without authorization, whether through cyberattack, human error, or system failure.

    A data breach occurs when personal data is exposed to unauthorized access, disclosure, alteration, loss, or destruction. Data breaches can result from a wide range of causes, including cyberattacks (such as hacking, phishing, ransomware, and malware), insider threats (disgruntled or careless employees), system vulnerabilities (unpatched software, misconfigured databases), physical theft of devices, and accidental exposure (such as sending personal data to the wrong email recipient or leaving a database publicly accessible). The consequences of a data breach can be severe for both the individuals whose data is compromised and the organizations responsible for protecting it.

    Under the GDPR, a personal data breach is specifically defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. The GDPR classifies breaches into three types: confidentiality breaches (unauthorized disclosure or access), integrity breaches (unauthorized alteration), and availability breaches (accidental or unauthorized loss of access or destruction). Importantly, a breach does not have to involve a malicious actor -- accidentally deleting a database without a backup, or a ransomware attack that encrypts data making it inaccessible, both qualify as personal data breaches.

    Data breach notification obligations are a cornerstone of modern privacy regulation. Under the GDPR, controllers must notify their supervisory authority within 72 hours of becoming aware of a qualifying breach unless it is unlikely to result in a risk to individuals' rights and freedoms. If the breach is likely to result in a high risk, affected individuals must also be notified without undue delay. US requirements vary by state and sector. California's adjusted 2025–2026 CCPA private-action range is $107 to $799 per consumer per incident for specified security breaches, subject to the statute's conditions and defenses.

    IBM's 2025 Cost of a Data Breach Report reports a $4.4 million global average cost, down 9% from the prior year. That is an average from IBM and Ponemon Institute research, not a forecast for every incident. Actual costs depend on the data, scale, response, business interruption, notification duties, claims, and enforcement. Risk reduction can include verified access controls, encryption where appropriate, patching, tested incident response, workforce training, backups, and vendor oversight; organizations should describe only safeguards they actually maintain.

    Key Points About Data Breachs

    • 1Includes unauthorized access, disclosure, alteration, loss, or destruction of personal data.
    • 2Can result from cyberattacks, human error, system failures, or physical theft.
    • 3GDPR requires notification to supervisory authorities within 72 hours of becoming aware of a qualifying breach.
    • 4Affected individuals must be notified if the breach poses a high risk to their rights and freedoms.
    • 5California's adjusted 2025–2026 CCPA private-action range is $107-$799 per consumer per incident for specified security breaches.
    • 6IBM's 2025 research reports a $4.4 million global average cost of a data breach.
    • 7Risk reduction should be based on the organization's actual threats, data, systems, and verified controls.

    Example

    A healthcare company discovers that an employee's email account was compromised through a phishing attack, exposing the names, dates of birth, and medical records of 15,000 patients. The company activates its incident response plan: it contains the breach within 4 hours, notifies its GDPR supervisory authority within 72 hours, sends individual notification letters to all affected patients within a week, offers 24 months of free credit monitoring, and engages a forensic firm to determine the full scope and prevent recurrence.

    Need a Privacy Policy With Breach Notification Terms?

    Free to start. No legal expertise required.