GUIDANCE: personal data breach reporting

  This a page sub article Click here to view the full page article
A breach is defined in section 111(1) of the Law as:

“personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”

There will be a breach whenever any personal data (including any special category data) is accidentally lost, corrupted or disclosed, or if someone accesses it or passes it on without proper authorisation to do so. A breach may be broadly defined as an incident that affected the availability, integrity or confidentiality of the personal data. This therefore includes a network intrusion by an unauthorised third party and also a deliberate or accidental act by a service provider that disrupts the availability of personal data to those that need to use it. For example, the unintended deletion of personal data where no appropriate back-up exists would constitute a breach.