Total breaches down in second quarter of 2026

The Office of the Data Protection Authority (ODPA) has released personal data breach statistics for the second quarter of 2026, revealing a decrease in the number of reported data breaches in comparison with the previous quarter.

Breach statistics

Of the 49 breach reports that came into the ODPA from April to June, only four were classified as high-risk compared to seven in the previous period. Ten breach reports were determined not to have met the threshold of a reportable data breach. This proactivity in reporting potential breaches demonstrates how many organisations recognise the importance of complying with the law to not only meet their obligations but protect their organisations and clients.   

If you are unsure whether an incident constitutes a reportable breach, you can call the ODPA to discuss the matter and seek guidance in navigating the process. 

 

“It is encouraging to see high-risk breach incident reports decline for a second quarter” said Commissioner Homan. “When organisations report breaches they not only fulfil an important legal obligation but can benefit from our office’s expertise in mitigating any harmful effects of a security incident. This report also reminds us that breaches are not just about records, but include overheard conversations.” 

 

As has historically been the case, emails sent to incorrect recipients was again the most common type of breach reported, with loss of confidentiality the most prevalent potential harm.  

Organisations are legally required to notify the ODPA of any personal data breach within 72 hours of becoming aware of it (see section 42 (2) of the Law). You can report a breach to us here.

 

Why does the ODPA publish breach statistics?  

We publish statistics of the number of self-reported breaches we receive every quarter. 

Publishing this information allows everyone to benefit from a better understanding of how and why breaches happen and how they can be avoided in future. 

Case study

A healthcare provider reported a personal data breach after a medical professional answered a telephone call while conducting a medical examination and remained in the examination room throughout the conversation. 

Due to the volume of the conversation and close proximity to others, it was overheard by the patient being examined and others present in the room. During the call, personal information relating to another individual was disclosed, including identifying details and sensitive health information. 

The information was heard by people who had no legitimate reason to receive it and who were unconnected to the care of the patient on the phone. The incident arose from a failure to keep confidential the information discussed during a clinical conversation. 

The breach involved the unauthorised disclosure of special category data and created a risk of distress and loss of privacy for the affected individual. It also served as a reminder of the need for healthcare professionals to ensure that conversations involving patient information take place in a setting where confidentiality can be guaranteed.  

As a result of the incident, the healthcare provider reminded the doctor involved of their data protection obligations and arranged for the lessons learned to be addressed as an urgent topic at an academic session for all doctors.  

The Authority also advised that this training should become a recurring measure, provided to new staff and refreshed each year to maintain awareness and reduce the risk of a similar breach. 

What can be learned?  

Organisations should ensure that staff take appropriate steps to prevent confidential conversations from being overheard, particularly where sensitive personal information is involved.  

Maintaining confidentiality is a fundamental part of handling personal data across sectors, not just in healthcare where it carries extra weight due to the special category data involved. 

Further guidance: 

How organisations discovered breaches

 

Assessments of self reported breaches

 

Nature of relationship with people affected

 

Potential harms identified

 

What happened to personal data as a result of breach?