Organisations under-report because they picture a breach as an attack. The definition is wider than that, and the most commonly missed category is the one that arrives as a complaint rather than an alert.
The definition is broader than “security incident”
A personal dataPersonal dataAny information relating to an identified or identifiable person: names, IDs, location, online identifiers, and combinations that single someone out. breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Three consequences:
- Disclosure counts. Sending personal data to an organisation that had no basis to receive it is capable of being a breach. Nothing has to be attacked.
- Internal counts. Access by a colleague who had no business looking is unauthorised access.
- Loss of availability counts. Deleting the only copy is a breach even if nobody ever sees the data.
The word “security” does the least work in that sentence. It is the unauthorised part that matters.
Assess, do not dismiss
When a complaint alleges that data went somewhere it should not have, run the assessment properly:
- Establish what happened — what data, whose, to whom, when, and on what basis, if any.
- Assess the risk to the individuals, not to the organisation. Their rights, their exposure, their circumstances.
- Decide whether it is unlikely to result in a risk. If it is not unlikely, notify the supervisory authority within 72 hours of awareness.
- Assess separately whether it is likely to result in a high risk, which is the different and higher threshold for telling the individuals.
- Record it either way — the facts, the effects, the remedial action, and the reasoning for the decision.
The mechanics are in the breach notification procedure.
Why “not notifiable” is a perfectly good answer
Most incidents are not notifiable, and a regulator does not want to be told about every misdirected email. What it wants to see is that you can tell the difference and can show your working.
The asymmetry is worth internalising:
| Position | How it reads later |
|---|---|
| Assessed, documented, not notified | A controllerControllerDecides why and how personal data is processed. Carries most of the duties — and the fines. exercising judgement it is entitled to exercise |
| Assessed, documented, notified | A controller taking its obligations seriously |
| Not assessed, not notified | A controller that did not notice — and cannot show otherwise |
The third row is the risk, and it is the default outcome when a disclosure allegation is handled as a customer complaint and never reaches anyone who thinks in breach terms.
When the complainant raises it
Correspondence sometimes suggests you “may wish to consider whether this meets the threshold for self-reporting”. Read it as what it is: a prompt from someone who knows the obligation exists, and who will mention to the regulator that they raised it.
Do not treat it as adversarial and do not answer it rhetorically. Run the assessment, record the outcome, and say in your reply that you have considered it and what you concluded. That sentence closes off an entire line of escalation.
Awareness, and the clock
The 72 hours run from awareness — a reasonable degree of certainty that a breach has occurred — not from the incident, and not from when someone senior was told. A complaint alleging an unauthorised disclosure can be the moment of awareness. If you conclude it was, say so and record the time; if you conclude a short investigation was needed first, record that reasoning too.
The one position with no defence is discovering months later that the information sat in a service queue while nobody applied the definition.
The accountability point underneath
You must be able to demonstrate compliance, not merely achieve it. For breaches that means the register is not administrative overhead — it is the evidence. An organisation with a sparse register and a large support function has not shown it has few incidents; it has shown it does not detect them.