Have We Had a Data Breach?
A helpful guide
💭 Ask yourself...
"Has the confidentiality, integrity or availability of personal information been affected?"
If the answer is yes...
You may have a personal data breach.
Short answer
Not every mistake involving information is a personal data breach.
Similarly, not every personal data breach needs to be reported.
The first step is simply understanding whether a breach has actually occurred.
What is a personal data breach?
A personal data breach occurs when personal information is:
- lost;
- destroyed;
- altered;
- disclosed to someone who shouldn't receive it;
- accessed without permission;
- unavailable when it should be available.
The key question isn't:
"Did somebody make a mistake?"
It's:
"Has personal information been affected?"
Common examples
✅ Email containing customer information sent to the wrong person.
✅ Laptop containing unencrypted personal information stolen.
✅ HR file accessed by an employee who shouldn't have seen it.
✅ Personal information accidentally published online.
Situations that may NOT be personal data breaches
These are exactly the questions people ask.
Someone sent an email to the wrong person, but it didn't contain any personal information.
Probably not.
If no personal information was involved, it isn't a personal data breach.
"It was only employee information."
It can still be a personal data breach.
Employee information is still personal information.
The fact that the individuals work for your organisation doesn't reduce your responsibilities.
We accidentally shared information, but we've recovered it immediately.
Possibly still a breach.
Recovering the information may reduce the risk, but it doesn't necessarily mean a breach never occurred.
The circumstances still need to be considered.
We stopped the information being sent before anyone saw it.
Maybe not.
If the information was never disclosed and confidentiality wasn't affected, it may not amount to a reportable personal data breach.
However, it's still worth recording what happened and considering whether improvements can be made.
Nobody outside the business knows.
That doesn't determine whether it's a breach.
Whether something is a personal data breach depends on what happened to the personal information—not whether anyone has complained or noticed.
Practical steps
- Stop the incident getting worse.
- Identify what personal information was involved.
- Understand what actually happened.
- Consider whether confidentiality, integrity or availability has been affected.
- Record your initial findings.
- Move on to considering whether the breach needs to be reported.
Common Misconceptions
❌ "It wasn't customer information, so it isn't a data breach."
Not correct.
Employee, supplier and contractor information can all be personal data.
❌ "Nobody knows it happened."
That doesn't determine whether it's a breach.
A personal data breach can still exist even if nobody has complained or discovered the incident.
❌ "We fixed it quickly, so it isn't a breach."
Not necessarily.
Acting quickly may reduce the risk, but you should still assess what happened and record your decision.
❌ "We sent an email to the wrong person."
It depends.
If the email didn't contain personal information, it probably isn't a personal data breach.
If it did, you should assess the risk.
❌ "Only customer information counts."
No.
Personal data is personal data, whether it relates to customers, employees, suppliers or anyone else.
🤝 Need a little support?
Not every incident is a reportable data breach, but every incident deserves a calm assessment.
If you're unsure whether a breach has occurred or would like someone to sense-check the situation, we're here to help.
Sometimes a short conversation is all it takes to decide on the right next steps.
Related Guides