Personal Data Breach

Last updated:
22.11.2022
Every company collects data that is subject to GDPR regulations. We explain when a personal data breach occurs and the obligations that arise from such an incident. Furthermore, we show you how to minimize potential legal consequences.
Personal Data Breach
Key Takeaways
  • Protection of personal data in companies in accordance with the GDPR.
  • Data protection breaches and associated obligations.
  • Classification of data breaches by risk level.
  • Notification and documentation requirements for data breaches.
  • Practical examples of low, medium, and high risks.

Whether it concerns customers or employees, every company collects personal data. Handling this data responsibly means complying with GDPR regulations and implementing them diligently within your organization. A breach of data protection can have unpleasant consequences. We explain what constitutes a personal data breach and the obligations that arise from such an event. Furthermore, we use various examples to illustrate the legal implications and how you can minimize them.

The protection of personal data - what does it mean?

According to Art. 4 (1) GDPR, personal data refers to any information relating to an identified or identifiable natural person. This includes, for example, names, email addresses, or exact residential addresses. Health data or bank account details are also considered sensitive information. To prevent unauthorized parties from accessing and misusing this data, the GDPR has been in effect since May 2018. As directly applicable law, it applies in all EU member states, including Germany, and the European Economic Area. It governs the collection, storage, and processing of personal data.

A regulation for the protection of personal data provides a framework within which data processing can be carried out in a company. The General Data Protection Regulation is based on various fundamental principles, some of which are reflected in Art. 5 GDPR. According to these, technical and organizational measures must always be taken to ensure, among other things, the confidentiality and integrity of personal data. A personal data breach always involves a failure to comply with one of these principles.

Consequences of a personal data breach

If a personal data breach occurs, the exact consequences depend on the severity of the event. The primary factor is the risk, which is determined by the likelihood and the potential severity of the impact on the rights and freedoms of the affected individuals. Data protection breaches are classified as having no, low, medium, or high risk to the individuals concerned. Depending on the severity, the company must fulfill internal documentation requirements, reporting obligations, or notification duties toward the affected individuals.

Art. 33 GDPR sets out the obligations for reporting personal data breaches to the supervisory authority. Art. 33 (1) GDPR states that the breach must be reported to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, provided that the breach poses a risk to data protection. Furthermore, Art. 33 (3) GDPR defines the details of the reporting procedure. As is the case for any data protection-related incident, Art. 33 (5) GDPR requires internal documentation of the respective event. 

What do such breaches look like, and how can you respond to them in practice?

To ensure you don't have to experience a data protection breach in your company firsthand, we have compiled some practical examples for you. The following scenarios differ primarily in terms of the risk and the severity of the data breach:

Example 1 - low risk: Your company laptop, which contains sensitive personal data, has been stolen. The data was stored in an encrypted format and is available as an external backup. It is highly unlikely that an outsider can access the personal data despite having access to the laptop. In this case, the probability of misuse is extremely low, and the risk is therefore considered low. You only need to document such a case internally. Furthermore, take appropriate countermeasures to ensure that such an event does not happen again in the future.

Example 2 - medium risk: Your company works with various marketing service providers. They receive access via a link to a cloud database containing a list of personal data, such as the names and email addresses of your newsletter subscribers. Due to an error in the sharing settings, anyone with the link can now access this data. You do not know to what extent the links were shared by your own employees or those of the service provider, or with whom. You also do not know if unauthorized copies were made. In this case, it must be assumed that the protection of names and email addresses has been compromised. Upon becoming aware of this security gap, the supervisory authority must be informed within 72 hours, and the incident must be documented internally. The risk to the affected individuals is considered medium, which is why they do not need to be informed.

Example 3 - high risk: Your employee database has been hacked, and all information is now freely accessible to the attackers. Not only were data such as names and addresses exposed, but also personal bank account details. These are sensitive data, which pose a particular risk to the individuals concerned if they fall into unauthorized hands. In such an event, you must also fulfill your internal documentation obligations. In addition, you must comply with the reporting obligation without delay, at the latest within 72 hours, and notify the affected individuals of the data breach in accordance with Art. 34 (1) GDPR. 

The risk from Example 3 can be significantly minimized with effective precautions. This includes, for example, storing data in an encrypted format. If the data cannot be deciphered even in the event of a hacker attack, the risk is no longer classified as high, but as low or virtually non-existent. You are spared the need to report to supervisory authorities and your employees, thereby avoiding a great deal of turmoil and potential loss of trust.

Do you see an incident in your company that involves a data protection breach? Do not hesitate to fulfill your internal documentation obligation. Additionally, conduct an immediate risk assessment. Based on your findings, decide whether you need to report the event to the relevant data protection authority and inform the affected individuals. To be on the safe side legally, regardless of the risk level you determine, the assessment should be completed within 72 hours.

Data protection in your company is not just about concrete compliance rules. Appropriate technical and organizational security measures also prevent security gaps and potential personal data breaches in your firm. Take action now and use our personal consultation and expertise to effectively protect personal data.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in