Skip to content
What You Have to Produce

Home / The breach

What Counts as a Breach

Wider than people assume. It is not only an attack, and most breaches in employment are somebody sending something to the wrong person.

The breach · Reference

72 hoursfrom becoming aware, to notify the regulator where requiredAwareness, not confirmation. The clock does not wait for certainty

INITIAL BREACH RECORD

Opened the moment somebody reports it

  • Became aware
    Date and time, and who first knewThe clock runs from here, not from escalation
  • What happened
    In plain terms, before anybody investigatesWritten while it is still uncertain
  • Data involved
    Categories and roughly how many peopleApproximate is fine at this stage
  • Special category
    Health, union membership, and the restChanges the risk assessment materially
  • Still happening
    Contained, or ongoingContainment comes before assessment
  • Reported by
    Name and routeIncluding whether they hesitated, which is a finding about the culture
  • Risk to people
    Initial view, to be refinedRisk to them, not embarrassment to you
  • Notifiable
    Decision, with the reasonRecorded either way, including a decision not to notify

A breach is any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. That definition is wider than the word suggests.

The breach workflow in “What Counts as a Breach” is easier to operate when systems, owners and evidence are known in advance. If daily schedule template with clear records supports daily schedule template, its records should sit inside the incident inventory with clear access, retention and escalation rules rather than being treated as an unexplained source of employee data.

What it covers that people do not expect

Sending something to the wrong person. The commonest breach in any employer, by a wide margin. An attachment with everybody's salaries, a reply-all with a grievance document, a reference sent to the wrong address.

For a separate benchmark relevant to “What Counts as a Breach”, consult the Proofpoint insider-threat reference. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.

Losing something. A laptop, a phone, a folder left on a train.

Deleting something you should not have. Loss includes destruction, and an accidental purge of records somebody needed is a breach.

Inability to access, where a ransomware event or a system failure means data cannot be reached.

Internal access without authorisation. Somebody reading a colleague's file out of curiosity is a breach, and the person affected would certainly call it one.

What it does not cover

A near miss where nothing was actually disclosed.

A deliberate, authorised disclosure, even if somebody disagrees with it.

Data that was never personal.

Why the definition matters more than it seems

Organisations under-report because they think breach means attack. An email to the wrong recipient does not feel like one, and it is the category that produces most of the actual harm in employment contexts.

Which means the internal reporting threshold should be set at "something happened with data that was not supposed to" rather than at anything narrower.

The clock

It starts when the organisation becomes aware, which means when any employee with responsibility becomes aware — not when it is confirmed, investigated or escalated.

Awareness of a possible breach starts it. Spending two days establishing whether it really was one consumes the window rather than preceding it.

Reporting culture

Most breaches are reported by the person who caused them, and only if they are not afraid to.

An organisation that disciplines for honest mistakes has bought one outcome and lost its early warning for everything afterwards. The reporting line should say explicitly: tell us immediately, you will not be in trouble for the mistake.

The threshold for reporting internally

Something happened with data that was not supposed to. Anything narrower produces under-reporting, because the person who sent an attachment to the wrong address does not think the word breach applies to them.

Why the culture is the control

Most breaches are reported by whoever caused them, and only where they are not afraid. An organisation that has disciplined somebody for an honest mistake has bought one outcome and lost its early warning permanently.

What it covers that people miss

Sending to the wrong person, losing a device, deleting something you should not have, inability to access, and internal access without authorisation. The first is the commonest breach in any employer by a wide margin.

Why under-reporting happens

People think breach means attack. An email to the wrong recipient does not feel like one, and it is the category producing most of the actual harm in employment contexts.

Internal access without authorisation

Somebody reading a colleague's file out of curiosity. It is a breach, the person affected would certainly call it one, and it is the category organisations are least likely to record as such.