Skip to content

Data Breach

What is Data Breach?

An incident where confidential, private, or protected data is accessed, disclosed, or stolen by an unauthorised party. May trigger breach notification requirements under GDPR, HIPAA, or other regulations.

Information Security

What the standards actually require on data breach

Requirements naming data breach across 6 standards, quoted from the control text.

Determine applicability and maintain a documented data breach response plan per the Notifiable Data Breaches scheme established by the Privacy Amendment (Notifiable Data Breaches) Act 2017 + Part IIIC of the Privacy Act 1988 (Cth) administered by the Office of...

AUNDB-A1 · Applicability, Scope, and Data Breach Response Plan

Breach assessment. Section 27 requires organisations to conduct a prompt assessment to determine whether a data breach is notifiable.

BN-PDPO-s27 · Duty to conduct assessment of a data breach
India DPDP Act4 controls

Sections 16-17 of DPDP Act 2023 address cross-border transfer + breach notification. Section 16 Processing of Personal Data Outside India: Central Government may by notification restrict the transfer of personal data by a Data Fiduciary for processing to such...

DPDP-CrossBorder-Transfer-Breach-Notification-Sec16-Sec17-DPBI-72Hour-IT-Act-Coord · DPDP Act Sections 16-17 + Cross-Border Personal Data Transfer + Negative List Approach + Personal Data Breach Notification to DPBI 72 Hours + Cooperation with Adjudication + Coord with CERT-In + IT Act 43A Repeal
GDPR2 controls

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, communicate the breach to the affected data subjects without undue delay, describing in clear and plain language the nature of the breach and giving...

GDPR-Art.34 · Communication of a personal data breach to the data subject

Sections 28-30 of the Jamaica Data Protection Act 2020 establish the Personal Data Breach Notification framework. (1) Section 28 Personal Data Breach Definition: (a) breach of security leading to accidental or unlawful (i) destruction; (ii) loss;

JM-DPA2020-Breach-Notification-Sec28-30-Duty-Notify-Commissioner-Affected-Subjects-72-Hours-Severe · Jamaica DPA 2020 Personal Data Breach Notification + Sections 28-30 + Duty to Notify Commissioner + Affected Subjects + 72-Hour Reporting + High Risk + Severe + Mitigation + Documentation

Article 19 of the Jordan PDPL establishes the Personal Data Breach Notification framework. (1) Personal Data Breach Definition: (a) Breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration;

JO-PDPL-Breach-Notification-Article19-Council-72Hour-High-Risk-Data-Subjects-Mitigation · Jordan PDPL Personal Data Breach Notification + Article 19 + Council Notification + 72-Hour SLA + High-Risk Affected Data Subjects + Mitigation + Documentation + Processor Notification Chain

Questions people ask about data breach

What is Data Breach?
An incident where confidential, private, or protected data is accessed, disclosed, or stolen by an unauthorised party. May trigger breach notification requirements under GDPR, HIPAA, or other regulations.
Why is Data Breach important for compliance?
Data Breach is a key concept in Information Security. Understanding data breach helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Data Breach?
Key concepts related to Data Breach include Breach Notification, Incident Response. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Data Breach?
Data Breach appears in the requirement text of Notifiable Data Breaches Scheme (Australia), Brunei Personal Data Protection Order 2022 (PDPO), India DPDP Act, GDPR, Jamaica Data Protection Act 2020. Across these standards we have identified 20 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data Breach?
Explore our compliance framework pages to see how data breach applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data Breach applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.