Data Breach
What is Data Breach?
An incident where confidential, private, or protected data is accessed, disclosed, or stolen by an unauthorised party. May trigger breach notification requirements under GDPR, HIPAA, or other regulations.
Related terms
Frameworks that govern data breach
What the standards actually require on data breach
Requirements naming data breach across 6 standards, quoted from the control text.
Determine applicability and maintain a documented data breach response plan per the Notifiable Data Breaches scheme established by the Privacy Amendment (Notifiable Data Breaches) Act 2017 + Part IIIC of the Privacy Act 1988 (Cth) administered by the Office of...
AUNDB-A1 · Applicability, Scope, and Data Breach Response Plan →Breach assessment. Section 27 requires organisations to conduct a prompt assessment to determine whether a data breach is notifiable.
BN-PDPO-s27 · Duty to conduct assessment of a data breach →Sections 16-17 of DPDP Act 2023 address cross-border transfer + breach notification. Section 16 Processing of Personal Data Outside India: Central Government may by notification restrict the transfer of personal data by a Data Fiduciary for processing to such...
DPDP-CrossBorder-Transfer-Breach-Notification-Sec16-Sec17-DPBI-72Hour-IT-Act-Coord · DPDP Act Sections 16-17 + Cross-Border Personal Data Transfer + Negative List Approach + Personal Data Breach Notification to DPBI 72 Hours + Cooperation with Adjudication + Coord with CERT-In + IT Act 43A Repeal →Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, communicate the breach to the affected data subjects without undue delay, describing in clear and plain language the nature of the breach and giving...
GDPR-Art.34 · Communication of a personal data breach to the data subject →Sections 28-30 of the Jamaica Data Protection Act 2020 establish the Personal Data Breach Notification framework. (1) Section 28 Personal Data Breach Definition: (a) breach of security leading to accidental or unlawful (i) destruction; (ii) loss;
JM-DPA2020-Breach-Notification-Sec28-30-Duty-Notify-Commissioner-Affected-Subjects-72-Hours-Severe · Jamaica DPA 2020 Personal Data Breach Notification + Sections 28-30 + Duty to Notify Commissioner + Affected Subjects + 72-Hour Reporting + High Risk + Severe + Mitigation + Documentation →Article 19 of the Jordan PDPL establishes the Personal Data Breach Notification framework. (1) Personal Data Breach Definition: (a) Breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration;
JO-PDPL-Breach-Notification-Article19-Council-72Hour-High-Risk-Data-Subjects-Mitigation · Jordan PDPL Personal Data Breach Notification + Article 19 + Council Notification + 72-Hour SLA + High-Risk Affected Data Subjects + Mitigation + Documentation + Processor Notification Chain →Questions people ask about data breach
What is Data Breach?
Why is Data Breach important for compliance?
What concepts are related to Data Breach?
Which compliance frameworks address Data Breach?
Where can I learn more about Data Breach?
See how Data Breach applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.