Laws · GDPR ·art-4-par-12 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
How it connects
Cited by
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
- Guidelines 01/2022 on data subject rights - Right of access
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 9/2022 on personal data breach notification under GDPR
- VB v Natsionalna agentsia za prihodite
All 15
- UODO fines accounting firm €2,760 for email breach security failures
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR
- Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria
- EDPB Annual Report 2021
- HDPA: Hellenic Open University found to have met breach notification duties after
- HDPA (Greece) - 15/2026
- Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access
Related across sources
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Apr 4, 2023 Notification Obligation Data Breaches Personal Data
Guidelines 01/2021 Examples regarding Personal Data Breach Notification Guidelines ·EDPB Jan 3, 2022 Notification Obligation Data Breaches Personal Data
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Aug 19, 2026 Data Breaches Notification Obligation Integrity and Confidentiality Principle
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Sep 22, 2026 Data Breaches Notification Obligation Controllers
€1,790 Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article… Poland · ·Art. 33 Apr 30, 2026 Notification Obligation Data Breaches Supervisory Authorities