Data Breaches
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Security incidents involving unauthorized access to personal data
Overview
21 sources · Jul 15, 2026Legal Framework
The GDPR governs personal data breaches primarily through Articles 33 and 34. Article 33 requires controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. A later notification is permissible but must be justified with reasons for the delay. Information may be provided in phases where not all details are immediately available, as confirmed by Recital 86. Article 34 imposes a corresponding obligation to communicate the breach to affected data subjects when the breach is likely to result in a high risk to their rights and freedoms. Article 4 provides the foundational definitions, including the scope of "personal data," which determines what constitutes a breach in the first place. The 72-hour clock starts when the controller gains awareness — meaning when the controller has a reasonable degree of certainty that a security incident has occurred affecting personal data, not merely when an anomaly is first flagged.
Key Developments
The Zeehondenmail case illustrates that breaches extend well beyond external cyberattacks. An employer was held accountable because its internal work processes allowed a colleague to access another employee's mailbox without authorization — the court found the employer's process design itself was at fault. This establishes that organizational failures in access management constitute reportable breaches. The GGD data leak litigation (WAMCA proceedings) demonstrates the severe civil liability exposure: claimants sought joint and several liability for all damages suffered, alongside court-ordered remediation of security deficiencies within a fixed timeframe. The RIVM vaccination data case confirms that even deletion requests involving special category data (Article 9) require stringent identity verification, and that mishandling such processes can itself constitute a breach. On the enforcement side, UODO fined the Mayor of Myślenice €1,790 under Article 33(1) for notification failures, and a Polish housing association €2,350 for insufficient breach notification compliance — signaling that even modest fines carry reputational and operational consequences, particularly in the public sector.
Practical Guidance
Establish internal breach detection and escalation procedures that feed into the 72-hour notification clock. The controller's awareness — not the IT team's initial detection — triggers the deadline. Ensure incident response protocols distinguish between preliminary investigation and confirmed awareness.
Document every decision point, including the rationale for any delayed notification beyond 72 hours. Recital 86 permits phased reporting, but each phase must be substantiated. Maintain an internal breach register as required by Article 33(5).
Conduct risk assessments for each breach to determine whether Article 34 communication to data subjects is triggered. The threshold is "high risk to rights and freedoms" — breaches involving special category data, financial data, or large-scale exposure will typically meet this standard.
Audit access controls and internal processes proactively. The Zeehondenmail ruling confirms that preventable internal access failures are attributable to the controller. Shared mailbox configurations, delegated access, and insufficient segregation of duties all create breach exposure.
Prepare breach notification templates in advance covering both Article 33 (authority) and Article 34 (data subject) requirements, including the mandatory content elements: nature of the breach, categories and approximate numbers of affected individuals and records, likely consequences, and mitigation measures taken or proposed.