It is not only cyber attacks
This is the misunderstanding that wastes most time at the worst moment. “Personal data breach” means destruction, loss, alteration or unauthorised disclosure of personal data — and in real casework a substantial share of episodes has nothing to do with an attack.
- An email with the client list sent to the wrong address.
- An attachment sent with visible copy instead of blind copy, exposing every recipient’s address.
- A laptop left on a train.
- A backup disk mislaid, or disposed of without secure erasure.
- A filing cabinet left accessible during an office move.
- A former collaborator who still reaches a shared mailbox.
All of these have to be assessed by the same standard as a cyber attack. What makes the difference is the risk to individuals, not how dramatic the event was.
Encryption genuinely changes the outcome
This is one of the few cases where a simple technical measure directly reduces an obligation.
A company laptop lost without encryption is a breach with a concrete risk: whoever finds it can read the data. The same laptop with an encrypted disk makes that data unintelligible, and this weighs decisively in the risk assessment.
It is worth saying explicitly because it is a more persuasive practical argument than most: encrypting devices is not one more box to tick, it is what turns the loss of an object into a notification you can avoid.
The seventy-two hours, explained without alarm
The clock starts from becoming aware, not from when it happened. And it is a deadline to notify, not to have resolved: notification can be staged, adding information as the picture is reconstructed.
The real problem is not the deadline: it is arriving at it with enough information. Without preparation, the first seventy-two hours are spent working out what happened, and the notification is made incomplete or not at all.
Three things make it manageable, and they are prepared while nothing is happening:
Knowing which data sits where. That is exactly what is needed to say whether the breach involves personal data and which. It is also the practical reason the record of processing activities should be kept current rather than compiled once and filed away.
Having logs enabled. Without traces the event cannot be reconstructed, and without reconstruction nobody can honestly say which data was involved.
Knowing who decides. Who assesses the risk, who signs the notification, who speaks to the people affected. Without those names settled beforehand, time is lost exactly when there is none.
Not everything is notified, but everything is assessed
What has to be notified to the authority is a breach posing a risk to the rights and freedoms of individuals. Where that risk is unlikely, notification may not be required.
But the assessment has to be made and documented, because accountability requires being able to demonstrate the decisions, not merely to have taken them. This is where the document almost no company keeps comes in: the breach register, which records every episode — including the ones not notified — with the reasoning behind the decision taken.
It is the first thing asked for if a related problem emerges later, and it is also what distinguishes a company that assessed the situation from one that never noticed.
When the individuals have to be told as well
When the risk is high, the people affected have to be informed alongside the authority, without undue delay. It is the step with the greatest reputational impact, and it should be prepared in advance: the text of that communication is written badly under pressure, at a moment when the company has ten urgent problems at once.
The rest
See also incident response for the technical sequence of the first hours, GDPR consulting for the obligations upstream, and GAPOFF, where the breach register is a module rather than a file nobody reopens.
The first step
If a breach is under way, call us before touching the systems. If instead you want to be ready for one, the assessment of what is missing — logs, inventory, procedure, names — is free and without obligation.