Availability Breach
An availability breach happens when an organisation temporarily or permanently loses access to the personal data it holds, or that data is destroyed or lost. For example, records might become unreachable due to a system outage or be accidentally deleted. It is one recognised type of personal data breach, alongside breaches affecting confidentiality and integrity.
An availability breach is a category of personal data breach in which a security incident results in the accidental or unlawful destruction or loss of, or loss of access to, personal data. Under the GDPR framework, a personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data; the availability sub-type specifically concerns the destruction, loss, or loss of access limb of that definition. Loss of access may be temporary or permanent, and whether a given incident triggers notification obligations is assessed on the facts, including the likely risk to individuals. This entry describes the concept as reflected in regulator guidance; readers should verify the precise notification thresholds and any applicable article references against the current official text, as regulatory guidance on categorisation and risk assessment continues to evolve.
Why it matters
Availability breaches are easy to overlook because organisations often associate a personal data breach only with data being stolen or exposed. Yet the GDPR framework treats a breach of security that leads to the accidental or unlawful destruction, loss, or loss of access to personal data as a personal data breach in its own right, even where no unauthorised party ever sees the data. This means a ransomware attack that encrypts records, an accidental deletion, or a prolonged system outage that leaves personal data unreachable can all qualify as a reportable incident, subject to assessment of the facts.
The practical significance is that availability incidents can trigger the same breach-handling and, where relevant, notification obligations as confidentiality breaches. Whether a given availability incident meets the threshold for notifying a supervisory authority or the affected individuals is assessed case by case, taking into account the likely risk to those individuals, including whether the loss of access is temporary or permanent and what harm the unavailability may cause. Organisations that treat downtime purely as an IT or business-continuity matter risk missing a data protection obligation.
Because regulator guidance on how breaches are categorised and how risk is assessed continues to evolve, and because member state implementation and the UK GDPR position can differ, teams should verify the precise notification thresholds and any applicable article references against the current official text rather than relying on a fixed interpretation.
Who it's relevant to
Inside Availability Breach
Common questions
Answers to the questions practitioners most commonly ask about Availability Breach.