Skip to main content
Category: Security & Breach Notification

Availability Breach

Also known as: availability breach of personal data
Simply put

An availability breach happens when an organisation temporarily or permanently loses access to the personal data it holds, or that data is destroyed or lost. For example, records might become unreachable due to a system outage or be accidentally deleted. It is one recognised type of personal data breach, alongside breaches affecting confidentiality and integrity.

Formal definition

An availability breach is a category of personal data breach in which a security incident results in the accidental or unlawful destruction or loss of, or loss of access to, personal data. Under the GDPR framework, a personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data; the availability sub-type specifically concerns the destruction, loss, or loss of access limb of that definition. Loss of access may be temporary or permanent, and whether a given incident triggers notification obligations is assessed on the facts, including the likely risk to individuals. This entry describes the concept as reflected in regulator guidance; readers should verify the precise notification thresholds and any applicable article references against the current official text, as regulatory guidance on categorisation and risk assessment continues to evolve.

Why it matters

Availability breaches are easy to overlook because organisations often associate a personal data breach only with data being stolen or exposed. Yet the GDPR framework treats a breach of security that leads to the accidental or unlawful destruction, loss, or loss of access to personal data as a personal data breach in its own right, even where no unauthorised party ever sees the data. This means a ransomware attack that encrypts records, an accidental deletion, or a prolonged system outage that leaves personal data unreachable can all qualify as a reportable incident, subject to assessment of the facts.

The practical significance is that availability incidents can trigger the same breach-handling and, where relevant, notification obligations as confidentiality breaches. Whether a given availability incident meets the threshold for notifying a supervisory authority or the affected individuals is assessed case by case, taking into account the likely risk to those individuals, including whether the loss of access is temporary or permanent and what harm the unavailability may cause. Organisations that treat downtime purely as an IT or business-continuity matter risk missing a data protection obligation.

Because regulator guidance on how breaches are categorised and how risk is assessed continues to evolve, and because member state implementation and the UK GDPR position can differ, teams should verify the precise notification thresholds and any applicable article references against the current official text rather than relying on a fixed interpretation.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams need to ensure that incident response and breach assessment processes capture availability events, not just confidentiality incidents. This includes documenting outages, deletions, and ransomware-related loss of access, and assessing on the facts whether notification thresholds are engaged. They should also monitor evolving regulator guidance, which may differ between the EU and UK GDPR contexts.
Engineers and IT / security teams
Those responsible for systems, backups, and recovery are often the first to detect events that may amount to an availability breach, such as outages, accidental deletion, or encryption of records. Their controls, including backup and restoration capabilities, directly affect whether loss of access is temporary or permanent, which in turn shapes the risk assessment. Timely escalation to the data protection function is generally important.
Controllers and processors
Both roles have obligations in relation to personal data breaches, but they differ. A processor experiencing an availability incident affecting personal data it handles on a controller's behalf typically has a duty to inform the controller, while the controller generally leads the assessment of risk and any regulator or individual notification. Contractual arrangements between the parties should reflect these respective responsibilities.
Business continuity and disaster recovery owners
Teams managing continuity and disaster recovery should recognise that a disruption to the availability of personal data can carry data protection consequences in addition to operational ones. Coordinating recovery planning with the breach-handling process helps ensure that an outage is evaluated both as a service issue and, where relevant, as a potential personal data breach.

Inside Availability Breach

Loss of Availability
A form of personal data breach in which access to, or the availability of, personal data is disrupted, whether temporarily or permanently. This is one of the three recognised breach types alongside confidentiality breaches (unauthorised disclosure or access) and integrity breaches (unauthorised alteration), as reflected in regulatory guidance on breach notification.
Temporary versus Permanent Disruption
Availability breaches range from temporary loss of access, where data is later restored, to permanent loss such as irrecoverable destruction. Guidance generally treats even a temporary loss as a breach, though the assessment of risk and notification obligations depends on duration and impact.
Accidental and Unlawful Causes
Availability breaches may arise from accidental causes (for example, hardware failure or accidental deletion) or unlawful acts (for example, ransomware that encrypts data). The GDPR definition of a personal data breach covers accidental or unlawful loss of personal data, so both categories fall within scope.
Notification Assessment
Where an availability breach occurs, the controller generally assesses whether it is likely to result in a risk to the rights and freedoms of individuals, which informs whether notification to the supervisory authority and communication to affected individuals is required. This assessment is context and risk dependent.
Relationship to Personal Data
The concept applies to personal data of individuals. Loss of availability of anonymous data would not typically constitute a personal data breach in this sense, since such data falls outside the material scope of the GDPR.

Common questions

Answers to the questions practitioners most commonly ask about Availability Breach.

Does an availability breach only occur when personal data is permanently lost or destroyed?
No. An availability breach generally refers to any accidental or unlawful loss of access to, or destruction of, personal data, and this includes temporary loss of access as well as permanent destruction. A ransomware incident that locks data, or a system outage that prevents authorised access, can constitute an availability breach even if the data is later recovered. Whether the temporary loss rises to the level of a notifiable personal data breach is a separate, risk-based assessment. You should verify the specific thresholds against the current official GDPR text and applicable regulator guidance.
Is an availability breach less serious than a confidentiality breach, so that it never needs to be reported?
Not necessarily. The GDPR recognises breaches affecting confidentiality, integrity, and availability, and an availability breach is not inherently less serious. The obligation to notify a supervisory authority generally depends on whether the breach is likely to result in a risk to the rights and freedoms of individuals, not on which security property was affected. In some cases loss of availability of critical data, for example health records, can create significant risk. Each incident should be assessed on its own facts, and you should check the applicable notification thresholds against the current official text.
How do we assess whether an availability breach needs to be notified to a supervisory authority?
The assessment is typically risk-based: consider the nature and volume of the personal data affected, the duration and extent of the loss of access, whether the data can be restored from backups, the potential consequences for individuals, and any mitigating measures. If the incident is likely to result in a risk to the rights and freedoms of individuals, notification obligations may be triggered. Document your reasoning regardless of the outcome. Timeframes and precise thresholds should be verified against the current official GDPR text and relevant regulator guidance, and note that member state or UK positions may vary.
What role do backups and recovery capabilities play in managing an availability breach?
Backups and tested recovery procedures are generally central to both preventing and mitigating availability breaches. The ability to restore access to personal data in a timely manner is typically treated as part of the security-of-processing expectations, and effective, verified backups can reduce the severity of an incident and inform the risk assessment. However, the existence of a backup does not automatically remove all risk or all obligations, since factors such as the duration of unavailability and the sensitivity of the data still matter. Recovery arrangements should be assessed as part of your broader technical and organisational measures.
Should availability breaches be recorded internally even if they are not notified to the regulator?
Generally yes. The accountability principle typically requires controllers to document personal data breaches, including the facts, effects, and remedial action taken, irrespective of whether the incident was notifiable. Maintaining an internal breach register supports the ability to demonstrate compliance and to justify a decision not to notify. You should confirm the exact scope of the record-keeping expectation against the current official text and applicable guidance.
How should responsibilities for availability breaches be allocated between a controller and a processor?
Responsibilities are generally shaped by the data processing arrangement between the parties. A processor typically must implement appropriate security measures and assist the controller, including by notifying the controller without undue delay after becoming aware of a breach affecting availability. The controller generally retains responsibility for assessing risk and making any notification to the supervisory authority or affected individuals. These allocations should be set out clearly in the relevant contractual terms governing the processing, and the precise obligations should be verified against the current official text.

Common misconceptions

An availability breach only occurs when data is stolen or disclosed to an unauthorised party.
That describes a confidentiality breach. An availability breach concerns loss of access to or availability of personal data, and can occur without any disclosure, for example through accidental deletion, hardware failure, or ransomware that renders data inaccessible.
A temporary loss of access is not a breach because the data is eventually recovered.
Guidance generally treats a temporary loss of availability as a personal data breach. Whether it triggers notification obligations depends on a risk assessment, but recovery of the data does not, by itself, mean no breach occurred.
Every availability breach must be notified to the supervisory authority and to affected individuals.
Notification is not automatic. It generally depends on an assessment of whether the breach is likely to result in a risk, and in some cases a high risk, to individuals' rights and freedoms. The obligation is context and risk dependent rather than universal.

Best practices

Classify each incident by breach type (confidentiality, integrity, availability), recognising that a single incident may involve more than one type, to ensure the correct assessment and response.
Document the cause, whether accidental or unlawful, and the duration of any loss of access, since these factors inform the risk assessment and any notification decision.
Maintain and test backup and recovery capabilities so that availability can be restored, and record recovery times as evidence relevant to the risk assessment.
Apply a documented risk assessment to each availability breach to determine whether notification to the supervisory authority or communication to individuals is required, rather than assuming notification is always or never needed.
Record all availability breaches in an internal breach register, including those that do not meet the threshold for external notification, to demonstrate accountability.
Verify notification timeframes, thresholds, and any national or UK GDPR divergences against the current official text and applicable regulatory guidance before acting.