Skip to main content
Category: Security & Breach Notification

Categories and Approximate Number of Records

Also known as: Categories and approximate number of personal data records concerned, Approximate number of records concerned
Simply put

This is one of the pieces of information an organisation is generally expected to provide when reporting a personal data breach to a supervisory authority. It describes the types of personal data records affected (for example, contact details, financial records, or health information) and roughly how many such records were involved. An approximate figure is acceptable because a precise count may not be available at the early stages of investigating a breach.

Formal definition

Under Article 33 GDPR, a notification of a personal data breach to the supervisory authority should, at a minimum, describe the nature of the breach including, where possible, the categories and approximate number of personal data records concerned (a related requirement covers the categories and approximate number of data subjects/individuals concerned). This element requires the controller to characterise the affected records by type or category and to provide an estimate of volume rather than an exact figure, reflecting that full information may not be available at the point of notification. Where the extent of the breach is not yet known, the controller may provide information in phases and update the notification as the assessment progresses. The precise triggering thresholds, timing obligations, and content requirements should be verified against the current text of Article 33 GDPR and any applicable UK GDPR provisions and national implementing law, which can vary; ICO guidance mirrors this content requirement for controllers subject to the UK regime.

Why it matters

When a controller notifies a supervisory authority of a personal data breach, the description of the affected records is one of the core pieces of information the authority uses to gauge the potential impact on individuals. Characterising the categories of records, for example, whether they contain contact details, financial information, or health data, helps the regulator and the controller assess the severity of the breach and the likely risk to affected individuals. A breach involving special category data (such as health information under Article 9 GDPR) generally carries a different risk profile from one involving only basic contact details, and this element is where that distinction begins to surface.

The approximate number of records concerned informs proportionality: it signals the scale of the incident and can influence whether individuals must also be notified, how the authority engages, and what remedial steps are expected. Because a precise count is often unavailable in the early stages of an investigation, the requirement is deliberately framed around an estimate. This allows a controller to meet its notification obligation without waiting for a complete forensic picture, and to update the figure as the assessment progresses.

Getting this element right matters for the credibility and completeness of the notification. An estimate that is materially wrong, or a category description that understates the sensitivity of the data involved, can undermine the authority's risk assessment and the controller's own subsequent communications with affected individuals. The categories and approximate number of records concerned typically appears alongside, but is distinct from, the categories and approximate number of individuals (data subjects) concerned, one describes the affected data, the other the affected people, and both are generally expected in a notification.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy leads coordinating breach response need to ensure the notification captures both the categories of records affected and a defensible volume estimate. They typically manage the phased-notification approach, updating figures as the investigation clarifies scope, and should distinguish the records-based element from the separate requirement to describe the categories and approximate number of individuals concerned.
Incident response and security engineers
Technical teams investigating a breach are generally the source of the underlying data on which records were exposed and in what volume. Their forensic findings drive both the category classification and the approximate count, and their ability to provide early estimates supports timely notification even before a full assessment is complete.
Compliance and legal teams
Those preparing or reviewing notifications must confirm the content requirements against the current text of Article 33 GDPR and, where relevant, UK GDPR and national implementing law, which can differ. They also assess whether affected records include special category data under Article 9, which can affect the risk evaluation and downstream obligations.
Controllers reporting a breach
The controller carries the notification obligation to the supervisory authority and is responsible for characterising the affected records and estimating their number. An approximate figure is generally acceptable, and the controller may update the notification in phases as more information becomes available.

Inside Categories and Approximate Number of Records

Categories of Personal Data
A structured description of the types of personal data involved, such as identification data, contact details, financial data, or special category data under Article 9. Under Article 30 records of processing activities, controllers and processors are generally expected to document the categories of data subjects and the categories of personal data being processed, rather than every individual field.
Categories of Data Subjects
The classes of individuals whose personal data is processed, for example customers, employees, prospects, or website visitors. This grouping supports transparency obligations and helps scope risk without requiring enumeration of each identified person.
Approximate Number of Records
An estimated volume or order-of-magnitude count of the personal data records or affected individuals within a category. In many contexts, such as breach notification under Articles 33 and 34, an approximate figure is generally acceptable where an exact count is not available at the time of reporting, subject to assessment.
Purpose and Legal Basis Linkage
The association between each data category and the processing purpose and its Article 6 legal basis (and, for special category data, an additional Article 9 condition). Documenting categories typically feeds into demonstrating lawfulness and the accountability principle.
Scope Qualifier
A note on what falls inside and outside the count, for instance whether anonymised data is excluded because it is generally outside the scope of the GDPR, and whether pseudonymised data remains in scope as personal data. This boundary should be stated to avoid over- or under-reporting.

Common questions

Answers to the questions practitioners most commonly ask about Categories and Approximate Number of Records.

Does 'approximate number of records' mean I must count every affected individual exactly before notifying a supervisory authority?
No. The term deliberately uses 'approximate' because a precise figure is often unavailable at the point of assessment or initial notification. In most cases you are expected to provide a reasonable estimate based on the information available at the time, and to update it as your investigation progresses. Attempting to delay action until an exact count is obtained can itself be problematic where timeliness obligations apply. You should document how the estimate was derived and revise it if better information emerges.
Is this concept only relevant when a personal data breach has occurred?
Not exclusively. While categorising records and estimating volumes is a well-known feature of breach documentation and notification content, describing the categories and approximate number of data subjects and records is also relevant to broader accountability activities, such as records of processing and risk assessments. The emphasis on approximation reflects that scope may not be fully known, but the exercise of categorising data and estimating volume supports several compliance functions, not breach response alone.
How should we categorise records when a single dataset contains several different types of personal data?
Generally you would break the dataset down by meaningful categories rather than treating it as one undifferentiated set. Categories are typically framed by the type of data subject affected and the nature of the data involved, and it is often useful to flag separately any data that may fall within special categories, as such data can carry additional conditions and heightened risk. Where a record spans multiple categories, document that overlap rather than forcing a single label, and note any assumptions made.
What documentation should we keep to support an approximate record count?
It is advisable to record the basis of the estimate, the data sources or systems queried, the date and time the figure was produced, and the person or team responsible. Because estimates commonly change, keeping a version history helps demonstrate that figures were revised in good faith as facts developed. This supporting material typically forms part of your internal accountability records and can assist if a regulator later asks how a figure was reached.
How do we handle uncertainty when systems or logs do not give us a reliable number?
Where reliable figures are not available, it is generally acceptable to provide a qualified estimate accompanied by a clear statement of the limitations, for example noting the range considered, the reason the exact figure is unknown, and what further steps are being taken to refine it. Overstating certainty can be misleading, so qualified language and an explanation of the assumptions used are usually preferable to a single precise-sounding number that cannot be substantiated.
Should we update the categories and approximate number of records after an initial assessment?
Yes, in most cases. Both the categorisation and the volume estimate should be treated as provisional and revisited as your understanding improves. If further investigation reveals additional categories of affected individuals or a materially different number of records, the documentation and any relevant notifications should be updated accordingly. Recording when and why figures changed supports accountability and helps evidence that the assessment reflected the best available information at each stage.

Common misconceptions

An exact record count must always be provided in a record of processing or a breach notification.
In most cases an approximate number is acceptable, particularly where the precise figure is not reasonably available at the time. The obligation is generally to give a good-faith estimate that can be refined; practitioners should verify the specific requirement against the current official text of the relevant provision.
Counting categories and records covers all data an organisation holds, including anonymous and legal-entity data.
The GDPR generally applies to personal data of individuals. Truly anonymous data falls outside scope, and data relating to legal entities (and, generally, deceased persons, subject to member state derogations) is typically not governed by the Regulation. The count should be scoped accordingly.
Listing data categories is a purely descriptive administrative exercise with no legal consequence.
Categorisation typically drives legal analysis: special category data under Article 9 requires an additional condition beyond an Article 6 basis, and accurate categorisation supports the accountability principle and risk assessment. Mislabelling categories can undermine the lawfulness assessment.

Best practices

Group data by categories of data subjects and categories of personal data rather than enumerating every field, consistent with the typical structure of Article 30 records.
Flag special category data separately, since it generally requires an additional Article 9 condition on top of an Article 6 legal basis.
State clearly whether counts include pseudonymised data (generally in scope) and exclude anonymous data (generally out of scope), and note where the boundary lies.
Provide approximate figures with a documented estimation method, and update them as more accurate information becomes available rather than delaying documentation.
Link each category to its processing purpose and legal basis to support the accountability principle and to make the lawfulness analysis auditable.
Verify any specific counting or reporting threshold against the current official text and applicable regulator guidance, noting that positions may differ between the EU GDPR, UK GDPR, and national implementing law.