Categories and Approximate Number of Records
This is one of the pieces of information an organisation is generally expected to provide when reporting a personal data breach to a supervisory authority. It describes the types of personal data records affected (for example, contact details, financial records, or health information) and roughly how many such records were involved. An approximate figure is acceptable because a precise count may not be available at the early stages of investigating a breach.
Under Article 33 GDPR, a notification of a personal data breach to the supervisory authority should, at a minimum, describe the nature of the breach including, where possible, the categories and approximate number of personal data records concerned (a related requirement covers the categories and approximate number of data subjects/individuals concerned). This element requires the controller to characterise the affected records by type or category and to provide an estimate of volume rather than an exact figure, reflecting that full information may not be available at the point of notification. Where the extent of the breach is not yet known, the controller may provide information in phases and update the notification as the assessment progresses. The precise triggering thresholds, timing obligations, and content requirements should be verified against the current text of Article 33 GDPR and any applicable UK GDPR provisions and national implementing law, which can vary; ICO guidance mirrors this content requirement for controllers subject to the UK regime.
Why it matters
When a controller notifies a supervisory authority of a personal data breach, the description of the affected records is one of the core pieces of information the authority uses to gauge the potential impact on individuals. Characterising the categories of records, for example, whether they contain contact details, financial information, or health data, helps the regulator and the controller assess the severity of the breach and the likely risk to affected individuals. A breach involving special category data (such as health information under Article 9 GDPR) generally carries a different risk profile from one involving only basic contact details, and this element is where that distinction begins to surface.
The approximate number of records concerned informs proportionality: it signals the scale of the incident and can influence whether individuals must also be notified, how the authority engages, and what remedial steps are expected. Because a precise count is often unavailable in the early stages of an investigation, the requirement is deliberately framed around an estimate. This allows a controller to meet its notification obligation without waiting for a complete forensic picture, and to update the figure as the assessment progresses.
Getting this element right matters for the credibility and completeness of the notification. An estimate that is materially wrong, or a category description that understates the sensitivity of the data involved, can undermine the authority's risk assessment and the controller's own subsequent communications with affected individuals. The categories and approximate number of records concerned typically appears alongside, but is distinct from, the categories and approximate number of individuals (data subjects) concerned, one describes the affected data, the other the affected people, and both are generally expected in a notification.
Who it's relevant to
Inside Categories and Approximate Number of Records
Common questions
Answers to the questions practitioners most commonly ask about Categories and Approximate Number of Records.