Skip to main content
Category: Security & Breach Notification

Confidentiality Breach

Also known as: Breach of Confidentiality
Simply put

A confidentiality breach generally occurs when private or personal information is disclosed to, or accessed by, someone who is not authorised to have it, without the permission of the person or organisation the information belongs to. This can happen deliberately or by accident, for example through a misdirected email, a lost or stolen device, or a conversation overheard in the wrong place. Whether such a disclosure is lawful or improper depends on the circumstances and any applicable legal obligations.

Formal definition

A confidentiality breach refers to the unauthorised or unlawful disclosure of, or access to, information, including personal data, without the consent or authorisation of the relevant party. Under EU/UK data protection terminology, confidentiality is commonly recognised as one dimension of a personal data breach (alongside integrity and availability), but practitioners should verify the precise wording and article references against the current official GDPR/UK GDPR text, as the evidence provided here does not establish a specific statutory citation. The concept also arises in non-data-protection contexts such as professional duties of confidence, contractual confidentiality obligations, and research/clinical settings, where lawfulness of any disclosure is assessed case by case and may be justified only in limited circumstances (for example, legal mandates or serious threats to safety). The scope of what constitutes a breach, and the resulting obligations (such as reporting), varies by legal regime and applicable regulatory or oversight framework.

Why it matters

A confidentiality breach can expose individuals to harm ranging from identity theft and financial loss to reputational damage, distress, or physical risk, depending on the sensitivity of the information disclosed and who gains access to it. For organisations, the unauthorised disclosure of personal data may trigger legal obligations, undermine the trust of customers, patients, or clients, and expose the organisation to regulatory scrutiny. In the EU/UK data protection context, confidentiality is commonly recognised as one dimension of a personal data breach, alongside integrity and availability, so a confidentiality breach may bring reporting and other duties into play depending on the applicable regime and the severity of the incident.

The practical significance is that breaches often arise from ordinary operational failures rather than sophisticated attacks. Misdirected emails, conversations held in the wrong place, and lost or stolen devices are recurring examples that illustrate how everyday activity can result in unauthorised disclosure. Because these routes are mundane and hard to eliminate entirely, confidentiality breaches represent a persistent risk that requires ongoing controls, training, and awareness rather than a one-off fix.

Whether a particular disclosure is improper also depends heavily on context. Outside data protection law, confidentiality obligations arise from professional duties, contracts, and research or clinical settings, and disclosure may be justified only in limited circumstances, such as legal mandates or a severe threat to the patient or others. The lawfulness of any disclosure, and the resulting obligations, is generally assessed case by case and varies by legal regime and oversight framework, so readers should verify the specific requirements applicable to their situation against the current official text and guidance.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for privacy compliance need to identify when an unauthorised disclosure of personal data amounts to a confidentiality breach and determine what obligations follow. Because confidentiality is generally treated as one dimension of a personal data breach, DPOs should map incidents against the applicable regime and verify reporting thresholds and timelines against the current official GDPR/UK GDPR text rather than relying on a fixed assumption.
Lawyers and Legal Advisers
Confidentiality obligations arise not only under data protection law but also from professional duties, contractual confidentiality clauses, and equitable duties of confidence. Legal advisers assess, case by case, whether a disclosure was improper or whether it fell within a recognised justification, such as a legal mandate. The lawfulness of any disclosure typically depends on the specific facts and the applicable legal regime.
Healthcare and Clinical Staff
In clinical settings, patient confidentiality is a core professional obligation, and accidental disclosures can occur through misdirected emails, conversations in the wrong place, lost or stolen devices, or social media. Breaking confidentiality is generally justified only in specific circumstances, such as a severe threat to the patient or others or a legal mandate, and staff should follow the governing framework applicable to their setting.
Researchers and Ethics Oversight Bodies
In research contexts, a breach of confidentiality may constitute an unanticipated problem that must be reported to an oversight body such as an Institutional Review Board, with additional requirements where particular categories of information are involved. Researchers should confirm the specific reporting duties that apply under their institutional and regulatory framework.
Engineers and Operational Staff
Because many confidentiality breaches stem from everyday operational failures such as misdirected emails, lost or stolen devices, and inadvertent sharing, technical and operational teams play a central role in prevention. Access controls, encryption, and secure handling of information generally reduce the likelihood and impact of unauthorised disclosure, though no single control eliminates the risk entirely.

Inside Confidentiality Breach

Unauthorised or unlawful disclosure
A confidentiality breach involves personal data being disclosed to, or accessed by, parties who are not authorised to receive or view it. This is one of the three recognised categories of personal data breach, alongside integrity breaches (unauthorised alteration) and availability breaches (loss of access to or destruction of data).
Relationship to the security principle
The concept connects to the requirement that personal data be processed in a manner ensuring appropriate security, including protection against unauthorised or unlawful processing. Confidentiality is generally treated as one component of this broader security obligation.
Personal data scope
A confidentiality breach is only relevant where the data disclosed or accessed is personal data of identifiable individuals. Disclosure of genuinely anonymous data, or data outside the scope of the GDPR, would not typically constitute a confidentiality breach under the Regulation, subject to assessment of whether the data can still identify individuals.
Accidental and deliberate causes
A confidentiality breach can arise from either accidental events (for example, sending an email to the wrong recipient) or deliberate acts (for example, an external attack or malicious insider access). The classification depends on the outcome, unauthorised access or disclosure, rather than solely on intent.
Notification and documentation triggers
Where a confidentiality breach meets the applicable risk thresholds, notification obligations to the supervisory authority and, in higher-risk cases, to affected individuals may be engaged. All breaches, including confidentiality breaches, are generally expected to be documented internally regardless of whether they are notifiable, subject to assessment against the current official text.

Common questions

Answers to the questions practitioners most commonly ask about Confidentiality Breach.

Does a confidentiality breach always have to be reported to the supervisory authority?
No. Notification to the supervisory authority is not automatic for every confidentiality breach. Under the GDPR's breach notification regime, notification generally turns on a risk assessment: whether the breach is likely to result in a risk to the rights and freedoms of natural persons. A confidentiality breach that is unlikely to result in such a risk may not require authority notification, though the controller should still document its reasoning. You should verify the specific notification thresholds and timing against the current official text, and note that member state and UK GDPR positions can differ.
Is a confidentiality breach the same thing as any security incident?
Not necessarily. A confidentiality breach is a specific type of personal data breach involving unauthorised or accidental disclosure of, or access to, personal data. Many security incidents do not involve personal data at all, or involve availability or integrity rather than confidentiality. The GDPR distinguishes confidentiality, integrity, and availability breaches as three categories of personal data breach, and an incident can fall into more than one category. Classifying an incident precisely is a fact-specific assessment.
How should we determine whether a confidentiality breach is likely to result in a risk to individuals?
Assessment typically considers factors such as the nature and volume of the personal data affected, the sensitivity of that data (including whether special category data under Article 9 is involved), the ease with which individuals could be identified, the potential consequences for those individuals, and whether any protective measures such as encryption rendered the data unintelligible. Regulatory guidance sets out such factors, and the weighting is context dependent. Document the assessment as it is made, and consult current guidance for the applicable criteria.
What should we record about a confidentiality breach even if we conclude it need not be notified?
The GDPR generally requires controllers to document personal data breaches regardless of whether they are notified, including the facts of the breach, its effects, and the remedial action taken. For a confidentiality breach this typically means recording what data was disclosed or accessed, how the exposure occurred, the assessment of risk to individuals, the rationale for any decision not to notify, and any mitigation steps. This internal record supports accountability and may be reviewed by a supervisory authority.
Who is responsible for handling a confidentiality breach when a processor is involved?
Roles should be distinguished carefully. A processor that becomes aware of a personal data breach is generally required to inform the controller without undue delay, but the primary obligations to assess risk and, where applicable, notify the supervisory authority and affected individuals typically rest with the controller. The Data Processing Agreement under Article 28 usually specifies breach handling, notification timelines, and cooperation duties between the parties. Confirm the allocation of responsibilities against the contract and the current legal text.
How does encryption affect the handling of a confidentiality breach?
Where affected personal data was rendered unintelligible to unauthorised persons, for example through appropriate encryption with keys not compromised, the risk to individuals may be reduced, which can affect whether notification to affected individuals is required. However, this is an assessment rather than an automatic exemption: the strength of the measure, whether keys were exposed, and the surrounding circumstances all matter. Encryption is one factor in the risk analysis, not a guarantee that a breach need not be addressed.

Common misconceptions

A confidentiality breach only occurs when an external attacker steals data.
Confidentiality breaches frequently arise from internal and accidental causes, such as misdirected correspondence or inappropriate internal access. The determining factor is unauthorised access to or disclosure of personal data, not whether an external threat actor was involved.
Every confidentiality breach must be reported to the supervisory authority and to affected individuals.
Notification obligations are risk-based rather than automatic. Reporting to a supervisory authority is generally required where the breach is likely to result in a risk to individuals, and notification to individuals is typically required only where there is a high risk. The specific thresholds and timing should be verified against the current official text, and regulator guidance on assessment may vary.
Confidentiality, integrity, and availability breaches are interchangeable labels.
These are three distinct categories of personal data breach. A confidentiality breach concerns unauthorised disclosure or access, an integrity breach concerns unauthorised alteration, and an availability breach concerns loss of access to or destruction of data. A single incident can fall into more than one category, and each should be assessed accordingly.

Best practices

Assess each suspected confidentiality breach against the relevant risk thresholds to determine whether notification to the supervisory authority or affected individuals is required, and document the reasoning even where notification is not triggered.
Maintain an internal breach register that records all breaches, including confidentiality breaches, capturing the facts, effects, and remedial action taken, so that the record can be verified against the applicable documentation requirements.
Confirm whether the data involved is personal data of identifiable individuals before classifying an incident as a personal data breach, and evaluate whether any purported anonymisation genuinely prevents re-identification.
Address both accidental and deliberate causes in breach prevention measures, including controls over internal access and processes that reduce misdirected communications, in line with the security principle.
Establish clear internal escalation and timing procedures so that any applicable notification deadlines can be met, and verify the current deadlines and thresholds against the official regulatory text.
Where the incident may involve more than one breach category, assess it separately as a potential confidentiality, integrity, and availability breach rather than assuming a single classification.