Identity Theft
Identity theft happens when someone uses your personal or financial information without your permission, typically to commit fraud or other crimes. The information involved can include details such as your name and address, Social Security number, bank account numbers, or credit card data. Recovering from identity theft is generally a process that may involve reporting the incident and taking steps to limit and repair the damage.
Identity theft is the unauthorized acquisition and use of an individual's personal or financial identifiers, such as name, address, Social Security number, bank account numbers, or credit card data, to commit fraud or other crimes. It typically encompasses both the compromise of identifying information and its subsequent misuse, and remediation generally involves reporting to relevant authorities and taking corrective actions (for example, addressing credit-related harm). Note: the evidence provided reflects US consumer-protection framing; identity theft is not itself a defined term under the GDPR, and readers should distinguish it from related data protection concepts (such as personal data breaches) and verify applicable legal definitions in their own jurisdiction.
Why it matters
Identity theft can cause significant and lasting harm to individuals, affecting their finances, credit standing, and ability to conduct everyday transactions. Because the misuse of stolen identifiers, such as a name, address, Social Security number, bank account numbers, or credit card data, can occur repeatedly and across multiple accounts, the damage is often not confined to a single event. As the evidence indicates, recovering from identity theft is generally a process rather than a one-time fix, typically involving reporting the incident and taking steps to limit and repair the harm, including addressing credit-related consequences.
For organizations that hold personal or financial identifiers, identity theft is a downstream risk that underscores why safeguarding such data matters. It is important to distinguish identity theft, which is the unauthorized acquisition and misuse of an individual's identifiers, from related data protection concepts such as a personal data breach, which concerns the security of personal data held by a controller or processor. Identity theft is not itself a defined term under the GDPR; the evidence and much of the available guidance reflect US consumer-protection framing, so readers should verify the applicable legal definitions and obligations in their own jurisdiction.
Who it's relevant to
Inside Identity Theft
Common questions
Answers to the questions practitioners most commonly ask about Identity Theft.