Skip to main content
Category: Security & Breach Notification

Identity Theft

Also known as: identity fraud
Simply put

Identity theft happens when someone uses your personal or financial information without your permission, typically to commit fraud or other crimes. The information involved can include details such as your name and address, Social Security number, bank account numbers, or credit card data. Recovering from identity theft is generally a process that may involve reporting the incident and taking steps to limit and repair the damage.

Formal definition

Identity theft is the unauthorized acquisition and use of an individual's personal or financial identifiers, such as name, address, Social Security number, bank account numbers, or credit card data, to commit fraud or other crimes. It typically encompasses both the compromise of identifying information and its subsequent misuse, and remediation generally involves reporting to relevant authorities and taking corrective actions (for example, addressing credit-related harm). Note: the evidence provided reflects US consumer-protection framing; identity theft is not itself a defined term under the GDPR, and readers should distinguish it from related data protection concepts (such as personal data breaches) and verify applicable legal definitions in their own jurisdiction.

Why it matters

Identity theft can cause significant and lasting harm to individuals, affecting their finances, credit standing, and ability to conduct everyday transactions. Because the misuse of stolen identifiers, such as a name, address, Social Security number, bank account numbers, or credit card data, can occur repeatedly and across multiple accounts, the damage is often not confined to a single event. As the evidence indicates, recovering from identity theft is generally a process rather than a one-time fix, typically involving reporting the incident and taking steps to limit and repair the harm, including addressing credit-related consequences.

For organizations that hold personal or financial identifiers, identity theft is a downstream risk that underscores why safeguarding such data matters. It is important to distinguish identity theft, which is the unauthorized acquisition and misuse of an individual's identifiers, from related data protection concepts such as a personal data breach, which concerns the security of personal data held by a controller or processor. Identity theft is not itself a defined term under the GDPR; the evidence and much of the available guidance reflect US consumer-protection framing, so readers should verify the applicable legal definitions and obligations in their own jurisdiction.

Who it's relevant to

Individuals and consumers
Individuals whose personal or financial identifiers are misused are directly affected by identity theft. The available consumer-protection guidance describes recovery as a process that may involve reporting the incident and taking steps to limit and repair the damage, including credit-related harm. Warning signs and reporting steps are addressed in general consumer guidance, which individuals should consult for their own jurisdiction.
Data protection and compliance professionals
Data protection officers and compliance leads should treat identity theft as a downstream harm that can result from the compromise of identifiers held by an organization. It is important to distinguish identity theft from a personal data breach and other data protection concepts, and to recognize that identity theft is not a defined term under the GDPR. Applicable definitions and obligations should be verified against the relevant law in each jurisdiction.
Security and engineering teams
Teams responsible for protecting systems that store personal or financial identifiers, such as names, addresses, Social Security numbers, bank account numbers, or credit card data, are relevant because the compromise of such data can enable identity theft. Their controls aim to reduce the likelihood of unauthorized acquisition of identifying information.

Inside Identity Theft

Fraudulent use of personal data
Identity theft typically involves the unauthorised acquisition and use of an individual's personal data (such as name, identification numbers, financial details, or authentication credentials) to impersonate that person, generally for financial gain or other advantage.
Relationship to a personal data breach
Under the GDPR, identity theft is not itself a defined term but is commonly recognised in guidance as a possible consequence or risk arising from a personal data breach. A breach exposing identifying data can enable identity theft, which is relevant when assessing risk to the rights and freedoms of data subjects.
Risk assessment trigger
The potential for identity theft is a factor practitioners typically weigh when assessing the severity of a breach for the purposes of notification obligations and when determining the likely impact on affected individuals. The precise thresholds and criteria should be verified against the current official text and applicable regulatory guidance.
Categories of data commonly implicated
Data frequently associated with identity theft risk includes government-issued identifiers, financial account information, and authentication data. Where special category data under Article 9 is involved, an additional condition beyond an Article 6 legal basis is generally required for its processing.
Interaction with national and criminal law
Identity theft is often addressed as a criminal or civil matter under member state national law rather than by the GDPR itself. The GDPR's role is generally centred on the protection and security of personal data and on obligations that arise when that data is compromised. The position can vary between member states and under the UK GDPR.

Common questions

Answers to the questions practitioners most commonly ask about Identity Theft.

Is identity theft the same thing as a personal data breach under the GDPR?
No. Identity theft describes the fraudulent use of another person's identifying information, typically to impersonate them or obtain goods, services, or credit. A personal data breach is a separate legal concept concerning a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. A breach may create conditions that later enable identity theft, but the two are distinct: a breach can occur without any identity theft following, and identity theft can arise from sources unrelated to any single controller's breach. You should assess each concept against its own criteria rather than treating them as interchangeable.
Does the GDPR contain a specific offence or article dealing with identity theft?
The GDPR is a data protection framework rather than a criminal statute, and identity theft as such is generally addressed through national criminal law, fraud legislation, and member state implementing measures, which vary. The Regulation is relevant because the misuse of personal data can engage controllers' obligations around security, breach handling, and the rights of affected individuals, and because the risk of identity theft is a factor typically weighed when assessing the severity of a breach. Treat identity theft primarily as a criminal and fraud matter, and verify the applicable offences against the relevant national law rather than assuming a GDPR provision governs it directly.
How should the risk of identity theft factor into a personal data breach assessment?
When assessing a breach, the potential for identity theft or fraud is generally treated as an indicator of risk to the rights and freedoms of affected individuals, and it can influence whether notification to a supervisory authority or communication to data subjects is required. Factors typically considered include the type of data involved, whether identifiers that facilitate impersonation are present, the ease of linking data to a person, and the number of individuals affected. This is a context-specific assessment, and the precise thresholds and expectations can differ between regulators, so document your reasoning and verify against current supervisory authority guidance.
What technical and organisational measures typically help reduce identity theft risk?
Measures often deployed include data minimisation to limit the identifiers held, encryption and pseudonymisation to reduce the utility of data if exposed, strong authentication and access controls, and monitoring for unusual access patterns. The appropriate measures depend on the nature, scope, context, and purposes of processing and on the risks to individuals, so they should be selected following a risk assessment rather than adopted as a fixed checklist. No single control eliminates the risk entirely, and the effectiveness of measures should be reviewed periodically.
How should identity verification requests be handled to avoid facilitating identity theft?
When responding to data subject requests or account access, controllers generally need to take reasonable steps to confirm the identity of the requester so that personal data is not disclosed to an impersonator. At the same time, verification should be proportionate and should not require the collection of excessive additional data. Balancing these considerations is context-dependent, and approaches may need to reflect regulator guidance on identity verification, so document the rationale for the verification method chosen and revisit it if requirements change.
What should an organisation do if it becomes aware that a breach may lead to identity theft?
Where a breach is likely to result in a risk such as identity theft, the organisation should follow its breach response process, which may include assessing severity, considering whether notification to the supervisory authority is required, and considering whether affected individuals should be informed so they can take protective steps. The specific obligations and timeframes derive from the applicable breach provisions and can vary by jurisdiction and regulator expectation, so confirm the current requirements and thresholds against the official text and relevant guidance before acting.

Common misconceptions

Identity theft is a formally defined term within the GDPR.
The GDPR does not, in its operative text, provide a standalone legal definition of identity theft. It is typically referenced in recitals and regulatory guidance as an example of a harm that can result from a personal data breach, and it is often governed substantively by national criminal or civil law. Readers should verify specifics against the current official text.
Any breach that could lead to identity theft automatically requires notification to individuals.
Notification obligations generally depend on an assessment of the likelihood and severity of risk to affected individuals. The potential for identity theft is one relevant factor, but the outcome is context and risk dependent, and thresholds should be assessed case by case and verified against applicable guidance.
Preventing identity theft is solely a data security matter.
While security measures are important, addressing identity theft risk also intersects with lawful processing, data minimisation, retention practices, and, in many cases, national criminal law. Treating it purely as a technical security issue can overlook these broader obligations.

Best practices

Assess and document the potential for identity theft when evaluating the risk severity of a personal data breach, so that notification decisions are supported by a recorded rationale.
Apply data minimisation and appropriate retention limits to identifying and financial data to reduce the volume of information exposed if a breach occurs.
Give particular attention to any special category data under Article 9, ensuring an appropriate additional condition applies to its processing alongside an Article 6 legal basis.
Implement and regularly review technical and organisational security measures proportionate to the risk, recognising that no set of measures can be presented as guaranteeing full compliance.
Check the interaction with applicable national criminal or civil law, and note that the position may differ between EU member states and under the UK GDPR.
Verify notification thresholds, timelines, and terminology against the current official text and up-to-date regulatory guidance rather than relying on a fixed snapshot.