Integrity Breach
An integrity breach happens when personal data is changed or corrupted without proper authorisation, whether deliberately or by accident. Unlike a breach where data is stolen or leaked, the information itself is altered or manipulated, so it may no longer be accurate or reliable. This is one recognised category of personal data breach alongside breaches affecting confidentiality and availability.
An integrity breach is a type of personal data breach characterised by the unauthorised or accidental alteration, manipulation, corruption, or destruction of personal data. It is generally distinguished from a confidentiality breach (unauthorised disclosure of, or access to, personal data) and an availability breach (accidental or unlawful loss of access to, or destruction of, personal data); a single incident may involve more than one of these categories. Integrity breaches may arise from intentional acts, such as unauthorised changes made after gaining access to systems, or from accidental events, and they can be difficult to detect where alterations are made without triggering defences. Note: the tripartite categorisation of breaches derives from regulatory guidance (notably guidance issued in relation to personal data breaches) rather than from an explicit definition of 'integrity breach' in the GDPR text; readers should verify the applicable categorisation and any notification obligations against the current official Regulation and relevant guidance. The evidence supplied includes an unrelated use of 'integrity breach' in an academic-conduct context, which is outside the scope of this data-protection definition.
Why it matters
An integrity breach can be more insidious than a breach involving theft or leakage of data, because the information itself is altered or corrupted rather than simply removed or exposed. Where personal data is changed without authorisation, it may no longer be accurate or reliable, which can undermine decisions taken on the basis of that data and erode trust in the systems that hold it. This category of breach also intersects with the accuracy principle: data that has been silently manipulated may present as complete and available while being fundamentally wrong.
Detection is a particular challenge. As some industry commentary notes, an integrity breach can occur where someone gains access to systems and quietly changes data or system behaviour without triggering defensive controls, meaning the alteration may go unnoticed for a considerable period. This makes both identification and remediation harder than in cases where data is exfiltrated and its absence or exposure is more readily apparent.
From a compliance perspective, it is important to recognise that the tripartite categorisation of breaches into confidentiality, integrity, and availability derives from regulatory guidance on personal data breaches rather than from an explicit definition of 'integrity breach' in the GDPR text itself. A single incident may fall into more than one category. Organisations should therefore assess each incident against the applicable categorisation and verify any notification obligations against the current official Regulation and relevant supervisory authority guidance, as the position may vary and evolve.
Who it's relevant to
Inside Integrity Breach
Common questions
Answers to the questions practitioners most commonly ask about Integrity Breach.