Nature of the Breach
In data protection, the "nature of the breach" is the description of what actually happened in a personal data breach, for example whether personal data was lost, stolen, altered, exposed, or made unavailable. It is one of the key pieces of information an organisation is generally expected to describe when it reports a personal data breach to a supervisory authority. It helps explain the character and circumstances of the incident so that the risk to affected individuals can be understood.
"Nature of the breach" refers to the required description of the personal data breach set out in GDPR Article 33(3)(a), which forms part of the content a controller must, where feasible, include when notifying a competent supervisory authority. Under Article 33(3)(a) the notification must describe the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned. This element characterises the incident, typically framed against the recognised breach types of confidentiality, integrity, and availability breaches, and, together with the other Article 33(3) elements, supports assessment of the risk to the rights and freedoms of natural persons that drives notification and communication obligations. The evidence packet provided does not contain sources addressing the GDPR meaning of this term; the definition above reflects the GDPR framework generally, and readers should verify the precise wording and article references against the current official text of the Regulation (and the UK GDPR, where the corresponding provision applies).
Why it matters
The nature of the breach is the anchor for an organisation's entire breach-response analysis. Under GDPR Article 33(3)(a), a controller must, where feasible, describe the nature of the personal data breach when notifying a supervisory authority. Getting this description right matters because it frames how the risk to the rights and freedoms of affected individuals is assessed, and that risk assessment generally determines whether notification to the authority is required at all (typically within the timeframe set by Article 33) and whether affected individuals must also be informed under Article 34. A mischaracterised or vague description can lead an organisation to under- or over-estimate risk, and can undermine the credibility of its overall response.
Who it's relevant to
Inside Nature of the Breach
Common questions
Answers to the questions practitioners most commonly ask about Nature of the Breach.