Skip to main content
Category: Security & Breach Notification

Nature of the Breach

Simply put

In data protection, the "nature of the breach" is the description of what actually happened in a personal data breach, for example whether personal data was lost, stolen, altered, exposed, or made unavailable. It is one of the key pieces of information an organisation is generally expected to describe when it reports a personal data breach to a supervisory authority. It helps explain the character and circumstances of the incident so that the risk to affected individuals can be understood.

Formal definition

"Nature of the breach" refers to the required description of the personal data breach set out in GDPR Article 33(3)(a), which forms part of the content a controller must, where feasible, include when notifying a competent supervisory authority. Under Article 33(3)(a) the notification must describe the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned. This element characterises the incident, typically framed against the recognised breach types of confidentiality, integrity, and availability breaches, and, together with the other Article 33(3) elements, supports assessment of the risk to the rights and freedoms of natural persons that drives notification and communication obligations. The evidence packet provided does not contain sources addressing the GDPR meaning of this term; the definition above reflects the GDPR framework generally, and readers should verify the precise wording and article references against the current official text of the Regulation (and the UK GDPR, where the corresponding provision applies).

Why it matters

The nature of the breach is the anchor for an organisation's entire breach-response analysis. Under GDPR Article 33(3)(a), a controller must, where feasible, describe the nature of the personal data breach when notifying a supervisory authority. Getting this description right matters because it frames how the risk to the rights and freedoms of affected individuals is assessed, and that risk assessment generally determines whether notification to the authority is required at all (typically within the timeframe set by Article 33) and whether affected individuals must also be informed under Article 34. A mischaracterised or vague description can lead an organisation to under- or over-estimate risk, and can undermine the credibility of its overall response.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy teams coordinate the breach assessment and often draft or review the supervisory authority notification. Accurately describing the nature of the breach is central to their risk analysis and to deciding whether Article 33 and Article 34 obligations are triggered.
Incident Response and Security Engineers
Technical teams establish the facts of what happened, whether data was exposed, altered, lost, or made unavailable, and classify the incident against confidentiality, integrity, and availability breach types. Their findings supply the factual basis for the nature described in any notification.
Compliance and Legal Counsel
Counsel translate the technical findings into a description that satisfies Article 33(3)(a) and support the risk assessment that determines notification timing and scope. They also account for divergence between EU and UK GDPR positions and relevant regulator guidance, subject to assessment of the specific incident.
Data Processors
Processors are generally required to notify the controller of a personal data breach without undue delay under Article 33(2). Their initial account of the nature of the breach feeds the controller's assessment, so clear characterisation at this stage is important even though the controller carries the supervisory authority notification duty.

Inside Nature of the Breach

Categories of Data Subjects Affected
A description of the types of individuals whose personal data is involved in the breach (for example, customers, employees, patients, or children). Article 33(3)(a) GDPR requires that a notification to the supervisory authority describe, where possible, the categories and approximate number of data subjects concerned.
Categories of Personal Data Records Affected
A description of the types of personal data records involved, such as contact details, financial data, or special category data under Article 9. The nature of the breach includes, where possible, the categories and approximate number of personal data records concerned per Article 33(3)(a).
Type of Breach
Whether the incident involves a breach of confidentiality (unauthorised or accidental disclosure of, or access to, personal data), integrity (unauthorised or accidental alteration), or availability (accidental or unlawful loss of access to, or destruction of, personal data). These three categories derive from guidance interpreting the personal data breach definition; a single incident may fall into more than one category.
Circumstances and Cause
The factual context of how the breach occurred, for example a lost device, a phishing-enabled intrusion, misdirected communication, or a system misconfiguration. This helps characterise the breach but should be distinguished from the separate risk assessment used to decide notification thresholds.
Approximate Scale
The approximate number of data subjects and records affected. GDPR uses qualified language ('where possible' and 'approximate'), recognising that precise figures may not be available at the time of initial notification and can be supplemented in phases.

Common questions

Answers to the questions practitioners most commonly ask about Nature of the Breach.

Does 'nature of the breach' refer to a breach of contract in the GDPR context?
No. Within data protection practice, 'nature of the breach' refers to a personal data breach as addressed in the Article 33(3)(a) notification requirement, not to a contractual breach. It describes the characteristics of an incident involving personal data, for example, whether it was a confidentiality, integrity, or availability breach, rather than a failure to perform contractual obligations. Practitioners should treat this term as part of the security and breach-notification vocabulary.
Is this concept unrelated to data-protection law?
No. In the privacy and GDPR context, describing the nature of the breach is an express element of the information a controller generally must provide when notifying a supervisory authority under Article 33(3)(a). It is therefore directly tied to data-protection law and breach-notification obligations, and the same descriptive information typically informs communication to affected individuals under Article 34 where required.
What information should we capture when documenting the nature of a personal data breach?
Documentation generally captures how the personal data was compromised, for instance, whether the breach affected confidentiality (unauthorised disclosure or access), integrity (unauthorised alteration), or availability (loss or destruction of data), and often a combination of these. It typically records what happened, the affected data types, the systems or processes involved, and the sequence of events. This descriptive record supports the Article 33(3)(a) notification content and internal record-keeping under Article 33(5). The precise level of detail expected can vary, so verify against current supervisory authority guidance.
How does the nature of the breach influence whether we must notify?
The nature of the breach feeds into the risk assessment that generally drives notification decisions. Notification to a supervisory authority is typically required unless the breach is unlikely to result in a risk to the rights and freedoms of individuals, and communication to affected individuals is generally required where a high risk exists. Understanding the type of breach, confidentiality, integrity, or availability, helps assess likely severity and impact. This is a risk-based assessment, so outcomes are context dependent and should be evaluated case by case.
Who should be responsible for describing the nature of the breach internally?
Responsibility typically sits with the controller, often coordinated by the data protection officer where one is appointed, together with security, IT, and incident-response teams who understand the technical facts. Where a processor is involved, it generally must inform the controller without undue delay under Article 33(2) and provide the relevant details, but the description that reaches the supervisory authority is usually the controller's responsibility. Allocation of these tasks should be reflected in internal incident-response procedures and, where relevant, in the Article 28 processing arrangements.
What if we cannot fully characterise the nature of the breach within the notification timeframe?
Where full details are not available in time, information may generally be provided in phases as permitted under Article 33(4), with the initial notification describing the nature of the breach to the extent known and further detail following as the investigation progresses. The description should be updated as facts become clearer, and the reasons for any delay in the initial notification should be documented. Specific expectations on phased notification and timing can vary between regulators, so confirm the current position with the relevant supervisory authority.

Common misconceptions

The 'nature of the breach' is the same as its likely consequences and the risk to individuals.
Under Article 33(3), the nature of the breach (point (a)) is a distinct element from the description of likely consequences (point (c)) and the measures taken or proposed (point (d)). The nature describes what happened and what data and individuals are involved; the risk assessment is a separate exercise that informs whether and how notification obligations are triggered.
Describing the nature of the breach requires exact, final numbers before notifying the supervisory authority.
Article 33(3)(a) uses qualified language such as 'where possible' and 'approximate.' In most cases regulators accept an initial description based on the information available, with phased or supplementary updates as the investigation develops. Waiting for complete figures should not delay a required notification beyond applicable timeframes.
Every personal data breach must be described and notified in the same way regardless of impact.
Whether notification to the supervisory authority or communication to affected individuals is required generally depends on a risk assessment, not merely on the fact that a breach occurred. Characterising the nature of the breach is an input to that assessment; obligations vary with the likelihood and severity of risk, and specifics can be affected by member state implementing law and regulator guidance.

Best practices

Maintain an internal breach record that captures the nature of each incident, including breach type (confidentiality, integrity, availability), categories of data subjects, and categories of personal data, so that Article 33(3)(a) information can be assembled quickly.
Use the categorisation of the breach to feed, but keep distinct from, the separate assessment of likely consequences and risk to individuals under Article 33(3)(c).
Adopt a phased notification approach where full details are not yet known, providing an initial description with approximate figures and supplementing it as facts are confirmed, consistent with the 'where possible' language in the text.
Flag at the point of characterisation whether special category data under Article 9 is involved, since this can materially affect the risk assessment and downstream obligations.
Document the reasoning behind how a breach was characterised and any decision on whether to notify, to support the accountability principle and demonstrate the assessment to a supervisory authority if asked.
Verify applicable notification timeframes, thresholds, and any variations under UK GDPR or relevant member state implementing law against the current official text and regulator guidance, as these can diverge and evolve.