Unauthorised Disclosure or Access
Unauthorised disclosure or access happens when personal information is exposed to, or reached by, someone who is not permitted to see or use it. For example, information being revealed to a third party who has no authorisation, or a person gaining entry to a system without the owner's permission. It is one of the main ways a data breach can occur, alongside loss of information.
Unauthorised disclosure refers to an event in which information is exposed or made available to entities or individuals not authorised to access it, thereby compromising confidentiality (see NIST CSRC; ScienceDirect). Unauthorised access refers to gaining entry to a system, whether physical or electronic, without the permission of the owner or controller (see BrightSec). In data protection terms, both are typically treated as forms of personal data breach: the Australian OAIC, for instance, characterises a data breach as unauthorised access to or disclosure of personal information, or loss of personal information. The evidence provided draws on sources spanning US federal guidance, Australian privacy regulation, and general information-security literature rather than the GDPR text itself; readers should note that the precise definition, notification thresholds, and consequences of a personal data breach vary by jurisdiction and should be verified against the applicable instrument (for example, the relevant GDPR provisions and any national implementing law or member state derogations). The boundary of this term lies with what constitutes 'authorisation' and whether the data in question is personal data within the relevant regime's scope; anonymous data generally falls outside such scope.
Why it matters
Unauthorised disclosure or access sits at the heart of what most data protection regimes recognise as a personal data breach. Across the sources reviewed, from US federal guidance to Australian privacy regulation, the concept is consistently framed as a compromise of confidentiality: information reaching or being revealed to someone who is not permitted to have it. Because it is one of the principal ways a breach can occur, alongside loss of information, identifying and characterising these events accurately is a foundational step in any incident response and breach-assessment process.
The practical significance lies in the consequences that can follow. The Australian OAIC notes that data breaches can have serious consequences, and the same logic underpins breach-notification frameworks generally. Whether a particular unauthorised disclosure or access triggers a notification obligation, and to whom, depends on the applicable law rather than on the label alone. Notification thresholds, timelines, and consequences vary by jurisdiction, so an event that must be reported under one regime may be assessed differently under another. Readers should verify the specific requirements against the applicable instrument, including the relevant GDPR provisions and any national implementing law or member state derogations, rather than assuming a uniform standard.
The boundary of the term also matters for compliance scoping. Whether an event counts as unauthorised disclosure or access turns on two questions: what constitutes authorisation in the relevant context, and whether the data involved is personal data within the regime's scope. Anonymous data generally falls outside that scope, so an exposure of genuinely anonymous information would typically not be treated as a personal data breach. Organisations should therefore assess both the nature of the access and the nature of the data before reaching a conclusion.
Who it's relevant to
Inside Unauthorised Disclosure or Access
Common questions
Answers to the questions practitioners most commonly ask about Unauthorised Disclosure or Access.