Skip to main content
Category: Security & Breach Notification

Unauthorised Disclosure or Access

Also known as: Unauthorised Access or Disclosure, Unauthorized Disclosure, Unauthorized Access
Simply put

Unauthorised disclosure or access happens when personal information is exposed to, or reached by, someone who is not permitted to see or use it. For example, information being revealed to a third party who has no authorisation, or a person gaining entry to a system without the owner's permission. It is one of the main ways a data breach can occur, alongside loss of information.

Formal definition

Unauthorised disclosure refers to an event in which information is exposed or made available to entities or individuals not authorised to access it, thereby compromising confidentiality (see NIST CSRC; ScienceDirect). Unauthorised access refers to gaining entry to a system, whether physical or electronic, without the permission of the owner or controller (see BrightSec). In data protection terms, both are typically treated as forms of personal data breach: the Australian OAIC, for instance, characterises a data breach as unauthorised access to or disclosure of personal information, or loss of personal information. The evidence provided draws on sources spanning US federal guidance, Australian privacy regulation, and general information-security literature rather than the GDPR text itself; readers should note that the precise definition, notification thresholds, and consequences of a personal data breach vary by jurisdiction and should be verified against the applicable instrument (for example, the relevant GDPR provisions and any national implementing law or member state derogations). The boundary of this term lies with what constitutes 'authorisation' and whether the data in question is personal data within the relevant regime's scope; anonymous data generally falls outside such scope.

Why it matters

Unauthorised disclosure or access sits at the heart of what most data protection regimes recognise as a personal data breach. Across the sources reviewed, from US federal guidance to Australian privacy regulation, the concept is consistently framed as a compromise of confidentiality: information reaching or being revealed to someone who is not permitted to have it. Because it is one of the principal ways a breach can occur, alongside loss of information, identifying and characterising these events accurately is a foundational step in any incident response and breach-assessment process.

The practical significance lies in the consequences that can follow. The Australian OAIC notes that data breaches can have serious consequences, and the same logic underpins breach-notification frameworks generally. Whether a particular unauthorised disclosure or access triggers a notification obligation, and to whom, depends on the applicable law rather than on the label alone. Notification thresholds, timelines, and consequences vary by jurisdiction, so an event that must be reported under one regime may be assessed differently under another. Readers should verify the specific requirements against the applicable instrument, including the relevant GDPR provisions and any national implementing law or member state derogations, rather than assuming a uniform standard.

The boundary of the term also matters for compliance scoping. Whether an event counts as unauthorised disclosure or access turns on two questions: what constitutes authorisation in the relevant context, and whether the data involved is personal data within the regime's scope. Anonymous data generally falls outside that scope, so an exposure of genuinely anonymous information would typically not be treated as a personal data breach. Organisations should therefore assess both the nature of the access and the nature of the data before reaching a conclusion.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads need to classify incidents accurately at the point of detection, distinguishing unauthorised disclosure and access from loss of information and from events involving non-personal or anonymous data. This classification typically drives whether an assessment against the applicable breach-notification framework is required. Because thresholds and definitions vary by jurisdiction, they should map each incident to the relevant instrument, for example the applicable GDPR provisions and any national implementing law, rather than relying on a single generic standard.
Privacy and Data Protection Lawyers
Legal advisers assess whether a given event meets the definition of a personal data breach under the applicable law and whether notification obligations are triggered. The evidence here spans US, Australian, and general information-security sources, so counsel should be careful to work from the controlling instrument in their jurisdiction and to note that notification thresholds and consequences differ. The contested boundary questions, what counts as authorisation and whether the data is personal data within scope, are often where legal analysis is decisive.
Security Engineers and IT Teams
Engineers implement and monitor the access controls whose failure or circumvention gives rise to unauthorised access, including entry to systems, whether physical or electronic, without the owner's or controller's permission. Their logging, detection, and access-management practices feed directly into how quickly an event is identified and how confidently it can be characterised for the compliance and legal teams that assess breach obligations.
Incident Response Teams
Those responding to incidents need a clear, shared understanding of unauthorised disclosure versus unauthorised access so that events are triaged consistently. Because data breaches can have serious consequences and the applicable notification timelines vary, response teams benefit from documented criteria for escalating events to DPOs and legal advisers for a formal assessment against the relevant instrument.

Inside Unauthorised Disclosure or Access

Unauthorised Access
The situation where personal data is accessed by a person or system that lacks the necessary authorisation or legitimate purpose to do so. This may arise externally (for example, an intrusion by a threat actor) or internally (for example, an employee viewing records outside the scope of their role). It generally falls within the concept of a personal data breach under the GDPR, which encompasses breaches of confidentiality.
Unauthorised Disclosure
The situation where personal data is made available or transmitted to a recipient that should not have received it, whether accidentally or deliberately. Examples typically include misdirected communications or improper sharing with third parties. Like unauthorised access, it generally constitutes a confidentiality breach within the broader personal data breach concept.
Relationship to Personal Data Breach
Unauthorised disclosure and unauthorised access are among the categories of security incident that make up a personal data breach as defined in the GDPR, alongside accidental or unlawful destruction, loss, and alteration. Not every security event amounts to such a breach; the assessment depends on whether personal data was affected.
Accidental versus Deliberate
The concept covers both accidental events (for example, human error leading to exposure) and deliberate acts (for example, a malicious insider or external attacker). The intent behind the event does not change whether it qualifies, though it may be relevant to assessing risk and to any subsequent enforcement or remediation.
Confidentiality Dimension of Security
Unauthorised disclosure or access primarily engages the confidentiality element of information security, as distinct from integrity (unauthorised alteration) and availability (loss or destruction). Appropriate technical and organisational measures are generally expected to protect against such events, subject to a risk-based assessment.
Assessment and Notification Considerations
Where an incident of this kind is a personal data breach, controllers generally need to assess the risk to affected individuals to determine notification obligations to the supervisory authority and, where the risk is high, to the individuals concerned. The precise thresholds and timeframes should be verified against the current official GDPR text and applicable guidance.

Common questions

Answers to the questions practitioners most commonly ask about Unauthorised Disclosure or Access.

Does an unauthorised disclosure or access always mean a reportable personal data breach?
Not automatically. An unauthorised disclosure or access is one category of personal data breach (a breach of security affecting confidentiality), but whether it must be reported depends on a risk assessment. Under the GDPR's breach notification framework, notification to a supervisory authority is generally required where the breach is likely to result in a risk to the rights and freedoms of individuals, and communication to affected individuals is generally required where there is likely to be a high risk. Some incidents may fall below these thresholds subject to assessment, and you should document the reasoning either way. Verify the applicable notification criteria and any national variations against the current official text.
Is unauthorised access only a concern when an external attacker is involved?
No. Unauthorised access is defined by whether access exceeds authorisation, not by who obtains it. This can include internal actors, such as an employee viewing records they have no business need to access, as well as external parties. It can also arise from accidental exposure, such as data made visible to the wrong recipient. The focus is on whether the access or disclosure was permitted, not solely on malicious external activity. The precise characterisation of a given incident is fact-dependent and should be assessed case by case.
How should we determine whether an unauthorised disclosure or access needs to be notified?
Typically this involves assessing the likelihood and severity of risk to affected individuals, considering factors such as the nature and volume of the data involved, whether it includes special category data under Article 9, how easily individuals could be identified, and the potential consequences such as identity theft, financial loss, or distress. Many organisations use a documented severity assessment methodology and record the outcome regardless of whether notification is triggered. Because regulator expectations and available guidance can differ, confirm the approach against current supervisory authority guidance in the relevant jurisdiction.
What should we record when we identify an unauthorised disclosure or access?
The GDPR requires controllers to document personal data breaches, generally including the facts relating to the breach, its effects, and the remedial action taken, so that the supervisory authority can verify compliance. In practice this typically covers what happened, when it was detected, the data and individuals affected, the assessed risk, the notification decision and its rationale, and containment and mitigation steps. Maintaining this internal record is expected even where the incident is assessed as not requiring notification. Check the exact documentation obligations against the current official text.
How can we reduce the likelihood of unauthorised access by internal users?
Common technical and organisational measures include role-based access controls aligned to a need-to-know principle, logging and monitoring of access to sensitive records, timely removal of access when roles change, and staff training. Such measures relate to the security obligations under the GDPR and are typically calibrated to the risk and the nature of the processing. The appropriateness of any specific control is context-dependent and should be assessed rather than assumed to be sufficient in all cases.
If we contain an unauthorised access quickly, does that remove the need to assess or notify?
Fast containment can reduce the risk to individuals and may influence the outcome of the risk assessment, but it does not by itself remove the obligation to assess the incident or, where the relevant thresholds are met, to notify. The assessment should still consider whether risk arose during the period of exposure. Whether containment sufficiently mitigates risk is a matter of judgement to be documented, and you should verify the applicable notification timing and criteria against the current official text and relevant guidance.

Common misconceptions

Any unauthorised access to a system is automatically a personal data breach requiring notification.
Whether an incident qualifies depends on whether personal data was actually affected, and notification obligations generally turn on a risk assessment for the individuals concerned. Not every security incident meets these thresholds, and the position should be assessed case by case against the current text and guidance.
Unauthorised disclosure or access only refers to external attacks by malicious third parties.
The concept typically also covers internal events, such as an employee accessing records without authorisation or a misdirected message, and it includes accidental as well as deliberate acts. The source of the event does not determine whether it falls within scope.
Unauthorised disclosure or access is a separate legal category from a personal data breach.
These events are generally sub-categories of the broader personal data breach concept under the GDPR, specifically engaging its confidentiality dimension, rather than a distinct standalone regime.

Best practices

Implement appropriate technical and organisational measures, applying a risk-based approach, to reduce the likelihood of both external and internal unauthorised access or disclosure of personal data.
Apply access controls and role-based permissions so that individuals can access only the personal data necessary for their role, and monitor for access outside those boundaries.
Establish a documented incident response process that enables prompt identification, containment, and assessment of whether an event involves personal data and constitutes a breach.
Assess each qualifying incident for the risk it poses to affected individuals to determine notification obligations, verifying applicable thresholds and timeframes against the current official GDPR text and guidance.
Maintain records of incidents and the reasoning behind notification decisions, including cases where notification was assessed as not required.
Provide staff training on recognising and reporting accidental and deliberate unauthorised access or disclosure, since internal events are a common source of such incidents.