Legal and compliance
What is Data breach notification?
The obligation to report a personal data breach to the supervisory authority within 72 hours of becoming aware of it, where it is likely to risk people’s rights, and to tell the affected individuals directly where the risk is high.
Also called: personal data breach · 72-hour rule
What counts as a breach
- Unauthorised access — a compromised admin account or database
- Accidental disclosure — an email sent to the wrong list, or an exposed backup
- Loss of availability — ransomware, or a deletion with no working backup
- Alteration of data by someone without authority
What to do in the first hours
Contain it, record what you know and when you learned it, assess the likely risk to individuals, and start the notification clock from the moment of awareness rather than from the moment of certainty. A partial report on time is expected; a complete report late is not.
The preparation that makes it survivable
Know who your processors are, know what data you hold, keep a tested backup off-host, and have logging that can answer what was accessed. Every one of those is a build decision made long before an incident.
Where this is covered in depth
A definition can only go so far. Technical SEO, in the order the problems actually block you covers this properly — 4 minutes, free, no email required.
Who wrote this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan. These definitions come from client work rather than from a content brief — where an entry describes a mistake, it is usually one found on a real site. More about how I work.