It may result from malicious activity, human error, system failure, or misuse of legitimate access. Whether a particular event is legally a breach depends on the governing law, contract, sector, and type of data involved.
A breach does not require an external attacker or proven data theft. Investigation should establish what happened, which data and people are affected, whether unauthorized parties could access the data, and whether trustworthy versions remain available.
Key points
Event assessmentPreserve evidence, identify affected systems and records, determine the time and method of compromise, and distinguish verified facts from assumptions or unresolved possibilities.
Containment and recoveryStop continuing harm, revoke unsafe access, correct the cause, restore trustworthy data and services, and monitor for renewed access or misuse.
ObligationsEvaluate notification, documentation, contractual, insurance, and regulatory duties promptly with qualified legal review in each applicable jurisdiction.
Important limitation“Data breach” is not defined identically everywhere. Notification thresholds, deadlines, affected-data tests, and risk assessments vary; there is no universal rule that every incident must be reported within 72 hours.