Legal and Compliance

Personal Data Breach

Also called data breach, breach notification

A security incident that leads to personal data being lost, altered, disclosed or accessed without permission, by accident or on purpose.

Quick facts: Personal Data Breach

Category
Legal and Compliance
Also called
data breach, breach notification
Level
Beginner
Affects
Customer trust, ICO enforcement risk, email lists, CRM data, enquiry forms
Where to see it
ICO breach reporting form, breach log, CRM and email platform user access settings
In this article4
  1. How a personal data breach works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A personal data breach is a security incident that leads to personal data being lost, destroyed, changed, disclosed to someone who should not have it, or accessed without permission, whether by accident or deliberately. It is not only hacking: emailing a customer list to the wrong person is a breach too.

How a personal data breach works

UK GDPR defines a breach broadly. It covers confidentiality (data seen by the wrong people), integrity (data changed without authority) and availability (data lost or locked away, for example by ransomware or a deleted account with no backup).

In marketing, breaches are usually ordinary mistakes rather than cyber attacks:

  • A newsletter or event invitation sent with every recipient in the CC field instead of BCC, exposing hundreds of email addresses to each other.
  • A CRM export saved to a shared drive with a public link, or attached to an email to a freelancer.
  • A website enquiry form that sends submissions to a former employee’s mailbox, or stores them on a page search engines can find.
  • An agency that still has access to the email platform months after the contract ended.
  • A customer list for an ad audience shared through a personal file-transfer account.

Once you become aware of a breach, the clock starts. If it is likely to result in a risk to people’s rights and freedoms, you must report it to the ICO within 72 hours. If the risk is high, for example where health details, financial information or passwords are exposed, you must also tell the people affected without undue delay. Whether you report or not, you must keep an internal record of every breach: what happened, its effects and what you did about it.

If an agency, freelancer or software provider handles data on your behalf, it is normally a processor and must tell you without undue delay; you, as the controller, decide whether to report. The controller and processor roles settle who does what.

Why it matters

Marketing teams hold large amounts of personal data spread across many tools: the CRM, the email platform, ad accounts, form plugins and spreadsheets. Every copy is another place a breach can happen. A missed 72-hour deadline, or a breach that reveals weak basic security, tends to make an ICO investigation more likely and more serious than the original slip would justify.

Trust is the other cost. Telling customers their data was exposed is uncomfortable, and complaints and unsubscribes usually follow. The kind of data matters too: a private clinic that exposes patient enquiries, which may describe symptoms, has a far more serious breach than a shop exposing a list of names.

Common mistakes

  • Not recognising a CC email or wrong attachment as a breach, so nothing is recorded or assessed.
  • Waiting to finish the investigation before reporting; you can report what you know within 72 hours and add detail later.
  • Keeping old exports in downloads folders and shared drives long after the campaign ended.
  • Giving every freelancer full admin access to the CRM and never removing it.
  • Having no contract requiring processors to report breaches to you promptly.

How to act on it

Write a one-page breach procedure before you need it: who to tell internally, how to contain the incident, how to judge the risk, and how to report through the ICO’s online form. Keep a breach log, even if most entries are minor and never reported.

Then shrink the places a breach can happen. Use BCC or your email platform for any group message. Export only the fields you need and delete exports when you finish. Review who has access to each marketing tool every quarter, and send form notifications to a shared, monitored inbox. When I review a business’s tools as part of a digital marketing strategy, I list every system that holds customer data and who can reach it, because forgotten access is one of the easiest gaps to close.

Do and do not

Do

  • Keep a breach log and a one-page response procedure
  • Report risky breaches to the ICO within 72 hours
  • Review user access to marketing tools every quarter

Do not

  • Send group emails with recipients in CC
  • Leave CRM exports on shared drives
  • Wait for a full investigation before reporting

Questions people ask about this

Is sending an email with everyone in CC a reportable breach?

It is always a breach, because addresses were disclosed to people who should not have them. Whether you must report it to the ICO depends on the risk. A handful of business contacts may be low risk, but a list that reveals people are clients of a clinic, a debt service or a support group exposes sensitive information, and the ICO has taken action against organisations for exactly this mistake.

What if I cannot work out the full facts within 72 hours?

Report what you know within the deadline, explain what you are still investigating and send the rest when you have it. The ICO accepts reports in stages. If you decide a breach does not need reporting, record your reasons in your breach log so you can show how you reached that decision.

If my agency causes a breach, who is responsible?

Usually you, as the controller, remain responsible for deciding whether to report and for telling the people affected. The agency, as a processor, must tell you without undue delay and help you respond. Your data processing agreement should set out how quickly it must notify you and what information it will provide.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.