A personal data breach is a security incident that leads to personal data being lost, destroyed, changed, disclosed to someone who should not have it, or accessed without permission, whether by accident or deliberately. It is not only hacking: emailing a customer list to the wrong person is a breach too.
How a personal data breach works
UK GDPR defines a breach broadly. It covers confidentiality (data seen by the wrong people), integrity (data changed without authority) and availability (data lost or locked away, for example by ransomware or a deleted account with no backup).
In marketing, breaches are usually ordinary mistakes rather than cyber attacks:
- A newsletter or event invitation sent with every recipient in the CC field instead of BCC, exposing hundreds of email addresses to each other.
- A CRM export saved to a shared drive with a public link, or attached to an email to a freelancer.
- A website enquiry form that sends submissions to a former employee’s mailbox, or stores them on a page search engines can find.
- An agency that still has access to the email platform months after the contract ended.
- A customer list for an ad audience shared through a personal file-transfer account.
Once you become aware of a breach, the clock starts. If it is likely to result in a risk to people’s rights and freedoms, you must report it to the ICO within 72 hours. If the risk is high, for example where health details, financial information or passwords are exposed, you must also tell the people affected without undue delay. Whether you report or not, you must keep an internal record of every breach: what happened, its effects and what you did about it.
If an agency, freelancer or software provider handles data on your behalf, it is normally a processor and must tell you without undue delay; you, as the controller, decide whether to report. The controller and processor roles settle who does what.
Why it matters
Marketing teams hold large amounts of personal data spread across many tools: the CRM, the email platform, ad accounts, form plugins and spreadsheets. Every copy is another place a breach can happen. A missed 72-hour deadline, or a breach that reveals weak basic security, tends to make an ICO investigation more likely and more serious than the original slip would justify.
Trust is the other cost. Telling customers their data was exposed is uncomfortable, and complaints and unsubscribes usually follow. The kind of data matters too: a private clinic that exposes patient enquiries, which may describe symptoms, has a far more serious breach than a shop exposing a list of names.
Common mistakes
- Not recognising a CC email or wrong attachment as a breach, so nothing is recorded or assessed.
- Waiting to finish the investigation before reporting; you can report what you know within 72 hours and add detail later.
- Keeping old exports in downloads folders and shared drives long after the campaign ended.
- Giving every freelancer full admin access to the CRM and never removing it.
- Having no contract requiring processors to report breaches to you promptly.
How to act on it
Write a one-page breach procedure before you need it: who to tell internally, how to contain the incident, how to judge the risk, and how to report through the ICO’s online form. Keep a breach log, even if most entries are minor and never reported.
Then shrink the places a breach can happen. Use BCC or your email platform for any group message. Export only the fields you need and delete exports when you finish. Review who has access to each marketing tool every quarter, and send form notifications to a shared, monitored inbox. When I review a business’s tools as part of a digital marketing strategy, I list every system that holds customer data and who can reach it, because forgotten access is one of the easiest gaps to close.
