Readiness assessment

Concept

Personal Data Breach

A personal data breach is any unauthorised or accidental event that compromises the confidentiality, integrity or availability of personal data.

Defined inSection 2(u)
CategoryCore Concepts
Applies toAny incident affecting personal data security

What the Act says

DPDP Act 2023, Section 2(u)

"personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.

In plain language

A breach is not only a hack. Accidental disclosure, loss of access, or unauthorised alteration all count if they compromise the data.

The definition maps to the classic security triad: confidentiality (who can see it), integrity (whether it is accurate and intact), and availability (whether you can reach it).

Example

Emailing a spreadsheet of customers to the wrong recipient is a breach, even though no attacker was involved.

Related terms

Related sections of the Act

Related Rules

Frequently asked questions

Is a ransomware lockout a breach?

Yes. Loss of access that compromises availability falls within the definition.

Does a breach have to be malicious?

No. Accidental disclosure or loss is expressly included.

Continue learning