Breach Notification and DPIAs
Responding to and assessing privacy risk.
What Counts as a Breach
A personal data breach is a security incident leading to accidental or unlawful destruction, loss, alteration, disclosure, or unauthorized access to personal data.
It is broader than a hack. A lost laptop, a misaddressed email, ransomware that encrypts (loses availability of) personal data, or an exposed S3 bucket all qualify.
The CIA Lens
Breaches map to the three security pillars:
- Confidentiality breach: unauthorized disclosure or access
- Integrity breach: unauthorized alteration
- Availability breach: loss or destruction (e.g., ransomware)
Recognizing that availability loss is also a reportable breach is a common blind spot.
All lessons in this course
- Why Data Privacy Matters
- GDPR and KVKK Essentials
- Data Classification and Minimization
- Breach Notification and DPIAs