Data breaches
A data breach record covers a security incident that affected personal data. It exists to answer the questions a regulator will ask after the fact: when did you find out, what was exposed, how many people, what was the risk to them, who did you tell and when, and what did you do about it. The register keeps all of that on one object, with the notification timestamps you will be asked to produce.
Where to find it
Section titled “Where to find it”Privacy → Data Breaches in the sidebar. Record a data breach opens the form.
The record
Section titled “The record”Identification — Ref ID, Name, Description, Domain, Assigned to, and Discovered on, a date and time, because the 72-hour notification window runs from the moment of awareness.
Classification — Breach type is one of Destruction, Loss, Alteration, Unauthorized Disclosure, Unauthorized Access or Other. Risk level is your assessment of the risk to the individuals: No Risk, Risk or High Risk. That judgement is what decides your duties — a breach at Risk is notifiable to the authority, and High Risk normally means telling the data subjects too.
Scope — Affected processings and Affected personal data point at the register entries involved, with Affected data subjects count and Affected personal data count for the approximate volumes.
Notification — Authorities picks the regulators to notify from the entity register, and Authority notified on, Authority notification ref and Data subjects notified on record that you did.
Response — Potential consequences describes the harm to individuals, Remediation measures links the applied controls put in place, Evidences holds the notification letters and forensics, Incident links to the security incident being investigated in parallel, and Reference link plus Observation cover the rest.
The status ladder
Section titled “The status ladder”The Status field follows the notification duties rather than a generic workflow:
| Status | Meaning |
|---|---|
| Discovered | You know something happened; scope is not yet established |
| Under Investigation | Scope and risk are being assessed |
| Authority Notified | The supervisory authority has been informed |
| Data Subjects Notified | The affected individuals have been informed |
| Closed | Response complete, record kept for the file |
Not every breach climbs the whole ladder: a No Risk breach can go from Under Investigation straight to Closed, provided the record explains why.
Working the register
Section titled “Working the register”The list shows Ref ID, Name, Discovered on, Breach type, Risk level, Status, Affected data subjects count and Domain, most recent first, and filters by domain, breach type, risk level, status and affected processing. Data breaches by type on the privacy dashboard charts the same data.
Related
Section titled “Related”- Incidents — the security investigation behind a breach.
- Processings (ROPA) and Personal data — what was affected.
- Evidences — where notification records are stored.
