Personal Data Breach UK — Definition, Examples, Reporting
UK GDPR Article 4(12) defines personal data breach as 'a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to' personal data. Three breach types: confidentiality (unauthorised disclosure / access), integrity (alteration), availability (destruction / loss). Most cyber incidents qualify. We define what's in scope and what's reportable to ICO.
3 types
confidentiality, integrity, availability — CINA triad breaches
Art. 4(12) + 33
Art. 4(12) defines breach; Art. 33 mandates 72-hour reporting
Retainer
Gridisys breach response retainer — out-of-scope vs in-scope determination
~1,000+
examples ICO has investigated — narrowing the reportable scope
Cybersecurity Consulting + 24/7 SOC Monitoring
Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.
Cybersecurity Consulting
UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.
- Risk assessment + security architecture review
- Conditional access + Entra ID hardening design
- Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
- Incident response planning + tabletop exercises
- Vendor + supply-chain security assessment
- Board / DPO reporting + evidence pack
Managed SOC Monitoring · 24/7
AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.
- 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
- BEC + mailbox-compromise + OAuth grant abuse detection
- Suspicious sign-in + conditional access drift alerting
- Ransomware + lateral-movement detection from EDR + Defender
- Sub-hour triage on critical alerts, monthly ops report
- Optional + integrated with consulting engagements
Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.
Pricing tailored to your needs
Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.
What we cover
Practical, board-ready consulting — no jargon, no surprise invoices.
Breach definition determination
When an incident occurs, GDPR Article 4(12) determination is the first analysis — is it CINA (confidentiality / integrity / availability) breach of personal data? Many IT incidents don't qualify (e.g., phishing with no compromise, brute-force stopped). Many do (ransomware on systems processing personal data is availability breach). We document the determination.
Confidentiality breach handling
Unauthorised disclosure / access to personal data — most familiar kind: lost laptop with unencrypted customer data, leaked email of customer list, mailbox compromise exposing customer records, OAuth grant abuse leaking CRM data. Risk to individuals = identity theft, fraud, distress.
Integrity breach handling
Alteration of personal data without authorisation — examples: fraudster modifies customer addresses in CRM (reroutes deliveries), insider corrupting records, ransomware encrypts personal data (technical integrity breach + availability). Risk = incorrect processing downstream.
Availability breach handling
Accidental or unlawful destruction / loss of personal data — examples: ransomware disabling access, lost USB drive, deleted customer database with no backup. Risk to individuals = depends on impact (e.g., no appointment booking if healthcare)
Risk-to-individuals assessment
Determine whether the breach is 'likely to result in a risk to the rights and freedoms of natural persons' — Article 33 trigger. Examples high-risk: financial data, special category data, identity-enabling data. Examples non-high-risk: internal-only data with no personal data shown externally. We document the assessment.
Door-of-no-fear evidence
Where incident falls outside Article 33 (e.g., encrypted laptop with verified remote-wipe, single phishing email blocked by MFA), we document the 'rationale for non-notification' evidence. Critical to ICO defence if challenged post-incident — easy to forget but states-your-reasoning-with-evidence document.
How we work
On incident (T+0 – T+6)
Phone Gridisys. Quick triage: is personal data in scope? If yes, is it a CINA breach? Document awareness timestamp.
Risk assessment (T+6 – T+24)
Categorise data subjects, data amounts, security measures (encryption, MFA), risk to individuals. Determine Art. 33 trigger + Art. 34 high-risk.
Notification or no-notification (T+24 – T+48)
If Art. 33 triggered: draft ICO notification; if high-risk: prepare Art. 34 customer comms. If not triggered: document rationale for non-notification.
Submit + post-incident (T+48 – T+72)
Submit ICO notification in clock; dispatch customer comms in parallel. Post-incident report + DPIA refresh + training + controls.
Sectors we protect
Personal data breach defined, scoped, and reported cleanly
Free 30-minute consultation to scope whether your incident is a personal data breach, whether Article 33 applies, and what your response timeline is.
RELATED UK CYBERSECURITY SERVICES