PERSONAL DATA BREACH — UK GDPR · United Kingdom

Personal Data Breach UK — Definition, Examples, Reporting

UK GDPR Article 4(12) defines personal data breach as 'a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to' personal data. Three breach types: confidentiality (unauthorised disclosure / access), integrity (alteration), availability (destruction / loss). Most cyber incidents qualify. We define what's in scope and what's reportable to ICO.

Article 4(12) definition Confidentiality / integrity / availability CINA framework Reportable vs non-reportable Examples by sector Retainer available

3 types

confidentiality, integrity, availability — CINA triad breaches

Art. 4(12) + 33

Art. 4(12) defines breach; Art. 33 mandates 72-hour reporting

Retainer

Gridisys breach response retainer — out-of-scope vs in-scope determination

~1,000+

examples ICO has investigated — narrowing the reportable scope

Cybersecurity Consulting + 24/7 SOC Monitoring

Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.

Cybersecurity Consulting

UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.

  • Risk assessment + security architecture review
  • Conditional access + Entra ID hardening design
  • Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
  • Incident response planning + tabletop exercises
  • Vendor + supply-chain security assessment
  • Board / DPO reporting + evidence pack

Managed SOC Monitoring · 24/7

AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.

  • 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
  • BEC + mailbox-compromise + OAuth grant abuse detection
  • Suspicious sign-in + conditional access drift alerting
  • Ransomware + lateral-movement detection from EDR + Defender
  • Sub-hour triage on critical alerts, monthly ops report
  • Optional + integrated with consulting engagements

Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.

GET A QUOTE

Pricing tailored to your needs

Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.

What we cover

Practical, board-ready consulting — no jargon, no surprise invoices.

Breach definition determination

When an incident occurs, GDPR Article 4(12) determination is the first analysis — is it CINA (confidentiality / integrity / availability) breach of personal data? Many IT incidents don't qualify (e.g., phishing with no compromise, brute-force stopped). Many do (ransomware on systems processing personal data is availability breach). We document the determination.

Confidentiality breach handling

Unauthorised disclosure / access to personal data — most familiar kind: lost laptop with unencrypted customer data, leaked email of customer list, mailbox compromise exposing customer records, OAuth grant abuse leaking CRM data. Risk to individuals = identity theft, fraud, distress.

Integrity breach handling

Alteration of personal data without authorisation — examples: fraudster modifies customer addresses in CRM (reroutes deliveries), insider corrupting records, ransomware encrypts personal data (technical integrity breach + availability). Risk = incorrect processing downstream.

Availability breach handling

Accidental or unlawful destruction / loss of personal data — examples: ransomware disabling access, lost USB drive, deleted customer database with no backup. Risk to individuals = depends on impact (e.g., no appointment booking if healthcare)

Risk-to-individuals assessment

Determine whether the breach is 'likely to result in a risk to the rights and freedoms of natural persons' — Article 33 trigger. Examples high-risk: financial data, special category data, identity-enabling data. Examples non-high-risk: internal-only data with no personal data shown externally. We document the assessment.

Door-of-no-fear evidence

Where incident falls outside Article 33 (e.g., encrypted laptop with verified remote-wipe, single phishing email blocked by MFA), we document the 'rationale for non-notification' evidence. Critical to ICO defence if challenged post-incident — easy to forget but states-your-reasoning-with-evidence document.

How we work

1

On incident (T+0 – T+6)

Phone Gridisys. Quick triage: is personal data in scope? If yes, is it a CINA breach? Document awareness timestamp.

2

Risk assessment (T+6 – T+24)

Categorise data subjects, data amounts, security measures (encryption, MFA), risk to individuals. Determine Art. 33 trigger + Art. 34 high-risk.

3

Notification or no-notification (T+24 – T+48)

If Art. 33 triggered: draft ICO notification; if high-risk: prepare Art. 34 customer comms. If not triggered: document rationale for non-notification.

4

Submit + post-incident (T+48 – T+72)

Submit ICO notification in clock; dispatch customer comms in parallel. Post-incident report + DPIA refresh + training + controls.

Sectors we protect

Any UK organisation processing personal data FCA-regulated firms (operational resilience reference) Solicitors (client confidentiality + Art. 33) Healthcare providers (special category + Art. 34 risks) Schools (safeguarding records = special category) Retail + e-commerce (customer data + payment data)
FREE CONSULTATION

Personal data breach defined, scoped, and reported cleanly

Free 30-minute consultation to scope whether your incident is a personal data breach, whether Article 33 applies, and what your response timeline is.

Frequently asked questions

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.