Under GDPR, what constitutes a 'personal data breach'?
- A.A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data
- B.Only the theft of personal data by hackers, citing Article 4(12), which defines a personal data breach as limited to unauthorised disclosure, excluding accidental loss or destruction
- C.Only data breaches involving more than 1,000 records, citing Article 7(3), which prevents a data subject from ever withdrawing consent once given in writing
- D.Any cyberattack on a company
Why A is correct
Article 4(12) defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
Know someone studying for GDPR? Send them this one.