Data Breach
An incident involving unauthorised access to or acquisition, use, or disclosure of personal information that may trigger legal duties; definitions vary.
Full definition
A data breach is an unauthorised acquisition, access, use, or disclosure of personal information. All 50 US states have breach-notification statutes, but the covered data, harm thresholds, recipients, and deadlines differ; some deadlines run from discovery while others use a different trigger. Under GDPR, a controller generally must notify the supervisory authority within 72 hours of becoming aware of a notifiable breach, unless an exception applies. Some breaches trigger a private right of action; the CCPA provides a limited private action for certain breaches involving nonencrypted and nonredacted personal information.
Go deeper
What to do after a data breach →Related terms
CCPA
California Consumer Privacy Act, the first comprehensive US state privacy law, which can grant eligible California consumers rights to know, delete, correct, and opt out of sale or sharing, subject to covered-business scope, verification, exemptions, and other limits.
GDPR
General Data Protection Regulation, the European Union's comprehensive data-protection law governing processing within its territorial scope.
Generate requests in under 60 seconds
Generate requests across 1,000+ brokers
One-time from $9