GDPR Data Breach Examples: What Must Be Reported — and What Doesn't

Most GDPR breach mistakes are classification mistakes: teams either report trivia or — far more dangerously — sit on reportable incidents because 'it was just an email'. The legal test in Article 33 GDPR is risk-based: a personal-data breach must be notified to the supervisory authority within 72 hours unless it is unlikely to result in a risk to the rights and freedoms of individuals. That makes concrete examples the most useful compliance tool, because the same event type can fall on either side of the line depending on data, scale and safeguards.

Typically reportable: an email with salary data, health information or a full customer list sent to the wrong external recipient; a ransomware attack that encrypts or exfiltrates personal data; a lost or stolen unencrypted laptop or USB stick containing personal data; a misconfigured database or cloud bucket exposing customer records to the internet; credential-stuffing takeovers of user accounts. Typically not reportable: a lost laptop with strong full-disk encryption and no compromised key; a misdirected email caught within a closed circle where the recipient credibly confirms deletion and the data was innocuous; brief unavailability of systems with no data compromised and no consequences for individuals.

Two duties are independent of the reporting decision, and international companies miss both. First, every breach — reported or not — must be recorded internally with facts, effects and remedies under Article 33(5), and the non-reporting decision must be justified in that record. Second, the GDPR reaches non-EU companies serving EU customers, so a breach in a US system holding German customer data starts the same 72-hour clock. Our 72-hour response checklist covers the drill, and the GDPR breach fines page what notification failures cost.

Your checklist

  1. 1Judge every incident by risk to individuals, not by embarrassment to the company: data categories, number of people affected, likelihood and severity of harm are the criteria.
  2. 2Treat special-category data as a red flag: incidents involving health, financial, biometric or similar sensitive data are reportable in almost all realistic scenarios.
  3. 3Treat encryption as the decisive factor for lost devices: a properly encrypted laptop with uncompromised keys usually stays below the reporting threshold; an unencrypted one usually does not.
  4. 4Classify ransomware conservatively: encryption of personal data is an availability breach even without proven exfiltration, and authorities expect notification in most ransomware cases.
  5. 5Do not let 'the recipient deleted it' end the analysis for misdirected emails: sensitivity, scale and who the recipient was determine the risk — one wrong recipient of a payroll file can be reportable.
  6. 6Check the second threshold too: where the breach likely creates a high risk for individuals, Article 34 additionally requires informing the affected persons themselves.
  7. 7Record every breach internally under Article 33(5), including the ones you decide not to report — the documented reasoning is your defense when an authority asks later.
  8. 8Decide within the deadline: run the risk assessment fast enough that a notification, if needed, still lands within 72 hours of awareness — a late 'correct' decision is still a violation.

Matching tool

Report every data breach on time and securely.

GDPR 72h Leak Shield → Check now for free

Frequently asked questions

Is a misdirected email a reportable GDPR breach?

It depends on risk. An email with sensitive content — payroll data, health information, a customer database — sent to an unauthorized external recipient is typically reportable to the supervisory authority under Article 33 GDPR. A misdirected message with harmless content to a trustworthy recipient who confirms deletion may fall below the threshold. In both cases the incident and the assessment must be documented internally.

Do we have to report a ransomware attack under the GDPR?

In most cases yes. Encryption of personal data by ransomware is a breach of availability even if no data was stolen, and exfiltration can rarely be excluded early. European guidance treats ransomware affecting personal data as notifiable in the majority of scenarios, so the working assumption should be a 72-hour notification, refined as forensics progress — the GDPR expressly allows notifying in phases.

Is a lost company laptop always a data breach?

It is always a security incident, but not always a notifiable breach. With state-of-the-art full-disk encryption and no compromise of the keys, the risk to individuals is usually low enough that notification is not required — though the loss must still be recorded internally. An unencrypted device containing personal data is the opposite case and generally needs to be reported.

What if we assess an incident as non-reportable and the authority disagrees?

The decisive protection is documentation. Article 33(5) GDPR requires recording every breach with facts, effects and remedial action, including the reasoning for not notifying. A documented, plausible risk assessment made in good time is treated very differently from an incident that was never analyzed — the latter pattern is what supervisory authorities sanction as a notification failure.

More about GDPR 72h Leak Shield →