Skip to content

Personal data breaches

A personal data breach is a security incident that results in the accidental or unlawful destruction, loss or change of personal data. It may also result in the unauthorised disclosure of, or unauthorised access to, personal data. It does not matter whether it occurred accidentally or intentionally. In both cases, it is a personal data breach.

Examples of personal data breaches

Example

  • An unauthorised party gains access to personal data, for example if someone sends personal data to a recipient who is not supposed to receive it.
  • Computers containing personal data are lost or stolen.
  • Someone is changing personal data without permission.
  • Personal data is no longer available to those who need it, thus resulting in negative consequences for the data subjects.

 

The European Data Protection Board’s (EDPB) guidelines contain more examples, as well as guidance on how different types of personal data breaches should be handled.

Guidelines 01/2021 on Examples regarding Personal Data Breach Notification

Data subjects can suffer serious consequences

A personal data breach may pose risks to the freedoms and rights of data subjects and may lead to serious consequences, such as:

  • financial loss
  • discrimination
  • identity theft
  • fraud
  • damage to reputation

Act quickly and report certain personal data breaches

The General Data Protection Regulation (GDPR) requires you, as the data controller, to act quickly when a personal data breach has occurred. You must prioritise the investigation of personal data breaches and set aside sufficient resources for this work.

As a data controller, you must assess the risks of the breach affecting the rights and freedoms of data subjects and maintain documentation of any personal data breaches that occur.

You must report the breach if it is not unlikely that the personal data breach poses a risk to the rights and freedoms of natural persons. As a general rule, a notification must be made within 72 hours of you becoming aware of the personal data breach.

If the personal data breach is likely to pose a high risk to the rights and freedoms of natural persons, the general rule is that you, as the data controller, must inform the data subjects of the personal data breach. You must provide this information to the data subjects without undue delay.

Notification of a personal data breach

 

Cross-border personal data breaches

A personal data breach may involve several EU Member States. Such breaches must be reported to the supervisory authority that you, as the data controller, have assessed as being the competent supervisory authority.

Before you start a new processing of personal data, it is therefore important that you determine which authority will be your competent supervisory authority, so that you know which authority to contact if a personal data breach occurs.

To determine which authority is the competent supervisory authority, you should base your assessment on where your main or sole place of business is located.

Work in a risk-aware and preventative manner

To avoid personal data breaches and minimise their impact, it is important to work in a risk-aware and proactive manner. You can read more about this on the information security page below.

You must be prepared for the possibility of data breaches and have procedures in place to deal with them as quickly and effectively as possible. It is important to take preventative measures, for example by

  • creating clear routines to easily detect personal data breaches,
  • developing an action plan for how your organisation will handle personal data breaches,
  • involving the data protection officer in the handling of personal data breaches,
  • documenting all personal data breaches and assessing the potential risks of new breaches.

Information security

If you have appointed a data processor

If you appoint a data processor and a personal data breach occurs with the data processor, the data processor must report it to you without undue delay.  As the data controller, you are always responsible for reporting the personal data breach to the supervisory authority.

The data processor's obligations (in Swedish)

IT supplier targeted by a cyberattack

Example

You appoint an IT supplier to archive and store customer data. The IT supplier suffers a data breach, resulting in unauthorised parties gaining access to your customers’ data. As this incident constitutes a personal data breach, the IT supplier must immediately report it to you, the data controller, and you must report it to IMY.

 

About the information on this page

If the information in English is different from the Swedish version of this page, the Swedish version applies.

Latest update: 29 September 2026