BLOG
What Is a Data Breach The UK, the EU and the US Compared
Published 10 August 2026 · By P Larner
Regulation & Legislation#data breach#NIS2#UK GDPR#ICO#breach notification#DORA
What Is a Data Breach: The UK, the EU and the US Compared
Illustration for: What Is a Data Breach, The UK, the EU and the US Compared
A laptop is left on a train. It is encrypted, the disk is locked, and the member of staff reports it within the hour. Ask a British privacy lawyer whether that is a data breach and you will get a qualified yes with a note about risk. Ask an American one and you will most likely get a no, because encrypted data usually falls inside a safe harbour and nobody was harmed. Ask about the same laptop in a Dublin office of a company that also supplies a bank, and the answer arrives with three regulators attached.
The word breach does more work than any other in this field, and it means materially different things in the three regimes most British organisations touch. Getting the definition wrong is expensive, because the clock starts when you become aware, not when you finish arguing about terminology.
What counts in the UK and the EU
The UK and the EU share a definition, because the UK kept the GDPR text after leaving. A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data. An earlier post in this series gives the wider regulation a practitioner’s refresher, but this one clause deserves reading twice.
It covers three failures, not one
Confidentiality, where data goes somewhere it should not. Integrity, where data is altered without authorisation. Availability, where you lose access to it. That third limb surprises people. Ransomware that encrypts a database and exfiltrates nothing at all is still a personal data breach, and so is a botched migration that destroys the only copy of a customer record.
Intent is irrelevant
An email sent to the wrong recipient is a breach. The ICO’s own statistics have shown for years that misdirected post and email, rather than intrusion, sit at the top of the reported categories. If your incident process only triggers on malicious activity, it is missing most of what you will actually have to report.
The threshold to notify is risk, not certainty
You tell the ICO within 72 hours of becoming aware unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Note the double negative, which puts the burden the other way round from where most people assume. Where the risk is high, you must also tell the individuals themselves without undue delay.
The clocks, and when they start
Seventy two hours sounds generous until you notice what it runs from. Awareness means the point at which you have a reasonable degree of certainty that a security incident has occurred that compromised personal data, and that is usually hours or days before the investigation is finished. The regulator expects a phased notification rather than a late complete one, so an initial report with what you know, followed by detail as it emerges, is the correct behaviour rather than an admission of disorganisation.
Timeline diagram of breach notification deadlines
The clocks start when you become aware rather than when the incident happened. The 72 hour deadline belongs to data protection, the 24 hour early warning comes from the European network rules, and the final report is the odd one out because its month runs from the 72 hour notification rather than from awareness. An organisation in scope of both regimes runs these in parallel rather than in sequence.
Where the EU adds layers
The EU applies the same data protection definition and then stacks sector rules on top of it. NIS2 obliges essential and important entities to send an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours and a final report within one month of that notification rather than one month from awareness, and it triggers on operational significance rather than on personal data. DORA does something similar for financial entities with its own initial, intermediate and final reports. An earlier post in this series walks through those three clocks in detail.
The consequence is that one incident in a European subsidiary can require a data protection notification, a network security notification and a financial supervisory notification, to three different authorities, on three different schedules, describing the same event in three different vocabularies.
The United Kingdom is on a similar path by a different route. The NIS Regulations already impose incident duties on operators of essential services and digital providers, and the Cyber Security and Resilience Bill extends that reach, which an earlier post examined from the perspective of managed service providers.
What counts in the United States
There is no American equivalent of the GDPR definition, and that single fact explains most transatlantic confusion.
The trigger is data elements, not a security failure
State breach notification laws, which now exist in all fifty states, generally define personal information as a name combined with something specific such as a social security number, a driving licence number, a financial account number or, increasingly, health or biometric data. A leak of names and email addresses alone is frequently not a notifiable breach at all.
Harm is usually a condition
Most states allow you to withhold notification where a risk assessment concludes that misuse is unlikely, and nearly all provide a safe harbour for encrypted data where the key was not also taken. That is the opposite of the European default, which starts from notification and lets you argue your way out.
Deadlines vary and some are tighter than Europe’s
Many states specify thirty or forty five days from discovery. Some require nothing more than the most expedient time possible. Sector rules cut across all of it, so a healthcare organisation reports under HIPAA within sixty days, and a listed company that judges an incident material must file with the SEC within four business days of reaching that judgement, which is a disclosure duty to investors rather than to the people whose data was taken.
The plaintiff is a regulator’s equal
Class action litigation, and the private right of action created by California’s legislation for certain breaches, means the American cost of a breach is frequently driven by lawyers rather than by supervisory fines.
Question | UK | EU | US |
|---|---|---|---|
Core definition | Security breach affecting personal data | Same as UK | Access to specified data elements, state by state |
Availability loss counts | Yes | Yes | Rarely |
Regulator deadline | 72 hours from awareness | 72 hours, plus 24 hours under network rules | Commonly 30 to 60 days, 4 business days for listed company disclosure |
Notify individuals | Where risk is high | Where risk is high | Usually mandatory once the threshold is met |
Encryption safe harbour | A mitigating factor | A mitigating factor | Frequently a full exemption |
Main financial exposure | Regulatory fine and enforcement | Regulatory fine and enforcement | Litigation and settlement |
What this means in practice
One incident, several clocks
Build the map before you need it. For each jurisdiction and each regulator you are subject to, record what triggers a duty, how long you have, who signs the notification and where the template lives. Doing that work during an incident is how the 72 hours disappears.
Awareness needs an owner and a timestamp
Someone must be empowered to declare that the organisation is now aware, and that moment must be recorded. Without it you cannot demonstrate that you met the deadline, and under the accountability principle demonstrating is the obligation.
Assess against the strictest regime you are in
If you handle European and American data, the European definition will almost always capture more events. Assess everything against it, then decide separately which American duties are engaged. Running the loose test first means you will not even ask the right question.
The honest counterarguments
The European approach produces noise
Regulators receive large volumes of reports about incidents that harmed nobody, and organisations that report defensively to avoid criticism make the pile deeper. There is a serious argument that a harm based threshold, as most American states use, directs limited supervisory attention better than a security based one.
The American patchwork is not simply worse
Fifty state laws is an administrative absurdity, but the underlying instinct, which is to notify people when they can actually do something about it, has merit. Notifying a customer about an encrypted laptop that was never opened teaches them to ignore the next letter, and that next letter may be the one that matters.
Harmonisation may be a fantasy anyway
The regimes differ because the underlying rights differ. Europe treats data protection as a fundamental right, and the United States treats it as consumer protection against identifiable harm. Those are different premises, and no amount of drafting reconciles them.
Common mistakes
Waiting for certainty
The duty triggers on reasonable belief, and a phased notification is expected. Late and complete scores worse than early and partial.
Treating processors as a lower tier
A processor must tell the controller without undue delay, with no 72 hour allowance of its own, and your contracts should say so explicitly rather than restating the regulation and hoping.
Forgetting that a breach can be a paper one
A file left in a meeting room and a report posted to a former address are both notifiable. Controls that only cover the network cover only part of the exposure.
The laptop on the train is a useful test to run at your next incident rehearsal. Ask the room whether it is a breach, and watch how long it takes to reach an answer, and how many people disagree along the way. The organisations that handle this well are not the ones with the best lawyers. They are the ones that decided in advance what counts, who declares it, and which clocks start running, and wrote it down while nobody was panicking.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free — every module, offline licence activation, nothing phones home.
Register / Download Contact us