A data breach is an incident where confidential, protected or personal data is accessed, disclosed, altered or destroyed without authorization, whether by external attack, insider action or mistake. Most breaches start on the human layer, phishing and stolen credentials, arriving by email.
Key facts
- The human element (phishing, stolen credentials, misuse) is behind the majority of breaches, as reported in the Verizon Data Breach Investigations Report.
- A breach involving personal data triggers GDPR''s notification duties: 72 hours to the supervisory authority.
- All personal data breaches are data breaches, but not every data breach is a personal data breach; classification affects reporting duties.
How breaches actually begin
The channel is almost always human. Phishing and stolen credentials, business email compromise, mailbox compromise, consent phishing that hands attackers OAuth access without touching a password, misdirected email, lost devices and vendor compromise. Server-side exploits still exist, but the everyday breach starts in an inbox.
What the law requires
Under GDPR, Articles 33 and 34 require notification of a personal data breach to the supervisory authority within 72 hours of becoming aware, and communication to affected individuals when the risk is high. Sector rules add their own: NIS2 has 24/72-hour reporting for significant incidents, and DORA requires financial entities to report major ICT-related incidents on fixed timelines.
The first 72 hours
Detection, scoping, containment, assessment, notification. Detection speed determines everything downstream: you cannot report what you have not noticed, and every hour of undetected intrusion is an hour of expanding scope. The 72-hour clock starts when you become aware, and supervisory authorities expect awareness to arrive quickly.
How to reduce the risk
Protect the channel where most breaches begin: email-layer detection of phishing, BEC and consent phishing. Enforce phishing-resistant MFA, apply least privilege, review third-party OAuth grants regularly, and rehearse an incident response plan so the 72-hour clock does not start with a scramble.
How Sentaro helps
Sentaro protects the channel where most breaches begin, detects mailbox compromise early, and supplies the who/what/when/scope evidence that notification deadlines require. When a breach happens, the reporting chain starts with facts instead of a blank incident record.
This page is general guidance, not legal advice.