data breach
noun · Verletzung des Schutzes personenbezogener Daten
A data breach is a Verletzung des Schutzes personenbezogener Daten, Art. 4 Nr. 12 DSGVO: a breach of security leading to destruction, loss, alteration, unauthorised disclosure of or access to personal data. It is narrower than a GDPR violation in general, and it is the trigger of the notification duties of Art. 33 and 34 DSGVO.
Which translation, when
Why
The data breach of the GDPR has the most cumbersome official rendering in the field, Verletzung des Schutzes personenbezogener Daten, and precisely because the phrase is long, translations and machines shorten it, to Datenpanne, Datenschutzverletzung or Verletzung des Datenschutzes. The shortening is where the legal risk sits. Art. 4 Nr. 12 DSGVO defines the term as a breach of security leading, whether accidentally or unlawfully, to the destruction, loss or alteration of, or to the unauthorised disclosure of or access to, personal data; the marker is the security incident, commonly grouped as breaches of confidentiality, integrity and availability. That makes the term narrower than a violation of the GDPR at large: processing without a legal basis is unlawful, but without a security incident it is no Verletzung in this sense, so the loose rendering Verletzung des Datenschutzes either inflates every violation into a notifiable event or, read from the other side, buries the security element. The consequences hang on the term: under Art. 33 Abs. 1 DSGVO the Verantwortlicher must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to natural persons, and a processor must inform the controller without undue delay, Art. 33 Abs. 2 DSGVO; under Art. 34 Abs. 1 DSGVO the persons affected must be informed only where a high risk is likely, a distinctly higher threshold. Failing to notify is itself fineable, Art. 83 Abs. 4 DSGVO. So the translation should carry the full statutory phrase at least once and keep the security element and the two-tier duties visible.
Typical mistakes
- The statutory term requires a breach of security, Art. 4 Nr. 12 DSGVO, so the loose Verletzung des Datenschutzes makes every GDPR violation look notifiable or hides the security element.
- The notification to the supervisory authority, Art. 33 DSGVO, and the communication to the persons affected, Art. 34 DSGVO, have different thresholds, risk against high risk, so the two duties must not be merged.
- The duty to notify runs from awareness, without undue delay and where feasible within 72 hours, Art. 33 Abs. 1 DSGVO, so a rendering that drops the trigger misstates the clock.
What matters
Rendering an incident clause or breach notification, the translation should carry the full statutory phrase Verletzung des Schutzes personenbezogener Daten at least once, keep the security element of Art. 4 Nr. 12 DSGVO visible, and hold apart the notification to the authority and the communication to the persons affected.
What the machine misses
Machine output shortens data breach to Datenpanne or Verletzung des Datenschutzes and loses the statutory phrase of Art. 4 Nr. 12 DSGVO. That drops the security element that separates a breach from a GDPR violation at large and blurs the two-tier duties, notification to the authority under Art. 33 DSGVO and communication to the persons affected under Art. 34 DSGVO. The rendering misstates what must be reported, to whom and when.
Examples
| a personal data breach | eine Verletzung des Schutzes personenbezogener Daten |
| to notify the supervisory authority of the breach | die Verletzung der Aufsichtsbehörde melden |
| communication of the breach to the data subject | Benachrichtigung der betroffenen Person von der Verletzung |
| a breach of security | eine Verletzung der Sicherheit |