Skip to main content

Finepost · Notes · Law

data breach

noun · Verletzung des Schutzes personenbezogener Daten

A data breach is a Verletzung des Schutzes personenbezogener Daten, Art. 4 Nr. 12 DSGVO: a breach of security leading to destruction, loss, alteration, unauthorised disclosure of or access to personal data. It is narrower than a GDPR violation in general, and it is the trigger of the notification duties of Art. 33 and 34 DSGVO.

Which translation, when

Legaldefinitionthe trigger: the Verletzung des Schutzes personenbezogener Daten is a breach of security leading, whether accidentally or unlawfully, to the destruction, loss or alteration of, or to the unauthorised disclosure of or access to, personal data transmitted, stored or otherwise processed, Art. 4 Nr. 12 DSGVO; the classic groupings are breaches of confidentiality, of integrity and of availability.
engerer Begriffthe boundary: not every GDPR violation is a Verletzung in this sense; processing without a legal basis is unlawful but, without a security incident, it is no data breach, so a text that renders data breach loosely as Verletzung des Datenschutzes turns every violation into a notifiable event or, read the other way, hides the security element the statutory term requires.
Meldung an die Aufsichtsbehördethe first duty: the Verantwortlicher must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, Art. 33 Abs. 1 DSGVO; a late notification must explain the delay, and failure to notify is itself fineable, Art. 83 Abs. 4 DSGVO.
Benachrichtigung der betroffenen Personthe second duty: the persons affected must be informed without undue delay only where the breach is likely to result in a high risk to their rights and freedoms, Art. 34 Abs. 1 DSGVO, a higher threshold than the notification to the authority, so the two duties must not be merged.

Why

The data breach of the GDPR has the most cumbersome official rendering in the field, Verletzung des Schutzes personenbezogener Daten, and precisely because the phrase is long, translations and machines shorten it, to Datenpanne, Datenschutzverletzung or Verletzung des Datenschutzes. The shortening is where the legal risk sits. Art. 4 Nr. 12 DSGVO defines the term as a breach of security leading, whether accidentally or unlawfully, to the destruction, loss or alteration of, or to the unauthorised disclosure of or access to, personal data; the marker is the security incident, commonly grouped as breaches of confidentiality, integrity and availability. That makes the term narrower than a violation of the GDPR at large: processing without a legal basis is unlawful, but without a security incident it is no Verletzung in this sense, so the loose rendering Verletzung des Datenschutzes either inflates every violation into a notifiable event or, read from the other side, buries the security element. The consequences hang on the term: under Art. 33 Abs. 1 DSGVO the Verantwortlicher must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to natural persons, and a processor must inform the controller without undue delay, Art. 33 Abs. 2 DSGVO; under Art. 34 Abs. 1 DSGVO the persons affected must be informed only where a high risk is likely, a distinctly higher threshold. Failing to notify is itself fineable, Art. 83 Abs. 4 DSGVO. So the translation should carry the full statutory phrase at least once and keep the security element and the two-tier duties visible.

Typical mistakes

  • The statutory term requires a breach of security, Art. 4 Nr. 12 DSGVO, so the loose Verletzung des Datenschutzes makes every GDPR violation look notifiable or hides the security element.
  • The notification to the supervisory authority, Art. 33 DSGVO, and the communication to the persons affected, Art. 34 DSGVO, have different thresholds, risk against high risk, so the two duties must not be merged.
  • The duty to notify runs from awareness, without undue delay and where feasible within 72 hours, Art. 33 Abs. 1 DSGVO, so a rendering that drops the trigger misstates the clock.

What matters

Rendering an incident clause or breach notification, the translation should carry the full statutory phrase Verletzung des Schutzes personenbezogener Daten at least once, keep the security element of Art. 4 Nr. 12 DSGVO visible, and hold apart the notification to the authority and the communication to the persons affected.

Authority

  1. Art. 4 Nr. 12 DSGVO
  2. Art. 33 DSGVO
  3. Art. 34 DSGVO

What the machine misses

Machine output shortens data breach to Datenpanne or Verletzung des Datenschutzes and loses the statutory phrase of Art. 4 Nr. 12 DSGVO. That drops the security element that separates a breach from a GDPR violation at large and blurs the two-tier duties, notification to the authority under Art. 33 DSGVO and communication to the persons affected under Art. 34 DSGVO. The rendering misstates what must be reported, to whom and when.

See what the machine does with this clause →

Examples

a personal data breacheine Verletzung des Schutzes personenbezogener Daten
to notify the supervisory authority of the breachdie Verletzung der Aufsichtsbehörde melden
communication of the breach to the data subjectBenachrichtigung der betroffenen Person von der Verletzung
a breach of securityeine Verletzung der Sicherheit
Checked 30 Jul 2026 finepost.co.uk/notes/data-breach