Personal data breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data, notified to the authority within 72 hours unless unlikely to result in a risk 1. AI adds regurgitation, inversion and prompt-injection exfiltration as routes.

Developed in
ch. 19, AI-specific privacy breaches
Chapters
ch. 19, Privacy & AI
Source
1 numbered reference, listed below

Where it is used

3 chapters of the Body of Knowledge use the term. Each link opens the first section that does.

Patterns that use this term

One pattern page uses the term.

Sources

  1. [1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Personal data breach. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/personal-data-breach. CC BY 4.0

BibTeX

@misc{aige2026personaldatabreach,
  author  = {Jorge García Aibar},
  title   = {{Personal data breach}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/personal-data-breach}
}