---
title: "Personal data breach"
description: "A breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data, notified to the authority within 72 hours unless…"
canonical: https://aigovernanceengineer.com/glossary/personal-data-breach
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Personal data breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data, notified to the authority within 72 hours unless unlikely to result in a risk [1]. AI adds regurgitation, inversion and prompt-injection exfiltration as routes.

- Developed in: [ch. 19, AI-specific privacy breaches](https://aigovernanceengineer.com/bok/privacy-and-ai#ai-specific-privacy-breaches)
- Chapters: [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-personal-data-breach

## Sources

[1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
