Search Sustopedia

MetricConsumers and product responsibility

Identified customer-data leak, theft and loss events

Measurement answer

What this metric measures

Distinct identified customer-data leak, theft or loss events under the declared reporting profile, without claiming that every event is a legal personal-data breach.

Specification

Metric specification

Result format
Structured table
Unit
Distinct identified customer-data leak, theft or loss events
Reporting basis
Reporting period
Aggregation
Add only non-overlapping records after applying the stated identity and deduplication controls
Pillar
Social
Topic
Consumers and product responsibility
Controlled domain
Consumers and end users
Entity type
Metric

Reporting boundary

Add only disjoint events after cross-system, customer-population and jurisdiction deduplication. Keep complaints and legally defined breach events separate.

Verified source occurrences

Framework coverage

This is one canonical metric. The bindings below show every verified framework occurrence without creating duplicate metric pages. Edition, disclosure, role, and relationship remain source-specific.

  • Adopting Disclosure

    GRI Standards

    Source evidence
    Publisher
    Global Reporting Initiative
    Edition
    2016
    Requirement
    Not Specified
    Relationship
    Defines Disclosure
    Mapping outcome
    Direct Evidence
    Source locator
    Disclosure 418-1, PDF page 8; customer scope, PDF page 9
    Open official framework source

Value structure

Dimensions and units

Unit
Distinct identified customer-data leak, theft or loss events
Reporting basis
Reporting period

Unit meaning: A non-negative source-reported event count under an explicit event identity and deduplication rule; it does not by itself assert a legal breach.

Table fields and units

  • Event identity
  • Event type
  • Customer population
  • Data category
  • Identification date
  • Prior-period relation
  • System scope

Published dimensions

  • leak, theft or loss type
  • customer population
  • data category
  • occurrence and identification dates
  • prior-period relation
  • system or service
  • jurisdiction
  • event identity
  • privacy state

Disclosure method

Formula information

Status
Not applicable
Formula type
Structured Disclosure

Disclosure form

No single formula

Populate the structured fields from qualifying source observations and retain each field-level unit, boundary, status, and method; do not collapse the disclosure into one calculated value.

Verified sources

Evidence and status sources

Sustopedia checked each record-specific claim directly against primary publisher material. Labels distinguish current measurement authority from future compatibility and corroborative, legal, edition, or method status context. Corroborative evidence can support a stated limitation but cannot establish the core measurement by itself.

Measurement evidence

  • Measurement evidenceChecked 15 August 2026

    GRI 418: Customer Privacy 2016

    Publisher
    Global Reporting Initiative
    Edition
    2016
    Locator
    Disclosure 418-1, PDF page 8; customer scope, PDF page 9

    Supports: Supports the separate identified customer-data leak, theft and loss observation.

    Open official source

Use with context

Interpretation boundaries

Method disclosures required

Source-edition basis: GRI 418: Customer Privacy 2016, current effective edition at the research cutoff.

  • Define the event categories and identity rule.
  • State customer population, system scope, period and earlier-period relation.
  • Do not merge this count with complaints or legal breach events.

Record-specific limitations

  • The count depends on detection and reporter classification.
  • It does not prove legal breach status, number of affected customers, harm, notification duty or remediation.

Interpret this metric with the stated reporting boundary, period convention, value shape, and unit. Results prepared with different boundaries or conventions may not be directly comparable.

Measurement evidence supports the core record-specific claims described above. Corroborative evidence can support limitations, while compatibility and status sources provide their separately labelled context. None of these cards by itself determines an organisation's legal applicability, filing readiness, assurance status, or compliance conclusion.