Identified customer-data leak, theft and loss events
Measurement answer
What this metric measures
Distinct identified customer-data leak, theft or loss events under the declared reporting profile, without claiming that every event is a legal personal-data breach.
Specification
Metric specification
- Result format
- Structured table
- Unit
- Distinct identified customer-data leak, theft or loss events
- Reporting basis
- Reporting period
- Aggregation
- Add only non-overlapping records after applying the stated identity and deduplication controls
- Pillar
- Social
- Topic
- Consumers and product responsibility
- Controlled domain
- Consumers and end users
- Entity type
- Metric
Reporting boundary
Add only disjoint events after cross-system, customer-population and jurisdiction deduplication. Keep complaints and legally defined breach events separate.
Verified source occurrences
Framework coverage
This is one canonical metric. The bindings below show every verified framework occurrence without creating duplicate metric pages. Edition, disclosure, role, and relationship remain source-specific.
- Adopting DisclosureSource evidence
GRI Standards
- Publisher
- Global Reporting Initiative
- Edition
- 2016
- Requirement
- Not Specified
- Relationship
- Defines Disclosure
- Mapping outcome
- Direct Evidence
- Source locator
- Disclosure 418-1, PDF page 8; customer scope, PDF page 9
Value structure
Dimensions and units
- Unit
- Distinct identified customer-data leak, theft or loss events
- Reporting basis
- Reporting period
Unit meaning: A non-negative source-reported event count under an explicit event identity and deduplication rule; it does not by itself assert a legal breach.
Table fields and units
- Event identity
- Event type
- Customer population
- Data category
- Identification date
- Prior-period relation
- System scope
Published dimensions
- leak, theft or loss type
- customer population
- data category
- occurrence and identification dates
- prior-period relation
- system or service
- jurisdiction
- event identity
- privacy state
Disclosure method
Formula information
- Status
- Not applicable
- Formula type
- Structured Disclosure
Disclosure form
No single formulaPopulate the structured fields from qualifying source observations and retain each field-level unit, boundary, status, and method; do not collapse the disclosure into one calculated value.
Verified sources
Evidence and status sources
Sustopedia checked each record-specific claim directly against primary publisher material. Labels distinguish current measurement authority from future compatibility and corroborative, legal, edition, or method status context. Corroborative evidence can support a stated limitation but cannot establish the core measurement by itself.
Measurement evidence
- Measurement evidenceChecked 15 August 2026
GRI 418: Customer Privacy 2016
- Publisher
- Global Reporting Initiative
- Edition
- 2016
- Locator
- Disclosure 418-1, PDF page 8; customer scope, PDF page 9
Supports: Supports the separate identified customer-data leak, theft and loss observation.
Open official source
Use with context
Interpretation boundaries
Method disclosures required
Source-edition basis: GRI 418: Customer Privacy 2016, current effective edition at the research cutoff.
- Define the event categories and identity rule.
- State customer population, system scope, period and earlier-period relation.
- Do not merge this count with complaints or legal breach events.
Record-specific limitations
- The count depends on detection and reporter classification.
- It does not prove legal breach status, number of affected customers, harm, notification duty or remediation.
Interpret this metric with the stated reporting boundary, period convention, value shape, and unit. Results prepared with different boundaries or conventions may not be directly comparable.
Measurement evidence supports the core record-specific claims described above. Corroborative evidence can support limitations, while compatibility and status sources provide their separately labelled context. None of these cards by itself determines an organisation's legal applicability, filing readiness, assurance status, or compliance conclusion.