Search Sustopedia

MetricConsumers and product responsibility

Personal-data breach events

Measurement answer

What this metric measures

Distinct events meeting the named jurisdiction's legal personal-data breach definition, with event type, risk, notification and communication states retained.

Specification

Metric specification

Result format
Structured table
Unit
Distinct legally defined personal-data breach events
Reporting basis
Reporting period
Aggregation
Add only non-overlapping records after applying the stated identity and deduplication controls
Pillar
Social
Topic
Consumers and product responsibility
Controlled domain
Consumers and end users
Entity type
Metric

Reporting boundary

Count disjoint breach events after controller, system, campaign and cross-jurisdiction deduplication. Exclude security events that do not meet the named legal definition.

Verified source occurrences

Framework coverage

This is one canonical metric. The bindings below show every verified framework occurrence without creating duplicate metric pages. Edition, disclosure, role, and relationship remain source-specific.

  • Adopting Disclosure

    EU laws and regulatory guidance

    Source evidence
    Publisher
    European Union
    Edition
    Consolidated 4 May 2016
    Requirement
    Not Specified
    Relationship
    Defines Disclosure
    Mapping outcome
    Direct Evidence
    Source locator
    Article 4(12), PDF page 4; Article 33, page 29; Article 34, page 30
    Open official framework source

Value structure

Dimensions and units

Unit
Distinct legally defined personal-data breach events
Reporting basis
Reporting period

Unit meaning: A non-negative event count under a named jurisdiction, legal definition and consolidation rule; it is not the number of attacks, records or affected people.

Table fields and units

  • Event identity
  • Jurisdiction
  • Legal definition
  • Breach type
  • Knowledge date
  • Risk state
  • Authority notification
  • Data-subject communication

Published dimensions

  • jurisdiction and legal definition
  • controller or processor role
  • event identity
  • occurrence, discovery and knowledge dates
  • breach-type flags
  • risk state
  • authority notification
  • data-subject communication
  • privacy state

Disclosure method

Formula information

Status
Not applicable
Formula type
Structured Disclosure

Disclosure form

No single formula

Populate the structured fields from qualifying source observations and retain each field-level unit, boundary, status, and method; do not collapse the disclosure into one calculated value.

Verified sources

Evidence and status sources

Sustopedia checked each record-specific claim directly against primary publisher material. Labels distinguish current measurement authority from future compatibility and corroborative, legal, edition, or method status context. Corroborative evidence can support a stated limitation but cannot establish the core measurement by itself.

Measurement evidence

  • Measurement evidenceChecked 15 August 2026

    Regulation (EU) 2016/679, consolidated with corrigendum

    Publisher
    European Union
    Edition
    Consolidated 4 May 2016
    Locator
    Article 4(12), PDF page 4; Article 33, page 29; Article 34, page 30

    Supports: Supports the legal personal-data breach definition and notification and communication states.

    Open official source

Use with context

Interpretation boundaries

Method disclosures required

Source-edition basis: Regulation (EU) 2016/679, current consolidated public-law reference at the research cutoff.

  • Name the jurisdiction and legal breach definition.
  • Define event identity and consolidation across systems and jurisdictions.
  • Keep affected people, records, risk, notification and communication as separate fields.

Record-specific limitations

  • Legal definitions, risk tests, notification duties and detection capability vary.
  • The count does not show attack count, records exposed, people harmed, severity, liability, control effectiveness or remediation.

Interpret this metric with the stated reporting boundary, period convention, value shape, and unit. Results prepared with different boundaries or conventions may not be directly comparable.

Measurement evidence supports the core record-specific claims described above. Corroborative evidence can support limitations, while compatibility and status sources provide their separately labelled context. None of these cards by itself determines an organisation's legal applicability, filing readiness, assurance status, or compliance conclusion.