Personal-data breach events
Measurement answer
What this metric measures
Distinct events meeting the named jurisdiction's legal personal-data breach definition, with event type, risk, notification and communication states retained.
Specification
Metric specification
- Result format
- Structured table
- Unit
- Distinct legally defined personal-data breach events
- Reporting basis
- Reporting period
- Aggregation
- Add only non-overlapping records after applying the stated identity and deduplication controls
- Pillar
- Social
- Topic
- Consumers and product responsibility
- Controlled domain
- Consumers and end users
- Entity type
- Metric
Reporting boundary
Count disjoint breach events after controller, system, campaign and cross-jurisdiction deduplication. Exclude security events that do not meet the named legal definition.
Verified source occurrences
Framework coverage
This is one canonical metric. The bindings below show every verified framework occurrence without creating duplicate metric pages. Edition, disclosure, role, and relationship remain source-specific.
- Adopting DisclosureSource evidence
EU laws and regulatory guidance
- Publisher
- European Union
- Edition
- Consolidated 4 May 2016
- Requirement
- Not Specified
- Relationship
- Defines Disclosure
- Mapping outcome
- Direct Evidence
- Source locator
- Article 4(12), PDF page 4; Article 33, page 29; Article 34, page 30
Value structure
Dimensions and units
- Unit
- Distinct legally defined personal-data breach events
- Reporting basis
- Reporting period
Unit meaning: A non-negative event count under a named jurisdiction, legal definition and consolidation rule; it is not the number of attacks, records or affected people.
Table fields and units
- Event identity
- Jurisdiction
- Legal definition
- Breach type
- Knowledge date
- Risk state
- Authority notification
- Data-subject communication
Published dimensions
- jurisdiction and legal definition
- controller or processor role
- event identity
- occurrence, discovery and knowledge dates
- breach-type flags
- risk state
- authority notification
- data-subject communication
- privacy state
Disclosure method
Formula information
- Status
- Not applicable
- Formula type
- Structured Disclosure
Disclosure form
No single formulaPopulate the structured fields from qualifying source observations and retain each field-level unit, boundary, status, and method; do not collapse the disclosure into one calculated value.
Verified sources
Evidence and status sources
Sustopedia checked each record-specific claim directly against primary publisher material. Labels distinguish current measurement authority from future compatibility and corroborative, legal, edition, or method status context. Corroborative evidence can support a stated limitation but cannot establish the core measurement by itself.
Measurement evidence
- Measurement evidenceChecked 15 August 2026
Regulation (EU) 2016/679, consolidated with corrigendum
- Publisher
- European Union
- Edition
- Consolidated 4 May 2016
- Locator
- Article 4(12), PDF page 4; Article 33, page 29; Article 34, page 30
Supports: Supports the legal personal-data breach definition and notification and communication states.
Open official source
Use with context
Interpretation boundaries
Method disclosures required
Source-edition basis: Regulation (EU) 2016/679, current consolidated public-law reference at the research cutoff.
- Name the jurisdiction and legal breach definition.
- Define event identity and consolidation across systems and jurisdictions.
- Keep affected people, records, risk, notification and communication as separate fields.
Record-specific limitations
- Legal definitions, risk tests, notification duties and detection capability vary.
- The count does not show attack count, records exposed, people harmed, severity, liability, control effectiveness or remediation.
Interpret this metric with the stated reporting boundary, period convention, value shape, and unit. Results prepared with different boundaries or conventions may not be directly comparable.
Measurement evidence supports the core record-specific claims described above. Corroborative evidence can support limitations, while compatibility and status sources provide their separately labelled context. None of these cards by itself determines an organisation's legal applicability, filing readiness, assurance status, or compliance conclusion.