What Is a Confidentiality Breach in the Context of GDPR? The AI Risk Most Offices Miss

AgentHub.ie logo
Dr. Shadi Ghaith Founder, AgentHub.ie ·

A confidentiality breach, in the context of GDPR, is any unauthorised or accidental disclosure of, or access to, personal data. The email to the wrong client, the lost laptop, the colleague reading a file they had no reason to open — and, increasingly, a client's file pasted into a public AI chatbot. It sits beside integrity breaches and availability breaches.

Letting agent's desk with a tenant application open while its pages drift out of a laptop chatbot towards a cloud
The tenant file never left the desk. Its contents did, in about four seconds.

What Is a Confidentiality Breach in the Context of GDPR?

A confidentiality breach is "an unauthorised or accidental disclosure of, or access to, personal data". That is the European Data Protection Board's definition in its Guidelines 9/2022 on breach notification, and it covers the wrong recipient, the wrong reader and the wrong destination alike. Nobody needs to be hacked. Somebody only needs to see data they should not.

Monday, 9.40am, a letting agency in Galway. A two-bed in Salthill went up on Friday and there are 23 applications in the inbox, each with payslips, bank statements, an employer reference and, in two cases, a PPS number nobody asked for. The lettings negotiator has a viewing at eleven. She opens ChatGPT on her own login, pastes in three applications and asks which tenant looks strongest on affordability. The answer is sensible and arrives in seconds. So does the disclosure: three people's salaries, account balances and employment details are now with a company in California, under its terms, on her personal account. Nobody in the office would call that a breach. It felt like using a calculator.

The legal definition, in one line

Article 4(12) GDPR defines a personal data breach as "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data". Read it again and you will see three different failures folded into one sentence. Regulators split them out using three old information-security principles: confidentiality, integrity and availability. Article 5(1)(f) makes the first two a core principle of the regulation, literally titled "integrity and confidentiality", and Article 32 adds availability when it asks for "the ongoing confidentiality, integrity, availability and resilience of processing systems".

Three panels showing one personal file seen by a stranger, altered by a pencil, and locked away out of reach
Same file, three ways to fail it: the wrong person sees it, the wrong change is made to it, or nobody can reach it at all.

Confidentiality, integrity and availability breaches compared

Breach typeEDPB definitionIn a letting agencyIrish figure (DPC, 2024)
ConfidentialityUnauthorised or accidental disclosure of, or access to, personal dataTenant reference emailed to the wrong landlord; application pasted into a public chatbot60% of notifications were unauthorised disclosures to individuals or small groups
IntegrityUnauthorised or accidental alteration of personal dataA rent arrears note saved against the wrong tenant10% were accidental or unauthorised alteration
AvailabilityAccidental or unauthorised loss of access to, or destruction of, personal dataRansomware encrypts the only copy of the tenancy files8% were accidental loss or destruction

The figures are from the Data Protection Commission's 2024 annual report, which logged 7,781 valid breach notifications. The EDPB is clear that one incident can be all three at once: ransomware that encrypts files and copies them out first is an availability breach and a confidentiality breach on the same morning.

What is an integrity breach in the context of GDPR?

An integrity breach is the unauthorised or accidental alteration of personal data. The record still exists and nobody outside saw it, but it is now wrong: a deposit marked as returned when it was not, a reference attached to the wrong applicant, a phone number overwritten by a careless merge. It matters because decisions get made on the altered version.

What is an availability breach in the context of GDPR?

An availability breach is the accidental or unauthorised loss of access to, or destruction of, personal data. Deletion with no backup, ransomware on the only copy, a lost encryption key. The EDPB adds that a temporary loss can count too, though planned maintenance does not, because nobody broke anything.

Why is confidentiality important?

Because it is the breach that happens most. The DPC's 2025 annual report counted 6,521 valid notifications, and unauthorised disclosures affecting individuals or small groups made up half of them. Half of those were correspondence sent to the wrong person. For a business that holds payslips and bank statements, confidentiality is the whole basis of being trusted with them. A tenant who learns their salary was read by the wrong landlord does not care which article was breached.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

Is Pasting Client Data Into a Chatbot a Confidentiality Breach?

Usually, yes. Pasting personal data into a public AI tool is processing, and specifically "disclosure by transmission" to the tool's provider. If your business has no contract with that provider and never authorised the use, the disclosure is unauthorised, which is the definition of a confidentiality breach. Whether you must report it depends on the risk; whether you must record it does not.

What does processing mean in the context of GDPR?

Processing is almost anything you do with personal data. Article 4(2) lists "collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available", and more. Reading a file is processing. Copying it is processing. Sending it to a chatbot's servers so a model can read it is disclosure by transmission, and that phrase is the bridge between "I asked an AI a question" and "we disclosed personal data to a third party". I wrote about where personal data begins and ends in What is personal data?; payslips and bank statements are well inside the line.

There is a second hook most guides skip. Article 32(4) requires the business to ensure that anyone with access to personal data "does not process them except on instructions from the controller". A negotiator using her own ChatGPT account to read tenant files is processing outside any instruction you gave. It is a training gap and a confidentiality breach at the same time.

The DPC has already seen this exact breach

The regulator is not speculating. In its 2025 case studies, Case Study 28 describes a financial-sector firm whose monitoring tool caught an employee uploading 32 CVs, with "passport/visa details, and photographs", to "an external free AI tool". The employee did it "in an effort to carry out their role more efficiently", and the firm "had no policies in place around the use of free external tools, including AI". It was notified as a breach because the data "had been uploaded to a third-party site where there was no data processing agreement in place" and was "no longer under the control of the Data Controller".

The Dutch regulator reported the same pattern in 2024, after multiple breach notifications from staff entering data into chatbots, including a GP practice employee who typed in patient medical details. And it is common: LayerX's 2025 browser-telemetry study found 77% of employees paste data into generative AI tools, with 82% of those pastes coming from personal accounts. In a five-person agency, those odds put three or four people pasting, most of them on logins you have never seen.

Where the tenant file goes, and what it counts as

Where the application is pastedLeaves the office?Contract with the provider?Confidentiality breach?
Staff member's personal ChatGPT, Gemini or DeepSeek loginYesNoYes — unauthorised disclosure; record it, assess the risk
Company AI plan with a data processing agreementYesYes, Article 28No, if the use is authorised and documented, though a DPIA is likely
Model running on a machine in your own officeNoNot needed for the AI stepNo — nothing was disclosed to anyone

The middle row is a legitimate answer, and I covered what the paperwork involves in What is a data processor under GDPR? But it still sends the file out of the building and asks you to trust a sub-processor list you approved in general terms.

The breach nobody writes down

Most of these pastes are never recorded anywhere, and that is now a problem in its own right. Article 33(5) requires you to "document any personal data breaches", reported or not. The DPC's 2025 annual report says it has "commenced an initiative to examine organisations' compliance with this obligation", to understand breaches "both those reported and not reported to the DPC". An internal breach register with nothing in it used to look tidy. It is starting to look like nobody is checking.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

How Local AI Removes the Disclosure Instead of Banning the Tool

The usual response to this breach is a ban, and bans mostly fail. Samsung banned generative AI tools in May 2023 after engineers pasted source code into ChatGPT. Staff who have found a faster way to do the job do not stop because of a memo; they switch to their phones, which is how the Galway negotiator ended up on her personal login in the first place. The DPC's case study makes the same point from the other side: the employee was trying to do the job well.

So we take the other route. Local AI is a dedicated machine installed at your premises, running open-weight models, with private chat, document search and custom assistants on it. The negotiator still pastes three applications and asks which tenant is strongest on affordability. The model reading them sits in the back office, behind the firm's own Microsoft or Google sign-in, and the payslips never leave the building they were already in. There is no disclosure, so there is nothing to record as a breach.

Cutaway of an estate agency with an AI machine in the back office and tenant files circulating inside the building
The files go round the office, not out of it. The cloud is still there; it just is not involved.

Ban, enterprise plan or Local AI: what each one actually fixes

ApproachStaff still get the summary?Disclosure removed?What you take on
Ban AI tools by policyOfficially no; in practice on personal phonesNo — it moves out of sightEnforcement, and breaches you never hear about
Company cloud AI planYesAuthorised, but the data still leavesArticle 28 contract, transfer assessment, DPIA, vendor reviews
Local AI on your premisesYesYes — nothing is sent anywhereA machine in the office and your existing access rules

What it looks like in a letting agency

  • Private chat for affordability summaries, reference checks and the polite refusal email to the 20 applicants who did not get the flat.
  • Document spaces for tenancy templates, the RTB process notes and your own AML procedures, searchable with citations back to the page.
  • Custom assistants for the jobs that repeat: the move-in checklist, the deposit return letter, the quarterly AML file review.
  • Your existing access control, so who can read which tenant's file is a decision you have already made.

We launched the service in September, so I will not pretend to a year of client results. What I can describe precisely is the design choice. Every breach guide, this one included, eventually asks where the data went. With the model in your back office, the answer is the shortest one available: nowhere. It stayed where it was. To be exact about our role, AgentHub acts as a processor only for any support access you grant, under an agreement scoped to that and nothing wider.

And where the cloud is the better tool, we say so. Triaging a shared lettings inbox is a job for our cloud Email Manager, which comes with a processor agreement because that is what it is; our privacy policy sets out how. Local AI earns its place on the files that should never have gone near a consumer chatbot: the payslips, the bank statements, the passports in the AML folder.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

Confidentiality Breaches: Frequently Asked Questions

What is a confidentiality breach in the context of GDPR?

It is an unauthorised or accidental disclosure of, or access to, personal data. Examples include an email sent to the wrong person, a lost unencrypted laptop, staff looking at records they have no reason to see, and client data pasted into a public AI tool. No hacker is needed; someone only has to see data they should not.

What is an integrity breach in the context of GDPR?

An integrity breach is the unauthorised or accidental alteration of personal data. The record still exists but is now wrong, such as a payment saved against the wrong customer or a field overwritten during an import. In 2024, alteration accounted for 10% of breaches notified to Ireland's Data Protection Commission.

What is an availability breach in the context of GDPR?

An availability breach is the accidental or unauthorised loss of access to, or destruction of, personal data. Ransomware on the only copy, deletion without a backup and a lost encryption key all qualify. A temporary loss of access can count too, but planned maintenance does not.

Is sending an email to the wrong person a data breach?

Yes, if it contains personal data. It is the most common confidentiality breach in Ireland: in 2025, half of all valid notifications to the DPC were unauthorised disclosures, and half of those were correspondence sent to the wrong recipient. Record it, assess the risk, and report it within 72 hours if there is one.

How long do you have to report a data breach in Ireland?

You must notify the Data Protection Commission without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to people. If the risk is high, you must also tell the people affected without undue delay.

Do you have to record a breach you do not report?

Yes. Article 33(5) GDPR requires every personal data breach to be documented, with its facts, effects and remedial action, whether or not it is reported. The DPC began examining organisations' compliance with this record-keeping duty in 2025, so an empty breach register now attracts questions.

Is putting client data into ChatGPT a GDPR breach?

Often, yes. If a staff member pastes personal data into a public AI tool without your authorisation or a data processing agreement, it is an unauthorised disclosure. The DPC treated an employee uploading 32 CVs to a free AI tool as a notifiable breach. Running the model on your own premises avoids the disclosure entirely.

If it has already happened: the first 72 hours

  1. Contain it. Delete the chat in the tool, and switch off chat history or model training on that account, knowing the provider may keep its own copy for a time.
  2. Record it. What was pasted, whose data, which tool, which account, when you found out. This goes in the breach register whatever happens next.
  3. Assess the risk. Payslips, bank details, PPS numbers and identity documents rarely come out as "no risk". The DPC's breach notification page sets out what it expects.
  4. Notify if needed, within 72 hours of becoming aware, and tell the people affected if the risk is high. Failing to notify can carry a fine of up to €10 million or 2% of turnover under Article 83(4).

None of this is legal advice, and a solicitor or your data protection officer should make the final call on a real incident. The useful thing to do this week is simpler: ask the team, without a disciplinary tone, which AI tools they use and on which logins. The answer is your baseline, not the offence.

Back in Galway, the negotiator still gets her affordability summary at 9.41am, and still makes the viewing at eleven. The three applications she pasted never left the office to produce it, which leaves three applicants who will never know how close their payslips came to California, and one breach register that stays honestly empty.

If you would like to talk through what your files contain and where they currently go, book a Local AI consultation — I read every enquiry myself — or open the chat on this page and ask it what it does with what you type. It is a cloud agent, and it will tell you.