What Is a Confidentiality Breach in the Context of GDPR?
A confidentiality breach is "an unauthorised or accidental disclosure of, or access to, personal data". That is the European Data Protection Board's definition in its Guidelines 9/2022 on breach notification, and it covers the wrong recipient, the wrong reader and the wrong destination alike. Nobody needs to be hacked. Somebody only needs to see data they should not.
Monday, 9.40am, a letting agency in Galway. A two-bed in Salthill went up on Friday and there are 23 applications in the inbox, each with payslips, bank statements, an employer reference and, in two cases, a PPS number nobody asked for. The lettings negotiator has a viewing at eleven. She opens ChatGPT on her own login, pastes in three applications and asks which tenant looks strongest on affordability. The answer is sensible and arrives in seconds. So does the disclosure: three people's salaries, account balances and employment details are now with a company in California, under its terms, on her personal account. Nobody in the office would call that a breach. It felt like using a calculator.
The legal definition, in one line
Article 4(12) GDPR defines a personal data breach as "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data". Read it again and you will see three different failures folded into one sentence. Regulators split them out using three old information-security principles: confidentiality, integrity and availability. Article 5(1)(f) makes the first two a core principle of the regulation, literally titled "integrity and confidentiality", and Article 32 adds availability when it asks for "the ongoing confidentiality, integrity, availability and resilience of processing systems".
Confidentiality, integrity and availability breaches compared
| Breach type | EDPB definition | In a letting agency | Irish figure (DPC, 2024) |
|---|---|---|---|
| Confidentiality | Unauthorised or accidental disclosure of, or access to, personal data | Tenant reference emailed to the wrong landlord; application pasted into a public chatbot | 60% of notifications were unauthorised disclosures to individuals or small groups |
| Integrity | Unauthorised or accidental alteration of personal data | A rent arrears note saved against the wrong tenant | 10% were accidental or unauthorised alteration |
| Availability | Accidental or unauthorised loss of access to, or destruction of, personal data | Ransomware encrypts the only copy of the tenancy files | 8% were accidental loss or destruction |
The figures are from the Data Protection Commission's 2024 annual report, which logged 7,781 valid breach notifications. The EDPB is clear that one incident can be all three at once: ransomware that encrypts files and copies them out first is an availability breach and a confidentiality breach on the same morning.
What is an integrity breach in the context of GDPR?
An integrity breach is the unauthorised or accidental alteration of personal data. The record still exists and nobody outside saw it, but it is now wrong: a deposit marked as returned when it was not, a reference attached to the wrong applicant, a phone number overwritten by a careless merge. It matters because decisions get made on the altered version.
What is an availability breach in the context of GDPR?
An availability breach is the accidental or unauthorised loss of access to, or destruction of, personal data. Deletion with no backup, ransomware on the only copy, a lost encryption key. The EDPB adds that a temporary loss can count too, though planned maintenance does not, because nobody broke anything.
Why is confidentiality important?
Because it is the breach that happens most. The DPC's 2025 annual report counted 6,521 valid notifications, and unauthorised disclosures affecting individuals or small groups made up half of them. Half of those were correspondence sent to the wrong person. For a business that holds payslips and bank statements, confidentiality is the whole basis of being trusted with them. A tenant who learns their salary was read by the wrong landlord does not care which article was breached.
