skip to content

Under the GDPR, a spreadsheet of customer records is emailed to the wrong business partner, who confirms deletion; must you notify, and what goes in the breach record?

level: seniorimportance: should knowfreq 46%

answer

  1. a confidentiality breach regardless
  2. trusted recipient lowers likelihood
  3. what the columns reveal
  4. facts, effects, remedial action
  5. record the reasoning too

basics

~20 s

Under the GDPR it is a confidentiality breach whatever the recipient does. A trusted partner's confirmed deletion may make risk unlikely, so no notice may be due, but Art. 33(5) still requires recording facts, effects and remedial action.

solid answer

~40 s

Sending customer data to the wrong recipient is an **unauthorised disclosure**, so it is a personal data breach under Art. 4(12). The recipient's deletion does not undo that. EDPB Guidelines 9/2022 let the controller count a **trusted recipient** in its risk assessment: a known partner it has an ongoing relationship with and can reasonably expect to return or destroy the data. That may make the breach unlikely to result in a risk, so there is no Art. 33 notice and no Art. 34 communication. The content decides it, though: bank details, ID numbers or special-category data can keep the risk real. Either way **Art. 33(5)** requires a record of the *facts, effects and remedial action*, and the EDPB recommends adding the **reasoning** for not notifying.

go deeper

for a junior

Recall that a misdirected email is a confidentiality breach, and that every breach is documented under Art. 33(5) whether or not anyone is notified.

for a middle

Apply the EDPB risk factors, especially data sensitivity and the trusted-recipient point, to decide between recording only, notifying the authority, and also telling individuals.

for a senior

Show how the same misdirected file flips from record-only to notifiable as its columns change, and write a record that would survive an authority's review of a decision not to notify.

for a principal

Consider what a breach record regime must capture across hundreds of low-grade incidents a year so patterns such as repeated misdirection become visible and fixable.

## Step 1: it is a breach **Art. 4(12)** includes *"unauthorised disclosure of, or access to, personal data"*, accidental or not. An email with the wrong address is the textbook **confidentiality breach**. The EDPB guidelines say plainly that a trusted recipient *"does not mean that a breach has not occurred"*. What the recipient does next affects the **risk**, not the classification. ## Step 2: assess the risk, not the embarrassment Notification turns on two tests: **Art. 33(1)** (notify the authority unless the breach is *unlikely to result in a risk*) and **Art. 34(1)** (tell individuals if it is *likely to result in a high risk*). EDPB Guidelines 9/2022 list the factors to weigh: | Factor | Question for this spreadsheet | |---|---| | **Type of breach** | disclosure only, or also lost or altered? | | **Nature, sensitivity, volume** | names and emails, or bank details, ID numbers, health data? how many rows? | | **Ease of identification** | directly identifying, or pseudonymised identifiers? | | **Severity of consequences** | could it enable fraud, identity theft or humiliation? | | **Special characteristics of individuals** | children or other vulnerable people? | | **Recipient** | a known, trusted partner, or someone whose intentions are unknown? | | **Number affected** | a handful, or tens of thousands? | The guidelines address the **trusted recipient** directly. Where data goes to a party the controller has an ongoing relationship with, and whose procedures and history it knows, the controller can reasonably expect that party not to read the data and to return or destroy it. That *"may eradicate the severity of the consequences"* and may remove the likelihood of risk, so that neither notification is required. It is **case by case**, and the guidelines also say that *if in doubt, the controller should err on the side of caution and notify*. Two readings of the same event: - **Names and business emails of 40 contacts**, sent to a long-standing partner that confirms deletion in writing within the hour: very plausibly *unlikely to result in a risk*, so it is recorded and not notified. - **Names, dates of birth and bank account numbers of 12,000 customers**, sent to the same partner: the data could enable fraud if the deletion is wrong. The risk is much harder to rule out, so the authority is notified, and the high-risk test for individuals needs a hard look. If a high risk did exist, the partner's prompt, confirmed deletion is also relevant to **Art. 34(3)(b)**: subsequent measures that ensure the high risk is *no longer likely to materialise*. ## Step 3: the record, notified or not **Art. 33(5)**: *"The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article."* What a useful entry holds, following the Article and the EDPB guidelines: - **facts**: what was sent, to whom, when, how it was discovered, which data categories and how many people; - **effects**: the consequences for individuals, as assessed; - **remedial action**: the deletion request and written confirmation, and any process fix such as recipient checks for outbound files; - **reasoning**: why the breach was judged unlikely to result in a risk. The EDPB recommends documenting this whenever a breach is not notified; - **evidence** for any Art. 34(3) condition relied on. The EDPB *encourages* an internal register of breaches, notifiable or not. It notes that the entries can sit inside the **Art. 30 record of processing activities**, provided breach information is clearly identifiable and can be extracted on request. The GDPR sets **no retention period** for this documentation. The controller decides it, bearing in mind it may need to show compliance with Art. 33 later. ## Why the record carries weight The authority can ask to see the record. A record that only says "breach, not notified" cannot show that the risk judgement was made properly. The guidelines add that failing to document a breach properly can itself lead the authority to use its Art. 58 powers.

  • Under the GDPR, does the partner's deletion satisfy any Art. 34(3) condition?
    It can support Art. 34(3)(b): subsequent measures ensuring a high risk is no longer likely to materialise. The EDPB's example is acting against the recipient before it could use the data. The controller must be able to evidence the deletion and still weigh what a disclosure of that data could mean.
  • Under the GDPR, must the breach record be a separate register?
    No. Art. 33(5) requires documentation, not a specific format. The EDPB encourages an internal register and says the entries may sit inside the Art. 30 record of processing activities, as long as breach information is clearly identifiable and can be extracted on request.

It is like a courier handing a parcel to the wrong neighbour who hands it straight back: the misdelivery still happened and goes in the log, but how worried the sender should be depends on who the neighbour is and what was in the box.

saying these in an interview costs you the question

  • The recipient deleted the file, so no breach occurred.
  • A breach nobody notified needs no record, since the authority never hears of it.
  • Writing 'breach, not notified' in a log satisfies Art. 33(5).
  • Every misdirected email with personal data must be reported to the authority.
  • The GDPR fixes a set retention period for the breach register.