skip to content

GDPR

The EU regulation governing personal data end to end — a lawful basis for every processing activity, enforceable rights for data subjects, breach reporting deadlines, and rules on moving data abroad. Interviewers ask because GDPR turns into concrete engineering work: deletion paths, consent records, retention limits and audit trails.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

questions

page 1 of 2

Under the GDPR, what counts as a personal data breach, and does it only mean data being stolen?

level: juniorimportance: must knowfreq 66%

answer

  1. a security failure, not any violation
  2. Art. 4(12) wording
  3. three security properties
  4. losing access counts too

basics

~20 s

Under GDPR Art. 4(12), a personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It covers confidentiality, integrity and availability failures, not just theft.

solid answer

~40 s

Art. 4(12) of the GDPR defines a **personal data breach** as "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data". EDPB Guidelines 9/2022 sort breaches into three types: **confidentiality** (disclosure or access), **integrity** (alteration) and **availability** (loss of access or destruction). So ransomware that encrypts a clinic's booking database is a breach even with no sign of exfiltration, and so is an employee accidentally deleting records with no backup. It must be a *security* failure, though: processing without a lawful basis is a GDPR infringement, not a personal data breach. Every breach is documented under Art. 33(5); whether it is also notified depends on risk.

go deeper

for a junior

Recall the Art. 4(12) wording and the three breach types: confidentiality, integrity and availability. Show that losing access to data counts, not only leaking it.

for a middle

Classify a concrete event, such as ransomware, a lost stick or a bad script, into one or more breach types. Then separate 'is it a breach' from 'must it be notified'.

for a senior

Show that classifying an event as a breach opens a decision chain: record it, assess risk, notify the authority, possibly tell individuals. Explain why an availability-blind team leaves no record.

for a principal

Frame how a definition that covers availability and integrity shapes what an organisation's detection and escalation have to catch before any clock can start.

## The definition in the Regulation The GDPR defines the term in **Art. 4(12)**: a personal data breach is *"a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed."* Three parts of that sentence do the work: - **"a breach of security"**: the trigger is a security failure. A GDPR infringement that is not a security failure, such as processing without a lawful basis or keeping data too long, is a different problem under different Articles. It is not a "personal data breach". - **"accidental or unlawful"**: intent does not matter. A misaddressed email, a lost USB stick or an accidental deletion qualifies as much as an intrusion. - **the five outcomes**: destruction, loss, alteration, unauthorised disclosure, unauthorised access. Only two of them, disclosure and access, are defined by data reaching someone. EDPB Guidelines 9/2022 add a useful distinction: all personal data breaches are security incidents, but not every security incident is a personal data breach. A phishing attempt blocked before it reaches any personal data is an incident, not a breach. ## Three kinds of breach The EDPB guidelines borrow the classic information-security triad to classify breaches. One event can fall into several at once. | Type | What happened | Example | |---|---|---| | **Confidentiality** | unauthorised or accidental disclosure of, or access to, personal data | a customer file emailed to the wrong recipient | | **Integrity** | unauthorised or accidental alteration of personal data | a faulty script overwrites delivery addresses | | **Availability** | accidental or unauthorised loss of access to, or destruction of, personal data | ransomware encrypts records with no usable backup | The availability row is the one candidates forget. The guidelines say a **permanent** loss or destruction of personal data is always an availability breach. A **temporary** loss caused by a security incident is also a breach. Unavailability caused by **planned maintenance** is not, because it is not a "breach of security". ## Worked example: ransomware at a clinic A clinic's booking database is encrypted by ransomware. The investigation finds no evidence that anything was copied out. 1. **Is it a breach?** Yes. Patients' appointment data has been made unavailable by a security failure, so this is at least an availability breach. The lack of exfiltration evidence rules out nothing about availability. It only changes the confidentiality question, which stays open until the investigation can answer it. 2. **Does it have to be notified?** That is a separate question. Under **Art. 33(1)** the controller notifies the supervisory authority unless the breach is *unlikely to result in a risk* to people's rights and freedoms. The EDPB guidelines give examples in both directions. Patient data that is unavailable, even for a while, can put people at risk because appointments and treatment are disrupted. Data restored from a backup in good time, with no other malware, may not need reporting. 3. **Does it have to be recorded?** Yes, always. **Art. 33(5)** requires the controller to document *any* personal data breach, notifiable or not. ## Why the label matters Calling something a breach does not mean calling the regulator. It starts the GDPR's decision chain: 1. Is this a personal data breach under Art. 4(12)? 2. If yes, record it (Art. 33(5)). 3. Is it likely to result in a risk to individuals? If yes, notify the supervisory authority (Art. 33(1)). 4. Is it likely to result in a *high* risk? If yes, also tell the affected individuals (Art. 34(1)), unless an Art. 34(3) exception applies. A team that only looks for "data stolen" will miss availability and integrity breaches entirely. Those breaches then never reach the record or the risk assessment, and the controller cannot show the supervisory authority that it complied. ## Common traps - **"No exfiltration, so no breach."** Wrong: loss of access and destruction are breaches in their own right. - **"It was an accident, so it doesn't count."** Wrong: the definition says "accidental or unlawful". - **"Any GDPR violation is a breach."** Wrong: the term is limited to security failures. - **"Not notifiable means nothing to do."** Wrong: the Art. 33(5) record is still required.

  • Under the GDPR, is a system outage during planned maintenance a personal data breach?
    No. EDPB Guidelines 9/2022 say personal data that is unavailable because of planned system maintenance is not a 'breach of security' under Art. 4(12). An unplanned outage caused by a security incident is different: it can be an availability breach. Like any breach, it is documented under Art. 33(5) even if it does not need notifying.
  • Under the GDPR, does a breach have to involve an outside attacker?
    No. Art. 4(12) covers 'accidental or unlawful' events, and the EDPB notes that security incidents include failures inside the organisation's own processing. A misaddressed email, a lost device or a bad deployment that corrupts records can all be personal data breaches.

saying these in an interview costs you the question

  • A breach only happens when an attacker copies personal data out.
  • Ransomware with no sign of exfiltration is not a GDPR breach.
  • An accidental loss doesn't count because nobody acted maliciously.
  • Processing without a lawful basis is itself a 'personal data breach'.
  • A breach that doesn't need notifying doesn't need recording either.
open as a page

Under the GDPR, what does a subscriber's right of access entitle them to receive, and by when must the controller respond?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Under GDPR Art. 15, the person gets confirmation that their data is processed, a copy of it, and context: purposes, categories, recipients, retention, source, rights and automated decisions. Art. 12(3) requires a reply within one month of receipt, extendable by two further months.

open as a page

Under GDPR Art. 6(1), what are the six lawful bases for processing, and why is consent not the default?

level: juniorimportance: must knowfreq 74%

basics

~20 s

GDPR Art. 6(1) lists consent, contract, legal obligation, vital interests, public task and legitimate interests. None ranks above the others; consent fits only when the person has a real choice, because it can be withdrawn and processing must then stop.

open as a page

Under the GDPR, is a table of SHA-256-hashed email addresses handed to an ad partner still personal data?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Yes. A hashed email is a stable identifier that anyone holding the address can recompute and match, so under the GDPR it is pseudonymised data, which Recital 26 treats as personal data. Only data rendered anonymous leave the Regulation's scope.

open as a page

Under GDPR Chapter V, what routes can make a transfer of personal data to a third country lawful, and in what order?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Under GDPR Chapter V, a transfer needs an adequacy decision (Art. 45), or appropriate safeguards such as SCCs or BCRs (Art. 46), or, as a narrow exception, an Art. 49 derogation. The rest of the Regulation must be met too.

open as a page

Under GDPR Art. 33, when does the 72-hour clock start, and what must the notification to the supervisory authority contain?

level: middleimportance: must knowfreq 72%

basics

~20 s

Under GDPR Art. 33(1), the controller notifies without undue delay and, where feasible, within 72 hours of becoming aware of the breach. The notice gives at least the Art. 33(3) items and may be completed in phases.

open as a page

Under the GDPR, a laptop with full-disk encryption is stolen and its key is held elsewhere; must anyone be notified?

level: middleimportance: must knowfreq 58%

basics

~20 s

Under the GDPR the theft is still a breach and is recorded. With effective encryption, an uncompromised key and another copy of the data, it is usually unlikely to cause risk, so neither the authority nor individuals are notified.

open as a page

Under GDPR Art. 6(1)(f), how does a bank justify fraud-screening card payments on legitimate interests, and what must it record?

level: middleimportance: must knowfreq 60%

basics

~20 s

Under GDPR Art. 6(1)(f), the bank must show a legitimate interest (Recital 47 names fraud prevention), that the screening is necessary for it, and that customers' interests and rights do not override it, and document that assessment before screening starts.

open as a page

Under the GDPR, how do you decide whether a vendor is a controller, a processor or a joint controller?

level: middleimportance: must knowfreq 68%

basics

~20 s

Under the GDPR, whoever determines the purposes and means of processing is the controller (Art. 4(7)); a party processing on the controller's behalf is a processor (Art. 4(8)); parties that jointly determine purposes and means are joint controllers (Art. 26).

open as a page

Under GDPR Art. 3, does the Regulation apply to a US product-analytics SaaS vendor with EU users but no EU establishment?

level: middleimportance: must knowfreq 62%

basics

~20 s

Very likely yes. GDPR Art. 3(2) reaches a non-EU company whose processing relates to offering services to, or monitoring the behaviour of, people in the Union, and product analytics monitors behaviour. Art. 27 then generally requires an EU representative.

open as a page

Under GDPR Art. 83, what is the maximum fine for an unlawful transfer, and how does 'whichever is higher' apply to a corporate group?

level: middleimportance: must knowfreq 56%

basics

~20 s

Under GDPR Art. 83(5)(c), infringing the transfer rules (Arts. 44-49) risks up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. For a group, turnover is that of the whole undertaking under Arts. 101-102 TFEU.

open as a page

Under the GDPR, a contracted support desk in India views EU customer records hosted in the EU; is that a transfer, and what is needed?

level: middleimportance: must knowfreq 55%

basics

~20 s

Under the GDPR, making EU-hosted data viewable by a contractor in India is a transfer. Absent an adequacy decision, it needs Art. 46 safeguards, typically SCC Module Two with a Clause 14 assessment, plus notice to customers.

open as a page

Under the GDPR, a streaming subscriber demands erasure while tax law requires their invoices to be kept and a billing dispute is open; what does Art. 17 require?

level: seniorimportance: must knowfreq 62%

basics

~20 s

Under GDPR Art. 17, data must be erased without undue delay where a ground applies, except to the extent an Art. 17(3) exception covers it: invoices kept under tax law (point (b)) and dispute records needed for legal claims (point (e)) stay; the rest goes.

open as a page

Under GDPR Art. 9(1), which personal data are special categories, and why are criminal records and bank details not among them?

level: juniorimportance: should knowfreq 55%

basics

~20 s

GDPR Art. 9(1) lists data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, plus genetic, identifying biometric, health, and sex-life or sexual-orientation data. Criminal data fall under Art. 10; bank details are ordinary personal data.

open as a page

Under GDPR Art. 37, when must an organisation designate a Data Protection Officer, and could its CTO hold that role?

level: middleimportance: should knowfreq 54%

basics

~20 s

Under GDPR Art. 37(1), a DPO is mandatory for public authorities, and where core activities involve large-scale regular and systematic monitoring or large-scale special-category or criminal data. A CTO is a poor fit: Art. 38(6) bars conflicting duties.

open as a page

Under the GDPR, how may a controller verify a requester's identity, and when may it refuse or charge for a data subject request?

level: middleimportance: should knowfreq 44%

basics

~20 s

Under GDPR Art. 12(6), a controller with reasonable doubts may ask only for the extra information necessary to confirm identity. Requests are free; under Art. 12(5) it may charge a reasonable fee or refuse only manifestly unfounded or excessive ones, and must prove that.

open as a page

Under the GDPR, how does objecting to direct marketing differ from objecting to other legitimate-interest processing, and where does restriction fit?

level: middleimportance: should knowfreq 42%

basics

~20 s

Under GDPR Art. 21(2)-(3), a direct-marketing objection is absolute: that processing stops, with no balancing. Other objections under Art. 21(1) rest on the person's situation and yield to compelling legitimate grounds; Art. 18 restriction limits data to storage while that is checked.

open as a page

Under the GDPR, which of a streaming subscriber's data falls under the Art. 20 right to data portability, and which does not?

level: middleimportance: should knowfreq 48%

basics

~20 s

Under GDPR Art. 20, portability covers personal data the subscriber provided, processed on consent or contract by automated means, delivered in a structured, commonly used, machine-readable format. Scores the service computes and data processed on other lawful bases fall outside.

open as a page

Under GDPR Art. 6(1)(b), can an online shop rely on contract necessity to use past purchases for product recommendations?

level: middleimportance: should knowfreq 50%

basics

~20 s

Usually not. Under GDPR Art. 6(1)(b), processing must be objectively necessary to perform the contract. A shop can sell and deliver without recommendations, so EDPB guidance treats that personalisation as outside the contract basis; another basis must carry it.

open as a page

Under the GDPR, a fitness app stores users' heart-rate data; why is an Art. 6 lawful basis alone not enough?

level: middleimportance: should knowfreq 48%

basics

~20 s

Heart-rate readings are data concerning health, a special category that GDPR Art. 9(1) prohibits processing by default. The app needs both an Art. 6(1) basis and one of the Art. 9(2) conditions, for a consumer app typically explicit consent under Art. 9(2)(a).

open as a page

Under GDPR Art. 28, what must a controller-processor contract contain, and what does it commit the processor to?

level: middleimportance: should knowfreq 48%

basics

~20 s

GDPR Art. 28(3) requires a written, binding contract describing the processing and committing the processor to documented instructions, confidentiality, Art. 32 security, sub-processor rules, assistance with rights and Arts. 32-36, deletion or return at the end, and audits.

open as a page

Under the GDPR, when can an EU startup rely on the EU-US Data Privacy Framework to send personal data to a US-headquartered cloud provider?

level: middleimportance: should knowfreq 52%

basics

~20 s

Under Decision (EU) 2023/1795, only US organisations on the Data Privacy Framework List are adequate. The startup checks that the recipient is listed, current and covers the data type; otherwise it needs SCCs or another Art. 46 route.

open as a page

Under the GDPR, a spreadsheet of customer records is emailed to the wrong business partner, who confirms deletion; must you notify, and what goes in the breach record?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Under the GDPR it is a confidentiality breach whatever the recipient does. A trusted partner's confirmed deletion may make risk unlikely, so no notice may be due, but Art. 33(5) still requires recording facts, effects and remedial action.

open as a page

Under the GDPR, when your processor discovers a breach of your customers' data, who must notify whom, and when does your 72-hour clock start?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Under GDPR Art. 33(2), the processor notifies the controller without undue delay, with no risk assessment first. Per EDPB guidance, the controller is in principle aware once informed, and then owns the Art. 33 and 34 decisions.

open as a page

showing 1–30 of 36