03 · What You Need to Know
A Data Breach Is Not Limited to Stolen Data
Data breaches can take several forms
Under the GDPR, a personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
The Philippine National Privacy Commission similarly recognizes different forms of personal data breach within its breach-management framework.
A useful way to understand breaches is through confidentiality, integrity, and availability.
| Type |
What goes wrong |
Research example |
| Confidentiality breach |
Personal data are disclosed or accessed without authorization. |
A participant spreadsheet is emailed to the wrong recipient. |
| Integrity breach |
Personal data are altered or corrupted without authorization. |
Malware changes participant outcome records or a user overwrites the master dataset incorrectly. |
| Availability breach |
Authorized users lose access to personal data. |
Ransomware encrypts the only accessible participant database or records are accidentally deleted without recoverable backup. |
One incident can involve all three. A ransomware attack might expose participant records, modify systems, and make the dataset unavailable simultaneously.
Unauthorized access can be a breach even without downloading
A person does not necessarily need to copy or publish a dataset for unauthorized access to matter.
If someone who should not have access can view identifiable participant information, that can constitute unauthorized access. Examples might include a former research assistant whose account was never disabled, a collaborator granted access to the wrong folder, or a public link exposing records to anyone who discovers it.
The investigation should determine what access was possible and, where evidence is available, what access actually occurred.
Accidental mistakes can be breaches
A breach does not need malicious intent. Data protection definitions expressly include accidental events.
A researcher who mistakenly sends data to the wrong person has not become a cybercriminal. The disclosure can nevertheless require formal breach management because participants' information has left the authorized environment.
Separating blame from response is useful. The first priority is containment and risk management, not deciding whose annual performance review will become unexpectedly interesting.
Not every security incident is a personal data breach
A phishing email that is blocked before credentials are compromised may be a security incident without a personal data breach. A server outage affecting only public, non-personal research material may be an availability problem without engaging personal-data breach rules.
Conversely, a seemingly minor mistake involving personal data may qualify as a breach.
This is why the broader guidance on accidental disclosure or loss of research data emphasizes reporting suspected incidents before trying to make the final classification yourself.
A breach does not automatically mean regulator notification is required
One of the most important distinctions is between having a personal data breach and having a personal data breach that meets the legal threshold for external notification.
Under the EU GDPR, controllers must notify the competent supervisory authority unless the personal data breach is unlikely to result in a risk to individuals' rights and freedoms. Where the breach is likely to result in a high risk, affected individuals generally must also be informed, subject to the Regulation's conditions and exceptions.
The Philippine framework uses a different mandatory-notification test. The Data Privacy Act implementing rules require notification when specified categories of information are reasonably believed to have been acquired by an unauthorized person and the unauthorized acquisition is likely to create a real risk of serious harm.
The NPC emphasizes that not all personal data breaches require notification to the Commission and affected individuals.
Researchers should therefore avoid two opposite mistakes: assuming every incident must immediately be reported externally, or assuming a small-looking incident requires no formal assessment.
The 72-hour clock is organizationally important
Both the EU GDPR and Philippine breach frameworks contain 72-hour notification provisions in specified circumstances, although their legal tests and starting points should be applied according to the relevant law.
Under GDPR Article 33, a controller must notify a reportable breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. A processor must notify the controller without undue delay.
Philippine rules likewise provide a 72-hour notification framework following knowledge or reasonable belief that a personal data breach requiring notification has occurred.
The practical implication for researchers is simple: your institution cannot use time it does not know it has. Report suspected breaches internally immediately.
Philippine mandatory notification has specific criteria
Under current NPC guidance, mandatory notification is not triggered merely because any personal information was involved. The Commission identifies specific elements that must be assessed, including the type of information, unauthorized acquisition, and likelihood of real risk of serious harm.
Relevant information can include sensitive personal information or other data capable of enabling identity fraud, such as certain financial information, login credentials, biometric information, identification documents, and unique identifiers.
The responsible personal information controller should make that assessment through its breach-management process. Researchers should provide accurate facts rather than attempting to compress the legal test into "sensitive data equals automatic notification."
Containment should begin immediately
The precise response depends on the incident. Possible actions include disabling compromised credentials, revoking shared links, isolating affected devices, recovering mistakenly sent information, blocking unauthorized accounts, restoring from clean backups, or stopping a system from continuing to disclose data.
The NPC requires breach-management procedures designed to contain incidents, restore system integrity, mitigate harm, and ensure compliance with notification requirements.
ICO guidance likewise recommends attempting to recover affected information and taking immediate steps to protect those most affected.
Preserve evidence while containing the problem
Do not delete logs, wipe devices, destroy messages, or otherwise remove information that investigators may need unless directed to do so as part of containment.
Useful evidence can include system logs, access records, emails, file-sharing histories, device information, screenshots, malware alerts, timestamps, recipient confirmations, encryption status, and backup records.
A reliable timeline is particularly important because regulatory notification deadlines can depend on when the organization became aware of the breach.
Risk assessment should focus on people, not only the institution
A breach can be inconvenient for the university while posing little risk to participants, or operationally minor for the institution while creating substantial risk for particular individuals.
Possible consequences can include identity fraud, discrimination, reputational harm, financial loss, embarrassment, threats to personal safety, exposure of medical or psychological information, loss of confidentiality, or other context-specific harms.
The seriousness of the research topic can matter. Disclosure that someone participated in a study of an innocuous consumer preference may have very different consequences from disclosure of participation in research concerning a stigmatized illness, domestic violence, political activity, immigration status, or illegal behavior.
Encryption can change the consequences without erasing the incident
A stolen laptop containing strongly encrypted data may present much less confidentiality risk than an unencrypted laptop containing the same records.
Under GDPR Article 34, appropriate technical measures that render personal data unintelligible to unauthorized people, such as encryption, can affect whether communication to individuals is required.
The institution should nevertheless verify that encryption was actually applied and effective. "I think BitLocker was on" is useful as an initial recollection, not as the final forensic conclusion.
Document even breaches that are not externally reportable
Under GDPR Article 33, controllers must document personal data breaches, including the facts, effects, and remedial action, so supervisory authorities can verify compliance.
The Philippine Data Privacy Act implementing rules likewise require written documentation of all security incidents and personal data breaches, including those outside mandatory notification requirements.
A decision not to notify externally should therefore be an assessed and documented decision, not the absence of a record because nobody wanted to create paperwork.
Processors and service providers need to escalate incidents
Research data may be held by survey platforms, transcription companies, cloud providers, laboratories, repositories, or other processors.
Under GDPR Article 33, processors must notify controllers without undue delay after becoming aware of a personal data breach.
Philippine breach rules likewise recognize responsibilities of personal information processors within breach management, while the notification obligation to the NPC remains associated with the responsible PIC under the applicable framework.
Contracts should therefore specify incident-notification routes and timing. Discovering a vendor breach through social media several days later is not an especially elegant incident-response architecture.
A breach can affect whether research should continue normally
Some incidents can be contained without changing study operations. Others reveal a continuing vulnerability that could expose additional participants if recruitment or data collection continues unchanged.
Researchers should not independently assume that a breach either automatically stops the study or has no effect on it. The institution may need to coordinate privacy, security, ethics, sponsor, and participant-safety assessments.
Where continuing the study could expose additional people or compromise further information, the question of whether data collection or other study activities should be paused deserves separate consideration.
Do Not Wait for Certainty
You do not need a completed forensic investigation before reporting a suspected breach internally. Initial reports can contain uncertainty. What matters is getting the incident into the formal response process early enough to contain harm and meet any applicable deadlines.