Learning 4 - Security, breaches and complaints
1. Section 4: Security, breaches and complaints
1.1. 4.1 Security and personal data breaches
4.1 Security and personal data breaches
Recognising security measures and different forms of breach.
Appropriate security
The UK GDPR requires appropriate technical and organisational measures. “Appropriate” depends on risk, context, cost, current technology and the nature of the data.
| Technical measures | Organisational measures |
|---|---|
| Multi-factor authentication, encryption, patching, backups, logging, network controls, secure configuration, malware protection and tested recovery. | Policies, training, access reviews, supplier management, incident plans, clear roles, secure disposal, physical security and auditing. |
What is a personal data breach?
It is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Knowledge checkpoint
Answer each question before opening the suggested answer.
1. A spreadsheet is sent to the wrong external recipient. Is this potentially a breach?
Suggested answer: Yes. It may be an unauthorised disclosure.
2. A system encrypts its own database after a ransomware attack. Which aspects may be affected?
Suggested answer: Availability and potentially confidentiality and integrity.
3. Does every personal data breach have to be reported to the ICO?
Suggested answer: No. The reporting threshold depends on risk, but every breach should be assessed and documented.
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.