- Data Breach
- An incident in which personal or confidential data is accessed, disclosed, altered, or destroyed without authorization.
- Personal Data
- Any information that can directly or indirectly identify a living individual β including names, email addresses, IP addresses, and health records.
- Notification Window
- The legally mandated time period within which affected individuals and regulators must be informed of a confirmed breach β 72 hours under GDPR, up to 60 days under HIPAA.
- Containment
- Immediate actions taken to stop an ongoing breach or prevent its spread β such as isolating affected systems, revoking credentials, or blocking network traffic.
- Eradication
- Removing the root cause of a breach from the environment β deleting malware, closing exploited vulnerabilities, or purging unauthorized access.
- Incident Response Team (IRT)
- A cross-functional group β typically including IT, legal, HR, and communications β responsible for coordinating the organization's response to a confirmed breach.
- Data Controller
- Under GDPR and similar frameworks, the organization that determines the purposes and means of processing personal data β and bears primary breach notification responsibility.
- Data Processor
- A third party that processes personal data on behalf of a controller β contractually required to notify the controller of any breach without undue delay.
- Risk Assessment
- An evaluation of the likelihood and severity of harm to affected individuals resulting from a breach, used to determine whether notification is legally required.
- Forensic Investigation
- A technical examination of affected systems to determine the scope, origin, timeline, and method of a breach β typically conducted before or alongside notification.
- Supervisory Authority
- The regulatory body empowered to receive breach notifications and enforce data protection law in a given jurisdiction β such as the ICO in the UK or the DPA in EU member states.