What is Data Breach Notification?
A data breach notification is the formal message an organisation must send to regulators and/or people affected when personal data is exposed, lost or accessed without authorization. Its purpose is to explain what happened, what risk it creates, and what steps are being taken to reduce harm.
A data breach notification is a legal and practical requirement to tell relevant authorities and impacted individuals that personal data under your control has been compromised. Different laws set different rules (for example, GDPR requires notifying the supervisory authority within 72 hours where feasible). Notifications typically follow an internal incident assessment that determines who was affected, what types of data were exposed, the likely consequences, and the mitigation steps being taken. The notification must be clear, timely and include contact information so people can protect themselves.
Usage example
A school using Hearo discovers that a survey link was accidentally published publicly and exposed parent names, phone numbers and some free-text comments. The school’s team assesses the scope, secures the survey, and issues a data breach notification to the regulator (within the local legal deadline) and to affected families. The notification explains what data was exposed, what the school did to contain the issue, steps families can take (e.g., monitor for suspicious messages), and how to get help—in the home languages of the families where possible.
Practical application
Data breach notifications matter because they protect people from harm, preserve trust, and help organisations meet legal obligations. For teams collecting multilingual responses (schools, councils, charities), prompt, clear and translated notifications prevent confusion and reduce risk of further harm (fraud, identity misuse). Preparing templates, an incident response plan and translated contact points in advance makes notification faster and more reliable, reduces regulatory risk, and shows communities you take privacy and inclusion seriously.
FAQ
When do we have to notify regulators and affected people?
Requirements depend on local law and the breach’s severity. Under GDPR you must notify the supervisory authority within 72 hours of becoming aware of a personal data breach (if feasible). Notifying individuals is required when the breach is likely to result in a high risk to their rights or freedoms. Even when notification isn’t legally required, you should document the incident and your risk assessment.
What should a good data breach notification include?
A useful notification states what happened (nature and timing), the categories of personal data involved, likely consequences, measures already taken and planned to mitigate harm, practical steps people can take to protect themselves, and contact details for further information and support. Keep language plain and actionable.
If our data was encrypted, do we still need to notify?
Encryption reduces the risk of harm. Many laws allow an exemption from notifying individuals when strong encryption protected the data and keys were not compromised, but you should still assess the incident, notify regulators if required, and document the rationale. Don’t assume exemption—record technical facts and consult legal guidance if unsure.
How should we communicate notifications to multilingual communities?
Translate notifications into the languages your affected audience speaks or provide clear, simple multilingual summaries. Use the same trusted channels you use for engagement (email, SMS, school letters, community contacts) and offer ways for people to get help in their language. Having translated templates and a plan ready speeds response and reduces confusion.