An employee emails a spreadsheet of welfare claimants to the wrong external address. Which characterisation best fits GDPR personal-data breach analysis?
Select an answer to reveal the explanation.
Short Explanation
Wrong inbox, real people—classic oops that still counts. Sending welfare claimant details to a stranger is a confidentiality breach scenario, not just a manners problem. You assess risk and notification duties; you don't shrug because it was 'only email.'
Full Explanation
Unauthorised disclosure of personal data—such as sending a welfare claimant spreadsheet to an unintended external recipient—fits the GDPR concept of a personal-data breach affecting confidentiality. Controllers should assess likely risk to data subjects and apply notification rules to the supervisory authority and, where required, to individuals; internal apology alone does not redefine the event.