Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Is a Research Data Breach, and What Should You Do When One Happens?

A research data breach can involve unauthorized disclosure, loss, alteration, destruction, or loss of access to personal data. Researchers should report suspected breaches immediately so the responsible organization can contain, assess, document, and notify as required.

322
Research Data Breaches Guide 322 of 398
01 · The Question

What Actually Counts as a Research Data Breach?

A hacker steals a participant database. That obviously sounds like a breach.

But what about an email sent to the wrong collaborator? A deleted dataset with no backup? An unauthorized researcher viewing records without downloading them? A ransomware attack that makes files unavailable? A public sharing link that nobody appears to have opened?

Personal data breaches are broader than successful data theft. Depending on the applicable framework, they can involve unauthorized disclosure or access, accidental or unlawful destruction, loss, or alteration, and loss of availability. Researchers need to recognize these events early because breach-response and notification timelines can begin quickly.

02 · The Short Answer

A Breach Can Affect Confidentiality, Integrity, or Availability

In Brief

A personal research data breach occurs when a security failure results in personal data being accidentally or unlawfully destroyed, lost, altered, disclosed without authorization, or accessed without authorization under the applicable data protection framework.

If you suspect a breach, contain what you reasonably can, report it immediately through the institutional incident process, preserve the facts, and allow the responsible organization to assess risk and notification obligations. Do not wait until the investigation is complete before reporting internally.

03 · What You Need to Know

A Data Breach Is Not Limited to Stolen Data

Data breaches can take several forms

Under the GDPR, a personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

The Philippine National Privacy Commission similarly recognizes different forms of personal data breach within its breach-management framework.

A useful way to understand breaches is through confidentiality, integrity, and availability.

Type What goes wrong Research example
Confidentiality breach Personal data are disclosed or accessed without authorization. A participant spreadsheet is emailed to the wrong recipient.
Integrity breach Personal data are altered or corrupted without authorization. Malware changes participant outcome records or a user overwrites the master dataset incorrectly.
Availability breach Authorized users lose access to personal data. Ransomware encrypts the only accessible participant database or records are accidentally deleted without recoverable backup.

One incident can involve all three. A ransomware attack might expose participant records, modify systems, and make the dataset unavailable simultaneously.

Unauthorized access can be a breach even without downloading

A person does not necessarily need to copy or publish a dataset for unauthorized access to matter.

If someone who should not have access can view identifiable participant information, that can constitute unauthorized access. Examples might include a former research assistant whose account was never disabled, a collaborator granted access to the wrong folder, or a public link exposing records to anyone who discovers it.

The investigation should determine what access was possible and, where evidence is available, what access actually occurred.

Accidental mistakes can be breaches

A breach does not need malicious intent. Data protection definitions expressly include accidental events.

A researcher who mistakenly sends data to the wrong person has not become a cybercriminal. The disclosure can nevertheless require formal breach management because participants' information has left the authorized environment.

Separating blame from response is useful. The first priority is containment and risk management, not deciding whose annual performance review will become unexpectedly interesting.

Not every security incident is a personal data breach

A phishing email that is blocked before credentials are compromised may be a security incident without a personal data breach. A server outage affecting only public, non-personal research material may be an availability problem without engaging personal-data breach rules.

Conversely, a seemingly minor mistake involving personal data may qualify as a breach.

This is why the broader guidance on accidental disclosure or loss of research data emphasizes reporting suspected incidents before trying to make the final classification yourself.

A breach does not automatically mean regulator notification is required

One of the most important distinctions is between having a personal data breach and having a personal data breach that meets the legal threshold for external notification.

Under the EU GDPR, controllers must notify the competent supervisory authority unless the personal data breach is unlikely to result in a risk to individuals' rights and freedoms. Where the breach is likely to result in a high risk, affected individuals generally must also be informed, subject to the Regulation's conditions and exceptions.

The Philippine framework uses a different mandatory-notification test. The Data Privacy Act implementing rules require notification when specified categories of information are reasonably believed to have been acquired by an unauthorized person and the unauthorized acquisition is likely to create a real risk of serious harm.

The NPC emphasizes that not all personal data breaches require notification to the Commission and affected individuals.

Researchers should therefore avoid two opposite mistakes: assuming every incident must immediately be reported externally, or assuming a small-looking incident requires no formal assessment.

The 72-hour clock is organizationally important

Both the EU GDPR and Philippine breach frameworks contain 72-hour notification provisions in specified circumstances, although their legal tests and starting points should be applied according to the relevant law.

Under GDPR Article 33, a controller must notify a reportable breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. A processor must notify the controller without undue delay.

Philippine rules likewise provide a 72-hour notification framework following knowledge or reasonable belief that a personal data breach requiring notification has occurred.

The practical implication for researchers is simple: your institution cannot use time it does not know it has. Report suspected breaches internally immediately.

Philippine mandatory notification has specific criteria

Under current NPC guidance, mandatory notification is not triggered merely because any personal information was involved. The Commission identifies specific elements that must be assessed, including the type of information, unauthorized acquisition, and likelihood of real risk of serious harm.

Relevant information can include sensitive personal information or other data capable of enabling identity fraud, such as certain financial information, login credentials, biometric information, identification documents, and unique identifiers.

The responsible personal information controller should make that assessment through its breach-management process. Researchers should provide accurate facts rather than attempting to compress the legal test into "sensitive data equals automatic notification."

Containment should begin immediately

The precise response depends on the incident. Possible actions include disabling compromised credentials, revoking shared links, isolating affected devices, recovering mistakenly sent information, blocking unauthorized accounts, restoring from clean backups, or stopping a system from continuing to disclose data.

The NPC requires breach-management procedures designed to contain incidents, restore system integrity, mitigate harm, and ensure compliance with notification requirements.

ICO guidance likewise recommends attempting to recover affected information and taking immediate steps to protect those most affected.

Preserve evidence while containing the problem

Do not delete logs, wipe devices, destroy messages, or otherwise remove information that investigators may need unless directed to do so as part of containment.

Useful evidence can include system logs, access records, emails, file-sharing histories, device information, screenshots, malware alerts, timestamps, recipient confirmations, encryption status, and backup records.

A reliable timeline is particularly important because regulatory notification deadlines can depend on when the organization became aware of the breach.

Risk assessment should focus on people, not only the institution

A breach can be inconvenient for the university while posing little risk to participants, or operationally minor for the institution while creating substantial risk for particular individuals.

Possible consequences can include identity fraud, discrimination, reputational harm, financial loss, embarrassment, threats to personal safety, exposure of medical or psychological information, loss of confidentiality, or other context-specific harms.

The seriousness of the research topic can matter. Disclosure that someone participated in a study of an innocuous consumer preference may have very different consequences from disclosure of participation in research concerning a stigmatized illness, domestic violence, political activity, immigration status, or illegal behavior.

Encryption can change the consequences without erasing the incident

A stolen laptop containing strongly encrypted data may present much less confidentiality risk than an unencrypted laptop containing the same records.

Under GDPR Article 34, appropriate technical measures that render personal data unintelligible to unauthorized people, such as encryption, can affect whether communication to individuals is required.

The institution should nevertheless verify that encryption was actually applied and effective. "I think BitLocker was on" is useful as an initial recollection, not as the final forensic conclusion.

Document even breaches that are not externally reportable

Under GDPR Article 33, controllers must document personal data breaches, including the facts, effects, and remedial action, so supervisory authorities can verify compliance.

The Philippine Data Privacy Act implementing rules likewise require written documentation of all security incidents and personal data breaches, including those outside mandatory notification requirements.

A decision not to notify externally should therefore be an assessed and documented decision, not the absence of a record because nobody wanted to create paperwork.

Processors and service providers need to escalate incidents

Research data may be held by survey platforms, transcription companies, cloud providers, laboratories, repositories, or other processors.

Under GDPR Article 33, processors must notify controllers without undue delay after becoming aware of a personal data breach.

Philippine breach rules likewise recognize responsibilities of personal information processors within breach management, while the notification obligation to the NPC remains associated with the responsible PIC under the applicable framework.

Contracts should therefore specify incident-notification routes and timing. Discovering a vendor breach through social media several days later is not an especially elegant incident-response architecture.

A breach can affect whether research should continue normally

Some incidents can be contained without changing study operations. Others reveal a continuing vulnerability that could expose additional participants if recruitment or data collection continues unchanged.

Researchers should not independently assume that a breach either automatically stops the study or has no effect on it. The institution may need to coordinate privacy, security, ethics, sponsor, and participant-safety assessments.

Where continuing the study could expose additional people or compromise further information, the question of whether data collection or other study activities should be paused deserves separate consideration.

Do Not Wait for Certainty

You do not need a completed forensic investigation before reporting a suspected breach internally. Initial reports can contain uncertainty. What matters is getting the incident into the formal response process early enough to contain harm and meet any applicable deadlines.

04 · A Practical Example

When a Shared Research Folder Becomes Public

Hypothetical Example

An incorrect cloud permission

A researcher creates a cloud folder containing pseudonymized interview transcripts for three authorized collaborators. While changing permissions, the researcher accidentally enables access to anyone possessing the link. Two days later, another team member notices the setting. It is not immediately known whether anyone outside the team accessed the files.

Contain Public-link access is disabled immediately and permissions are restricted to the authorized collaborators.
Report The researcher reports the incident through the institution's designated breach-response channel without waiting to determine whether an outsider actually opened the folder.
Preserve evidence Sharing settings, audit logs, timestamps, affected file lists, user-access records, and other relevant information are preserved.
Assess The incident team determines whether unauthorized access occurred or was reasonably possible, how identifiable the transcripts are, what sensitive information they contain, how many participants are affected, and what consequences disclosure could create.
Decide notification The responsible organization applies the notification threshold under the governing law rather than assuming that public accessibility automatically means either "notify everyone" or "no evidence of download, so nothing happened."
Correct The team reviews default sharing permissions, staff training, folder structure, access approval, and whether particularly sensitive files should be held in a more restricted environment.
05 · What Researchers Often Get Wrong

Common Misconceptions About Research Data Breaches

Misconception

Does Someone Have to Steal Data for a Breach to Occur?

No. Accidental disclosure, unauthorized access, loss, destruction, or alteration can fall within personal data breach definitions. Malicious theft is only one possible scenario.

Misconception

Does Every Breach Have to Be Reported to the Regulator?

No. Notification thresholds vary by jurisdiction. Both GDPR and Philippine frameworks distinguish personal data breaches from breaches that meet the threshold for mandatory regulatory notification. The incident should still be assessed and documented.

Misconception

If Nobody Downloaded the Data, Was There No Breach?

Not necessarily. Unauthorized access or exposure can matter even without a confirmed download. The assessment should examine what access occurred or was possible and what evidence is available.

Misconception

Does Encryption Mean a Lost Device Cannot Be a Breach?

No. Effective encryption can substantially reduce risk and affect notification requirements, but the event still needs assessment. Availability, key security, device state, synchronization, and other circumstances may matter.

Misconception

Can the Principal Investigator Decide Alone Whether to Notify Participants?

That is usually inappropriate in institutional research. Notification decisions should follow the organization's breach-management process and applicable law, often involving the data protection officer, privacy office, security team, legal counsel, and other responsible units.

06 · What This Means for You

Your Job Is to Escalate Quickly and Preserve Useful Facts

A simple breach-response framework

If you suspect personal research data have been compromised
Report the incident immediately through the institutional response route.
If the exposure is continuing
Take authorized containment steps such as revoking access, isolating affected systems, or recovering information.
If important facts are uncertain
State the uncertainty and preserve evidence; do not delay the initial report while attempting to establish every detail.
If the breach may create immediate risk to participants
Escalate that concern explicitly so mitigation and any necessary communication can be prioritized.
If external notification may be required
Allow the responsible organization to apply the jurisdiction-specific threshold and notification procedure within the applicable timeline.

Notification is not necessarily the same for regulators, participants, ethics committees, sponsors, and collaborating institutions. The next question is therefore who must be told when a research data breach occurs.

07 · A Quick Checklist

When You Suspect a Research Data Breach

Immediately:
Contain continuing exposure or loss where you can do so safely and within your authority.
Report the suspected breach through the institution's designated privacy or security incident process.
Record when the incident occurred, when it was discovered, and when it was reported.
Identify the systems, devices, files, participant groups, and categories of personal data potentially affected.
Preserve logs, emails, access records, screenshots, and other evidence needed to establish what happened.
Confirm relevant safeguards such as encryption, pseudonymization, authentication, and access restrictions rather than assuming they were active.
Assess possible participant harms and identify any urgent mitigation measures.
Document the breach and the reasoning behind any decision to notify or not notify external parties.
Review technical and procedural causes after containment and implement measures to reduce recurrence.
08 · Frequently Asked Questions

Common Questions About Research Data Breaches

What is a confidentiality breach?

It occurs when personal data are disclosed or accessed without authorization. Examples include emailing participant data to the wrong person, exposing a research folder publicly, or allowing an unauthorized user to view records.

Can deleting research data accidentally be a personal data breach?

Yes, potentially. Personal data breach definitions can include accidental destruction or loss. Whether the incident creates regulatory notification obligations depends on the applicable framework and risk.

Does ransomware count as a data breach?

It can. Ransomware may create an availability breach by making personal data inaccessible and may also involve unauthorized access, disclosure, alteration, or exfiltration. The actual incident must be investigated rather than assuming ransomware affects only availability.

Does every Philippine personal data breach have to be reported to the NPC?

No. The NPC states that mandatory notification applies when the required elements under its breach rules are present. Incidents outside that threshold still require appropriate documentation and organizational handling.

How quickly must a GDPR breach be reported?

Where notification to the supervisory authority is required, GDPR Article 33 requires notification without undue delay and, where feasible, within 72 hours after the controller becomes aware of the breach.

How quickly must a breach be reported in the Philippines?

For breaches meeting the Philippine mandatory-notification requirements, the Data Privacy Act implementing rules and NPC Circular No. 16-03 provide a 72-hour notification framework following knowledge or reasonable belief that the relevant personal data breach has occurred.

Should a breach always stop the research study?

No. The appropriate response depends on whether continued activity would create further privacy, security, ethical, scientific, or participant-safety risks. Some incidents can be contained while research continues; others may justify temporarily pausing particular activities.

09 · The Bottom Line

A Breach Is About What Happened to the Data, Not Whether Someone Meant Harm

The Bottom Line

A research data breach can involve unauthorized access or disclosure as well as accidental loss, destruction, alteration, or unavailability of personal data; it does not require hacking, theft, or malicious intent.

When you suspect a breach, contain what you reasonably can and report it internally immediately. The responsible organization can then establish the facts, assess participant risk, document the event, determine notification obligations, and decide what needs to change before the same incident gets an opportunity for peer replication.

10 · Sources and Further Reading

Authoritative Sources on Personal Data Breaches

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes