northdan.
Vezi pagina în română

IT Glossary

What is a data breach?

An incident in which protected data — belonging to customers or to the company — reaches unauthorised hands, with a 72-hour legal clock attached.

A data breach is the moment when information you were supposed to guard — customer records, employee files, card data, contracts — reaches someone who had no right to see it. That someone might be an attacker, but it might equally be an email containing the payroll spreadsheet sent to the entire company, or an unencrypted laptop left on a train. The GDPR attaches a merciless clock to such incidents: where the breach presents a risk to the individuals concerned, you have 72 hours from becoming aware of it to notify the supervisory authority, which in Romania is ANSPDCP, the national data protection authority, and in serious cases the affected people must be told directly. The real invoice for a breach has three lines: the possible fine, the cost of investigation and remediation, and — usually the most expensive — lost customer trust. Reasonable preparation before anything happens is unglamorous: data access on a need-to-know basis, encryption on laptops, two-factor authentication, and a written response plan with named owners.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

A response in hours, not in panic

A plan agreed in advance — who investigates, who notifies, who communicates — is the difference between a managed incident and chaos that attracts a fine.

Reduced legal exposure

Documented measures such as encryption, restricted access and logging reduce both the probability of a breach and the penalty if one occurs anyway.

Customer trust protected

Companies that communicate an incident honestly and quickly emerge with a repairable reputation; those that conceal one and are found out rarely do.

Frequently asked questions

Does every security incident have to be reported to the data protection authority?

No. Notification applies to breaches involving personal data that present a risk to individuals; ransomware that encrypted only internal technical files may not be notifiable. Even so, the assessment must be documented in writing precisely when you decide not to notify.

How do I find out whether my company's data has appeared in a breach?

For email accounts there are free checking services such as Have I Been Pwned. For your own infrastructure, monitoring and access logs are what reveal abnormal activity — provided they exist and somebody actually reads them.

What do I do in the first hours after discovering a breach?

Contain it by changing passwords, cutting compromised access and disconnecting affected systems; preserve the evidence rather than deleting logs; assess which data was exposed; and start the notification clock. The wrong order — quietly erasing traces out of embarrassment — makes everything worse, legally and technically.