---
title: "personal data breach: meaning under the DPDP Act"
url: https://dpdp.myndsolution.com/wiki/glossary/personal-data-breach/
description: "\"personal data breach\" as defined in section 2(u) of the DPDP Act, 2023: the official definition, its plain meaning, and where the term is used."
kind: term
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/glossary/personal-data-breach/
---
# personal data breach

## Official definition

**Act, s. 2(u):** (u) “personal data breach” means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data;


## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

The Digital Personal Data Protection Act defines a "personal data breach" as specific types of incidents that compromise the confidentiality, integrity, or availability of personal data. This definition is broad and covers two main categories of events. The first category is any "unauthorised processing" of personal data. Processing generally refers to operations performed on data, so any unauthorized action falls under this umbrella.<br><br>The second category covers a wide range of "accidental" events. These include the accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data. This means a breach is not limited to malicious attacks or theft by outside parties. It equally applies to internal mistakes, such as accidentally deleting files, unintentionally sharing information with the wrong person, or losing access to a database.<br><br>However, an unauthorized or accidental event only becomes a "personal data breach" under the Act if it results in a specific outcome. The event must compromise the confidentiality, integrity, or availability of the personal data. Confidentiality means keeping data secret, integrity means keeping it accurate and unchanged, and availability means being able to access it when needed. If an incident compromises any of these three elements, it meets the definition of a personal data breach.

### Key points

- A personal data breach includes any unauthorized processing of personal data [2(u)].
- It also covers accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data [2(u)].
- To qualify as a breach, the event must compromise the confidentiality, integrity, or availability of the personal data [2(u)].

### Common misreadings

- A reader might think a breach only involves data theft, but the text explicitly includes accidental destruction or loss of access.
- A reader might assume any accidental sharing is automatically a breach, but the text requires that the event actually compromises the data's confidentiality, integrity, or availability.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

## Used in

- [s. 8 General obligations of Data Fiduciary](https://dpdp.myndsolution.com/wiki/act/section-8-general-obligations-of-data-fiduciary/)
- [s. 27 Powers and functions of Board](https://dpdp.myndsolution.com/wiki/act/section-27-powers-and-functions-of-board/)
- [s. 40 Power to make rules](https://dpdp.myndsolution.com/wiki/act/section-40-power-to-make-rules/)
- [r. 6 Reasonable security safeguards](https://dpdp.myndsolution.com/wiki/rules/rule-6-reasonable-security-safeguards/)
- [r. 7 Intimation of personal data breach](https://dpdp.myndsolution.com/wiki/rules/rule-7-intimation-of-personal-data-breach/)
