Skip to main content
Category: Breach and Risk Assessment

Breach Notification Threshold

Also known as: Notification Threshold, Breach Reporting Threshold
Simply put

A breach notification threshold is the point at which a data security incident becomes serious enough that an organization is legally required to report it, rather than simply handle it internally. Whether a given incident crosses this threshold depends on factors set out in the applicable law, such as whether personal information was compromised and whether harm is likely. If an incident falls below the threshold, notification may not be required, though assessment and internal documentation are still generally expected.

Formal definition

The breach notification threshold is the set of legal criteria that determine whether a security incident must be assessed and reported to affected individuals, regulators, or both, as opposed to being managed without external notification. Requirements are jurisdiction-specific and not uniform: in the United States, all 50 states have enacted security breach notification laws requiring disclosure to consumers when personal information is compromised, and these laws impose sometimes unique criteria that vary by state. Thresholds may turn on factors such as the type of information involved, the number of individuals affected, and the likelihood of harm; for example, certain federal reporting rules distinguish incidents affecting fewer than 500 individuals and incidents where there is no reasonable likelihood of harm, with corresponding differences in reporting obligations. This entry defines the concept of the threshold only and does not enumerate the specific triggers, timelines, or content requirements of any particular statute, nor does it cover enforcement penalties, cross-border reporting mechanics, or non-U.S. regimes; practitioners should consult the applicable law and current guidance, since treatment differs across jurisdictions and organizations must be able to demonstrate that their assessment and reporting decisions were properly made.

Why it matters

The breach notification threshold determines whether a security incident triggers a legal duty to notify affected individuals, regulators, or both, or whether it can be managed internally. Getting this determination right matters because the assessment itself is an accountability obligation: organizations must generally be able to demonstrate how and why they concluded that a given incident did or did not cross the threshold. Treating notification as optional or making an undocumented judgment call exposes an organization to regulatory scrutiny even where the underlying incident was minor.

The practical difficulty is that thresholds are not uniform. In the United States, all 50 states have enacted security breach notification laws requiring disclosure to consumers when personal information is compromised, and these statutes impose sometimes unique criteria that vary from state to state. A single incident affecting individuals across multiple states can therefore trigger different obligations under different laws simultaneously, which is why practitioners often rely on comparative resources rather than assuming a single national standard applies.

Thresholds can also turn on factors such as the type of information involved, the number of individuals affected, and the likelihood of harm. Certain federal reporting rules, for instance, distinguish incidents affecting fewer than 500 individuals and incidents where there is no reasonable likelihood of harm, with corresponding differences in how and when reporting must occur. Because these distinctions carry legal consequences, the threshold analysis is a core step in incident response rather than an afterthought.

Who it's relevant to

Incident response and security teams
These teams typically perform the initial assessment of an incident and must determine, against the applicable criteria, whether personal information was compromised and whether the incident meets a notification threshold. They are generally responsible for capturing the facts and documentation needed to support that determination, even where the incident falls below the threshold and no external notification is required.
Data protection officers and privacy leads
Those accountable for privacy compliance must apply the relevant legal criteria to decide whether notification to individuals, regulators, or both is required. Because thresholds vary by jurisdiction and a single incident may implicate several state laws at once, they must be able to demonstrate that the threshold analysis and any resulting reporting decisions were properly made, not merely stated.
Legal and compliance counsel
Counsel advising on breach response must map an incident to the sometimes unique requirements of each applicable statute, including any that distinguish incidents by the number of individuals affected or the likelihood of harm. This entry does not enumerate specific statutory triggers, timelines, penalties, or non-U.S. regimes, so counsel should consult the current text of the applicable law and guidance.
Organizations that collect, store, or process personal information
Any organization in possession of personal information may become subject to notification obligations if an incident compromises that information. Understanding where the threshold lies helps such organizations build response processes that both meet legal duties when they are triggered and maintain the internal documentation generally expected even for incidents that do not require external notification.

Inside Breach Notification Threshold

Risk-based trigger
Under the EU GDPR and UK GDPR, notification to a supervisory authority is generally required when a personal data breach is likely to result in a risk to the rights and freedoms of natural persons. The threshold is framed around risk assessment rather than the mere occurrence of a breach.
Heightened threshold for notifying data subjects
Communication to affected individuals is typically required only where a breach is likely to result in a high risk to their rights and freedoms, a higher bar than the threshold for notifying the authority. These two thresholds should not be treated as identical.
Regime-specific definitions
What constitutes a reportable breach and the applicable threshold differ across instruments. The EU GDPR, UK GDPR, HIPAA, and US state laws such as the CCPA and CPRA each define breach scope, triggers, and covered data differently, so the threshold must be scoped to the governing regime rather than treated as universal.
Controller and processor responsibilities
Under the GDPR framework, the controller generally bears the obligation to assess whether the threshold is met and to notify the supervisory authority and, where applicable, data subjects. A processor is typically obligated to notify the controller of a breach it becomes aware of, but does not itself make the threshold determination toward the authority.
Documentation of the assessment
Even where a breach is assessed as not meeting the notification threshold, the reasoning and facts supporting that conclusion are generally expected to be documented as part of accountability, so the decision is demonstrable rather than merely asserted.

Common questions

Answers to the questions practitioners most commonly ask about Breach Notification Threshold.

Does every personal data breach have to be reported to a supervisory authority?
No. Under the EU and UK GDPR, notification to the supervisory authority is generally required only where the breach is likely to result in a risk to the rights and freedoms of individuals; breaches unlikely to pose such a risk typically do not trigger the authority notification obligation, though they should still be documented internally. A separate and higher threshold applies to notifying affected individuals, which is generally required only where the breach is likely to result in a high risk to their rights and freedoms. Thresholds and terminology differ across regimes such as the CCPA and CPRA, HIPAA, and others, so the applicable standard depends on jurisdiction and the nature of the data. This answer does not cover timing mechanics, cross-border coordination, or enforcement consequences.
If the breached data was encrypted or tokenized, does that automatically mean no notification is required?
Not automatically. Encryption or tokenization can reduce the assessed risk to individuals and may weigh against a duty to notify, but such measures do not, by themselves, render the assessment complete or place the data outside scope. The analysis generally turns on whether the protection was effective in the specific circumstances, for example whether keys or mapping tables were also compromised. Encrypted or tokenized personal data typically remains personal data. The notification determination still depends on a case-by-case risk assessment under the applicable regime; this answer does not address specific control adequacy criteria.
Who is responsible for deciding whether the notification threshold is met and for making any required notification?
Accountability for the threshold assessment and for notifying a supervisory authority generally rests with the data controller. Where a processor detects or experiences a breach, its obligation is typically to inform the controller so the controller can carry out the assessment and any required notifications, with the precise contractual and statutory duties depending on the arrangement and jurisdiction. The controller should be able to demonstrate, with documented evidence, how the risk assessment and any resulting decision were reached. This answer does not cover the detailed contractual allocation of duties between the parties.
How should an organization document a breach that was assessed as below the notification threshold?
Even where a breach is assessed as not requiring notification, organizations subject to the GDPR are generally expected to record the facts of the breach, its effects, and the remedial action taken, so that the supervisory authority can verify compliance if requested. This documentation supports the accountability principle, which typically requires demonstrable evidence rather than a stated conclusion alone. The record should capture the reasoning behind the threshold decision. This answer does not prescribe a specific format, retention period, or tooling.
What factors typically feed into the risk assessment used to apply the threshold?
Assessments commonly consider factors such as the type and sensitivity of the data involved, including whether special category or sensitive data is affected, the volume of records and number of individuals, the ease of identifying affected individuals, the potential severity of consequences, and whether protective measures were effective. The presence of special category data may raise the assessed risk relative to ordinary personal data. These factors are generally weighed together rather than applied as a fixed checklist, and their treatment can vary by regime. This answer does not provide a scoring methodology or jurisdiction-specific criteria.
How does the threshold assessment relate to the timing of a notification?
The threshold determines whether a notification obligation arises, while separate timing rules govern how quickly a required notification must be made once the obligation is established. Under the GDPR framework the two are linked, because the assessment is generally expected to be conducted without undue delay, but the risk determination and the deadline for acting on it are distinct considerations. Timing rules and how any applicable time limits are calculated differ across regimes and are outside the scope of this entry, which addresses only the threshold itself.

Common misconceptions

Any personal data breach must always be reported to the supervisory authority.
Under the EU and UK GDPR, notification to the authority is generally required only where the breach is likely to result in a risk to individuals' rights and freedoms. Some breaches assessed as unlikely to pose such a risk may not require notification, though the assessment should still be documented. Treatment differs under other regimes such as HIPAA and US state laws.
The threshold for notifying the authority and the threshold for notifying affected individuals are the same.
These are distinct thresholds. Notifying data subjects is generally triggered only by a likely high risk to their rights and freedoms, which is a higher bar than the risk threshold for notifying the supervisory authority.
Encrypted or tokenized data means a breach is automatically below the notification threshold.
Encryption or tokenization may reduce the assessed risk of a breach, but it does not by itself render data non-personal or guarantee that the threshold is not met. The determination depends on the specific facts, the strength and scope of the measures, and the applicable regime, and still requires a documented risk assessment.

Best practices

Identify the governing regime or regimes for the affected data and apply that instrument's specific breach definition and threshold, rather than assuming a single universal standard across the EU GDPR, UK GDPR, HIPAA, and US state laws.
Maintain separate, documented assessment criteria for the two thresholds: risk to rights and freedoms for authority notification and likely high risk for notifying affected individuals.
Establish clear controller and processor roles in advance, including processor obligations to promptly notify the controller so the controller can make and document the threshold determination.
Document the facts and reasoning behind every threshold decision, including cases assessed as not requiring notification, to support demonstrable accountability rather than stated intent.
Do not rely on encryption or tokenization alone to conclude a breach falls below the threshold; incorporate the effectiveness and scope of such measures into a documented, case-specific risk assessment.
Pre-agree assessment workflows and evidence-capture procedures before an incident occurs, so threshold determinations can be made and recorded consistently under time pressure.