Breach Register
A breach register is a documented log an organization keeps to record personal data breaches, including what happened, who was affected, the consequences, and what was done in response. It serves as an internal record so the organization can track incidents and demonstrate that breaches were identified and handled. It is a record-keeping tool and is distinct from any obligation to notify regulators or affected individuals, which is governed separately.
A breach register is an internal, maintained record documenting personal data breaches, where a personal data breach is generally understood as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data (ICO, in the UK context). Typical entries capture the nature of each breach, categories and approximate numbers of affected individuals, the likely consequences, and the remedial or mitigating actions taken. The register functions as accountability evidence rather than a compliance guarantee: maintaining one supports an organization's ability to demonstrate breach handling, but it does not itself satisfy any external notification duty. Notification thresholds, timelines, and recipients differ by regime and jurisdiction (for example, sectoral U.S. state breach notification laws and separate regulator-facing obligations under data protection regimes), and this entry does not cover those mechanics, retention periods, or enforcement consequences. The register is an operational and governance artifact and should not be conflated with the broader question of whether a given incident is reportable, which depends on context, applicable law, and a risk assessment.
Why it matters
A breach register is a core accountability artifact. Under data protection regimes that operate on an accountability principle, an organization is generally expected to be able to demonstrate that it identified, assessed, and responded to personal data breaches, not merely to assert that it did so. A maintained register provides that demonstrable evidence: a documented log of what happened, who was affected, the likely consequences, and the remedial actions taken. Without such a record, an organization may struggle to show, after the fact, that a given incident was recognized and handled appropriately.
The register is also an operational tool that helps an organization spot patterns across incidents, track whether remediation was completed, and maintain institutional memory that survives staff turnover. It should not, however, be treated as a substitute for external obligations. Maintaining a register does not itself satisfy any duty to notify a regulator or affected individuals; those notification thresholds, timelines, and recipients are governed separately and differ by regime and jurisdiction. In the United States, breach notification is governed by state-level laws that impose their own disclosure requirements, and in the UK the ICO frames breaches around a specific security-based definition, so what triggers an external notification is a distinct question from what belongs in the internal log.
A common expert-level error is to assume that logging an incident equals compliance, or that every recorded breach is automatically reportable. Whether an incident is reportable depends on context, applicable law, and a risk assessment. The register supports that assessment and preserves evidence of it, but it does not answer the reportability question on its own, and it does not cover retention periods or enforcement consequences.
Who it's relevant to
Inside Breach Register
Common questions
Answers to the questions practitioners most commonly ask about Breach Register.