Open the workflow when monitoring, support, a processor, a third party, a user report, or an internal team flags an incident that may involve personal data. The first triage question is not whether the incident is embarrassing or severe; it is whether there has been a breach of security involving personal data.
Classify the event as a suspected confidentiality, integrity, availability, or combined breach. GDPR Article 4(12) covers accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. The EDPB also distinguishes personal data breaches from security incidents that do not involve personal data.