Open the workflow when monitoring, support, a processor, a third party, a user report, or an internal team flags an incident that may involve personal data. The first triage question is not whether the incident is embarrassing or severe; it is whether there has been a breach of security involving personal data.
Classify the event as a suspected confidentiality, integrity, availability, or combined breach. GDPR Article 4(12) covers accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. The EDPB also distinguishes personal data breaches from security incidents that do not involve personal data.
Representative examples include a customer file sent to the wrong recipient as a confidentiality breach, unauthorised alteration of account or health information as an integrity breach, and permanent loss or a ransomware outage that makes personal data unavailable as an availability breach. A temporary outage can still be a breach when the lack of access can harm people. Classification and notification still depend on the actual facts, protections, recovery time, and likely consequences.