
Calling a Data Breach 'Immaterial' Won't Satisfy Regulators
A global organisation has experienced a personal data breach. The damage appears contained, and the executive team decides not to notify anyone, determining internally that the breach is "not material".
This decision, based on a company's internal assessment of "materiality", is a dangerous gamble that ignores the strict, statutory notification duties mandated by global data protection laws, particularly in key markets like the United Kingdom, the European Union, the UAE, and Saudi Arabia. Here is why self-assessing a breach as "immaterial" may lead directly to high-risk enforcement actions worldwide.
The Legal Definition of a Breach vs. Business Materiality
Under major data regimes, the definition of a personal data breach is broad and immediate: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
The legal trigger for notification is based on the risk to the individual's rights and freedoms, not the financial impact on the company.
1. The UK and EU Standard: Risk, Risk, and High Risk
For companies processing personal data subject to the UK GDPR or EU GDPR, the threshold for reporting is low and the timeline is extremely tight.
- Reporting to the Regulator: the Controller must notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This is only excused if the breach is "unlikely to result in a risk to the rights and freedoms of natural persons". If notification is delayed beyond 72 hours, the delay must be accompanied by reasons.
- Reporting to the Data Subject: the Controller has a separate duty to communicate the breach directly to the data subject "without undue delay" when the breach is "likely to result in a high risk to the rights and freedoms of natural persons".
- The Accountability Principle: even if the company deems the breach low risk and decides not to notify, it must document the event, including the facts relating to the breach, its effects, and the remedial action taken.
The decision to conceal the breach must be supported by verifiable evidence proving the lack of risk; otherwise, the organisation is in violation of its notification duties under Article 33 and Article 34.
2. The Global Requirement for Transparency
If the global company processes data relating to individuals in other jurisdictions, those local laws impose independent and equally strict notification obligations.
- UAE Protection of Personal Data (Federal Decree by Law No. (45) of 2021): the Controller must notify the UAE Data Bureau (Office) if the breach or violation "would prejudice the privacy, confidentiality and security of data", and must notify the Data Subject if the breach "would prejudice the privacy and confidentiality of the security of his/her Personal Data".
- Saudi Arabia Personal Data Protection Law (PDPL): the Controller must notify the Competent Authority upon knowing of "any breach, damage, or illegal access" to personal data, and must notify the Data Subject if the breach "would cause damage to their data or cause prejudice to their rights and interests".
In all these jurisdictions, the legal language focuses on the potential damage or prejudice to the data subject, not the financial quantification of the breach by the company.
The True Cost of Silence: Aggravating Factors and Massive Fines
Failing to meet these notification duties constitutes a serious infringement of the Controller's obligations. For a global undertaking operating under the GDPR/UK DPA framework, this violation can result in substantial administrative fines: infringement of notification obligations falls under the "standard maximum amount" category, meaning fines can reach up to £8,700,000 or 2% of the undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher.
Crucially, when regulatory authorities assess a penalty, the company's lack of transparency is considered an aggravating factor. The severity of the penalty is determined by factors including the manner in which the infringement became known to the supervisory authority — specifically, whether and to what extent the controller or processor notified the infringement. The company's choice to hide the breach could transform a small incident into a major regulatory failure, substantially increasing the final penalty imposed.
In summary, a company's internal belief that a breach is "not material" is legally irrelevant if the breach carries a demonstrable risk (or high risk) to the affected individuals. The failure to notify promptly transforms a technical security failure into a failure of accountability, guaranteeing harsher penalties when the breach inevitably comes to light.
Concealing a data breach is like quietly ignoring a small engine fire on an airplane. The safety manual mandates immediate reporting based on the risk to passengers, not the cost of the repair. If the plane lands safely, the company might save face briefly, but when regulators investigate the black box (the required documentation), the intentional failure to report, despite the risk, subjects the company to far greater liability than the fire itself.