{"id":4076,"date":"2026-07-30T10:00:00","date_gmt":"2026-07-30T08:00:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/?p=4076"},"modified":"2026-09-13T22:48:52","modified_gmt":"2026-09-13T20:48:52","slug":"cybersecurity-incident-vs-personal-data-breach","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/","title":{"rendered":"Cybersecurity incident vs personal data breach: what is the difference?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for data protection officers and security teams \u2022 published July 30, 2026 \u2022 updated August 19, 2026 \u2022 10 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">They differ in what they protect, and that is why they are determined separately. A cybersecurity incident \u2013 which the Polish Act on the National Cybersecurity System simply calls an incident \u2013 concerns the security of information systems and the continuity of the service, while a breach within the meaning of the GDPR concerns personal data and the rights of the individuals it relates to. The scopes of the two concepts overlap, but neither contains the other. There are incidents without a breach and breaches without an incident within the meaning of the act. A single event may therefore call for two independent determinations, two notifications with different content and two entries in separate records.<\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego\" class=\"wp-block-heading\">Why the question comes up at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The first source of doubt is linguistic. In most organisations the word \u201cincident\u201d means anything that went wrong in the systems \u2014 from a failed login to a halt in production. That is the name of the queue in the ticketing system, the name of the procedure and the word used in meetings. The act gives the word a narrower meaning and attaches specific obligations to it, so from the moment an organisation falls under the national cybersecurity rules, the same word describes two different things.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second source is conceptual. Both definitions speak of security, so they sound like two names for the same state of affairs. Their centre of gravity is different, though. An incident describes the effect of an event on an information system; a breach describes the effect of an event on personal data. That distinction decides whether an obligation towards the data protection authority arises at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third source is organisational and the most practical. The determination is usually made in a single meeting and led by a single role \u2014 most often someone from the security team or from IT. If that person closes the matter with one determination, the second track is not consciously rejected, it is simply never opened. It shows later in the documentation. There is a technical description of the event and no trace of an assessment of whether the event touched personal data.<\/p>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What to establish before deciding<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What each concept covers<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Act on the National Cybersecurity System (KSC) defines an incident as an event that has or may have an adverse effect on the security of information systems. The act describes the security of information systems itself as the resilience of those systems to events compromising the confidentiality, integrity, availability and authenticity of the data processed or of the related services. An information system means an ICT system or a set of devices and software intended for processing data \u2014 <strong>together with the data processed in electronic form<\/strong>. The point of reference is therefore the system and the service that system supports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Here the point of reference is the data, not the system it sits in. The medium is irrelevant \u2014 the definition covers data transmitted, stored or otherwise processed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In its guide on breaches, the President of the Personal Data Protection Office (UODO) breaks that definition into three conditions that must be met together. The event is a security incident, it concerns personal data being processed and, in the wording of the guide, it may lead to one of the listed consequences. The regulation itself is narrower here, because Article 4(12) GDPR speaks of a breach of security leading to those consequences, while the guide frames the condition as a possibility. In practice the difference rarely decides a case, because loss of the data is itself one of the consequences named in the definition \u2014 a lost storage device holding data is a breach even if nobody accessed the data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One terminological caveat is needed here, because without it the two documents look contradictory. A \u201csecurity incident\u201d, as the guide uses the term, is a general concept and also covers events outside ICT systems. An \u201cincident\u201d within the meaning of the KSC act is narrower and relates solely to the security of information systems. Every personal data breach is therefore a security incident in that first, general sense, but not every one is an incident within the meaning of the act.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two typical divergences follow. A repelled attack, a blocked connection to a production system or a failure of an environment that holds no personal data all fall within the definition of an incident and are not breaches. It also works the other way round. A lost personnel file, a fire in an archive or a letter delivered to the wrong address are personal data breaches even though they touch no information system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The overlap is larger than usually assumed. Since the security of information systems covers the confidentiality of the data processed, an event compromising the confidentiality of personal data in a system will usually meet both definitions at once. Separating the two determinations is therefore not about choosing one of them, but about not overlooking the second.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who each obligation applies to<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This question is settled before the event is assessed, not after. The obligations on handling and reporting incidents bind only essential and important entities, that is, organisations meeting the qualification criteria in the KSC act. The obligations on breaches bind every controller and every processor, irrespective of size, sector or entry in any register.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In practice this makes for an asymmetric arrangement. Most organisations always have breach obligations, and incident obligations only once they have been qualified. Organisations without their status settled in writing usually start with <a href=\"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/\">establishing the scope of obligations under NIS2 and the KSC<\/a> before they merge the two tracks into a single procedure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are also the transitional provisions, without which the picture is false. The amendment to the KSC act entered into force on April 3, 2026. Entities that met the criteria for being treated as an essential or important entity on that day implement the obligations under Chapter 3 of the act \u2014 including incident handling and reporting \u2014 within 12 months, that is by April 3, 2027. Entities that were previously operators of essential services report significant incidents under the new rules within 6 months of the amendment entering into force \u2014 for them the rules change at the beginning of October 2026. The obligations arising from the GDPR have no adjustment period and run independently of that timetable.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">From which moment time starts running<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each regime sets its own starting point and this is the most common source of error in documentation. The deadlines towards the competent CSIRT run from <strong>detection<\/strong> of a significant incident. The deadline towards the President of UODO runs from <strong>becoming aware<\/strong> of a breach, that is, from the moment the controller obtained sufficient certainty that an event concerning personal data had occurred.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those moments rarely fall in the same hour. Detection is a technical finding and happens early. Awareness requires knowing which data the event concerned, so it comes after analysis. A single shared date in the register means one of the two deadlines was counted wrongly. The order of steps in the first 24 hours and how to document them is set out in <a href=\"https:\/\/www.lablogic.pl\/en\/what-to-do-after-detecting-an-incident\/\">What to do after detecting an incident?<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What threshold triggers a notification<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The thresholds are built differently too and cannot be used interchangeably. What must be reported is a <strong>significant<\/strong> incident, and the thresholds for treating an incident as significant are set by the Council of Ministers in a regulation, separately for sectors and sub-sectors. Entities for which the European Commission has set thresholds in an implementing regulation are excluded from that delegation. The criteria are quantitative. They cover the number of users affected by the disruption, the duration of the incident\u2019s effect on the service, the geographical spread and other factors specific to the sector.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is a gap here worth knowing about. Until new implementing provisions are issued, the existing ones apply, but for no longer than 12 months from the entry into force of the amendment. The act in force is the Regulation of the Council of Ministers of October 31, 2018, issued under the original act. It contains thresholds for six sectors of the former operators of essential services \u2014 from energy and transport to digital infrastructure \u2014 and uses the concept of an essential service, which the amendment no longer employs. For entities in the sectors added by the amendment there is therefore no threshold expressed in implementing provisions today. That is an assessment of the position rather than the wording of a provision; the gap is to be closed by a new regulation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the GDPR side there is no table of thresholds at all. Notification is the rule, and the controller may depart from it only where its assessment shows that the breach is unlikely to result in a risk to the rights or freedoms of natural persons. The assessment is qualitative and concerns the consequences for people, not the scale of the disruption to a service. The mechanism of that assessment is set out in <a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\">Does every data breach need to be reported?<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical consequence is that an event below the threshold of a significant incident may still be a notifiable breach, and a significant incident may be an event that touched no personal data at all. The outcome of one assessment does not decide the outcome of the other.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What each notification contains<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The difference is easiest to see by comparing the required content. A significant incident report describes the effect of the event on the provision of the service. It states which service it covered, how many users it affected, what the geographical spread was and whether it affected the provision of services by other entities. To that are added the causes, the course of events and the preventive and remedial action taken.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A breach notification to the President of UODO describes something else. The nature of the breach together with the categories and approximate number of data subjects and data records, the contact details of the data protection officer, the likely consequences of the breach and the measures taken to address it. The first notification speaks about the service, the second about people. Practically the only thing they share is the chronology of the event, which is why the content of one cannot be copied into the other without omitting most of the required information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What the difference looks like in brief<\/h3>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Dimension<\/th><th>Incident \u2014 the KSC act<\/th><th>Breach \u2014 the GDPR<\/th><\/tr><\/thead><tbody><tr><td>What is protected<\/td><td>The security of information systems and the continuity of the service<\/td><td>Personal data and the rights and freedoms of individuals<\/td><\/tr><tr><td>Condition for it to arise<\/td><td>An effect on the security of the system \u2014 actual or possible<\/td><td>The event concerns personal data and may lead to their destruction, loss, alteration, disclosure or unauthorised access<\/td><\/tr><tr><td>Relevance of the medium<\/td><td>Information systems only<\/td><td>Any medium, including paper<\/td><\/tr><tr><td>Who it applies to<\/td><td>Essential and important entities<\/td><td>Controllers and processors<\/td><\/tr><tr><td>Start of the deadline<\/td><td>Detection of the incident<\/td><td>Becoming aware of the breach<\/td><\/tr><tr><td>Notification threshold<\/td><td>Quantitative thresholds in a Council of Ministers regulation<\/td><td>Assessment of the risk to the rights and freedoms of individuals<\/td><\/tr><tr><td>Who the notification goes to<\/td><td>The competent CSIRT<\/td><td>The President of UODO and, where the risk is high, the individuals as well<\/td><\/tr><tr><td>Who makes the determination<\/td><td>The security team, under the responsibility of the head of the entity<\/td><td>The controller, in practice with the DPO involved<\/td><\/tr><tr><td>Where the record remains<\/td><td>Registered incidents made available to the competent CSIRT<\/td><td>Breach documentation covering unreported breaches as well<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The table puts the concepts in order but does not replace the assessment of a specific event.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What decides is what the event actually covered, not how it was labelled in the first internal ticket.<\/p>\n\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Where the outcome of both determinations is recorded<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each regime requires its own record. An essential or important entity gives the competent CSIRT access to information about registered incidents to the extent necessary for it to carry out its tasks. A controller documents any personal data breaches together with the circumstances, effects and remedial action taken, and the documentation has to enable the supervisory authority to verify compliance. The duty to document also covers breaches the organisation did not report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A single ticketing system will serve both obligations only if it has separate fields. It has to keep the moment of detection and the moment of awareness apart, the incident classification and the breach determination apart, and the reasoning behind each of the two decisions apart. A shared record with one date and one status looks tidy right up to the authority\u2019s first question about when and on what basis the organisation decided the matter.<\/p>\n\n\n\n<h2 id=\"uklady\" class=\"wp-block-heading\">Four configurations of a single event<\/h2>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Situation<\/th><th>Incident under the KSC act<\/th><th>Breach under the GDPR<\/th><th>What follows<\/th><\/tr><\/thead><tbody><tr><td>Disruption of a process control system in which no personal data are processed<\/td><td>Yes<\/td><td>No<\/td><td>Handling and registration on the KSC side, classification against the thresholds; no obligations towards the data protection authority<\/td><\/tr><tr><td>Encryption of customer-facing systems by ransomware<\/td><td>Yes<\/td><td>Yes<\/td><td>Two tracks in parallel, two deadlines counted from different moments, two notifications with different content<\/td><\/tr><tr><td>Loss of paper documentation containing personal data<\/td><td>No<\/td><td>Yes<\/td><td>The GDPR track only \u2014 assessment of the risk to individuals, decision on notification, entry in the breach documentation<\/td><\/tr><tr><td>An event at a supplier processing data on the organisation\u2019s behalf<\/td><td>On the supplier\u2019s side, if it is covered by the act<\/td><td>On the organisation\u2019s side as controller<\/td><td>The supplier notifies the controller of the breach, and the controller decides whether to notify the authority<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The last row shows what causes the most trouble in practice. Both determinations may arise at two different entities in connection with a single event. The processing agreement should then set the time and channel for notification, because without it the controller learns of the matter at the end of the chain.<\/p>\n\n\n\n<h2 id=\"bledy\" class=\"wp-block-heading\">Most common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>A determination made by a single role.<\/strong> The security team closes the matter as a low-severity incident and the information never reaches the data protection officer. What is missing then is not so much the notification as the assessment of whether there was anything to notify.<\/li>\n\n\n\n<li><strong>Carrying thresholds across regimes.<\/strong> Assessing a breach by the number of affected service users instead of by the risk to individuals systematically understates the result, because an event of limited reach can involve special categories of personal data.<\/li>\n\n\n\n<li><strong>A shared register without separate fields.<\/strong> One date, one status and one set of reasons mean the organisation has failed one of the two documentation obligations.<\/li>\n\n\n\n<li><strong>Copying the content of one notification into the other.<\/strong> A description of the effect on the service does not answer questions about the categories and number of individuals or the likely consequences for them, so a notification built that way is incomplete from the outset.<\/li>\n\n\n\n<li><strong>Concluding that failing to qualify under the KSC act removes breach obligations.<\/strong> The regimes have different personal scopes. An organisation outside the register of essential and important entities is fully subject to the GDPR.<\/li>\n\n\n\n<li><strong>Treating the KSC transitional period as a suspension of all obligations.<\/strong> The adjustment deadlines concern only the obligations under the KSC act. The duty to notify a breach runs unchanged throughout.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After every event two questions have to be asked separately. The first is whether the event affected or could have affected the security of information systems, and the second whether it touched personal data or could have led to that. The answer to the first does not decide the answer to the second, and settling one regime does not close the other. An organisation that asks only one of those questions is not so much taking a bad decision as failing to take the second one at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before the next event it is worth settling four things. Who asks the second question and at what point in handling the matter. How the register is built so that it holds two moments, two determinations and two sets of reasons. Where the incident classification thresholds come from and by what criteria the risk to individuals is assessed. From when the obligations under the KSC act genuinely bind the organisation, taking the transitional provisions into account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Separating the two determinations does not increase the number of procedures. It usually leads to one procedure in which two decisions have named owners and separate places in the documentation \u2014 and it is that change, rather than the scale of the event itself, that later decides what the organisation is able to demonstrate.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-to-do-after-detecting-an-incident\/\">What to do after detecting an incident?<\/a><\/strong> \u2014 the order of actions in the first 24 hours, preserving evidence and the parallel running of deadlines.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\">Does every data breach need to be reported?<\/a><\/strong> \u2014 the notification threshold and the assessment of risk to the rights and freedoms of individuals.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-organization-fall-under-nis2\/\">Does every organization fall under NIS2?<\/a><\/strong> \u2014 the qualification of an entity, which decides whether incident obligations arise at all.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/\">What should a personal data breach register contain?<\/a><\/strong> \u2014 what to record once the event has been classified, including where there is no breach.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-does-a-significant-incident-report-to-a-csirt-contain\/\">What does a significant incident report to a CSIRT contain?<\/a><\/strong> \u2014 the content of the early warning, the report and the follow-up reports on the KSC side<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), Article 4(12), Article 33 and Article 34, consolidated text \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:02016R0679-20160504\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed August 19, 2026)<\/li>\n\n\n\n<li>Act of July 5, 2018 on the National Cybersecurity System, Article 2(3d), (5), (7) and (14), Articles 11, 12 and 12a, consolidated text \u2014 Chancellery of the Sejm, ISAP: <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001560\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n\n\n\n<li>Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252), Articles 32 and 33 \u2014 transitional provisions, Journal of Laws: <a href=\"https:\/\/dziennikustaw.gov.pl\/D2026000025201.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">dziennikustaw.gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n\n\n\n<li>Regulation of the Council of Ministers of October 31, 2018 on the thresholds for treating an incident as significant (Journal of Laws 2018, item 2180) \u2014 Chancellery of the Sejm, ELI: <a href=\"https:\/\/api.sejm.gov.pl\/eli\/acts\/DU\/2018\/2180\/text.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">api.sejm.gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n\n\n\n<li>Guide to personal data breaches, version of February 20, 2025 \u2014 Personal Data Protection Office (UODO): <a href=\"https:\/\/uodo.gov.pl\/pl\/598\/3563\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n\n\n\n<li>Other obligations and provisions related to breaches \u2014 Personal Data Protection Office (UODO): <a href=\"https:\/\/uodo.gov.pl\/pl\/542\/2586\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish; accessed August 19, 2026)<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Separate the two determinations before an event forces you to<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If a single role determines an event in your organisation today and the register has one date and one status, it is worth putting that process in order calmly. Support with incidents and breaches covers assessing the situation, decisions on notifications, documentation and remedial action.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/incident-response\/\">Support with incidents and breaches<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An incident under the Polish KSC act and a breach under the GDPR are two independent determinations of the same event. The scopes overlap but neither contains the other, so settling one does not close the other.<\/p>\n","protected":false},"author":2,"featured_media":5567,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"August 2026","footnotes":""},"categories":[71],"tags":[],"class_list":["post-4076","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-incidents"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"A cybersecurity incident under the KSC act and a personal data breach under the GDPR are two determinations of one event. How they differ and when both arise.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Cybersecurity incident vs data breach\" \/>\n\t\t<meta property=\"og:description\" content=\"The same event can be one, the other, or both at once.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"Incidents and Breaches\" \/>\n\t\t<meta property=\"article:tag\" content=\"incidents\" \/>\n\t\t<meta property=\"article:tag\" content=\"gdpr\" \/>\n\t\t<meta property=\"article:tag\" content=\"ksc\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-30T08:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-13T20:48:52+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Cybersecurity incident vs data breach\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The same event can be one, the other, or both at once.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#article\",\"name\":\"Incident vs personal data breach \\u2014 where the line runs\",\"headline\":\"Cybersecurity incident vs personal data breach: what is the difference?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg\",\"width\":1200,\"height\":630,\"caption\":\"One event, two separate assessments \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-07-30T10:00:00+02:00\",\"dateModified\":\"2026-09-13T22:48:52+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#webpage\"},\"articleSection\":\"Incidents and Breaches, Optional\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"position\":2,\"name\":\"Incidents and Breaches\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#listItem\",\"name\":\"Cybersecurity incident vs personal data breach: what is the difference?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#listItem\",\"position\":3,\"name\":\"Cybersecurity incident vs personal data breach: what is the difference?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/\",\"name\":\"Incident vs personal data breach \\u2014 where the line runs\",\"description\":\"A cybersecurity incident under the KSC act and a personal data breach under the GDPR are two determinations of one event. How they differ and when both arise.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"One event, two separate assessments \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/cybersecurity-incident-vs-personal-data-breach\\\/#mainImage\"},\"datePublished\":\"2026-07-30T10:00:00+02:00\",\"dateModified\":\"2026-09-13T22:48:52+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Incident vs personal data breach \u2014 where the line runs","description":"A cybersecurity incident under the KSC act and a personal data breach under the GDPR are two determinations of one event. How they differ and when both arise.","canonical_url":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#article","name":"Incident vs personal data breach \u2014 where the line runs","headline":"Cybersecurity incident vs personal data breach: what is the difference?","author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg","width":1200,"height":630,"caption":"One event, two separate assessments \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-07-30T10:00:00+02:00","dateModified":"2026-09-13T22:48:52+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#webpage"},"articleSection":"Incidents and Breaches, Optional"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","position":2,"name":"Incidents and Breaches","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#listItem","name":"Cybersecurity incident vs personal data breach: what is the difference?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#listItem","position":3,"name":"Cybersecurity incident vs personal data breach: what is the difference?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/en\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author","url":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","width":96,"height":96,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/","name":"Incident vs personal data breach \u2014 where the line runs","description":"A cybersecurity incident under the KSC act and a personal data breach under the GDPR are two determinations of one event. How they differ and when both arise.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"creator":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg","@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#mainImage","width":1200,"height":630,"caption":"One event, two separate assessments \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/#mainImage"},"datePublished":"2026-07-30T10:00:00+02:00","dateModified":"2026-09-13T22:48:52+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"Cybersecurity incident vs data breach","og:description":"The same event can be one, the other, or both at once.","og:url":"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg","og:image:width":1200,"og:image:height":630,"article:section":"Incidents and Breaches","article:tag":["incidents","gdpr","ksc","compliance"],"article:published_time":"2026-07-30T08:00:00+00:00","article:modified_time":"2026-09-13T20:48:52+00:00","twitter:card":"summary_large_image","twitter:title":"Cybersecurity incident vs data breach","twitter:description":"The same event can be one, the other, or both at once.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg"},"aioseo_meta_data":{"post_id":"4076","title":"Incident vs personal data breach \u2014 where the line runs","description":"A cybersecurity incident under the KSC act and a personal data breach under the GDPR are two determinations of one event. How they differ and when both arise.","keywords":null,"keyphrases":{"focus":{"keyphrase":"incident vs personal data breach","score":0,"analysis":[]},"additional":[{"keyphrase":"difference between incident and breach","score":0,"analysis":[]},{"keyphrase":"security incident and GDPR breach","score":0,"analysis":[]},{"keyphrase":"when is an incident a data breach","score":0,"analysis":[]}]},"primary_term":null,"canonical_url":null,"og_title":"Cybersecurity incident vs data breach","og_description":"The same event can be one, the other, or both at once.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Incidents and Breaches","og_article_tags":[{"label":"incidents","value":"incidents"},{"label":"GDPR","value":"GDPR"},{"label":"KSC","value":"KSC"},{"label":"compliance","value":"compliance"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-19 18:09:57","updated":"2026-09-13 20:52:41","seo_analyzer_scan_date":null,"focus_keyword":"cybersecurity incident vs personal data breach","additional_keywords":[{"word":"difference between incident and breach","score":0},{"word":"security incident and GDPR breach","score":0},{"word":"when is an incident a data breach","score":0}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-cybersecurity-incident-vs-personal-data-breach-en-1.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4076","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=4076"}],"version-history":[{"count":15,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4076\/revisions"}],"predecessor-version":[{"id":5514,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4076\/revisions\/5514"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5567"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=4076"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=4076"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=4076"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}