
Something went wrong. A file went to the wrong person. A system was accessed without authorisation. A customer’s details ended up somewhere they should not have.
The first question most businesses ask is how serious is this? The answer depends on one thing, whether what happened was an incident or a breach. The distinction is not just semantic. It determines what your business is legally required to do next, how quickly it needs to act, and who needs to be notified.
Most businesses do not know the difference until they are already in the middle of one.
What Is a Privacy or Security Incident?
An incident is a security or privacy event that was identified and contained before personal information was actually accessed, disclosed or lost.
Common examples include a failed unauthorised login attempt, a phishing email intercepted before it reached its target, or a misdirected email recalled before the recipient opened it.
Incidents warrant documentation and internal review. They are early warning signals that indicate vulnerabilities worth addressing. However they do not automatically trigger external notification obligations because no personal information was ultimately compromised.
What Is a Data Breach or Privacy Breach?
A breach occurs when personal information has actually been accessed, disclosed, lost or misused, regardless of whether the cause was external or internal.
A data breach typically involves a security failure. Unauthorised access to a system, stolen credentials, exposed files, a compromised platform. This is the scenario most businesses are familiar with.
A privacy breach is broader in scope. It encompasses any mishandling of personal information, including:
- Sending customer data to the wrong recipient
- Using personal information for a purpose the individual never consented to
- Retaining personal data beyond its required retention period
- Disclosing data to a third party without appropriate authorisation
No external attack is required for a privacy breach to occur. Many happen entirely within an organisation’s own systems and processes, which is precisely why they are often harder to identify and easier to misclassify.
Why Getting This Right Matters
Misclassifying a breach as an incident delays the response and can significantly increase legal exposure. Under Australian privacy law, certain breaches carry mandatory notification obligations, to affected individuals and in some cases to the relevant authority, within a defined timeframe.
Getting the initial classification wrong from the start makes meeting those obligations considerably harder.
Beyond the legal dimension, the ability to correctly identify and respond to a breach depends entirely on how well a business understands its own data.
Businesses with clear processes for classifying and responding to privacy events are the ones that act faster, communicate more clearly and limit their exposure when something goes wrong.
Not every security event is a breach. But every business should know how to tell the difference.





