Breach Laws: Security Breach and Risk-of-Harm
A security breach is generally unauthorized access to or acquisition of computerized personal data that compromises its confidentiality, security, or integrity. Nearly all states apply a risk-of-harm analysis, often excusing notice where harm is not reasonably likely.
How this supports CIPP/US study
Use this lesson to compare state-law scope, rights, exceptions and enforcement before choosing an answer. Continue with the CIPP/US practice exam.
The definition typically covers unauthorized access to or acquisition of electronic files or computerized data containing personal information that compromises confidentiality, security, or integrity, where the data was not secured by encryption or rendered unreadable/unusable.
Nearly all states apply a risk-of-harm analysis. An incident is commonly excluded where it is not reasonably likely that harm (identity theft, fraud, or financial loss) will result. The risk language may sit in the definition of 'security breach' or in the notification requirements.
The text notes that California, Georgia, Illinois, Minnesota, North Dakota, and Texas do NOT include a risk-of-harm analysis. In those states you cannot rely on a 'no likely harm' argument to avoid notice.
Key terms - quick answers
What is “Security breach”?
What is “Risk-of-harm analysis”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.