You couldn't have missed it: a major data breach at Odido. Many information security or risk professionals have a personal data breach high up in their risk register. But why, exactly?
Our gut feeling tells us that the impact of such a risk is high. But as soon as you ask for a justification of that impact, things quickly become murky.
A Risk
First, let's take a step back. When it comes to information security risks, it is important to keep two things in mind:
- A risk is an uncertainty regarding an (organizational) objective. Think of making a profit, providing care, or serving citizens. No relationship to an objective? No risk.
- Risk is a function of probability and impact. Only if a data breach can occur AND you as an organization experience negative consequences from it, is there a risk. A data breach of the 2024 annual report already filed by the organization is not very interesting.
With this in mind, the question arises: in what way does (a data breach of) personal data pose an uncertainty to business objectives?
The Impact
The direct impact on an organization in the event of a data breach is not necessarily significant. After all:
- There is no business interruption; primary business processes can continue as usual
- A GDPR fine is not automatically on the table in the event of a data breach, and certainly not the 4% of global annual turnover that many executives are scared with
Because of this, there seems to be little relationship with the organization's business objectives.
Or... is there?
The core of a data breach lies in the indirect impact on an organization. While the organization may still be able to function, a lot happens behind the scenes immediately following a data breach:
- Affected individuals must be informed in accordance with the GDPR, all while you are still searching for answers yourself.
- Reporting obligations under GDPR and NIS2/Cbw come into play.
- The press has questions, speculation runs wild on LinkedIn, and before you know it, an inaccurate picture is being painted on a talk show that same evening.
- The old doomsday story about a GDPR fine of 4% of global annual turnover is being dragged out again.
- Customer service capacity needs to be increased, as there is a lot of confusion among customers.
- Depending on the cause of the data breach, a forensic IT investigation into the circumstances may need to be conducted.
Simply organizing a response to these points can already come with a hefty price tag (read: impact).
Conclusion
For for-profit organizations, making a profit is a clear business objective. Costs incurred to manage a data breach reduce short-term profit (business objective). In the long term, profit can be reduced by declining market share, liability, fines, and legal judgments.
Government institutions and NGOs are slightly different. After all, they are not profit-driven. For their business objectives, they depend on a budget to achieve their goals. Costs incurred due to a data breach cannot be used for your business objectives.
The impact of a personal data breach therefore strongly depends on the long-term impact your organization expects. Short-lived media hype does not necessarily lead to a high impact on the bottom line.
Is the impact of a personal data breach clear for your organization?






