Coverage evidence
What can—and cannot—be compared
Breach Gazette combines official publications without pretending that different thresholds, windows, and record units measure the same thing.
A larger source count can reflect a broader law, a longer publication window, or repeated notifications. It does not by itself establish more breaches.
Source coverage matrix
Periods are calculated from the records in this exact publication.
| Source | Jurisdiction | Published unit | Records | Observed period | Public window | Comparison boundary |
|---|---|---|---|---|---|---|
| Curated OAIC data-breach regulatory actionsHealthy | Australia Australia | Regulatory Action One manually reviewed legal-status event supported by a fixed official OAIC page | 7 | 10 Sept 2021–16 July 2026 | Versioned curated manifest; not a complete index of every OAIC action. | Legal-status events only; not a notification or incident count. |
| NSW IPC MNDB Scheme Data SnapshotHealthy | Australia New South Wales | State Aggregate One explicitly identified cell in the sector snapshot table | 25 | 1 July 2025–31 Dec 2025 | Historical six-month PDF snapshots indexed by the IPC. | Compare only matching periods, dimensions, units, and population scopes. |
| NSW IPC Public Notifications RegisterHealthy | Australia New South Wales | Regulator Register Entry One public notification register entry published by a NSW public sector agency | 14 | 9 July 2023–17 Feb 2026 | Links are published for at least 12 months; the page also lists expired entries without their former links. | Published source records only; not a count of unique incidents. |
| OAIC Notifiable Data Breaches statisticsHealthy | Australia Australia | National Aggregate One published aggregate metric cell for a reporting period and source-defined dimension | 173 | 1 July 2025–31 Dec 2025 | Historical reporting-period workbook published through Data.gov.au and subject to revision. | Compare only matching periods, dimensions, units, and population scopes. |
| CNIL personal data breach notificationsHealthy | France France | Anonymized Notification One anonymized notification row, published by Breach Gazette only as grouped counts | 43,502 rows / 135 cells | 1 May 2018–31 Dec 2025 | Published rows from May 2018 through December 2025; the official dataset excludes notifications received in the three months before each extraction. | Anonymous source-report counts only; no organization or incident inference. |
| ICO data security incident trendsHealthy | United Kingdom United Kingdom | Anonymized Notification One unique source report reference, published by Breach Gazette only as grouped counts | 116 | 1 Apr 2019–31 Dec 2025 | Q2 2019 through the latest reviewed quarterly workbook; Q1 2019 is excluded because the ICO says incidents were recorded differently before Q2 2019. | Anonymous source-report counts only; no organization or incident inference. |
| California Attorney General Data Security Breach ListHealthy | United States California | Named Notification One row in the official full data breach CSV | 5,221 | 5 July 2007–23 July 2026 | Historical public CSV. | Published source records only; not a count of unique incidents. |
| HHS OCR Breach PortalDeferred | United States United States | Named Notification One public portal row for a breach affecting 500 or more individuals | 0 | Not published | The current list describes the last 24 months and separate archive behavior. | Published source records only; not a count of unique incidents. |
| Massachusetts Data Breach Notification ReportsHealthy | United States Massachusetts | Named Notification One reporting-organization row in a reviewed annual report | 5,695 | 9 Feb 2014–23 July 2026 | Bounded to the complete published 2024 through 2026 annual reports. | Published source records only; not a count of unique incidents. |
| Washington Attorney General Data Breach NotificationsHealthy | United States Washington | Named Notification One notice submitted to the Attorney General, joined to zero or more source information-type rows | 1,597 | 1 Apr 2008–29 June 2026 | Historical public datasets from August 2015 to present. | Published source records only; not a count of unique incidents. |
Four publication lanes
Keeping these lanes separate is the central comparability control.
Source-labelled notifications
The displayed entity retains the role assigned by its source. Repeated rows are not silently merged into one incident.
Privacy-minimised notifications
Countries may publish report-level facts without organization names. These records never enter entity resolution.
Aggregate reporting cells
Dimensions remain tied to their source period, unit, scope, and denominator.
Regulatory actions
Inquiries, allegations, findings, undertakings, judgments, and penalties remain distinct events.