Observatory

Coverage evidence

What can—and cannot—be compared

Breach Gazette combines official publications without pretending that different thresholds, windows, and record units measure the same thing.

A larger source count can reflect a broader law, a longer publication window, or repeated notifications. It does not by itself establish more breaches.

9implemented sources
4countries represented
12,527named notification rows
449aggregate source cells

Source coverage matrix

Periods are calculated from the records in this exact publication.

SourceJurisdictionPublished unitRecordsObserved periodPublic windowComparison boundary
Curated OAIC data-breach regulatory actionsHealthyAustralia
Australia
Regulatory Action
One manually reviewed legal-status event supported by a fixed official OAIC page
710 Sept 2021–16 July 2026Versioned curated manifest; not a complete index of every OAIC action.Legal-status events only; not a notification or incident count.
NSW IPC MNDB Scheme Data SnapshotHealthyAustralia
New South Wales
State Aggregate
One explicitly identified cell in the sector snapshot table
251 July 2025–31 Dec 2025Historical six-month PDF snapshots indexed by the IPC.Compare only matching periods, dimensions, units, and population scopes.
NSW IPC Public Notifications RegisterHealthyAustralia
New South Wales
Regulator Register Entry
One public notification register entry published by a NSW public sector agency
149 July 2023–17 Feb 2026Links are published for at least 12 months; the page also lists expired entries without their former links.Published source records only; not a count of unique incidents.
OAIC Notifiable Data Breaches statisticsHealthyAustralia
Australia
National Aggregate
One published aggregate metric cell for a reporting period and source-defined dimension
1731 July 2025–31 Dec 2025Historical reporting-period workbook published through Data.gov.au and subject to revision.Compare only matching periods, dimensions, units, and population scopes.
CNIL personal data breach notificationsHealthyFrance
France
Anonymized Notification
One anonymized notification row, published by Breach Gazette only as grouped counts
43,502 rows / 135 cells1 May 2018–31 Dec 2025Published rows from May 2018 through December 2025; the official dataset excludes notifications received in the three months before each extraction.Anonymous source-report counts only; no organization or incident inference.
ICO data security incident trendsHealthyUnited Kingdom
United Kingdom
Anonymized Notification
One unique source report reference, published by Breach Gazette only as grouped counts
1161 Apr 2019–31 Dec 2025Q2 2019 through the latest reviewed quarterly workbook; Q1 2019 is excluded because the ICO says incidents were recorded differently before Q2 2019.Anonymous source-report counts only; no organization or incident inference.
California Attorney General Data Security Breach ListHealthyUnited States
California
Named Notification
One row in the official full data breach CSV
5,2215 July 2007–23 July 2026Historical public CSV.Published source records only; not a count of unique incidents.
HHS OCR Breach PortalDeferredUnited States
United States
Named Notification
One public portal row for a breach affecting 500 or more individuals
0Not publishedThe current list describes the last 24 months and separate archive behavior.Published source records only; not a count of unique incidents.
Massachusetts Data Breach Notification ReportsHealthyUnited States
Massachusetts
Named Notification
One reporting-organization row in a reviewed annual report
5,6959 Feb 2014–23 July 2026Bounded to the complete published 2024 through 2026 annual reports.Published source records only; not a count of unique incidents.
Washington Attorney General Data Breach NotificationsHealthyUnited States
Washington
Named Notification
One notice submitted to the Attorney General, joined to zero or more source information-type rows
1,5971 Apr 2008–29 June 2026Historical public datasets from August 2015 to present.Published source records only; not a count of unique incidents.

Four publication lanes

Keeping these lanes separate is the central comparability control.

Named records

Source-labelled notifications

The displayed entity retains the role assigned by its source. Repeated rows are not silently merged into one incident.

Anonymous records

Privacy-minimised notifications

Countries may publish report-level facts without organization names. These records never enter entity resolution.

Statistics

Aggregate reporting cells

Dimensions remain tied to their source period, unit, scope, and denominator.

Legal status

Regulatory actions

Inquiries, allegations, findings, undertakings, judgments, and penalties remain distinct events.