Observatory
Source information

Provenance directory

Source policies

Each policy defines what one row means, who can appear, what threshold applies, how long records remain visible, and which publication rights were reviewed.

Healthy

CNIL personal data breach notifications

France · Anonymized Notification

The official dataset concerns GDPR notifications to CNIL of personal data breaches presenting a risk to the rights and freedoms of affected people.

Redistribution: Approved With Conditions

Deferred

HHS OCR Breach Portal

United States · Named Notification

The public list covers reported breaches of unsecured protected health information affecting 500 or more individuals.

Redistribution: Deferred

Healthy

ICO data security incident trends

United Kingdom · Anonymized Notification

The source covers personal data breaches reported to the ICO under UK GDPR reporting requirements; it is not a register of every data security incident in the United Kingdom.

Redistribution: Approved With Conditions

Deferred

Ireland DPC data breach statistics

Ireland · National Aggregate

The annual figures concern valid personal data breach notifications received by the Data Protection Commission.

Redistribution: Deferred

Deferred

Maine Attorney General data security breach notices

Maine · Named Notification

The official site describes notices submitted under Maine data security breach law; the database is not currently available for bounded collection.

Redistribution: Deferred

Healthy

Netherlands AP data breach statistics

Netherlands · National Aggregate

The figures concern personal data breach notifications received by Autoriteit Persoonsgegevens under the GDPR reporting framework.

Redistribution: Approved With Conditions

Healthy

NSW IPC MNDB Scheme Data Snapshot

New South Wales · State Aggregate

Eligible data breach notifications made by NSW public sector agencies under Part 6A of the PPIP Act.

Redistribution: Approved With Conditions

Healthy

NSW IPC Public Notifications Register

New South Wales · Regulator Register Entry

Public notification is used where direct notification is not reasonably practicable; exemptions and direct notifications affect publication.

Redistribution: Approved With Conditions

Healthy

OAIC Notifiable Data Breaches statistics

Australia · National Aggregate

Notifications concern eligible data breaches under Part IIIC of the Privacy Act 1988; the workbook contains aggregate statistics, not a register of named notifications.

Redistribution: Approved With Conditions

Deferred

Texas Attorney General data security breach reports

Texas · Regulator Register Entry

The public reporting requirement applies to data breaches affecting at least 250 Texas residents, subject to the official statutory guidance.

Redistribution: Deferred