Information Technology Act, 2000

Data Breach vs Unauthorised Access: Difference and Duties Explained

The two phrases are used interchangeably in headlines and must be separated in law: unauthorised access is conduct, someone entering or using a computer resource without permission, while a data breach is an event, personal data's confidentiality, integrity or availability compromised, however that happened. Each can occur without the other, and each sets a different liability stream running, the intruder's prosecution on one side, the custodian's duties on the other. Topics 53, 64 and 87 built the components; this note, as asked, is the dedicated comparison.

1. Conduct Against Event

The boundary and the data

Figure 1: The boundary and the data

  • Unauthorised access. The s.43 conduct: accessing or securing access to a computer resource without the permission of the owner or person in charge, judged at the system's boundary and complete whether or not any data is touched; done dishonestly or fraudulently it is the s.66 offence (Topics 53, 58, 108)
  • Data breach. The event the DPDP Act defines: any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. The definition looks only at the data's state, so it needs no intruder at all: accidental exposure, a lost laptop, a misdirected email and an insider's mistake all qualify (Topic 87)
  • Different questions. Access asks who crossed the boundary, and points at an actor to prosecute; breach asks what happened to the data, and points at a custodian to discipline. The vocabulary of each regime follows: intent and permission on the access side, safeguards and notification on the breach side.

2. The Three Scenarios and the Two Streams

Access, breach, and the usual case of both

Figure 2: Access, breach, and the usual case of both

  • Access without breach. The intruder ejected before reaching data, or the penetrated system holding no personal data: ss.43 and 66 are complete against the actor, yet no breach duties arise because no personal data was compromised.
  • Breach without access. The misconfigured storage bucket, the database left open to the internet, the backup tape lost in transit: no one intruded, but confidentiality stands compromised, the DPDP definition is met, and the notification machinery runs in full, the scenario that proves breach is about the data, not the intruder.
  • The usual case: both. The exfiltrating intrusion. Two liability streams then run from one incident: the intruder's, ss.43, 66, 66C onward, the fraud chain and prosecution (Topic 108), and the custodian's, its safeguards examined, its notifications owed, its penalties assessed, and neither stream answers for the other.
  • The custodian's clocks and exposure. The incident is CERT-In reportable within six hours; under the DPDP regime every affected data principal and the Board must be intimated in the prescribed manner, failed safeguards drawing the schedule's highest penalties; and through the transition the s.43A compensation claim for negligent security persists (Topics 64, 87, 95)
  • The victim's own routes. The person whose data leaked proceeds against the intruder on the offences, against the custodian through s.43A while it lasts and the Board's complaint route thereafter, and through the grievance and consumer forums the relationship supplies (Topic 95)

⚠ Exam trap

Fix the category difference first, conduct against event, then prove it with the two clean scenarios: an intruder ejected before reaching data commits unauthorised access with no breach, and a misconfigured server exposing records is a breach with no access. Quote the DPDP definition's sweep, unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, compromising confidentiality, integrity or availability, and keep the two liability streams apart: the intruder is prosecuted, the custodian is disciplined, and one incident routinely runs both.

3. Frequently Asked Questions

What is the difference between unauthorised access and a data breach?

Unauthorised access is conduct: entering or using a computer resource without the permission of its owner or person in charge, complete at the boundary whether or not data is touched, and answered by Section 43 compensation and the Section 66 offence against the actor. A data breach is an event defined by the DPDP Act: unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises personal data's confidentiality, integrity or availability, and it triggers the custodian's duties, CERT-In reporting within six hours and intimation of affected data principals and the Data Protection Board, whether or not any intruder existed.

Can there be a data breach without any hacking?

Yes, routinely. A misconfigured server exposing records to the internet, a lost or stolen unencrypted device, an email sent to the wrong recipients or an insider's accidental disclosure all compromise confidentiality without any intrusion, and the breach machinery, reporting, notification and scrutiny of safeguards, runs in full. Conversely, an intruder ejected before reaching personal data commits unauthorised access under Sections 43 and 66 without causing any breach, which is why the two concepts must be kept distinct.

4. Related Topics

  • Topic 87: Privacy and Data Protection. The breach duties inside the DPDP regime.
  • Topic 108: Hacking vs Identity Theft. The intruder's own liability chain.