Data Breaches in Europe 2005-2014
A growing number of massive data breaches are degrading the personal privacy of people around the world. Data security and privacy policy are ongoing concerns in Europe. But it can be difficult to assess privacy breaches in Europe in particular, since many of the biggest incidents of compromised personal records involve people and organizations from around the world. This working paper offers early descriptive statistics and analysis of the first cross-national, systematized event log of data breaches in Europe. The data is available for download at http://cmds.ceu.hu/.
Methodology. The sample frame includes major media news reports on compromised personal records and is unique for:
- sampling 28 European Union member countries, plus Norway and Switzerland;
- sampling from 2005 through the third quarter of 2014;
- sampling credible news sources in national languages;
- high social science standards for event database construction, with multiple sourcing, inter-coder reliability tests, recoding, and specific exclusion criteria.
Findings. A data breach is defined as any incident involving the loss or exposure of digital personal records. Personal records are defined as a) data containing privileged information about an individual that cannot be readily obtained through other public means and b) this information only known by an individual or by an organization under the terms of a confidentiality agreement. Preliminary analysis reveals that over the last decade:
- Some 229 data breach incidents involved the personal records of people in Europe. Globally, all these incidents resulted in the loss of some 645 million records, though not all of these breaches exclusively involved people in Europe. Within Europe, we confirmed 200 cases involving people in Europe, and 227 million records lost in Europe-specific breaches.
- The total population of the countries covered in this study is 524 million, and the total population of internet users in these countries is 409 million. Expressed in ratios, this means that for every 100 people in the study countries, 43 personal records have been compromised. For every 100 internet users in the study countries, 56 records have been compromised.
- Fully 51 percent of all the breaches involved corporations and 89 percent of all the breached records were from compromised corporations. Among all the kinds of organizations from which personal records have been compromised, 41 percent of the incidents involved clear acts of theft by hackers, but 57 percent of the incidents involved organizational errors, insider abuse, or other internal mismanagement (2 percent unspecified).