Share this post

Data Breach and Data Misuse: What’s the Difference?

Online security nowadays is paramount, but do you know the difference between a data breach and data misuse? Find out more and how you can protect yourself.

When it comes to online security, most of us are acutely aware of the need for vigilance, more so than ever before.

We all try to do our bit to stay safe, and we have to trust that companies, corporations and conglomerates do theirs too. Data protection is vital, simply because confidential data is such a valuable commodity in the modern world.

We regularly see, hear and read reports about when things don’t go to plan – data breaches occur when cyber-criminals bypass a company’s security systems to access sensitive data. Usually, the hackers’ aim is financial gain, either by selling the personal details they’ve stolen or by extorting money from the company or organisation in question by holding their sensitive data to ransom. In such cases, it’s customers who often have to face the threat of their bank accounts, social media platforms and online presence being affected. This is, at best, a mild inconvenience and, at worst, could be catastrophic for their finances and more, resulting in unnecessary (and avoidable) levels of stress and tension.

When your data is exposed via unauthorised access, there is usually fault attributed to those storing the data without incorporating effective security measures.

But what about an enemy within?

There’s a marked difference between data that’s been lost to hackers with nefarious intentions, and data that’s obtained legitimately but used improperly, incorrectly or inappropriately. The former is carried out with the intention of exploiting data for personal gain, while the latter is often due to human error. There are also instances in which data has been shared without express permission, leading to customers being subjected to intense levels of targeted marketing. That’s a clear, and unlawful, abuse of the trust put in a company storing confidential information.

Data misuse is often carried out by someone with authorisation to access the data but not to exceed the firm’s data boundaries. If a company shares personal and confidential information from their database to a sister company – known as commingling – that’s data misuse. Other examples could include employees transferring or copying data to their personal devices, for easy access when they want to work offline. Though carried out unintentionally in many cases, data misuse is every bit as harmful for those affected, and in both cases it’s important they act quickly and effectively to try to limit the damage and minimise its impact.

There are crucial differences between a data breach – unauthorised accessing of an organisation’s database – and incidents of data misuse, which is unintentional harm being caused by negligence, ignorance or failures in data handling practices.

So, data breach is a failure in access control and therefore a security issue, data misuse is incorrect use of personal data or going beyond its justified and, usually, pre-agreed purpose.

Both types mean data subjects’ privacy and security may be violated and compromised. Data misuse is a clear failing in the protection of data that was encoded and stored legitimately. It means a company’s clients, customers, staff members and others are affected.

Other differences between data breach and data misuse include the perpetrator; in breaches it’s usually an external hacker who has no legitimate business in the company’s online vaults and in misuse cases it would usually be an employee – someone with authority to access the data but not to use it beyond its intended scope.

Detecting an instance of data misuse can be more difficult than in data breach cases, since the accessing of the data may be perfectly legitimate. It could be only when audits or reviews of policies and access arise that the issue could then be discovered. Data breaches are usually detected by security logs or similar systems at the time, rather than months, or even years, later.

Consent is a factor too. A breach violates an organisation’s inadequately-protected data, while misuse is a failure in usage. This could mean that the data collected was intended to be used for one purpose but was sold without permission, kept for secondary purposes or was stored for longer than was necessary.

For example, when a cyber-criminal manages to exploit a gap in security or steals an employee’s unencrypted laptop outside the workplace and steals customer files, that’s a data breach; if data is sold to advertisers or marketers without consent, or is used without authorisation to train AI programs, that’s data misuse.

Large-scale examples of data misuse are common knowledge, and some of them spelled the end of firms at fault.

Cambridge Analytica (CA) is one such company. The consultancy and analytics firm acquired data from an estimated 87 million Facebook users. That data was gathered in 2018 by a researcher, supposedly collecting the data in the name of academic research via a personality profiling app that purported to be a typical quiz on the platform. It was later revealed that CA had collected millions of data points from participants or their friends. This misuse led to political microtargeting and both the social media platform and CA fell foul of regulators.

Facebook was hit with a $5billion fine for its part in the scandal and CA was bankrupted and eventually dissolved.

The social media platform formerly known as Twitter has also run into trouble due to data misuse. The Federal Trade Commission enforced a fine of $150million on X after it profited from obtaining data – users’ phone numbers and email addresses which it claimed was for security purposes – by granting advertisers access to the data of 140 million users.

These are extreme examples but the risks to your security and privacy caused by misuse of your data are real.

So, if you are the victim of data misuse by a business or organisation, you may be entitled to compensation. At Abbleys Solicitors, we are representing thousands of claimants who have had their data breached and misused, and we can help you.

If you believe your data has been breached or misused, click the button at the bottom of this page to start your claim today.

Share this post

Other Blog Posts

Start Your Data Privacy Claim

If you have been a victim of a data breach or data misuse, you are within your rights to claim compensation.