IDEAS home Printed from https://ideas.repec.org/a/gam/jdataj/v9y2024i2p27-d1330575.html

Understanding Data Breach from a Global Perspective: Incident Visualization and Data Protection Law Review

Author

Listed:
  • Gabriel Arquelau Pimenta Rodrigues

    (Professional Post-Graduate Program in Electrical Engineering (PPEE), Department of Electrical Engineering (ENE), University of Brasília (UnB), Brasília 70910-900, Brazil)

  • André Luiz Marques Serrano

    (Professional Post-Graduate Program in Electrical Engineering (PPEE), Department of Electrical Engineering (ENE), University of Brasília (UnB), Brasília 70910-900, Brazil)

  • Amanda Nunes Lopes Espiñeira Lemos

    (Graduate Program in Law (PPGD), Law School, University of Brasilia (UnB), Brasília 70910-900, Brazil
    School of Law, University of Minho (EDUM), Campus de Gualtar, 4710-057 Braga, Portugal)

  • Edna Dias Canedo

    (Professional Post-Graduate Program in Electrical Engineering (PPEE), Department of Electrical Engineering (ENE), University of Brasília (UnB), Brasília 70910-900, Brazil)

  • Fábio Lúcio Lopes de Mendonça

    (Professional Post-Graduate Program in Electrical Engineering (PPEE), Department of Electrical Engineering (ENE), University of Brasília (UnB), Brasília 70910-900, Brazil)

  • Robson de Oliveira Albuquerque

    (Professional Post-Graduate Program in Electrical Engineering (PPEE), Department of Electrical Engineering (ENE), University of Brasília (UnB), Brasília 70910-900, Brazil
    Group of Analysis, Security and Systems (GASS), Department of Software Engineering and Artificial Intelligence (DISIA), Faculty of Computer Science and Engineering, Office 431, Universidad Complutense de Madrid (UCM), Calle Profesor José García Santesmases, 9, Ciudad Universitaria, 28040 Madrid, Spain)

  • Ana Lucila Sandoval Orozco

    (Professional Post-Graduate Program in Electrical Engineering (PPEE), Department of Electrical Engineering (ENE), University of Brasília (UnB), Brasília 70910-900, Brazil
    Group of Analysis, Security and Systems (GASS), Department of Software Engineering and Artificial Intelligence (DISIA), Faculty of Computer Science and Engineering, Office 431, Universidad Complutense de Madrid (UCM), Calle Profesor José García Santesmases, 9, Ciudad Universitaria, 28040 Madrid, Spain)

  • Luis Javier García Villalba

    (Group of Analysis, Security and Systems (GASS), Department of Software Engineering and Artificial Intelligence (DISIA), Faculty of Computer Science and Engineering, Office 431, Universidad Complutense de Madrid (UCM), Calle Profesor José García Santesmases, 9, Ciudad Universitaria, 28040 Madrid, Spain)

Abstract

Data breaches result in data loss, including personal, health, and financial information that are crucial, sensitive, and private. The breach is a security incident in which personal and sensitive data are exposed to unauthorized individuals, with the potential to incur several privacy concerns. As an example, the French newspaper Le Figaro breached approximately 7.4 billion records that included full names, passwords, and e-mail and physical addresses. To reduce the likelihood and impact of such breaches, it is fundamental to strengthen the security efforts against this type of incident and, for that, it is first necessary to identify patterns of its occurrence, primarily related to the number of data records leaked, the affected geographical region, and its regulatory aspects. To advance the discussion in this regard, we study a dataset comprising 428 worldwide data breaches between 2018 and 2019, providing a visualization of the related statistics, such as the most affected countries, the predominant economic sector targeted in different countries, and the median number of records leaked per incident in different countries, regions, and sectors. We then discuss the data protection regulation in effect in each country comprised in the dataset, correlating key elements of the legislation with the statistical findings. As a result, we have identified an extensive disclosure of medical records in India and government data in Brazil in the time range. Based on the analysis and visualization, we find some interesting insights that researchers seldom focus on before, and it is apparent that the real dangers of data leaks are beyond the ordinary imagination. Finally, this paper contributes to the discussion regarding data protection laws and compliance regarding data breaches, supporting, for example, the decision process of data storage location in the cloud.

Suggested Citation

  • Gabriel Arquelau Pimenta Rodrigues & André Luiz Marques Serrano & Amanda Nunes Lopes Espiñeira Lemos & Edna Dias Canedo & Fábio Lúcio Lopes de Mendonça & Robson de Oliveira Albuquerque & Ana Lucila Sa, 2024. "Understanding Data Breach from a Global Perspective: Incident Visualization and Data Protection Law Review," Data, MDPI, vol. 9(2), pages 1-24, January.
  • Handle: RePEc:gam:jdataj:v:9:y:2024:i:2:p:27-:d:1330575
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/2306-5729/9/2/27/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/2306-5729/9/2/27/
    Download Restriction: no
    ---><---

    References listed on IDEAS

    as
    1. Grzegorz Strupczewski, 2020. "What Do We Know About Data Breaches? Empirical Evidence from the United States," Eurasian Studies in Business and Economics, in: Mehmet Huseyin Bilgin & Hakan Danis & Gökhan Karabulut & Giray Gözgor (ed.), Eurasian Economic Perspectives, pages 281-299, Springer.
    2. Eli Amir & Shai Levi & Tsafrir Livne, 2018. "Do firms underreport information on cyber-attacks? Evidence from capital markets," Review of Accounting Studies, Springer, vol. 23(3), pages 1177-1206, September.
    3. Bocong Yuan & Jiannan Li, 2019. "The Policy Effect of the General Data Protection Regulation (GDPR) on the Digital Public Health Sector in the European Union: An Empirical Investigation," IJERPH, MDPI, vol. 16(6), pages 1-15, March.
    Full references (including those not matched with items on IDEAS)

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Hamzeh Al Amosh & Saleh F. A. Khatib, 2025. "Cybersecurity Transparency and Firm Success: Insights From the Australian Landscape," Australian Economic Papers, Wiley Blackwell, vol. 64(2), pages 189-204, June.
    2. Michael McShane & Trung Nguyen, 2020. "Time-varying effects of cyberattacks on firm value," The Geneva Papers on Risk and Insurance - Issues and Practice, Palgrave Macmillan;The Geneva Association, vol. 45(4), pages 580-615, October.
    3. Jacopo Gambato & Bernhard Ganglmair & Julia K. Krämer, 2026. "Effective Regulation and Firm Compliance: The Case of German Privacy Policies," NBER Chapters, in: Data Privacy Protection and the Conduct of Applied Research: Methods, Approaches and New Findings, National Bureau of Economic Research, Inc.
    4. Lin, Weizheng & Wang, Chih-Wei & Li, Ying-Jie & Chen, Jian-Yun, 2025. "From green to digital: Exploring the role of ecological footprints on cybersecurity risk," Energy Economics, Elsevier, vol. 146(C).
    5. Camélia Radu & Nadia Smaili, 2022. "Board Gender Diversity and Corporate Response to Cyber Risk: Evidence from Cybersecurity Related Disclosure," Journal of Business Ethics, Springer, vol. 177(2), pages 351-374, May.
    6. Nadia Smaili & Camélia Radu & Amir Khalili, 2023. "Board effectiveness and cybersecurity disclosure," Journal of Management & Governance, Springer;Accademia Italiana di Economia Aziendale (AIDEA), vol. 27(4), pages 1049-1071, December.
    7. Chelsea Liu & Muhammad Ali Babar, 2026. "Corporate cybersecurity risk and data breaches: A systematic review of empirical research," Australian Journal of Management, Australian School of Business, vol. 51(1), pages 62-92, February.
    8. Martins, António Miguel & Moutinho, Nuno, 2025. "Stock-Term market impact of major cyber-attacks: Evidence for the ten most exposed insurance firms to cyber risk," Finance Research Letters, Elsevier, vol. 71(C).
    9. Han, Kookyoung & Choi, Jin Hyuk, 2023. "Implications of false alarms in dynamic games on cyber-security," Chaos, Solitons & Fractals, Elsevier, vol. 169(C).
    10. Xi Chen & Gilles Hilary & Xiaoli Tian, 2025. "Mandatory Data Breach Disclosure and Insider Trading," Journal of Business Finance & Accounting, Wiley Blackwell, vol. 52(5), pages 2091-2110, November.
    11. Rezaee, Zabihollah & Zhou, Gaoguang & Bu, Luofan (Luther), 2024. "Corporate social irresponsibility and the occurrence of data breaches: A stakeholder management perspective," International Journal of Accounting Information Systems, Elsevier, vol. 53(C).
    12. Sylvie Héroux & Anne Fortin, 2025. "How the three lines of defense can contribute to public firms’ cybersecurity effectiveness," International Journal of Disclosure and Governance, Palgrave Macmillan, vol. 22(2), pages 377-396, June.
    13. Lee, Chien-Chiang & Wang, Chih-Wei & Lin, Weizheng & Chen, En-Jia, 2025. "Cyber risk and corporate share repurchases," International Review of Financial Analysis, Elsevier, vol. 103(C).
    14. Masoud, Najeb & Al-Utaibi, Ghassan, 2022. "The determinants of cybersecurity risk disclosure in firms’ financial reporting: Empirical evidence," Research in Economics, Elsevier, vol. 76(2), pages 131-140.
    15. Kamiya, Shinichi & Kang, Jun-Koo & Kim, Jungmin & Milidonis, Andreas & Stulz, René M., 2021. "Risk management, firm reputation, and the impact of successful cyberattacks on target firms," Journal of Financial Economics, Elsevier, vol. 139(3), pages 719-749.
    16. Demek, Kristina C. & Kaplan, Steven E., 2023. "Cybersecurity breaches and investors’ interest in the firm as an investment," International Journal of Accounting Information Systems, Elsevier, vol. 49(C).
    17. Francesco Columba & Manuel Cugliari & Marco Orlandi & Federica Vassalli, 2026. "The Cyber Risk Of Non-Financial Firms," Mercati, infrastrutture, sistemi di pagamento (Markets, Infrastructures, Payment Systems) 75, Bank of Italy, Directorate General for Markets and Payment System.
    18. Strauss, Tal, 2026. "Cyber Risk, Regulation, and Firm Resilience," Other publications TiSEM efb58ae1-e7b6-41dc-b403-2, Tilburg University, School of Economics and Management.
    19. Wang, Duo & Hu, Yunge & Li, Yanxi, 2026. "Cybersecurity risk and corporate maturity mismatch," International Review of Financial Analysis, Elsevier, vol. 109(C).
    20. Akyildirim, Erdinc & Conlon, Thomas & Corbet, Shaen & Hou, Yang (Greg), 2024. "HACKED: Understanding the stock market response to cyberattacks," Journal of International Financial Markets, Institutions and Money, Elsevier, vol. 97(C).

    More about this item

    Keywords

    ;
    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jdataj:v:9:y:2024:i:2:p:27-:d:1330575. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.