Desk live·
ForensicPost
Breaches/Analysis/File 25-0704

Breach Notification Law Was Written for Consumers, Not the Workforce

Breach notification law was written to protect consumers. Workforce data falls outside most of it, which is why this corpus contains so little of it — and why nobody knows how much there is.

Constructed geometry · not a chart of case data
TargetWorkforce data
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

This file records a gap rather than an incident. Of the files in this database, the overwhelming majority concern customer or patient data. Employee data appears in a handful, of which 25-0613 is the clearest.

The Asymmetry Is In The Law, Not The World

Consumer breach notification is the most developed disclosure regime in this corpus: statutory windows, defined data categories, regulator filings and, in healthcare, a public register as at 25-0630.

Employment data is generally covered by general data-protection law rather than by anything with a public reporting mechanism. An organisation that loses its entire staff directory frequently has an obligation to inform the affected staff and no obligation to publish anything.

The result is that the corpus can state that healthcare filed 343 breaches in six months and cannot state anything comparable about workforce exposure, in any sector, at any scale.

And The Employee Is In The Worst Position Of Anyone Here

A customer can stop being a customer. That option is central to almost every remediation discussion in this corpus, however unsatisfying.

An employee cannot decline to give their employer a national identifier, a home address, a bank account and emergency contacts. They cannot leave over a breach without leaving their job, they will not be told which supplier held the data, and raising it is an act with career consequences.

That is a more constrained position than the declined applicant at 25-1105 or the crash-report subject at 25-0612, both of which this desk filed as cases of absent consent.

What We Can And Cannot Say

This desk is not asserting that workforce breaches are more common than customer breaches. We have no basis for that and neither does anyone else, which is the point.

The claim is narrower: a whole category of exposure is systematically under-recorded, this corpus inherits that bias directly from its sources, and any conclusion drawn from breach statistics about who is affected by data loss is measuring a reporting regime. Graded medium as an argument about evidence rather than a finding about incidents.

This is an analysis file

It records a limitation of this database and of the public record it is built from. Sources below support the regime description; the absence itself is not something any source measures. Corrections: corrections@forensicpost.com.

Sources
  1. June 2025 data breach round-up: major cybersecurity incidentsFindings
  2. Top third-party data breachesFortifyData
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary