BreachCensus

Privacy

What we collect

Breach Census does not collect personal data. There is no account system, no sign-up, no newsletter, and no form on the site — the Contact page is a plain mailto link, and the site’s middleware rejects any write request outright, so nothing you do on a page is sent back to the Breach Census team.

Standard hosting logs (IP address, browser type, pages requested) are generated as an ordinary part of running a website, kept only for security and reliability, and are not used to build a profile of any visitor.

Cookies

The site does not set any non-essential cookies. If that ever changes, this page would be updated first.

Data about organisations and people named on the site

The register itself — incidents, organisations, regulator actions — is built entirely from public sources: regulator filings, court records and company disclosures. It is not personal data collected from visitors. If a record is wrong or you want it corrected, see Contact for the right-of-reply process, and Methodology for how a record earns each confirmation level.

Licence for reuse

Derived signals, narratives and aggregates: CC BY 4.0 with attribution to breachcensus.com. Underlying regulator filings, court records and disclosures remain the property of their original publishers.

No warranties

The site and its data are provided as-is, without warranty of any kind, express or implied. Nothing on this site is legal advice.