RT Article T1 Amplifying victim vulnerability: Unanticipated harm and consequence in data breach notification policy JF International review of victimology VO 29 IS 3 SP 341 OP 365 A1 Gibson, Dennis A2 Harfield, Clive LA English YR 2023 UL https://krimdok.uni-tuebingen.de/Record/185762789X AB Loss of control over one’s identity through identity usurpation, or identity theft, results in victimization characterized by multiple species of harm: material harms such as financial loss; medical harms such as psychological distress and consequential physiological illness; and moral harms such as infringement of autonomy. Digital data breaches are a common means by which identity can be usurped and laws have been enacted requiring data-holders to notify data subjects when their personal information held on digital databases has been compromised. The intention is that victims should then be able to undertake their own mitigation measures. This paper explores the efficacy of this approach as a solution and argues that this policy – particularly in the light of new digital criminal methodologies – creates a conflict of victims’ interests. It is an unintended outcome of policy that exacerbates, rather than resolves, identity usurpation and associated victimization in the digital environment. K1 ransomware K1 Policy K1 harm mitigation K1 digital victimization K1 Data breach notification DO 10.1177/02697580221107683