Section 25: Notification of personal data breach
as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.
25. Notification of personal data breach
(1) (a) In the case of a personal data breach, the controller
shall without undue delay and, where feasible, not later than 72 hours
after having become aware of it, notify the personal data breach to the
Commissioner.
(b) Where the controller fails to notify the personal data
breach within the time limit specified in paragraph (a), he shall provide the
Commissioner with the reasons for the delay.
(2) Where a processor becomes aware of a personal data breach,
he shall notify the controller without any undue delay.
(3) The notification referred to in subsection (1) shall –
(a) describe the nature of the personal data breach, including
where possible, the categories and approximate number
of data subjects and the categories and approximate
number of personal data records concerned;
490 Acts 2017 Acts 2017 491
(b) communicate the name and contact details of any
appropriate data protection officer or other contact
point where more information may be obtained; and
(c) recommend measures to address the personal data
breach, including, where appropriate, measures to
mitigate the possible adverse effects of the breach.
(4) The controller shall specify the facts relating to the personal
data breach, its effects and the remedial action taken so as to enable the
Commissioner to verify compliance with this section.