juris

Section 25: Notification of personal data breach

Data Protection Act 2017 · PART IV: OBLIGATIONS ON CONTROLLERS AND PROCESSORS

as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.

25. Notification of personal data breach (1) (a) In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner. (b) Where the controller fails to notify the personal data breach within the time limit specified in paragraph (a), he shall provide the Commissioner with the reasons for the delay. (2) Where a processor becomes aware of a personal data breach, he shall notify the controller without any undue delay. (3) The notification referred to in subsection (1) shall – (a) describe the nature of the personal data breach, including where possible, the categories and approximate number of data subjects and the categories and approximate number of personal data records concerned; 490 Acts 2017 Acts 2017 491 (b) communicate the name and contact details of any appropriate data protection officer or other contact point where more information may be obtained; and (c) recommend measures to address the personal data breach, including, where appropriate, measures to mitigate the possible adverse effects of the breach. (4) The controller shall specify the facts relating to the personal data breach, its effects and the remedial action taken so as to enable the Commissioner to verify compliance with this section.

Ask juris about this section Official source