juris

Section 26: Communication of personal data breach to data subject

Data Protection Act 2017 · PART IV: OBLIGATIONS ON CONTROLLERS AND PROCESSORS

as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.

26. Communication of personal data breach to data subject (1) Subject to subsection (3), where a personal data breach is likely to result in a high risk to the rights and freedoms of a data subject, the controller shall, after the notification referred to in section 25, communicate the personal data breach to the data subject without undue delay. (2) The communication to the data subject shall describe in clear language the nature of the personal data breach and set out the information and the recommendations provided for in section 25. (3) The communication of a personal data breach to the data subject shall not be required where – (a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the breach, in particular, those that render the data unintelligible to any person who is not authorised to access it, such as encryption; (b) the controller has taken subsequent measures to ensure that the high risk to the rights and freedoms of the data subject referred to in subsection (1) is no longer likely to materialise; or (c) it would involve disproportionate effort and the controller has made a public communication or similar measure whereby data subject is informed in an equally effective manner. 492 Acts 2017 Acts 2017 493 (4) Where the controller has not already communicated the personal data breach to the data subject, the Commissioner may, after having considered the likelihood of the personal data breach resulting in a high risk, require it to do so.

Ask juris about this section Official source