(2) (3) (4) (5) (6) Where the notification of the personal data breach to the Commission is not made as per the provision of sub-Article (1) of this Article, the notification shall be accompanied by reasons for the delay. The data processor shall notify the data controller without undue delay after becoming aware of a personal data breach. The notification of the personal data breach to the Commission referred to in sub-Article (1) of this Article shall: (a) describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; (b) communicate the name and contact details of the data protection officer or other contact point where more information can be obtained; (c) describe the likely consequences of the personal data breach; and (d) describe the measures taken or proposed to be taken by the data controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. Where it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay. The data controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken in order to facilitate the Commission in its assessment of the data controller’s compliance with this provision. 55. Communication of Personal Data Breach to Data Subject (1) Where a personal data breach has occurred, the controller shall communicate the personal data breach to the data subject within 72 hours after having become aware of it. (2) The communication to the data subject shall describe in clear language the nature of the personal data breach and set out the information in Article 54 sub-Article (4) lit. (b)-(d) of this Proclamation. (3) The communication of a personal data breach to the data subject shall not be required where: (a) the data controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the breach, in particular, those that render the data unintelligible to any person who is not authorized to access it, such as encryption; (b) the data controller has taken subsequent measures to ensure that the high risk to the rights and freedoms of the data subject referred to in sub-Article (1) of this Article is no longer likely to materialize; or (c) it would involve disproportionate effort and the data controller has made a public communication or similar measure whereby data subject is informed in an equally effective manner. 24

اختر الفقرة المستهدفة3