No. 3
Data Protection
36.__(1) a data controller shall, in the case of a personal data
breach, notify the authority within seventy-two hours of becoming
aware of the breach.
(2) the notification referred to in subsection (1) shall include—
(a) a description of the nature of the personal data breach;
(b) where possible, a description of the categories of personal
data affected by the breach;
(c) where possible, the number of data subjects affected by the
breach;
(d) a description of the likely consequences of the personal
data breach;
(e) a description of the measures taken or proposed to be taken
by the data controller to address the personal data breach; and
(f) the name and contact details of the data protection officer of
the data controller.
21
notification
of personal
data breach
(3) where it is not practically possible for a data controller to
provide the information referred to in subsection (2) within the
period prescribed under subsection (1), the data controller shall
provide the information as soon as the information becomes
available.
(4) a data controller shall, with respect to each personal data
breach, keep a record of the breach and the information prescribed
under subsection (2).
(5) where a personal data breach occurs while data is being
processed by a data processor, the data processor shall notify the
data controller of the breach, within seventy-two hours of the data
processor becoming aware of the breach.
(6) the notification under subsection (5) shall contain the
particulars prescribed under subsection (2).
37.__(1) a data controller shall, where there is a personal data
breach which is of high risk to rights and freedoms of a data subject,
notify the data subject of the breach, within seventy-two hours of
the data controller becoming aware of the breach.
(2) a data controller shall, in evaluating whether a personal data
breach is likely to be of high risk to the rights and freedoms of a data
subject, take into account—
(a) the likely effectiveness of any technical and administrative
measures implemented to mitigate the likely harm resulting from
the personal data breach, including any encryption or
de-identification of the personal data;
communication of
personal data
breach to data
subjects