22
Data Protection
No. 3
(b) any subsequent measures taken by the data controller to
mitigate the risk; and
(c) the nature, scope and category of the personal data
involved.
(3) the notification referred to in subsection (1) shall describe the
nature of the personal data breach, the likely consequence of the
breach and the measures taken or proposed to be taken by the data
controller to address the breach.
(4) where the notification referred to in subsection (1) involves a
disproportionate effort or expense, the data controller shall make a
public notification, in at least one newspaper of wide circulation in
Malawi and any other mode of communication the data controller
considers appropriate.
(5) where the authority is of the opinion that the measures taken
by the data controller under this section are inadequate, the
authority may, at any time, make a public notification of the
personal data breach, in at least one newspaper of wide circulation
in Malawi or any other mode of communication the authority
considers appropriate.
cross-border
transfer of
personal data
adequacy of
protection of
personal data
Part VII—crOss-BOrDer transFers OF PersOnaL Data
38.__(1) a data controller and data processor shall not transfer
personal data from Malawi to another country or an international
organization, unless—
(a) the recipient of the data is subject to—
(i) a law;
(ii) a binding corporate rule;
(iii) a personal data protection contractual clause;
(iv) code of conduct; or
(v) a certification mechanism,
that affords an adequate level of protection of personal data in
accordance with section 39(2) and (3); or
(b) one of the conditions prescribed under section 39(4)
applies.
(2) a data controller and data processor shall keep a record of the
basis for the transfer of personal data from Malawi to another
country or an international organization.
39.__(1) the authority shall, on application by a data controller
or on its own initiative, assess whether an international organization