(2)
(3)
(4)
(5)
(6)
Where the notification of the personal data breach to the Commission is not made as per
the provision of sub-Article (1) of this Article, the notification shall be accompanied by
reasons for the delay.
The data processor shall notify the data controller without undue delay after becoming
aware of a personal data breach.
The notification of the personal data breach to the Commission referred to in sub-Article
(1) of this Article shall:
(a) describe the nature of the personal data breach including where possible, the
categories and approximate number of data subjects concerned and the categories
and approximate number of personal data records concerned;
(b) communicate the name and contact details of the data protection officer or other
contact point where more information can be obtained;
(c) describe the likely consequences of the personal data breach; and
(d) describe the measures taken or proposed to be taken by the data controller to
address the personal data breach, including, where appropriate, measures to
mitigate its possible adverse effects.
Where it is not possible to provide the information at the same time, the information
may be provided in phases without undue further delay.
The data controller shall document any personal data breaches, comprising the facts
relating to the personal data breach, its effects and the remedial action taken in order to
facilitate the Commission in its assessment of the data controller’s compliance with this
provision.
55. Communication of Personal Data Breach to Data Subject
(1) Where a personal data breach has occurred, the controller shall communicate the
personal data breach to the data subject within 72 hours after having become aware of
it.
(2) The communication to the data subject shall describe in clear language the nature of the
personal data breach and set out the information in Article 54 sub-Article (4) lit. (b)-(d)
of this Proclamation.
(3) The communication of a personal data breach to the data subject shall not be required
where:
(a) the data controller has implemented appropriate technical and organizational
protection measures, and those measures were applied to the personal data
affected by the breach, in particular, those that render the data unintelligible to
any person who is not authorized to access it, such as encryption;
(b) the data controller has taken subsequent measures to ensure that the high risk to
the rights and freedoms of the data subject referred to in sub-Article (1) of this
Article is no longer likely to materialize; or
(c) it would involve disproportionate effort and the data controller has made a public
communication or similar measure whereby data subject is informed in an equally
effective manner.
24