No. 3 Data Protection 36.__(1) a data controller shall, in the case of a personal data breach, notify the authority within seventy-two hours of becoming aware of the breach. (2) the notification referred to in subsection (1) shall include— (a) a description of the nature of the personal data breach; (b) where possible, a description of the categories of personal data affected by the breach; (c) where possible, the number of data subjects affected by the breach; (d) a description of the likely consequences of the personal data breach; (e) a description of the measures taken or proposed to be taken by the data controller to address the personal data breach; and (f) the name and contact details of the data protection officer of the data controller. 21 notification of personal data breach (3) where it is not practically possible for a data controller to provide the information referred to in subsection (2) within the period prescribed under subsection (1), the data controller shall provide the information as soon as the information becomes available. (4) a data controller shall, with respect to each personal data breach, keep a record of the breach and the information prescribed under subsection (2). (5) where a personal data breach occurs while data is being processed by a data processor, the data processor shall notify the data controller of the breach, within seventy-two hours of the data processor becoming aware of the breach. (6) the notification under subsection (5) shall contain the particulars prescribed under subsection (2). 37.__(1) a data controller shall, where there is a personal data breach which is of high risk to rights and freedoms of a data subject, notify the data subject of the breach, within seventy-two hours of the data controller becoming aware of the breach. (2) a data controller shall, in evaluating whether a personal data breach is likely to be of high risk to the rights and freedoms of a data subject, take into account— (a) the likely effectiveness of any technical and administrative measures implemented to mitigate the likely harm resulting from the personal data breach, including any encryption or de-identification of the personal data; communication of personal data breach to data subjects

Select target paragraph3