this Act. This shall not apply in situations where data collection is occasional unless
the processing results in the infringement of the fundamental rights and freedoms of
the data subject, as enshrined in the Constitution of the Islamic Republic of Pakistan,
1973.
13. Personal data breach notification. –
(1) In the event of a personal data breach, the data controller shall without undue delay
and where reasonably possible, not beyond 72 hours of becoming aware of the
personal data breach, must notify the Commission and the data subject except where
the breach is unlikely to result in the infringement of rights and freedoms of the data
subject.
(2) In the event of a delay in notifying personal data breach beyond 72 hours, the
notification of a personal data breach shall be furnished to the Commission and the
data subject with a valid reason for the delay.
(3) The personal data breach notification shall provide at least the following
information: (a) description of the nature of the personal data breach including where possible,
the categories and approximate number of data subjects concerned and the
categories and approximate number of concerned personal data records;
(b) name and contact details of the data protection officer or another point of contact
from where additional information can be obtained;
(c) likely consequences of the personal data breach;
(d) measures adopted or proposed to be adopted by the data controller to address the
personal data breach, including, where appropriate, measures to mitigate its
possible adverse effects.
(4) The data controller shall maintain a record of all personal data breaches, comprising
the facts concerning personal data breaches, their effects, and the remedial action
taken.
(5) After becoming aware of a personal data breach, the data processor shall also follow
the requirements of the personal data breach notification provided under this section
except that the data processor should only inform the data controller and commission.
CHAPTER III
17