On discovering a data breach, which regulators or other government agencies should be notified?
List: - Under the Data Protection Act (2021 Revision) (DPA), which came into effect on 30 September 2019, the relevant designated authority is the Ombudsman appointed under section 3 of the Ombudsman Act (2021 Revision).
-
In the case of a personal data breach, the DPA provides that the data controller is required to notify the data subject and the Ombudsman of the breach, without undue delay, but no longer than five days after the data controller should, with the exercise of reasonable diligence, have been aware of the breach. Failure to do so is an offence for which the fine is US$120,000 on conviction.
-
Notification of the breach should include the nature of the breach, the consequences of the breach, the measures proposed or taken by the data controller to address the breach and the measures recommended by the data controller to the data subject of the personal data in question to mitigate the possible adverse effects of the breach.