Law / Andorra

LQPD, personal data breach notification

Llei 29/2021, arts. 36-37 (personal data breach notification)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 17 May 2022.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Andorran Data Protection Agency of a personal data breach without undue delay and, where possible, within seventy-two hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
  • Justify the reasons for the delay if notifying the Agency after that seventy-two-hour period.
  • As a data processor, notify the data controller without delay of a personal data breach you become aware of.
  • Communicate a personal data breach to the affected data subject without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless an Article 37(3) exception applies.
  • Describe in the Agency notification the nature of the breach, the categories and approximate number of data subjects and records affected where possible, a contact point, the likely consequences, and the measures taken or proposed, supplying information in phases without undue delay where it cannot all be given at once.
  • Document every personal data breach, its facts, effects and remedial measures, so the Agency can verify your compliance.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 36(1) requires the controller, without undue delay and where possible within seventy-two hours of becoming aware of a personal data breach, to notify the Andorran Data Protection Agency of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 36(1) also requires a notification made after that seventy-two-hour period to justify the reasons for the delay.

Article 36(2) requires a processor to notify the controller without delay of any personal data breach it becomes aware of. Article 36(3) fixes what the Agency notification must contain at minimum, including the nature of the breach, the categories and approximate number of data subjects and personal data records concerned where possible, a contact point's name and details, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

Article 36(4) lets that information be given in phases without undue delay where it cannot all be given at once. Article 36(5) requires the controller to document every personal data breach, including its facts, effects and remedial measures, so the supervisory authority can verify compliance with the notification duty.

Article 37(1) requires the controller to communicate a personal data breach to the data subject without undue delay where the breach is likely to result in a high risk to the rights and freedoms of natural persons.

Article 37(3) excuses that communication where the controller had applied protective measures, such as encryption, that rendered the affected data unintelligible, where the controller has since eliminated the high risk, or where communication would take disproportionate effort and a public communication of equivalent effectiveness is made instead.

Article 37(4) still lets the Agency require the communication, or determine that one of the Article 37(3) conditions applies, where the controller has not itself communicated the breach to the data subject.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Consolidated statute text at portaljuridicandorra.ad

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app