Data Protection Act 2021, personal data breach notification
Data Protection Act, 2021 (Act No. 45 of 2021), ss. 60-62
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Commencement not set.
A breach notification rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Where feasible, notify the Data Protection Commissioner of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to risk a person's rights and freedoms.
- Where a personal data breach is likely to result in a high risk to a person's rights and freedoms, notify that person without undue delay.
What it reaches
Obligation class
Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 61 requires a data controller, where feasible, to notify the Commissioner of a personal data breach not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to a person's rights and freedoms, with reasons required for any later notification; a data processor must notify the controller without undue delay.
Section 62 requires the controller to notify an affected data subject without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless an exempting condition, such as prior encryption of the data, applies.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometrics
Read the law
Official text of the Data Protection Act
2021 (Act No. 45 of 2021), National Assembly of Belize, cited through an Internet Archive capture of the National Assembly's PDF