Personal Data Protection Proclamation, personal data breach notification
Proclamation No. 1321/2024, arts. 43-44 (personal data breach notification)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 24 July 2024.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Authority of a personal data breach within 72 hours of becoming aware of it, giving reasons for any delay.
- Communicate a personal data breach to the affected data subject within 72 hours of becoming aware of it, in clear language, describing the likely consequences, the contact point for more information and the measures taken to address it.
- As a data processor, notify the data controller without undue delay after becoming aware of a personal data breach.
- Describe in the notification the nature of the breach, including where possible the categories and approximate number of data subjects and of personal data records concerned, and supply information in phases without undue further delay where it cannot all be given at once.
- Document every personal data breach, its facts, its effects and the remedial action taken, so the Authority can assess compliance.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 43(1) requires a data controller, where there is a personal data breach, to notify the breach to the Authority within 72 hours after having become aware of it, and article 43(2) requires a notification made outside that period to be accompanied by reasons for the delay. Article 43(3) requires a data processor to notify the data controller without undue delay after becoming aware of a personal data breach.
Article 43(4) fixes what the notification to the Authority must contain: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, the name and contact details of the data protection officer or other contact point, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects, with information supplied in phases without undue further delay where it cannot all be given at once.
Article 43(6) requires the data controller to document every personal data breach, its facts, effects and remedial action, so that the Authority can assess compliance.
Article 44(1) requires the controller to communicate the personal data breach to the data subject within 72 hours after having become aware of it, in clear language and with the article 43(4) information on contact point, consequences and measures, and article 44(3) excuses that communication only where the affected data were protected by measures such as encryption that render them unintelligible, where subsequent measures have made the high risk no longer likely to materialize, or where direct communication would involve disproportionate effort and a public communication of equal effect has been made; article 44(4) lets the Authority require the communication anyway.
Article 70 enters the Proclamation into force on the date of its publication in the Negarit Gazeta, and it was signed at Addis Abeba on the 24th day of July 2024, so these provisions bind today.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsoperates_essential_service
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.