Data Protection Act 2025, personal data breaches
Data Protection Act 2025, ss. 19-20 (personal data breaches)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This Act is enacted but not in force: section 2 leaves commencement to a ministerial notice, and none was located as of this review, so no personal data breach obligation binds anyone yet.
- On commencement, notify the Digital Transformation Office of a personal data breach that has resulted in, or is likely to result in, significant harm to affected data subjects, as soon as practicable after becoming aware of the breach.
- On commencement, notify each affected data subject of that same harmful personal data breach as soon as practicable after becoming aware of the breach, or by public notification through widely used media where direct notification is not feasible or would involve disproportionate effort or expense.
- On commencement, describe in the notification the nature of the breach including, where possible, the categories and approximate numbers of data subjects and personal data records concerned, a point of contact, the likely consequences, and the measures taken or expected to address the breach and mitigate its effects, supplying information in phases without undue further delay where it cannot all be given at once.
- On commencement, as a person processing personal data on another person's behalf, inform that other person as soon as practicable after becoming aware of any personal data breach, regardless of whether it meets the significant-harm threshold for notifying the Office and data subjects.
- On commencement, keep a record of every personal data breach, regardless of whether it meets that threshold, including the facts, its effects and the remedial action taken, and make your threshold analysis available to the Office on request.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 19(1) requires a person processing personal data on another person's behalf to inform that other person as soon as practicable after becoming aware of any personal data breach, whether or not it meets the harm threshold in section 20, and section 19(3) requires every person to keep a record of any personal data breach, including its facts, effects and remedial action, whether or not that threshold is met.
Section 19(4) requires a controller to determine whether a breach meets the section 20(1) threshold, keep a written record of that analysis, and make it available to the Office on request.
Section 20 applies to a personal data breach that has resulted in, or is likely to result in, significant harm to affected data subjects, assessed against factors including encryption or other security measures, the nature of the likely harm, mitigating action taken, and whether lost or altered data has been recovered.
When a harmful personal data breach has occurred, section 20(2) requires the relevant controller, as soon as practicable after becoming aware of the breach, to notify the Office and each affected data subject, or to notify data subjects by public notification through widely used media where direct notification would involve disproportionate effort or expense or is otherwise not feasible.
Section 20(5) requires the notification to set out the nature of the breach including, where possible, the categories and approximate numbers of data subjects and records concerned, a point of contact, the likely consequences, and the measures taken or expected to address the breach, supplying the information in phases without undue further delay where it cannot all be given at once.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.