Data Protection Act 2021 Revision, personal data breach notification
Data Protection Act (2021 Revision), s. 16 (personal data breaches)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 30 September 2019.
A breach notification rule binding public and private bodies.
As of 7 September 2026.
What it requires
- Notify the Ombudsman and each affected data subject of a personal data breach without undue delay and no later than five days after becoming aware of it, describing the breach, its consequences, and the measures taken or recommended.
If you get it wrong
Criminal exposureYes
Criminal exposure note
A data controller who fails to notify the Ombudsman and the data subject of a personal data breach as section 16(1) requires commits an offence and is liable on conviction to a fine of one hundred thousand dollars.
Penalty structure
Section 16(2)'s fixed cap applies to a data controller's failure to notify a personal data breach as section 16(1) requires.
- Rule
- Fixed only
- As of
- 7 September 2026
- Currency
- KYD
- Fixed cap
- 100,000
Who enforces it
Enforcement body
Office of the Ombudsman
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
On a personal data breach, a data controller must, without undue delay and no more than five days after it should reasonably have become aware of the breach, notify both the affected data subject and the Ombudsman, describing the nature and consequences of the breach, the measures taken or proposed to address it, and the measures recommended to the data subject to mitigate adverse effects. Failing to notify is an offence.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
Data Protection Act (2021 Revision), Office of the Ombudsman