Loi sur la Protection des Données Personnelles, notification des violations de données
Loi n. 1.565 du 3 decembre 2024, art. 32 (personal data breach notification)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 13 December 2024.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Authority of a personal data breach as soon as possible and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to create a risk to the rights and freedoms of the persons concerned, and give the reasons for the delay when you notify later than that.
- Communicate a personal data breach to the affected person as soon as possible, in clear language, when it is likely to create a high risk to their rights and freedoms.
- As a processor, notify the controller of a personal data breach as soon as you become aware of it.
- Describe in the notification to the Authority the nature of the breach, including where possible the categories and approximate number of affected persons and records, a contact point, the likely consequences, and the measures taken or proposed to address it.
- Document every personal data breach, its facts, its effects, and the remedial steps you took, and expect the Authority to be able to require you to communicate the breach to the affected person if you have not already done so.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 32.I requires the controller to notify the Authority of a personal data breach as soon as possible and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to create a risk to the rights and freedoms of the persons concerned, and a notification made after that window must be accompanied by the reasons for the delay.
The notification to the Authority must describe the nature of the breach, including where possible the categories and approximate number of affected persons and records, a contact point, the likely consequences, and the measures taken or proposed, and the controller must document every breach, its facts, its effects, and the remedial steps taken. A processor must notify the controller of a breach as soon as it becomes aware of it, with no fixed number of hours stated.
Article 32.II requires the controller to communicate a breach likely to create a high risk to a person's rights and freedoms to that person as soon as possible, in clear language, but states no fixed number of hours for that communication the way it does for the Authority, and excuses it only where the affected data were already rendered unintelligible by measures such as encryption, where later measures mean the risk is no longer likely to materialise, or where individual notice would take disproportionate effort and an equally effective public communication is made instead.
The Authority can still require the controller to communicate the breach to the person if it has not done so. Article 32.I sets the 72 hour period for the notice to the Authority alone; article 32.II gives the notice to the affected person no fixed period, only "dans les meilleurs delais".
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsoperates_essential_service
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.