Data Protection Act, 2023, personal data breach notification
Data Protection Act, Law No. 005 of 2023, arts. 25-27 (data breach notifications)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Data Protection Authority of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals within 72 hours after becoming aware of it.
- Where you extend that deadline for the legitimate needs of law enforcement or to determine the scope of the breach, tell the Authority the grounds for the extension, with supporting evidence, before the original deadline expires.
- Communicate a breach likely to result in a high risk to a data subject to each affected data subject without undue delay, in plain and clear language, or through widely used media where direct communication would take disproportionate effort or expense.
- Set out in every breach notification and communication the nature of the breach, a contact point, the likely consequences, the measures taken to address it, and, for a communication to data subjects, advice on what they can do to mitigate it.
- Keep a record of every personal data breach.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 25(1) requires a data controller to notify the Authority of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals within seventy-two hours after having become aware of it.
Article 25(2) and (3) let the controller extend that period for the legitimate needs of law enforcement or as reasonably necessary to determine the scope of the breach, provided it tells the Authority the grounds for the extension, with supporting evidence, inside the same seventy-two hours.
Article 25(4) requires the controller to communicate a breach likely to result in a high risk to a data subject to each affected data subject without undue delay, in plain and clear language, and article 25(5) allows communication through widely used media where direct communication would involve disproportionate effort or expense. Article 26 sets out what a notification and a communication must contain, and article 27 requires a record of breaches.
The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance
the Data Protection Authority names the Act and its own copy of the text is not available
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.