Law / Somalia

Data Protection Act, 2023, personal data breach notification

Data Protection Act, Law No. 005 of 2023, arts. 25-27 (data breach notifications)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Data Protection Authority of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals within 72 hours after becoming aware of it.
  • Where you extend that deadline for the legitimate needs of law enforcement or to determine the scope of the breach, tell the Authority the grounds for the extension, with supporting evidence, before the original deadline expires.
  • Communicate a breach likely to result in a high risk to a data subject to each affected data subject without undue delay, in plain and clear language, or through widely used media where direct communication would take disproportionate effort or expense.
  • Set out in every breach notification and communication the nature of the breach, a contact point, the likely consequences, the measures taken to address it, and, for a communication to data subjects, advice on what they can do to mitigate it.
  • Keep a record of every personal data breach.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 25(1) requires a data controller to notify the Authority of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals within seventy-two hours after having become aware of it.

Article 25(2) and (3) let the controller extend that period for the legitimate needs of law enforcement or as reasonably necessary to determine the scope of the breach, provided it tells the Authority the grounds for the extension, with supporting evidence, inside the same seventy-two hours.

Article 25(4) requires the controller to communicate a breach likely to result in a high risk to a data subject to each affected data subject without undue delay, in plain and clear language, and article 25(5) allows communication through widely used media where direct communication would involve disproportionate effort or expense. Article 26 sets out what a notification and a communication must contain, and article 27 requires a record of breaches.

The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance
the Data Protection Authority names the Act and its own copy of the text is not available

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app