Law No. 12 of 2024 on Protection of Electronic Personal Data, personal data breach notification
Law No. 12 of 2024, art. 8 (personal data breach notification)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2025.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Authority immediately on becoming aware of the breach, and expect the Authority to immediately notify the competent authorities where the breach concerns national security matters.
- Within seventy two hours of becoming aware of the breach, give the Authority a description of its nature, form and causes, the approximate number of records, persons and categories affected, the data protection officer's contact details, the breach's likely effects, the measures taken or proposed to address it, and documentation of the breach and the corrective action taken.
- Tell the affected data subject what measures have been taken within three working days of the date you notified the Authority of the breach.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 8 requires a controller or processor, on becoming aware of a breach of the personal data in its possession, to notify the Authority immediately, and where the breach concerns national security matters, the Authority must immediately notify the competent authorities of the incident.
Article 8(b) requires the controller or processor to provide the Authority, within seventy two hours of becoming aware of the breach, with a description of its nature, form and causes, the approximate number of records, persons and categories affected, the data protection officer's details, the breach's likely effects, the measures taken or proposed to address it, documentation of the breach and the corrective steps taken, and any further document, information or data the Authority requests.
Article 8(c) requires the controller and processor to tell the data subject, within three working days of the date the Authority was notified, what measures have been taken.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voiceautomated_outreach
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://moct.gov.sy/news-0171Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.