Law / Tonga

Cybersecurity Act 2025, Duty to Report a Cybersecurity Incident

Act 14 of 2025, s. 15

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This duty does not yet bind: the Cybersecurity Act 2025 comes into force only on a date proclaimed by Cabinet under section 1(2), and no proclamation has been identified.
  • It reaches you only once the Minister responsible for cybersecurity policy and regulation (Minister CPR) has designated your physical, electronic or virtual infrastructure assets, systems or networks as critical infrastructure under section 11 and published that designation in the Government Gazette.
  • Within 24 hours of becoming aware of it, report to the Computer Emergency Response Team (CERT) a cybersecurity incident relating to the information systems of your designated critical infrastructure, an incident relating to any information system interconnected with or communicating with those systems, or any other cybersecurity incident or occurrence the Minister CPR has designated as requiring notification.
  • File that report in the form the Minister CPR prescribes.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Section 19(3) sets two separate fixed ceilings by class of contravener: not exceeding $500,000 for an individual and not exceeding $1,000,000 for a body corporate; the higher, body-corporate figure is recorded as fixed_cap. The Act does not define the currency the bare "$" denotes; Tonga's legal tender is the Pa'anga (ISO 4217: TOP), confirmed on the National Reserve Bank of Tonga's own site (reservebank.to); that currency is recorded here in the absence of an express definition in the Act itself. The amount is a court-ordered civil pecuniary penalty recovered through a civil action the Attorney General institutes under section 18, not a fixed administrative fine or a criminal sentence, and section 19 applies to a contravention of any provision of Division 2 of Part V, section 15's reporting duty included.

Rule
Fixed only
As of
19 September 2026
Currency
TOP
Fixed cap
1,000,000

Who enforces it

Enforcement body

The Attorney General, who may institute civil proceedings in a court of competent jurisdiction against an operator of critical infrastructure for a pecuniary penalty for contravening the reporting duty; the Computer Emergency Response Team and the Minister responsible for cybersecurity policy and regulation (Minister CPR) receive and act on reports under Part IV.

Settledness

As of
19 September 2026
Open questions
  • Has Cabinet proclaimed a commencement date for the Cybersecurity Act 2025 under section 1(2), and if so what is it?
  • Which infrastructure assets, systems or networks, if any, has the Minister responsible for cybersecurity policy and regulation designated as critical infrastructure under section 11, since the reporting duty binds only an operator so designated?
  • Does the pecuniary-penalty cap in section 19(3), stated only as "$500,000" and "$1,000,000", denote the Tongan Pa'anga or another currency?

What it reaches

Obligation class

Reporting, Security

Applicability criteria

The Act itself is not yet in force: section 1(2) makes commencement conditional on a date proclaimed by Cabinet, so this criterion cannot yet be satisfied by anyone.

As of
19 September 2026
Combinator
All of
Criteria
The Minister responsible for cybersecurity policy and regulation has designated your physical, electronic or virtual infrastructure assets, systems or networks as critical infrastructure under section 11 of the Cybersecurity Act 2025, and published that designation in the Government Gazette.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 15 requires an operator of critical infrastructure designated under section 11 to report a cybersecurity incident to the Computer Emergency Response Team (CERT) within 24 hours of becoming aware of it, whether the incident affects the information systems of the designated infrastructure itself, any information system interconnected with or communicating with those systems, or any other incident the Minister responsible for cybersecurity policy and regulation has designated as requiring notification, in a form that Minister prescribes.

When LexLint raises it

  • operates_essential_service
  • provides_financial_services
  • provides_telecom_services
  • handles_health_records

Read the law

Official Act text (Cybersecurity Act 2025, Act 14 of 2025), Attorney General's Office of Tonga, as captured in the Internet Archive
the publisher's own host presents an automated bot-verification challenge on the direct PDF

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app