Law / Tonga

Privacy Act 2025, personal information breaches

Privacy Act 2025, s. 37 (personal information breaches)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This law is recorded as enacted, but the Cabinet proclamation that would fix its commencement date under section 1(2) has not been located, so whether it is yet in force has to be established before relying on what follows.
  • Notify the Privacy Commission within 72 hours of becoming aware of a personal information breach that is likely to result in a risk to the rights and freedoms of individuals, describing its nature and, where possible, the categories and approximate numbers of data subjects and records concerned.
  • As a data processor, notify the data controller or the data processor that engaged you within 72 hours of becoming aware of a personal information breach, and answer their information requests without undue delay.
  • Communicate a breach likely to result in a high risk to a data subject to that person without undue delay, in plain and clear language, with advice on how to mitigate the effects, or through widely used media where direct communication would take disproportionate effort or expense.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 37(1) requires a data processor that becomes aware of a personal information breach to notify the data controller or the data processor that engaged it within seventy-two hours, describing the nature of the breach including, where possible, the categories and approximate numbers of data subjects and records concerned, and to respond without undue delay to information requests from whoever engaged it.

Section 37(2) requires a data controller to notify the Commission within seventy-two hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of individuals, with the same description.

Section 37(3) requires the controller to communicate a breach likely to result in a high risk to a data subject to that data subject without undue delay, in plain and clear language, with advice on measures they could take to mitigate the adverse effects, and allows a public communication through widely used media where direct communication would involve disproportionate effort or expense.

Section 1(2) provides that the Act comes into force on a date proclaimed by Cabinet, and no proclamation has been located, so whether these provisions bind today is not established.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Official English text, Privacy Act 2025 (Act 34 of 2025), Tonga Attorney General's Office legislation database, archived copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://ago.gov.to/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0052/PrivacyAct2025_1.pdf

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app