National Digital Identification Act 2024, personal data breach notification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 5 February 2024.
A breach notification rule binding public and private bodies.
As of 7 September 2026.
What it requires
- As a relying party or data processor in the National Digital Identification System, notify the Registrar General of a personal data breach within 72 hours of becoming aware of it, describing the categories and approximate number of records concerned.
- Where a personal data breach is likely to result in a high risk to a registered person's rights, ensure the Registrar General can communicate the breach to that person without undue delay, in plain language, with advice on mitigating measures.
- Keep a record of every personal data breach, its effects, and the remedial action taken, sufficient to demonstrate compliance with the Act's breach notification duties.
- Do not disclose, transmit, copy, or otherwise disseminate personal data collected or processed under the Act to a person not authorised under the Act or its regulations.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Section 56(1) makes unauthorised disclosure of data collected or processed under the Act an offence punishable on conviction by a fine not exceeding 50 penalty units (WST $5,000) or imprisonment not exceeding 5 years. Section 57, unauthorised access, tampering, and damage to the Identity Database, Biometric Database, passport database, or Register of Births, Deaths and Marriages, is punishable by a fine not exceeding 125 penalty units (WST $12,500) or imprisonment not exceeding 10 years for the more serious tampering and damage offences.
Penalty structure
Section 58(1)(a) caps the fine for a section 55 or 56 unauthorised-disclosure-type offence at 50 penalty units (WST $5,000), or imprisonment not exceeding 5 years. Section 58(1)(b) raises the cap to 125 penalty units (WST $12,500), or imprisonment not exceeding 10 years, for the more serious offences under sections 55(2)-(4) (tampering, damage, and related conduct). Samoa fixes the penalty unit at WST $100 under section 4 of the Fines (Review and Amendment) Act 1998.
- Rule
- Fixed only
- As of
- 7 September 2026
- Currency
- WST
- Fixed cap
- 12,500
Who enforces it
Enforcement body
Registrar General
What it reaches
Obligation class
Breach notice, Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 48 requires a relying party to notify the Registrar General of a personal data breach within 72 hours of becoming aware of it, describing the categories and approximate number of registered persons and personal data records concerned, and to respond without undue delay to the Registrar General's information requests.
Section 49 requires the Registrar General, on learning of a breach likely to result in a high risk to a registered person's rights, to communicate the breach to that person without undue delay in plain language, including advice on mitigating measures, or, where direct communication is not feasible, through public media.
Section 50 requires every such notification to name the notifying entity's contact details, describe the breach's likely consequences and the measures taken or proposed to address it, and requires the Registrar General, relying parties, and data processors to keep a record of all personal data breaches sufficient to demonstrate compliance.
Section 56 separately makes it an offence for a person engaged for the purposes of the Act, a relying party, a data processor, or any other person to disclose, transmit, copy, or otherwise disseminate personal data collected or processed under the Act to an unauthorised person without lawful excuse.
When LexLint raises it
processes_biometricshigh_risk_decisions
Read the law
Text of the National Digital Identification Act 2024, Samoa Bureau of Statistics