Law No. 06/L-082 on Protection of Personal Data, personal data breach notification
Law No. 06/L-082 on Protection of Personal Data, arts. 33-34 (personal data breach notification)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 12 March 2019.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Agency for Information and Privacy of a personal data breach without delay and, where feasible, no later than seventy-two hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
- Give reasons for the delay if notifying the Agency after that seventy-two-hour period.
- As a data processor, notify the data controller without undue delay after becoming aware of a personal data breach.
- Communicate a personal data breach to the affected data subject without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless an Article 34(3) exception applies.
- Describe in the Agency notification the nature of the breach, the categories and approximate number of data subjects and records affected where possible, a contact point, the likely consequences, and the measures taken or proposed, supplying information in phases without undue further delay where it cannot all be given at once.
- Document every personal data breach, its facts, effects and remedial action, so the Agency can verify your compliance.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 33(1) requires the controller, without delay and where feasible no later than seventy-two hours after becoming aware of a personal data breach, to notify the Agency of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 33(1) also requires a notification made after that seventy-two-hour period to be accompanied by reasons for the delay.
Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. Article 33(3) fixes what the Agency notification must contain at minimum, including the nature of the breach, the categories and approximate number of data subjects and personal data records concerned where possible, a contact point's name and details, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
Article 33(4) lets that information be given in phases without undue further delay where it cannot all be given at once. Article 33(5) requires the controller to document every personal data breach, including its facts, effects and remedial action, so the Agency can verify compliance. Article 34(1) requires the controller to communicate a personal data breach to the data subject without undue delay where the breach is likely to result in a high risk to the rights and freedoms of natural persons.
Article 34(3) excuses that communication where the controller had applied protective measures, such as encryption, that rendered the affected data unintelligible, where the controller has since eliminated the high risk, or where communication would take disproportionate effort and a public communication of equivalent effectiveness is made instead.
Article 34(4) still lets the Agency require the communication, or determine that one of the Article 34(3) conditions applies, where the controller has not itself communicated the breach to the data subject.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.