The organization must report any personal data breach to the competent authority within 72 hours of becoming aware of it if it may risk individuals’ rights or freedoms.
If the breach poses a high risk, affected individuals must also be notified without undue delay.
If all details are not available within the 72-hour period, the organization must justify the delay and provide the remaining information as soon as possible.
Notifications must include:
- A description of the breach, including timing, nature, and cause.
- The categories and approximate number of affected individuals and data types.
- An assessment of risks and potential impacts.
- Actions taken to mitigate the breach and planned measures to prevent recurrence.
- Contact details of the responsible officer or data protection contact.
The organization must retain copies of all notifications, document corrective and preventive actions, record lessons learned, and maintain supporting evidence to demonstrate compliance.
All reporting and documentation must align with requirements issued by the National Cybersecurity Authority or other applicable regulations.