If a controller becomes aware of a personal data breach in relation to personal data for which the controller is responsible, the controller must notify the breach to the Commissioner—
Subsection (1) does not apply if the personal data breach is unlikely to result in a risk to the rights and freedoms of individuals.
Where the notification to the Commissioner is not made within 72 hours, the notification must be accompanied by reasons for the delay.
Subject to subsection (5), the notification must include—
Where and to the extent that it is not possible to provide all the information mentioned in subsection (4) at the same time, the information may be provided in phases without undue further delay.
The controller must record the following information in relation to a personal data breach—
The information mentioned in subsection (6) must be recorded in such a way as to enable the Commissioner to verify compliance with this section.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
If a processor becomes aware of a personal data breach (in relation to personal data processed by the processor), the processor must notify the controller without undue delay.