Personal Data Protection Act 2025, government personal-data protection principles
Personal Data Protection Act 2025, 6 MIRC Ch. 4 (P.L. 2025-43), ss. 401-405, 409, 415, 418
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 12 months, effective 7 October 2025.
A comprehensive regime rule binding government bodies.
As of 19 September 2026.
What it requires
- This Chapter binds only core Government ministries and agencies, and a third party acting as their data controller or processor, not a private-sector service operating outside a government engagement.
- Process personal data lawfully, fairly, and transparently, for a specified and legitimate purpose, and do not further process it in a way incompatible with that purpose.
- Collect personal data only by lawful and fair means, and limit it to what is relevant and necessary to fulfill the purpose for which it is processed.
- Keep personal data accurate and up to date, and take reasonable steps to correct or delete inaccurate personal data without delay.
- Retain personal data in identifiable form only as long as necessary to fulfill the purpose for which it was collected.
- Store or process personal data with technical and organizational security measures that protect against unauthorized or unlawful processing and against unintentional loss, destruction, or damage, and limit access to staff who need it for their duties.
- Be able to demonstrate compliance with these principles on request of the competent authority, the Economic Policy, Planning and Statistics Office.
- Where sharing personal data with another core Government ministry or agency under the safe harbor provision, ensure the sharing serves a legitimate function of each ministry or agency involved and complies with the personal data protection principles.
What it reaches
Obligation class
Governance, Retention, Security, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Sections 401 to 405 apply this Chapter to core Government ministries and agencies of the Republic that collect, use, store, process, disclose, or transfer personal data of natural persons, and their definitions of data controller and data processor extend to a third party acting on behalf of such a ministry or agency; the Chapter excludes processing for law enforcement or national intelligence and national security purposes, non-personal data, and publicly available information lawfully obtained from government records, voluntarily made available by the data subject without audience restriction, or otherwise lawfully obtained, truthful, and a matter of public concern.
Section 409 sets six personal data protection principles binding core Government ministries and agencies: a legitimate-purpose principle requiring lawful, fair, transparent processing for specified purposes; a data-minimization principle limiting collection to what the purpose requires; an accuracy principle requiring inaccurate personal data to be corrected or deleted without delay; a retention principle limiting storage to what the purpose requires; an integrity and security principle requiring technical and organizational protection against unauthorized or unlawful processing and unintentional loss, destruction, or damage, and limiting staff access to what their duties need; and an accountability principle making the data controller responsible for demonstrating compliance.
Section 415 lets core Government ministries and agencies voluntarily share personal data with each other under a safe harbor, provided the sharing serves a legitimate function of each ministry or agency and complies with the section 409 principles, and lets the competent authority set standards for such sharing agreements.
Section 418 states the Chapter takes effect twelve months after the date of its certification under Article IV, section 21 of the Constitution, which the Act's own commencement note records as 7 October 2025. The Act states no consent requirement, no data-subject access, correction, deletion, or portability right, no heightened rule for sensitive or biometric data beyond the definition, and no cross-border transfer restriction.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0043/2025-0043_1.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.