Breach notification
Personal Data Protection Order 2025, breach notification
Personal Data Protection Order, 2025 (S 1/2025), Part 7 (ss.25-29)official gazette text, Attorney General's Chambers of Brunei Darussalam (agc.gov.bn), Internet Archive capture
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 9, 2026. Publisher's page: https://www.agc.gov.bn/AGC%20Images/LAWS/Gazette_PDF/2025/EN/S%201_2025%20%5BE%5D.pdfIn force 9 months, effective 1 January 2026. Binds private bodies.
What this law does
Part 7 defines a data breach as notifiable where it results in, or is likely to result in, significant harm to an affected individual, or is or is likely to be of significant scale (section 26), with the specific thresholds left to regulations not read, and an internal-only breach deemed not notifiable.
Section 28 requires the organisation to notify the Authority as soon as practicable and no later than 3 days after assessing that a breach is notifiable, and to notify each affected individual, subject to exceptions where remedial measures make significant harm unlikely or a law enforcement agency or the Authority directs otherwise. This duty reaches a breach involving a voiceprint, faceprint, or other biometric identifier exactly like any other personal data.
Government Gazette No. S 11/2025 confirms the Minister appointed 1 January 2026 as the commencement date for Parts 3 to 9 (which includes Part 7) of the Order, so this duty is in effect from that date.
What it requires