Breach notification
Law on Personal Data Protection, personal data breach notification
Law on Personal Data Protection, arts. 52-53 (personal data breach notification), Official Gazette RS No. 87/2018Zakon o zastiti podataka o licnosti, full consolidated statute text (paragraf.rs)
In force since 21 August 2019. Binds public and private bodies.
What this law does
Article 52 requires a controller to notify the Commissioner of a personal data breach that may create risk to a person's rights and freedoms without undue delay, and within 72 hours of becoming aware of the breach where that is possible, giving reasons for any delay beyond that period. A processor must notify the controller without undue delay after becoming aware of a breach.
The notification to the Commissioner must describe the nature of the breach, give the data protection officer's or another contact point's details, describe the likely consequences and the measures taken or proposed, and article 52 lets the controller supply this information in phases without undue further delay where it cannot all be given at once; the controller must also document every breach, including its facts, effects and remedial action, so the Commissioner can assess compliance.
Article 53 requires the controller to notify the affected person without undue delay, in clear and understandable language, wherever the breach may create high risk to their rights and freedoms, but excuses that notice where encryption or another measure has made the data unintelligible, subsequent measures have removed the high risk, or notifying would take disproportionate effort and a public communication substitutes for it, with the Commissioner able to order the notice anyway.
The act states no fixed number of hours for notifying the affected person; only the notice to the Commissioner carries the 72-hour figure.
What it requires