Section 27
Duty to conduct assessment of data breach
of Personal Data Protection Order, 2025
(1)
Subject to subsection (2), where an organisation has reason to believe that a data breach affecting personal data in its possession or under its control has occurred, the organisation shall conduct, in a reasonable and expeditious manner, an assessment of whether the data breach is a notifiable data breach.
(2)
Where a data processor (other than a data processor mentioned in section 29) has reason to believe that a data breach has occurred in relation to personal data that the data processor is processing on behalf of and for the purposes of another organisation -
30
(a} the data processor shall, without undue delay, notify the other organisation of the occurrence of the data breach; and
(b} the other organisation shall, on notification by the data processor, conduct an assessment of whether the data breach is a notifiable data breach.
(3)
The organisation shall carry out the assessment mentioned m subsection (1) or 2{b} in accordance with any prescribed requirements.