Security Requirements and Breach Notification
Jump to
Security Requirements and Breach Notification Start Comparison
Do data privacy laws or regulations impose obligations to maintain information security controls to protect personal data from unauthorized access or processing?

Last review date: 31 December 2024

Yes.

         general obligation to take appropriate / reasonable technical, physical and/or organizational security measures

         requirement to undertake third party due diligence (security assessment of third party providers)

Do other laws or regulations impose obligations to protect systems from cyberattack?

Last review date: 31 December 2024

         public company obligations

         network information security requirements (broader than telecommunications)

         financial services requirements

         telecommunication requirements

         providers of critical infrastructure

         digital or connected (IoT) products

         other

Requirements on public authorities/government entities and providers of critical national infrastructure under NCA’s cybersecurity controls.

Has there been regulatory activity – including enforcement action, investigations, regulatory guidance or other public statements by the regulator – relating to cybersecurity by the following regulators in the last 12 months?

Last review date: 31 December 2024

         Data privacy

         network information security

         financial services

         telecommunications

         critical infrastructure

Limited public enforcement actions, but significant developments in terms of new regulation and guidance.

Does data privacy or cybersecurity law impose obligations to make notifications about personal data security breaches?

Last review date: 31 December 2024

Yes. The PDPL contains data breach reporting obligations.

Controllers/Owners have to notify:

Last review date: 31 December 2024

         data protection authorities

         cybersecurity authorities

         affected individuals

Processors/Agents have to notify:

Last review date: 31 December 2024

☒         controller/ owner

Are there any additional sector-specific or non-personal data security breach notification requirements?

Last review date: 31 December 2024

Yes.

         cybersecurity authorities

         financial services requirements

         telecommunication requirements

         providers of critical infrastructure