Tonga Privacy Act 2025
Part III: obligations of data controllers and data processors – Tonga Privacy Act 2025

Tonga Privacy Act 2025 s37: s.37 Notify personal information breaches within 72 hours (from two years after commencement)

A processor must tell the engaging controller or processor of a breach within 72 hours of becoming aware and answer its information requests. A controller must notify the Commission within 72 hours of becoming aware of a breach likely to risk individuals' rights and freedoms (extendable for law enforcement needs or scoping, with grounds and evidence), and communicate high-risk breaches to affected data subjects without undue delay in plain language with mitigation advice (or by public communication if direct contact is disproportionate). Notices give a contact point, likely consequences and measures taken; information may be phased. Controllers and processors must keep a record of all breaches, effects and remedies. This section applies only from the second anniversary of the Act's commencement.

Maintained by Gerard Blokdyk

Other controls in Part III: obligations of data controllers and data processors – Tonga Privacy Act 2025

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.