Regulation 6
Notification to affected individuals
of Personal Data Protection (Notification of Data Breaches) Regulations 2021
For the purposes of section 26D(3) of the Act, the notification by an organisation to an affected individual affected by a notifiable data breach under section 26D(2) of the Act must contain all of the following information:
the circumstances in which the organisation first became aware that the notifiable data breach had occurred;
the personal data or classes of personal data relating to the affected individual affected by the notifiable data breach;
the potential harm to the affected individual as a result of the notifiable data breach;
information on any action by the organisation, whether taken before or to be taken after the organisation notifies the affected individual —
to eliminate or mitigate any potential harm to the affected individual as a result of the notifiable data breach; and
to address or remedy any failure or shortcoming that the organisation believes to have caused, or enabled or facilitated the occurrence of, the notifiable data breach;
the steps that the affected individual may take to eliminate or mitigate any potential harm as a result of the notifiable data breach, including preventing the misuse of the affected individual’s personal data affected by the notifiable data breach;
the business contact information of at least one authorised representative of the organisation.