Personal data breaches and the 72-hour notification

When and how the Commissioner is notified, what the notice contains and when affected people are told.

The law defines a “personal data breach” as any breach of security that leads, accidentally or unlawfully, to the destruction, loss, alteration, unauthorized disclosure of or access to personal data (Article 5(2)).

Notifying the Commissioner

  • The controller notifies the Commissioner as soon as possible, and no later than 72 hours after becoming aware of the breach (Article 29(1)).
  • No notification is required where the breach is unlikely to endanger data subjects' rights and freedoms.
  • Where the deadline is missed, the controller explains the reasons for the delay to the Commissioner.
  • A processor notifies the controller immediately after becoming aware of a breach (Article 29(2)).

What the notice contains (Article 29(4))

  • The nature of the breach and, where possible, the categories and approximate number of data subjects and records affected.
  • The name and contact details of the data protection officer or another contact point.
  • The likely consequences of the breach.
  • The measures taken or proposed, including those to mitigate its effects.

Where the information cannot all be provided at once, it may be provided in phases, as soon as possible.

Informing the people affected

Where the risk to their rights and freedoms is likely to be high, the controller also informs the data subjects themselves (Article 29(3)). This is not necessary where the data was protected by measures such as encryption, where the controller has taken measures that make the risk low, or where individual notice would be a disproportionate burden and a public communication is made instead.

Article 29(3) enters into force two years after the law's publication, that is, in January 2027 (Article 101(2)). Notification of the Commissioner within 72 hours is in force now. The Commissioner may order the controller to communicate the breach to the people affected (Article 29(7)).

Documentation

The controller documents every breach, with the facts, its effects and the corrective measures, so that the Commissioner can verify compliance (Article 29(6)). This also applies to breaches that are not notified.

This guide is for information and is not legal advice. It is based on the text of Law No. 124/2024 as published by the Commissioner. Last checked on 8 October 2026. Full text of the law (PDF, in Albanian)

Let's talk about your next engagement.

Tell us about your engagement — we typically respond within one business day.

WhatsApp +355 69 522 4573