On 11 July 2023, the Authority for Data and Artificial Intelligence published the draft Implementing Regulation of the Personal Data Protection Law (PDPL) and opened a public consultation until 31 July 2023. The draft stipulates that data controllers must implement comprehensive security measures to safeguard personal data and privacy. In the event of a data breach, the controller is obliged to notify the authority within 72 hours, providing a detailed account of the incident and the corrective measures that have been or will be taken. Furthermore, data controllers are required to notify affected data subjects if a breach may cause damage to their data or conflict with their rights or interests.
Original source