On 29 April 2025, the proposed Bill on amending data protection law (1948-D-2025) was introduced in the Chamber of Deputies. This Bill incorporates cybersecurity regulations, requiring data controllers and processors to implement necessary technical and organisational measures to ensure personal data security and prevent security incidents. It mandates the reporting of such incidents to relevant authorities and affected individuals within 72 hours of becoming aware of the incident. If the responsible party lacks the material means to comply with this notification within the specified timeframe, they must request an extension from the authorities, providing a justified and objective reason for the need for additional time.
Original source