| Sec. 8(6) | In the event of a personal data breach, intimate the Data Protection Board and each affected Data Principal in the form and manner prescribed. | Incident scope resolves through the catalogue into the exact list of affected Principals, and intimations to both the Board and each Principal are generated, tracked and evidenced from that list. |
|---|
| Sec. 8(5) | Take reasonable security safeguards to prevent a personal data breach. | Safeguards are evidenced continuously before an incident rather than reconstructed after one — which is what makes the defence available when the Board asks. |
|---|
| Sec. 2(u) | A personal data breach includes unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access. | The definition is broader than exfiltration, so detection covers unauthorised internal processing and loss of access, not only external attack. |
|---|
| Sec. 28 | The Board may inquire into a breach and determine whether penalty is warranted, taking account of mitigating action taken promptly. | The full incident trail — detection, containment, remediation and intimation, each timestamped — is the record the Board weighs when assessing mitigation. |
|---|
| Sec. 33 | Penalty is determined by the nature, gravity and duration of the breach, the type of data affected, repetition, and mitigating action. | Every factor the Board weighs is a field in the incident record, so the mitigation argument is evidenced rather than narrated after the fact. |
|---|