Duty to Assess Data Breaches (s 26C)
Is this legally binding?
Binding. Binding law. It applies to everyone in scope, whether or not anyone points at it.
Where an organisation has reason to believe a data breach affecting personal data in its possession or control has occurred, it must conduct, in a reasonable and expeditious manner, an assessment of whether the breach is notifiable. Data intermediaries must notify their client organisation without undue delay.
From the source
“the organisation must conduct, in a reasonable and expeditious manner, an assessment of whether the data breach is a notifiable data breach”
s 26C
What this connects to
2 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Cited by2
- ObligationDuty to Notify Notifiable Data Breaches (s 26D)Binding
s 26D notification duty follows the s 26C assessment
- SectionPart 6A, Notification of Data BreachesBinding
Structural decomposition of the source instrument
Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.