3. The Controller shall keep a copy of the reports submitted to the Competent Authority under paragraph (1) of this article and document the corrective measures taken in relation with the Personal Data Breach, as well as any relevant documents or supporting evidence.
4. The provisions of this article do not prejudice the obligations of the Controller or Processor to submit any report or notification about Personal Data Breaches according to what is issued by the National Cybersecurity Authority or any laws and Regulations applicable in the Kingdom.






The organization must report any personal data breach to the competent authority within 72 hours of becoming aware of it if it may risk individuals’ rights or freedoms. If the breach poses a high risk, affected individuals must also be notified without undue delay.
If all details are not available within the 72-hour period, the organization must justify the delay and provide the remaining information as soon as possible. Notifications must include:
The organization must retain copies of all notifications, document corrective and preventive actions, record lessons learned, and maintain supporting evidence to demonstrate compliance. All reporting and documentation must align with requirements issued by the National Cybersecurity Authority or other applicable regulations.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)