AI Obligation Atlas

Breach notification duties

Obligations to notify regulators or affected individuals after a data breach or security incident, usually within a statutory window.

29 jurisdictions30 laws & guidance30 binding← All obligations

Europe & Central Asia11 laws

Albania Law 124/2024

Republic of Albania

Binding

Processing of personal data in Albania or targeting Albanian data subjects by controllers and processors.

Law · In Force

Guernsey DP Law 2017

Bailiwick of Guernsey

Binding

Processing of personal data in the Bailiwick of Guernsey or by controllers established in the Bailiwick.

Law · In Force

Jersey DP Law 2018

Jersey

Binding

Processing of personal data in Jersey or by controllers established in Jersey targeting Jersey data subjects.

Law · In Force

Law No. 06/L-082 on Protection of Personal Data

Republic of Kosovo

Binding

Processing by public and private bodies in Kosovo; limited extraterritorial reach for equipment in Kosovo.

Law · In Force

Law of Georgia on Personal Data Protection

Georgia

Binding

Processing of personal data in Georgia or using technical means in Georgia; extraterritorial reach for Georgian data subjects.

Law · In Force

Law on Personal Data Protection (Official Gazette MK 42/20, 294/21)

Republic of North Macedonia

Binding

Processing of personal data in North Macedonia or targeting North Macedonian data subjects.

Law · In Force

Law on Personal Data Protection (Serbia) (Zakon o zaštiti podataka o ličnosti)

Republic of Serbia

Binding

Processing of personal data in Serbia or targeting Serbian data subjects; GDPR-aligned controller and processor obligations.

Law · In Force

Law on the Protection of Personal Data (Bosnia and Herzegovina)

Bosnia and Herzegovina

Binding

Processing of personal data in BiH or of BiH data subjects; foreign controllers must appoint local representative where required.

Law · In Force

Llei 29/2021, del 28 d'octubre, qualificada de protecció de dades personals (Andorra)

Principality of Andorra

Binding

Processing of personal data in Andorra or by controllers/processors subject to Andorran law, including extraterritorial targeting of Andorran data subjects.

Law · In Force

Monaco Law 1.565

Principality of Monaco

Binding

Processing by controllers/processors in Monaco or targeting data subjects in Monaco (GDPR-style territorial and extraterritorial scope).

Law · In Force

San Marino Law 171/2018

Republic of San Marino

Binding

Processing of personal data in San Marino or by controllers established in San Marino, including automated and filing-system processing.

Law · In Force

Asia Pacific8 laws

Act on the Protection of Personal Information (Act No. 57 of 2003)

Japan

Binding

Business operators handling personal information in Japan or providing services to individuals in Japan.

Law · In Force

Data Privacy Act of 2012 (Philippines)

Republic of the Philippines

Binding

Processing of personal information of individuals in the Philippines or by entities with a Philippine link.

Law · In Force

Data Protection Act 2025 (Kiribati)

Republic of Kiribati

Binding

Processing of personal data by controllers and processors in Kiribati — lawful basis, consent, data-subject rights, security and breach notification, data protection impact assessments, cross-border transfer standards; phased application for non–major-importance controllers.

Law · Pending

Indonesia Personal Data Protection Law (UU PDP, Law No. 27 of 2022)

Republic of Indonesia

Binding

Any controller or processor handling personal data of individuals in Indonesia, including extraterritorially.

Law · In Force

Law No. 91/2025/QH15 on Personal Data Protection (Viet Nam)

Socialist Republic of Viet Nam

Binding

Vietnamese and foreign agencies, organisations, and individuals processing personal data in Vietnam or related to Vietnamese citizens.

Law · In Force

NZ Privacy Act

New Zealand

Binding

Agencies handling personal information in connection with New Zealand operations.

Law · In Force

Personal Data Protection Act (Taiwan PDPA)

Republic of China (Taiwan)

Binding

Collection, processing, or use of personal data by government agencies or private-sector controllers targeting individuals in Taiwan, including automated decision-making and cross-border transfers.

Law · In Force

Personal Data Protection Act B.E. 2562 (2019) (Thailand)

Kingdom of Thailand

Binding

Controllers and processors handling personal data of individuals in Thailand or offering goods or services to them.

Law · In Force

Middle East & Africa7 laws

Cyber and Data Protection Act [Chapter 12:07] (Zimbabwe)

Republic of Zimbabwe

Binding

Processing of personal data in Zimbabwe; cyber and data protection obligations for digital services including AI.

Law · In Force

Data Privacy Protection Regulation (CITRA Administrative Decision No. 26/2024)

State of Kuwait

Binding

CITRA-licensed telecommunications and IT service providers collecting, processing, or storing personal data and user content in Kuwait.

Regulation · In Force

Lei n.º 133/V/2001 (Cabo Verde, as amended)

Republic of Cabo Verde

Binding

Processing of personal data in Cabo Verde or targeting Cabo Verdean data subjects.

Law · In Force

Nigeria Data Protection Act, 2023

Federal Republic of Nigeria

Binding

Data controllers and processors of personal data in Nigeria or processing personal data of Nigerians extraterritorially.

Law · In Force

Personal Data Protection and Privacy Act, 2025 (The Gambia) — not yet commenced

Republic of The Gambia

Binding

Processing of personal data in The Gambia or targeting Gambian data subjects.

Law · Pending

Royal Decree 6/2022 promulgating the Personal Data Protection Law (Oman)

Sultanate of Oman

Binding

Processing of personal data of individuals in Oman, including extraterritorial controllers offering goods or services to Omani data subjects.

Law · In Force

Rwanda DPP Law

Republic of Rwanda

Binding

Processing of personal data in Rwanda or targeting Rwandan data subjects.

Law · In Force

US Federal2 laws

Health Information Technology for Economic and Clinical Health Act (HITECH)

United States (federal)

Binding

Same covered entities and business associates as HIPAA; HITECH layered direct enforcement on business associates and increased penalties.

Law · In Force

Health Insurance Portability and Accountability Act — 45 CFR Parts 160 & 164

United States (federal)

Binding

Covered entities and their business associates that create, receive, maintain, or transmit protected health information (PHI) in the United States.

Law · In Force

Americas1 law

Data Protection Act, 2020 (Jamaica)

Jamaica

Binding

Processing of personal data in Jamaica or targeting Jamaican data subjects.

Law · In Force

Singapore1 law

Personal Data Protection Act 2012

Republic of Singapore

Binding

Organisations that collect, use, or disclose personal data in Singapore, regardless of where established.

Law · In Force

Sourced from the LegisGate™ intelligence library — our single source of truth (SSOT). Theme membership is computed deterministically from curated library text; run a LegisGate™ report to see how these obligations apply to your specific AI tool.

Talk to usWe're here to help