First: contain, assess, document

A data breach under the nFADP is any breach of security that leads to personal data being lost, deleted, altered or disclosed to unauthorised parties — a hacked server, a lost laptop, a misdirected email, a rogue employee. The first duties are operational, not legal: stop the bleeding, preserve the evidence, and understand what happened. Isolate affected systems without destroying logs, and pull together a small response team with authority — IT, legal, management, and specialists where needed.

Then assess, honestly: what categories of data are affected, how sensitive are they, how many people are concerned, and what could realistically happen to them — fraud, identity misuse, reputational or financial harm? This assessment drives every legal duty that follows, so write it down. Documentation is not bureaucracy here; it is what allows you to show later that you assessed the risk seriously and acted on it, whichever way the notification decision went.

If a service provider processing data for you suffers the breach, it must inform you — you remain responsible for the assessment and any notifications. Check today, not during an incident, that your processor contracts say so clearly.

When the FDPIC — and the people affected — must be told

The nFADP does not require every breach to be reported. The duty to notify the Federal Data Protection and Information Commissioner (FDPIC) arises where the breach is likely to result in a high risk to the personality or fundamental rights of the persons concerned, and notification must then be made as soon as possible. Whether the threshold is met is exactly the judgement your documented assessment supports: encrypted data on a lost device is a different case from an exfiltrated customer database with identity documents.

The persons affected must be informed where that is necessary for their protection — typically where they can do something with the warning, such as changing passwords or watching for fraud — or where the FDPIC requests it. Keep in mind that other regimes can apply in parallel and can be stricter: the EU GDPR for data of EU residents, contractual notification clauses towards customers and partners, and supervisory expectations for regulated firms. Map these duties before deciding that "no notification" is the answer.

Communication discipline

Breaches are lost twice: once technically, once in the communication. The rules are simple and hard to follow under stress. One team owns the facts; one voice speaks. Say what you know, say what you do not know yet, and never speculate — early false reassurance is worse than silence and is remembered longer than the breach. Keep statements to the FDPIC, affected persons, customers and the public consistent with each other and with your written assessment. And involve counsel early, before the first external statement is drafted.

What to do now

The companies that handle breaches well decided everything in advance: an incident-response plan with named roles, processor contracts with clear notification duties, a documentation template, and a rehearsal. If you are dealing with an incident now, or want to be ready before one happens, we are glad to discuss your specific situation.