The Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (Statutory Instrument 155 of 2024) operationalise the Cyber and Data Protection Act, requiring any person or organisation that determines the purposes and means of processing personal data to obtain a data controller licence from the Data Protection Authority (POTRAZ), appoint a certified Data Protection Officer, and comply with obligations covering data security, breach notification, children's data, and codes of conduct. NANGO shares these regulations as a resource for member organisations, since licensing is tiered by the number of data subjects processed (from a minimum of 50 up to over 500,000), carries prescribed fees, and non-compliance attracts significant fines or imprisonment. Members are encouraged to review the regulations, available in full below, and to assess promptly whether their organisation is required to license as a data controller and appoint a Data Protection Officer.