ePrivacy Directive, Article 4(3) to (5), Personal Data Breach Notification
Directive 2002/58/EC, Art. 4(3)-(5)
In force since .
A breach notification rule binding public and private bodies.
- Obligation class
- Breach notice, Governance
As of .
What it requires
- This Directive is addressed to the Member States (Article 21), which had to adopt and publish the measures necessary to comply with Directive 2009/136/EC, the amending Directive that added the breach notification paragraphs to Article 4, by (Article 4(1) of that Directive), so a provider meets these rules through each Member State's national law.
- If you provide a publicly available electronic communications service and a personal data breach occurs, notify the breach to the competent national authority without undue delay (Article 4(3)).
- Where the breach is likely to adversely affect the personal data or privacy of a subscriber or individual, also notify that subscriber or individual of the breach without undue delay (Article 4(3)).
- You need not notify the subscriber or individual if you have demonstrated to the satisfaction of the competent authority that you implemented appropriate technological protection measures, that those measures were applied to the data concerned by the breach, and that they render the data unintelligible to any person who is not authorized to access it (Article 4(3)).
- In the notification to the subscriber or individual, describe the nature of the breach and the contact points where more information can be obtained, and recommend measures to mitigate its possible adverse effects; in the notification to the competent national authority, also describe the consequences of the breach and the measures you propose or have taken to address it (Article 4(3)).
- Maintain an inventory of personal data breaches comprising the facts surrounding each breach, its effects and the remedial action taken, sufficient to enable the competent national authorities to verify compliance with the notification duty, and include in it only the information necessary for that purpose (Article 4(4)).
If you get it wrong
Criminal exposureNo
Criminal exposure note
Article 15a(1) requires Member States to lay down rules on penalties 'including criminal sanctions where appropriate' for infringements of the national provisions adopted under the Directive, but the Directive does not itself make a failure to notify a breach a criminal offense, and whether it is prosecuted as one is a matter for each Member State's own law.
Who enforces it
Enforcement body
The competent national authority of each Member State, which Article 4(4) requires to be able to audit whether providers have complied with their notification obligations and to impose appropriate sanctions for a failure to do so, and which Article 15a(2) and (3) give the power to order the cessation of infringements and the necessary investigative powers and resources.
What this law does
Article 4(3) requires the provider of publicly available electronic communications services, in the case of a personal data breach, to notify the breach to the competent national authority without undue delay.
Article 2, point (i), defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community.
When the breach is likely to adversely affect the personal data or privacy of a subscriber or individual, Article 4(3) requires the provider also to notify that subscriber or individual of the breach without undue delay. Notification of the subscriber or individual is not required if the provider has demonstrated to the satisfaction of the competent authority that it implemented appropriate technological protection measures and that they were applied to the data concerned by the breach.
Those technological protection measures must render the data unintelligible to any person who is not authorized to access it. Article 4(3) allows the competent national authority, having considered the likely adverse effects of the breach, to require the provider to notify the subscriber or individual if the provider has not already done so.
The notification to the subscriber or individual must at least describe the nature of the breach and the contact points where more information can be obtained, and recommend measures to mitigate the possible adverse effects of the breach. The notification to the competent national authority must in addition describe the consequences of the breach and the measures proposed or taken by the provider to address it.
Article 4(4) requires providers to maintain an inventory of personal data breaches comprising the facts surrounding the breach, its effects and the remedial action taken. The inventory may include only the information necessary to enable the competent national authorities to verify compliance.
Subject to any technical implementing measures adopted under paragraph 5, Article 4(4) provides that the competent national authorities may adopt guidelines and, where necessary, issue instructions concerning the circumstances in which providers are required to notify personal data breaches, the format of the notification and the manner in which it is made.
Article 4(4) also provides that the competent national authorities must be able to audit whether providers have complied with their notification obligations and must impose appropriate sanctions in the event of a failure to do so. Article 4(5) allows the Commission to adopt technical implementing measures concerning the circumstances, format and procedures applicable to the information and notification requirements of Article 4.
Directive 2009/136/EC, which added Article 4(3) to (5), required Member States in its Article 4(1) to adopt and publish the laws, regulations and administrative provisions necessary to comply with it by . Article 15a(1) leaves penalties to the Member States, which must lay down the rules on penalties, including criminal sanctions where appropriate, and the penalties must be effective, proportionate and dissuasive.
The Commission's Digital Omnibus proposal, COM(2025) 837 of , would delete Article 4 of Directive 2002/58/EC.
When LexLint raises it
When your app profile says your app provides telecom services.