Law / European Union

Commission Regulation on Personal Data Breach Notification by Electronic Communications Providers (Regulation (EU) No 611/2013)

Regulation (EU) No 611/2013

In force since .

A breach notification rule binding public and private bodies.

Obligation class
Breach notice

As of .

What it requires

  • If you provide a publicly available electronic communications service, notify every personal data breach to the competent national authority (Article 2(1)), no later than 24 hours after its detection, where feasible, with the information set out in Annex I; detection is deemed to have taken place when you have acquired sufficient awareness that a security incident has occurred that led to personal data being compromised (Article 2(2)).
  • Where all the information in Annex I is not available and further investigation is required, you may make an initial notification no later than 24 hours after detection containing the information in Section 1 of Annex I, and you must then make a second notification as soon as possible and at the latest within three days following the initial notification, containing the information in Section 2 of Annex I (Article 2(3)).
  • If you cannot provide all the information within the three-day period, notify as much as you have within it, submit to the competent national authority a reasoned justification for the late notification of the remaining information, and notify the remaining information as soon as possible (Article 2(3)).
  • Where the breach is likely to adversely affect the personal data or privacy of a subscriber or individual, also notify that subscriber or individual of the breach, in addition to notifying the competent national authority (Article 3(1)).
  • Assess whether the breach is likely to adversely affect a subscriber or individual by taking account of, in particular, the nature and content of the personal data (financial information, special categories of data referred to in Article 8(1) of Directive 95/46/EC, location data, internet log files, web browsing histories, e-mail data and itemized call lists), the likely consequences for the person (identity theft or fraud, physical harm, psychological distress, humiliation or damage to reputation), and the circumstances of the breach, in particular where the data has been stolen or you know it is in the possession of an unauthorized third party (Article 3(2)).
  • Notify the subscriber or individual without undue delay after detection of the breach, whether or not you have yet notified the competent national authority (Article 3(3)).
  • Include in the notification to the subscriber or individual the information set out in Annex II, express it in clear and easily understandable language, and do not use it as an opportunity to promote or advertise new or additional services (Article 3(4)).
  • Notify the subscriber or individual by means of communication that ensure prompt receipt of information and that are appropriately secured according to the state of the art, and keep the information about the breach dedicated to the breach and not associated with information about another topic (Article 3(6)).
  • In exceptional circumstances, where notifying the subscriber or individual may put at risk the proper investigation of the breach, you may delay that notification, after obtaining the agreement of the competent national authority, until the authority deems it possible to notify (Article 3(5)).
  • If you have a direct contractual relationship with the end user and, despite reasonable efforts, cannot identify within the timeframe all the individuals likely to be adversely affected, you may notify them through advertisements in major national or regional media in the relevant Member States within that timeframe, containing the Annex II information where necessary in a condensed form, and you must continue all reasonable efforts to identify and notify them as soon as possible (Article 3(7)).
  • You need not notify the subscriber or individual if you have demonstrated to the satisfaction of the competent national authority that you implemented appropriate technological protection measures, applied to the data concerned by the breach, that render the data unintelligible to any person who is not authorized to access it; data is unintelligible if it has been securely encrypted with a standardized algorithm, or replaced by its hashed value calculated with a standardized cryptographic keyed hash function, and the key has not been compromised in any security breach and cannot be ascertained by available technological means by any person who is not authorized to access the key (Article 4(1) and (2)).
  • If you are contracted to deliver part of the electronic communications service without a direct contractual relationship with subscribers, immediately inform the contracting provider in the case of a personal data breach (Article 5).

Who enforces it

Enforcement body

The competent national authority of each Member State, which receives the notifications (Regulation (EU) No 611/2013, Articles 2 and 3) and which Article 4(4) of Directive 2002/58/EC requires to be able to audit whether providers have complied with their notification obligations and to impose appropriate sanctions in the event of a failure to do so.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 1 applies the Regulation to the notification of personal data breaches by providers of publicly available electronic communications services. Article 2(1) requires the provider to notify all personal data breaches to the competent national authority.

Article 2(2) requires the provider to notify the breach to the competent national authority no later than 24 hours after its detection, where feasible, with the information set out in Annex I. Article 2(2) deems detection to have taken place when the provider has acquired sufficient awareness that a security incident has occurred that led to personal data being compromised.

Where all the information in Annex I is not available and further investigation is required, Article 2(3) permits an initial notification to the competent national authority no later than 24 hours after detection, containing the information in Section 1 of Annex I. The provider must make a second notification as soon as possible and at the latest within three days following the initial notification, containing the information in Section 2 of Annex I. A provider that cannot supply all the information within the three-day period must notify as much as it has within that period, submit a reasoned justification for the late notification of the remaining information, and notify the remaining information as soon as possible.

Article 3(1) requires the provider, when the breach is likely to adversely affect the personal data or privacy of a subscriber or individual, to notify that subscriber or individual of the breach in addition to the authority. Article 3(2) directs that the likelihood of adverse effect be assessed by taking account of the nature and content of the personal data, the likely consequences of the breach for the subscriber or individual, and the circumstances of the breach.

Article 3(3) requires the notification to the subscriber or individual to be made without undue delay after detection of the breach, whether or not the competent national authority has yet been notified. Article 3(4) requires the notification to the subscriber or individual to include the information set out in Annex II. The provider must not use that notification as an opportunity to promote or advertise new or additional services.

Article 3(5) permits the provider, in exceptional circumstances where notifying the subscriber or individual may put at risk the proper investigation of the breach, to delay that notification after obtaining the agreement of the competent national authority. Article 3(6) requires the provider to use, for the notification to the subscriber or individual, means of communication that ensure prompt receipt of information and that, according to the state of the art, are appropriately secured.

Article 4(1) dispenses with the notification to the subscriber or individual if the provider has demonstrated to the satisfaction of the competent national authority that it has implemented appropriate technological protection measures that were applied to the data concerned and that render the data unintelligible to any person who is not authorized to access it.

Article 4(2) treats data as unintelligible if it has been securely encrypted with a standardized algorithm, or replaced by its hashed value calculated with a standardized cryptographic keyed hash function, where in either case the key has not been compromised in any security breach and cannot be ascertained by available technological means by any person who is not authorized to access it.

Article 4(3) provides that the Commission may publish an indicative list of appropriate technological protection measures. Article 5 requires another provider contracted to deliver part of the service without a direct contractual relationship with subscribers to inform the contracting provider immediately in the case of a personal data breach.

The Regulation is adopted under Article 4(5) of Directive 2002/58/EC, which empowers the Commission to adopt technical implementing measures. Article 7 provides that the Regulation enters into force on and is binding in its entirety and directly applicable in all Member States.

When LexLint raises it

When your app profile says your app provides telecom services.

Back to the example  ·  Lint your app