eIDAS Regulation, Article 19a(1)(b): Notification of Security Breaches and Disruptions by Non-Qualified Trust Service Providers
Regulation (EU) No 910/2014, Article 19a(1)(b)
In force since .
A vulnerability and incident reporting rule binding public and private bodies.
- Obligation class
- Reporting, Security
As of .
What it requires
- This duty reaches you if you declare that you are an essential or important entity under Directive (EU) 2022/2555 and you are a non-qualified trust service provider, that is, you provide a trust service within the meaning of Article 3, point (16), of Regulation (EU) No 910/2014 (for example issuing certificates for electronic signatures, seals or website authentication, creating electronic timestamps, or providing electronic registered delivery) without being a qualified trust service provider. A qualified trust service provider carries the parallel duty in Article 24(2), point fb.
- Notify the supervisory body, the identifiable affected individuals, the public if it is of public interest and, where applicable, other relevant competent authorities of any security breach or disruption in the provision of the service, or in the implementation of the Article 19a(1), point (a), measures, that has a significant impact on the trust service provided or on the personal data maintained in it (Article 19a(1), point (b)).
- Make each notification without undue delay and in any case no later than 24 hours after you become aware of the security breach or disruption (Article 19a(1), point (b)).
If you get it wrong
Private right of actionYes
Penalty structure
Article 16(2) of Regulation (EU) No 910/2014 requires Member States to set the maximum administrative fine for an infringement by a qualified or non-qualified trust service provider at no less than EUR 5,000,000 where the provider is a natural person, or, where it is a legal person, no less than EUR 5,000,000 or 1 percent of the total worldwide annual turnover of the undertaking to which it belonged in the preceding financial year, whichever is higher. The figures are the floor each Member State's own law must set as its statutory maximum, not a cap the Union applies directly. Article 16(1) leaves the other penalty rules to the Member States and is without prejudice to Article 31 of Directive (EU) 2022/2555.
- Rule
- Higher of
- As of
- Currency
- EUR
- Fixed cap
- 5,000,000
- Turnover percentage cap
- 1
Who enforces it
Enforcement body
The supervisory body each Member State designates under Article 46b of Regulation (EU) No 910/2014, which takes action against non-qualified trust service providers established in its territory, by means of ex post supervisory activities, when informed that they allegedly do not meet the requirements laid down in the Regulation.
What this law does
Article 19a(1), point (b), requires a non-qualified trust service provider to notify the supervisory body, the identifiable affected individuals, the public if it is of public interest and, where applicable, other relevant competent authorities of any security breaches or disruptions that have a significant impact on the trust service provided or on the personal data maintained in it.
The notification is due without undue delay and in any case no later than 24 hours after the provider becomes aware of the security breach or disruption.
Article 3, point (16), of Regulation (EU) No 910/2014 defines a trust service as an electronic service normally provided for remuneration which consists of any of the listed activities, the first being the issuance of certificates for electronic signatures, certificates for electronic seals, certificates for website authentication or certificates for the provision of other trust services.
Qualified trust service providers carry the parallel duty in Article 24(2), point (fb), of Regulation (EU) No 910/2014. Article 2(2), point (a)(ii), of Directive (EU) 2022/2555 applies that Directive to entities of a type referred to in Annex I or II, whatever their size, where their services are provided by trust service providers. Article 3(2) of that Directive treats an entity of a type referred to in Annex I or II that does not qualify as an essential entity as an important entity.
Article 13(1) gives any natural or legal person who has suffered material or non-material damage as a result of an infringement of the Regulation by a trust service provider the right to seek compensation in accordance with Union and national law. The burden of proving the intention or negligence of a non-qualified trust service provider lies with the person claiming the damage.
Article 16(2) requires Member States to subject infringements by qualified and non-qualified trust service providers to administrative fines of a maximum of at least EUR 5,000,000 for a natural person or, for a legal person, EUR 5,000,000 or 1 percent of the total worldwide annual turnover, whichever is higher. Regulation (EU) 2024/1183 enters into force on the twentieth day following its publication in the Official Journal of the European Union.
When LexLint raises it
When your app profile says your app runs an essential service.