Notification of security breaches in the EU
Since then, the trend has gone global. In August, the Office of the Privacy Commissioner of
This trend is about to come to Europe too. The European data protection directives do not have any express provisions requiring companies that have suffered some sort of security breach to notify the individuals affected. The traditional thinking is that Europe does not need such a measure because there is already a well known obligation that calls for the adoption of appropriate technical and organisational measures to protect personal data against security breaches.
However, a European Commission consultation document of 2006 hinted at the prospect of security breaches notification obligations for providers of electronic communications networks and services, on the basis that network operators and ISPs, as the gatekeepers for users’ access to the online world, carry a special responsibility in this regard. This was followed by recommendations made by the Article 29 Working Party to extend those obligations to "data brokers," banks and other online service providers. The Working Party went on to say that for important breaches, all customers of the communications provider – not just those directly affected – should be informed.
The European Commission is now expected to include a formal proposal introducing mandatory security breach notifications or otherwise, into its review of the EU’s e-communications regulatory framework. Bearing in mind the experiences in other parts of the world and the latest thinking in jurisdictions like Canada and New Zealand, the risk of harm to the individual should be a determining factor in triggering notification obligations. Otherwise, the real risk is to trivialise notification obligations to such an extent that they become meaningless and ineffective in terms of data protection. In fact, the potential damage to consumers of a blanket notification obligation could be twofold: on the one hand, it can create unjustified anxieties and on the other hand, it may result in a lack of proper attention to more serious incidents.
Hopefully, the EU will benefit from other countries’ experiences in this area and adopt a balanced and realistic regime. It will be important to ensure from the outset a harmonised implementation of well-defined principles across the 27 EU countries, to avoid a patchwork of diverging laws. The ultimate purpose of security breach notification obligations should be to contribute to the protection of personal information by ensuring that consumers know when there has been a serious security leak and helping them to take prompt and effective action to avoid harm.
While there are 39 states that have some law, nearly all the states are tinkering with security breach legislation every year.
ReplyDeleteLike so much that goes through the state houses, this is constantly a moving target.
Peter, many EU states have either codified criminal code or common law to deal with such infractions. As you'll possibly be aware (or not) criminal law is not govered in the main be the central EU institutions, period. So perhaps you could go off and study the EU 27 member state and tell us which don't have security breach legislation? I think you'll find that most of them do.
ReplyDeleteAs a side note, most member states additionally have 'shields' from interference in criminal matters in relation to EU institutions, unless they fall into pillar 1. Even still certain countries are opting out.
Ronan
Peter, thanks for an interesting piece. FYI an influential UK legislative body has called for security breach legislation in the UK as a priority. An UK minister also admitted that this is "enticing" conceptually. However the complexities of establishing the correct notification triggers and appropriately balanced notification regime are likely to delay this for a while. As for linkage with EU harmonisation, the report calls for UK not to wait for an EU-led intiative.
ReplyDeleteSee chapter 5
http://www.publications.parliament.uk/pa/ld200607/ldselect/ldsctech/165/165i.pdf
好想你枣
ReplyDelete北京好想你枣
轴承
进口轴承
FAG轴承
NTN轴承
NSK轴承
SKF轴承
网站建设
网站推广
googel左侧优化
googel左侧推广
搜索引擎优化
铜米机
ReplyDelete