The EU’s ‘cyber security’ agency ENISA has issued a report on data breach notifications in the EU.  The report is in response to the 2009 amendments to the ePrivacy Directive requiring telecom and Internet service providers to issue notifications for personal data breaches, which Member States must transpose into national legislation by May 2011. 

The ENISA report reviews best practices in countries where data breaches already are required or are expected to be notified (e.g., Germany, Spain and Ireland), highlights concerns of providers and regulatory authorities regarding the new EU-wide mandatory notification regime, and identifies areas where further EU level or local guidance is needed. 

ENISA’s report is based on surveys and interviews that the agency conducted with various stakeholders last year.  It indicates that telecoms and internet service providers want to be able to categorize breaches according to specific risk levels in order to prevent “notice fatigue,” and are concerned that notification requirements will negatively impact their brands unless they maintain control over communications with relevant data subjects.  National regulatory authorities are also reported to support a system that prioritizes notifications, as many are concerned about whether they will have adequate resources and technical expertise to handle mandatory notifications.  Authorities also call for sufficient sanctioning powers to incentivize data controllers to comply with the regulations.             

In terms of next steps, the report identifies several areas where further EU and/or local level technical and procedural guidance is required, including criteria to measure risk to data subjects and to determine the threshold for notifying, and on how and when authorities and data subjects should receive notifications. 

If Member States take diverging approaches in these and other areas, the compliance burden for providers that operate across the Union could be heavy, and Europe could find itself lumbered with another set of unharmonised and potentially inconsistent laws.  ENISA’s report is especially timely given that the European Commission currently is considering introducing a generally-applicable breach notification regime as part of its consultation on the Union’s data protection framework. 

ENISA will be holding a one day workshop on January 24 to present the results of the report and to provide a forum for exchanging ideas on the way forward.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Mark Young Mark Young

Mark Young is an experienced tech regulatory lawyer and a vice-chair of Covington’s Data Privacy and Cybersecurity Practice Group. He advises major global companies on their most challenging data privacy compliance matters and investigations. Mark also leads on EMEA cybersecurity matters at the…

Mark Young is an experienced tech regulatory lawyer and a vice-chair of Covington’s Data Privacy and Cybersecurity Practice Group. He advises major global companies on their most challenging data privacy compliance matters and investigations. Mark also leads on EMEA cybersecurity matters at the firm. In these contexts, he has worked closely with some of the world’s leading technology and life sciences companies and other multinationals.

Mark has been recognized for several years in Chambers UK as “a trusted adviser – practical, results-oriented and an expert in the field;” “fast, thorough and responsive;” “extremely pragmatic in advice on risk;” “provides thoughtful, strategic guidance and is a pleasure to work with;” has “great insight into the regulators;” and “is technologically sophisticated and advises on true issues of first impression, particularly in the field of AI.”

Drawing on over 20 years of experience, Mark specializes in:

Providing practical guidance and advising on potential exposure under GDPR and international data privacy laws in relation to innovative products and services.
Handling complex regulatory investigations and enforcement actions involving data privacy regulators in the UK, EU and globally, and advising on follow-on litigation risk.
Helping clients respond to cybersecurity incidents, including ransomware, supply chain incidents, state-sponsored attacks, insider threats, personal data breaches, and IP and trade secret theft.
Advising various clients on the EU NIS2 Directive, Cyber Resilience Act (CRA), and other emerging EU, UK, and global cybersecurity laws and regulations.
Advising life sciences companies on industry-specific data privacy issues, including clinical trials, pharmacovigilance, and digital health products and services.
Advising on data privacy compliance in relation to employees and international transfers of data in connection with white collar investigations.
Providing strategic advice and advocacy on a range of UK and EU technology law reform issues relating to data privacy, cybersecurity, eIDs, and software.
Representing clients in connection with references to the Court of Justice of the EU.