Retained EU Law SI 2013/611 United Kingdom

Commission Regulation (EU) No 611/2013 of 24 June 2013 on the measures applicable to the notification of personal data breaches under Directive 2002/58/EC of the European Parliament and of the Council on privacy and electronic communications

Status
In Force
Penalty ceiling
Regulated

Does it bind you?

Business-side roles with duties under this instrument.

Data Controller2 Data Processor1

Other Acts binding the same actors

If a role above is yours, these are the other instruments that most often bind it.

Data Controller — also bound by 35 other Acts
Data Processor — also bound by 20 other Acts

What it requires

Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.

s.art002 Notification to the Information Commissioner Regulated
  • Notify ICO of personal data breaches within 72 hoursData Controller
s.art003 Notification to the subscriber or individual Regulated
  • Notify subscribers and individuals of personal data breaches likely to cause harmData Controller
s.art005 Use of another provider Regulated
  • Immediately notify the contracting provider of a personal data breachData Processor
5 other provisions — procedural and definitional
uri:annex/ii/division/9 uri:annex/ii/division/9
s.art001 Scope
s.art004 Technological protection measures
s.art006 Reporting and review
s.art007 Entry into force

Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.