Retained EU Law 2013 United Kingdom

Commission Regulation (EU) No 611/2013 of 24 June 2013 on the measures applicable to the notification of personal data breaches under Directive 2002/58/EC of the European Parliament and of the Council on privacy and electronic communications

At a glance

What's here

3 compliance obligations

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

s.art002

Notification to the Information Commissioner

  • Notify ICO of personal data breaches within 72 hours
s.art003

Notification to the subscriber or individual

  • Notify subscribers and individuals of personal data breaches likely to cause harm
s.art005

Use of another provider

  • Immediately notify the contracting provider of a personal data breach
Browse 5 other sections — procedural / definitional / commencement
uri:annex/ii/division/9

uri:annex/ii/division/9

s.art001

Scope

s.art004

Technological protection measures

s.art006

Reporting and review

s.art007

Entry into force

Explore more

Browse legislation

Find other UK business legislation with related guidance.