PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Austria: Under pressure: data breach notification must be made within 24 hours

Posted on August 21, 2013 by pogowasright.org

Günther Leissler and Veronika Wolfbauer explain:

The European regulatory framework on electronic communications obliges providers of public electronic communications services to notify personal data breaches to their national authorities.(1) However, the European Commission recently found a lack of harmonisation among member states in this respect, and exercised its power to issue technical implementing measures on the notification obligations by publishing EU Regulation 611/2013.(2) This directly applicable and fully binding regulation will enter into force on August 25 2013.

New regulation

The new regulation applies to all providers of public electronic communication services. If a provider detects a personal data breach it must notify the competent national authority of this breach within 24 hours.(3) This can put the provider under undue pressure, as it can be hard to meet this deadline when the attending circumstances are taken into account. However, the regulation provides a loophole by stating that the notification must occur within 24 hours “where feasible”. Therefore, in cases in which a provider cannot provide all information about the incident within this timeframe, the regulation permits it to file only an initial (but still comprehensive) notification within 24 hours. Within three days of this initial notification, the provider must provide a second set of information which gives further details about the data breach.

Read more on International Law Office (free sub. required)

Category: BreachesLawsNon-U.S.

Post navigation

← ‘RIP privacy’: New Zealand govt passes NSA-style snooping bill
Fighting back: Miranda challenges his detention by the UK and seizure of his electronics →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim

RSS Recent Posts on DataBreaches.net

  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy