nerdexam
IAPP

CIPP-E · Question #81

Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?

The correct answer is D. A mandatory notification for personal data breaches applicable to electronic communication. The e-Privacy Directive 2002/58/EC, also known as the Directive on privacy and electronic communications, is a specific directive that complements and particularises the GDPR for the electronic communications sector. It was amended in 2009 by the Directive 2009/136/EC, which…

Legislative Framework

Question

Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?

Options

  • AA voluntary notification for personal data breaches applicable to all data controllers.
  • BA voluntary notification for personal data breaches applicable to electronic communication
  • CA mandatory notification for personal data breaches applicable to all data controllers.
  • DA mandatory notification for personal data breaches applicable to electronic communication

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    88% (29)

Explanation

The e-Privacy Directive 2002/58/EC, also known as the Directive on privacy and electronic communications, is a specific directive that complements and particularises the GDPR for the electronic communications sector. It was amended in 2009 by the Directive 2009/136/EC, which introduced several changes to enhance the protection of personal data and privacy in the electronic communications sector. One of these changes was the introduction of a mandatory notification for personal data breaches applicable to providers of publicly available electronic communications services, such as telecom providers and internet service providers. According to Article 4 of the amended e-Privacy Directive, these providers must notify the competent national authority of any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community. The notification must be made without undue delay and, where feasible, not later than 24 hours after the provider has become aware of the breach. The notification must include information such as the nature and content of the personal data concerned, the circumstances and consequences of the breach, and the measures taken or proposed by the provider to address the breach. The provider must also notify the affected data subjects of the breach, unless the provider has demonstrated to the satisfaction of the competent authority that it has implemented appropriate technological protection measures that render the data unintelligible to any person who is not authorised to access it. The notification to the data subjects must describe the nature of the breach and the contact points where more information can be obtained, and must recommend measures to mitigate the possible adverse effects of the breach. The purpose of this mandatory notification is to ensure that the authorities and the data subjects are informed of the risks and the remedies related to the breach, and to encourage the providers to improve their security measures and prevent further breaches.

Topics

#e-Privacy Directive#data breach notification#electronic communications#2009 amendments

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice