Home / Business Scene / Telecom Operators Recommended to Encrypt Personal Data

Telecom Operators Recommended to Encrypt Personal Data

The European Commission will introduce new rules regarding what exactly telecommunications operators and internet service providers (ISPs) should do if their clients’ personal data is stolen, lost, or otherwise compromised.

The purpose of these ‘technical implementation measures’ is to ensure that all clients receive equal treatment throughout the EU and that all companies can address these issues on a pan-European basis if they operate in multiple countries. Telecom operators and ISPs possess a wide range of data about their clients, such as addresses, names, bank account details, as well as data about the websites they have visited and the calls they have made. According to a general obligation from 2011, these companies are required to notify national authorities and subscribers about the loss of personal data (IP/11/622). Thanks to this regulation, companies have received additional clarifications on how to fulfill these obligations, and clients will have additional assurance that their problem will be resolved.

Company Responsibilities Companies must notify the competent national authorities about the incident within 24 hours of noticing the data loss to maximize their protection. If it is not possible to provide all information within that period, companies should provide an initial amount of information during that time, and the remainder within three days. They must also explain which data has been affected and what measures the company has taken or will take.

In assessing the need to notify subscribers (by applying a test to determine whether the data loss will negatively affect personal data and privacy), companies should pay attention to the type of compromised data, particularly in the context of the telecommunications sector, financial information, location data, internet traffic records, email data, and items of phone calls, and use a standardized format (for example, the same online form for all member states) to notify the competent national authorities.

Technological Protection The Commission also wants to encourage companies to encrypt personal data and will therefore publish an indicative list of technological protection measures such as encryption techniques that would render the data unusable to anyone without authorization to view it. A company that would use such techniques and be a victim of data theft or loss would be exempt from the burden of notifying subscribers because such data would be unusable.

After a public consultation in 2011, the Commission decided to implement these rules with broad support from many stakeholders for a harmonized approach in this area. The rules were agreed upon by a committee of member states and reviewed by the European Parliament and the Council. Since this is a regulation, there is no need for incorporation into national legislation, and it will come into force two months after publication in the official EU gazette.