The European Commission will introduce new rules regarding what exactly telecommunications operators and internet service providers (ISPs) should do if their clients’ personal data is stolen, lost, or otherwise compromised.
The purpose of these ‘technical implementation measures’ is to ensure that all clients receive equal treatment throughout the EU and that all companies can address these issues on a pan-European basis if they operate in multiple countries. Telecom operators and ISPs possess a wide range of data about their clients, such as addresses, names, bank account details, as well as data about the websites they have visited and the calls they have made. According to a general obligation from 2011, these companies are required to notify national authorities and subscribers about the loss of personal data (IP/11/622). Thanks to this regulation, companies have received additional clarifications on how to fulfill these obligations, and clients will have additional assurance that their problem will be resolved.
Company Responsibilities Companies must notify the competent national authorities about the incident within 24 hours of noticing the data loss to maximize their protection. If it is not possible to provide all information within that period, companies should provide an initial amount of information during that time, and the remainder within three days. They must also explain which data has been affected and what measures the company has taken or will take.
