notification must be made without undue delay, no later than 24 h after the detection
of the personal data breach. The Regulation 611/2013 further specifies uniformly for
all EU member states in particular the circumstances to be taken into account when
assessing whether there is a likely adverse effect, which constitutes the obligation to
notify. Such circumstances are, namely, the nature and content of the personal data
concerned; the likely consequences of the breach; and the circumstances of the
breach.
The following subsections of the Section 88 of the Electronic Communications
Act contain specific rules about data breaches in accordance with the implementation
of the Directive 2002/58/EC on privacy and electronic communications:
Section 88
Securing the Protection of Personal, Traffic and Location Data and the Confidentiality of
Communications
(1) The undertaking providing publicly available electronic communications service is
obliged to:
(. . .)
c) inform the subscribers concerned about the specific risk of the disturbance of network
security in relation to data protection in accordance with Clause a) above, and if the risk is
beyond the scope of the measures taken by the undertaking providing publicly available
electronic communications service, the undertaking shall also inform the subscribers about
all the possible ways of remedying the situation, including the costs associated therewith.
(. . .)
(4) In the event a breach of security occurs concerning the personal data of a natural person,
the undertaking providing a publicly available electronic communications service is obliged
to notify the Office for Personal Data Protection of this fact without undue delay. This
notification shall contain a description of the outcome of the breach of security and the
technical protection measures the undertaking has adopted or proposes adopting.
(5) In the event the breach of security concerning a user’s personal data pursuant to
Subsection 4 above may affect the privacy of a natural person in a particularly serious
manner, or if the undertaking providing a publicly available electronic communications
service has failed to adopt measures that would remedy this situation and which would be
sufficient to protect the personal data at risk in accordance with the assessment made by the
Office for Personal Data Protection, it shall also notify the natural person concerned and the
Office for Personal Data Protection. In this notification, the undertaking shall describe the
nature of the breach of security concerning personal data, a recommendation to carry out
interventions to mitigate the impact of the breach of security concerning personal data and a
contact information site.
(6) After investigating the situation that has occurred after the breach of security pursuant to
Subsection 4, the Office for Personal Data Protection is entitled to impose on the undertaking
providing a publicly available electronic communications service an obligation to inform the
natural person affected of the breach of security regarding his data, if it has not already done
so itself.
(7) An undertaking providing a publicly available electronic communications service shall
make a summary of breaches of security concerning personal data, including information on
the circumstances of the breach, its impact and measures adopted to remedy the situation,
only for the purposes of the investigation into compliance with its obligations, in accordance
National Report: Czech Republic
133
Précédent

- 142/540

Suivant