with Subsections 4 and 5. An implementing legal regulation may lay down more detailed
conditions under which an undertaking providing a publicly available electronic communications service is obliged to notify any breach of personal data protection, the format of such
a notification and the manner in which the notification is to be made.
Concerning the personal data breach reporting, electronic communication services were until recently the only area, where such obligation was established on the
European harmonized level. Since May 2018 it was complemented by general
mandatory personal data breach notification and communication obligations
contained in Articles 33 and 34 of the GDPR respectively. Pursuant to these provisions, the data controller shall notify the personal data breach to the competent data
protection authority without undue delay and, where feasible, not later than 72 h after
having become aware of it.
However, as the specific notification obligation for undertakings providing publicly available electronic communications service pursuant to Section 88 of the
Electronic Communications Act lays down stricter requirements than the general
personal data breach notification obligation pursuant to Article 33 of the GDPR, and
as the supervisory authority to which such notification shall be made is in the Czech
Republic in both cases the Office for Personal Data Protection, the specific notification obligation absorbs the general notification obligation with regard to these
specifically obliged undertakings.
The similarity between the concept of personal data breach notification for the
electronic communication sector and the general personal data breach notification
contained in the GDPR can be mostly traced to the fact, that the specific provisions
for the electronic communication sector presented a template later adapted during the
preparation of the GDPR.
To complete the description of relevant notification obligations of entities operating in the electronic communications sector, the duty to inform about cyber
security incidents pursuant to Act No. 181/2014 Sb., on Cybersecurity (Act on
Cybersecurity) shall be shortly introduced. The obligations relevant to operators of
electronic communications pursuant to the Act on Cybersecurity depend on their
classification. Such entity may either be a controller or operator of communication
system included in the critical information infrastructure
22 (Section 3 lit. d) of the
Act on Cybersecurity); or, in case that the Section 3 lit. d) is not applicable, an entity
securing an important network
23 (Section 3 lit. b) of the Act on Cybersecurity); or a
provider of electronic communications service or an entity securing a network for
22 Pursuant to Section 2 lit. b) of the Act on Cybersecurity, “critical information infrastructure” is to
be perceived as an element or system of elements of the critical infrastructure in the communication
and information systems sector in the field of cybernetic security (as classified pursuant to the
Section 2 of the Act No. 240/2000 Sb., on Crisis Management and Amendment of Certain Acts in in
the Governmental Regulation No. 432/2010 Sb., on Criteria for Classification of an Element of the
Critical Infrastructure).
23 Pursuant to Section 2 lit. h) of the Act on Cybersecurity, “important network” means an electronic
communications network securing a direct connection of the public communication networks with
abroad or securing direct connection to the critical information infrastructure.
134
R. Polčák et al.
conditions under which an undertaking providing a publicly available electronic communications service is obliged to notify any breach of personal data protection, the format of such
a notification and the manner in which the notification is to be made.
Concerning the personal data breach reporting, electronic communication services were until recently the only area, where such obligation was established on the
European harmonized level. Since May 2018 it was complemented by general
mandatory personal data breach notification and communication obligations
contained in Articles 33 and 34 of the GDPR respectively. Pursuant to these provisions, the data controller shall notify the personal data breach to the competent data
protection authority without undue delay and, where feasible, not later than 72 h after
having become aware of it.
However, as the specific notification obligation for undertakings providing publicly available electronic communications service pursuant to Section 88 of the
Electronic Communications Act lays down stricter requirements than the general
personal data breach notification obligation pursuant to Article 33 of the GDPR, and
as the supervisory authority to which such notification shall be made is in the Czech
Republic in both cases the Office for Personal Data Protection, the specific notification obligation absorbs the general notification obligation with regard to these
specifically obliged undertakings.
The similarity between the concept of personal data breach notification for the
electronic communication sector and the general personal data breach notification
contained in the GDPR can be mostly traced to the fact, that the specific provisions
for the electronic communication sector presented a template later adapted during the
preparation of the GDPR.
To complete the description of relevant notification obligations of entities operating in the electronic communications sector, the duty to inform about cyber
security incidents pursuant to Act No. 181/2014 Sb., on Cybersecurity (Act on
Cybersecurity) shall be shortly introduced. The obligations relevant to operators of
electronic communications pursuant to the Act on Cybersecurity depend on their
classification. Such entity may either be a controller or operator of communication
system included in the critical information infrastructure
22 (Section 3 lit. d) of the
Act on Cybersecurity); or, in case that the Section 3 lit. d) is not applicable, an entity
securing an important network
23 (Section 3 lit. b) of the Act on Cybersecurity); or a
provider of electronic communications service or an entity securing a network for
22 Pursuant to Section 2 lit. b) of the Act on Cybersecurity, “critical information infrastructure” is to
be perceived as an element or system of elements of the critical infrastructure in the communication
and information systems sector in the field of cybernetic security (as classified pursuant to the
Section 2 of the Act No. 240/2000 Sb., on Crisis Management and Amendment of Certain Acts in in
the Governmental Regulation No. 432/2010 Sb., on Criteria for Classification of an Element of the
Critical Infrastructure).
23 Pursuant to Section 2 lit. h) of the Act on Cybersecurity, “important network” means an electronic
communications network securing a direct connection of the public communication networks with
abroad or securing direct connection to the critical information infrastructure.
134
R. Polčák et al.
