the former. In any event, an employer should not have access to an employee’s
private communications. As a rule, tracking websites visited by employees is not
allowed. Nevertheless, the employee’s activity in electronic social networks may be
used to justify dismissals, insofar as the information at stake is publicly
accessible.
114
3.1.5 Security Obligations and Data Breach Notifications Concerning
Data Processed by Electronic Means
The GDPR has also introduced stricter provisions regarding the notification of
security and data breaches. According to these provisions, the data controller and
the data processor are obliged to implement technical and organizational measures,
such as encryption, in order to ensure a level of security that is appropriate to the
risks inherent to the processing. The obligation to implement security measures was
already provided for in the Directive 95/46/EC.
115 The main novelty lies in the
provisions on data breach contained in the GPDR.
Data breach is defined in a very broad sense and there are specific obligations on
data controllers to notify a personal data breach to the supervisory authority and,
under certain circumstances, to the data subject.
116
In the United States, neither of these two topics, i.e., security obligations and data
breach notification obligations are regulated in a general federal law, despite efforts
to pass federal legislation in this respect. Security provisions and notification
obligations are therefore disseminated in various sector-specific legislative enactments. Notification provisions usually require the implementation of a notification
policy, including procedures for incident reporting, incident handling and data
breach notification requirements.
117
In the remaining legal systems, solutions differ. In certain countries, such as
Japan although there are provisions on security measures, there is no general
obligation to notify an authority or data subject of a data breach.
118 However, certain
practices have been implemented and guidelines were adopted in this respect.
119 In
Canada, there are data breach notification provisions.
120
It is expected that in the coming years more and more countries will implement
security obligations, as well as data breach notification obligations. This is a trend
that has started at the beginning of the twenty-first century and that has been steadily
114 See, for example, the French National Report, Sect. 2.
115 See the European Union Special Report, Sect. 2.5.
116 See the European Union Special Report, Sect. 2.5.
117 See the United States of America’s National Report, Sect. 2.7.
118 Except for the My Number Act, which set forth the obligation to report data breaches, for certain
relevant institutions. See the Japanese National Report, Sect. 3.1.5.
119 See the Japanese National Report, Sect. 3.1.5.
120 See the Canadian National Report, Sect. 2.5.
Data Protection in the Internet: General Report
23
private communications. As a rule, tracking websites visited by employees is not
allowed. Nevertheless, the employee’s activity in electronic social networks may be
used to justify dismissals, insofar as the information at stake is publicly
accessible.
114
3.1.5 Security Obligations and Data Breach Notifications Concerning
Data Processed by Electronic Means
The GDPR has also introduced stricter provisions regarding the notification of
security and data breaches. According to these provisions, the data controller and
the data processor are obliged to implement technical and organizational measures,
such as encryption, in order to ensure a level of security that is appropriate to the
risks inherent to the processing. The obligation to implement security measures was
already provided for in the Directive 95/46/EC.
115 The main novelty lies in the
provisions on data breach contained in the GPDR.
Data breach is defined in a very broad sense and there are specific obligations on
data controllers to notify a personal data breach to the supervisory authority and,
under certain circumstances, to the data subject.
116
In the United States, neither of these two topics, i.e., security obligations and data
breach notification obligations are regulated in a general federal law, despite efforts
to pass federal legislation in this respect. Security provisions and notification
obligations are therefore disseminated in various sector-specific legislative enactments. Notification provisions usually require the implementation of a notification
policy, including procedures for incident reporting, incident handling and data
breach notification requirements.
117
In the remaining legal systems, solutions differ. In certain countries, such as
Japan although there are provisions on security measures, there is no general
obligation to notify an authority or data subject of a data breach.
118 However, certain
practices have been implemented and guidelines were adopted in this respect.
119 In
Canada, there are data breach notification provisions.
120
It is expected that in the coming years more and more countries will implement
security obligations, as well as data breach notification obligations. This is a trend
that has started at the beginning of the twenty-first century and that has been steadily
114 See, for example, the French National Report, Sect. 2.
115 See the European Union Special Report, Sect. 2.5.
116 See the European Union Special Report, Sect. 2.5.
117 See the United States of America’s National Report, Sect. 2.7.
118 Except for the My Number Act, which set forth the obligation to report data breaches, for certain
relevant institutions. See the Japanese National Report, Sect. 3.1.5.
119 See the Japanese National Report, Sect. 3.1.5.
120 See the Canadian National Report, Sect. 2.5.
Data Protection in the Internet: General Report
23
