European Commission In Favor Of Security Breach Requirements
Client Alert | 1 min read | 09.15.06
The European Commission recently announced in a public consultation concerning the review of the EU telecom regulations that it favors adopting security breach notification requirements for network operators and electronic service providers, similar to the requirements contained in laws passed by more than 30 states in the U.S. in the last two years. If the Commission proposal finds acceptance within the broader political community, it could have important consequences for the communications sector, create important compliance issues and expose the sector to adverse publicity and associated liabilities. Analogous obligations may spill over to other business sectors, particularly to businesses that process sensitive personal information, such as, for instance, the banking and insurance industry, as well as the health-care sector.
The current EU Directive 2002/58 on privacy in the electronic communication sector (the E-Privacy Directive) imposes a notification requirement upon electronic communication service providers "in case of a particular risk of a breach of the security of the network […]" (Article 4 (2) of the E-Privacy Directive, stress added). An existing Directive does not directly require such service providers to notify of [or "in the event of"] actual security breaches. The general EU Data Protection Directive 1995/46 does not contain a security breach notification obligation either, as it only sets forth only general technical and organizational security and confidentiality requirements.
The Commission believes that "a requirement to notify [individuals of] security breaches would create an incentive for providers to invest in security but without micro-managing their security policies." If the proposal becomes effective, network operators and electronic service providers will be required to: (i) notify the National Regulatory Agency (NRA) of any security breach resulting in the loss of personal data and/or that may cause the interruption of the services', and (ii) notify customers of any security breach leading to the loss, modification or destruction of, or unauthorized access to, personal customer data.
Corporations and stake-holders can participate in the public consultation until October 27, 2006 by sending their opinions or position papers to the European Commission.
Insights
Client Alert | 4 min read | 03.25.26
NAIC Intensifies AI Regulatory Focus: What Health Insurance Payors Need to Know
The National Association of Insurance Commissioners (NAIC) is intensifying its oversight of how insurers use AI — and the pace of regulatory activity shows no signs of slowing. Over the past several months, the NAIC has published a formal Issue Brief staking out its position on federal AI legislation, launched a multistate AI Evaluation Tool pilot aimed at examining insurers’ AI governance programs, and continued to expand adoption of its AI Model Bulletin across state lines. These developments continue a trend towards enhancing regulation; the NAIC adopted AI Principles in 2020 and a Model Bulletin in 2023 clarifying that existing insurance laws apply to AI systems and establishing expectations for governance, documentation, testing, and third-party oversight. That Model Bulletin has now been adopted in approximately 24 states.
Client Alert | 11 min read | 03.25.26
White House National AI Policy Framework Calls for Preempting State Laws, Protecting Children
Client Alert | 3 min read | 03.24.26
California Considering A Massive Expansion of Its Antitrust Laws
Client Alert | 2 min read | 03.23.26
