[eu]cite

Home› Telecommunications & Digital Services› TKG (EN)

Part 10 · Public Safety and Emergency Preparedness  ›  Division 1 · Public Safety › Section 169

Data and information security

(1) A person providing publicly available telecommunications services must, in the event of a breach of the protection of personal data, notify the Federal Network Agency and the Federal Commissioner for Data Protection and Freedom of Information of the breach without delay. Where it is to be assumed that the breach of the protection of personal data will seriously affect the rights or legitimate interests of end users or other persons, the provider of the telecommunications service must additionally notify the data subjects of this breach without delay. Notification is not required in cases where it has been demonstrated in the security concept that the personal data affected by the breach were secured by suitable technical precautions, in particular stored using an encryption procedure recognised as secure. Independently of the third sentence, the Federal Network Agency may require the provider of the telecommunications service to notify the data subjects, having regard to the likely adverse effects of the breach of the protection of personal data. In other respects, section 42(4) and section 43(4) of the Federal Data Protection Act apply correspondingly.
(2) The notification under subsection (1), first and second sentences, must contain at least: 1. the nature of the breach of the protection of personal data, 2. particulars of the contact points at which further information is available, and 3. recommendations for measures to mitigate possible adverse effects of the breach of the protection of personal data. In the notification to the Federal Network Agency and the Federal Commissioner for Data Protection and Freedom of Information, the provider of the telecommunications service must additionally set out the consequences of the breach of the protection of personal data and the measures intended or taken.
(3) Providers of telecommunications services must keep a record of breaches of the protection of personal data, containing particulars of: 1. the circumstances of the breaches, 2. the effects of the breaches, and 3. the remedial measures taken. These particulars must be sufficient to enable the Federal Network Agency and the Federal Commissioner for Data Protection and Freedom of Information to examine whether subsections (1) and (2) have been complied with. The record contains only the information necessary for this purpose and need not cover breaches more than five years in the past.
(4) Where the provider of the telecommunications service under subsection (1), first sentence, becomes aware of disruptions originating from users' data-processing systems, it must notify the users of this without delay, insofar as they are already known to it. Insofar as technically possible and reasonable, it must inform the users of reasonable, effective, and accessible technical means by which they can identify and remove these disruptions. The provider of the telecommunications service may redirect the parts of the data traffic to and from a user from which a disruption originates, insofar as this is necessary in order to be able to notify the user of the disruptions.
(5) Where the provider of the telecommunications service under subsection (1), first sentence, is informed by the Federal Office for Information Security of concrete significant dangers originating from, or affecting, users' data-processing systems, it must notify the affected users of this without delay, insofar as they are known to it. Insofar as technically possible and reasonable, it must inform the users of reasonable, effective, and accessible technical means by which they can identify these dangers and take precautions against them. Where the provider of the telecommunications service under subsection (1), first sentence, becomes aware of dangers originating from, or affecting, users' data-processing systems, it may notify the users of this, insofar as they are known to it. Insofar as technically possible and reasonable, it may inform the users of reasonable, effective, and accessible technical means by which they can identify these dangers and take precautions against them.
(6) In the event of a disruption, the provider of the telecommunications service may restrict, redirect, or prevent use of the telecommunications service until the disruption ends, insofar as this is necessary to remove or prevent the impairment of the telecommunications and data-processing systems of the provider of the telecommunications service, of a user within the meaning of subsection (4), or of other users, and the user does not itself remove the disruption without delay, or it is to be expected that the user will not itself remove the disruption without delay.
(7) The provider of the telecommunications service may restrict, redirect, or prevent data traffic to and from sources of disruption, insofar as this is necessary to avoid disruptions in the telecommunications and data-processing systems of the users.
(8) Subject to technical implementing measures adopted by the Commission under Article 4(5) of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37; L 241, 10.9.2013, p. 9; L 162, 23.6.2017, p. 56), as last amended by Directive 2009/136/EC (OJ L 337, 18.12.2009, p. 11), the Federal Network Agency may issue guidelines on the format, procedure, and circumstances in which notification of a breach of the protection of personal data is required.

←→ also move between sections