The providers referred to in Article 11.2 shall take appropriate technical and organizational measures for the safety and security of the networks and services they offer in the interest of protecting personal data and privacy of subscribers and users. Taking into account the state of the art and the cost of implementation, the measures shall ensure an appropriate level of security commensurate with the risk involved.
The measures referred to in paragraph 1 shall include, in any case:
ensure that only authorized personnel have access to personal data for legally authorized purposes,
the protection of personal data stored or transmitted against inadvertent or unauthorized storage, processing, access, disclosure, alteration, loss, destruction, and
the introduction of a security policy regarding the processing of personal data.
The providers referred to in Article 11.2 shall ensure that subscribers are informed of:
particular risks of breaching the safety or security of the offered network or service;
the means, if any, by which the risks referred to in subsection (a) can be countered, insofar as these are measures other than those which the provider is obliged to take under subsection (1), as well as an indication of the expected costs.
By or pursuant to general order in council, further obligations and restrictions may be imposed on the providers referred to in Article 11.2 in the interest of the protection of personal data and the protection of the privacy of subscribers and users for the benefit of the safety and security of the networks and services offered by them.
Regulations based on this article (delegated regulations)
No
Policies and circulars that have this article as legal authority
No
Articles or similar text referring to this article
(14-07-2020)
|
Effective date |
Retroactivity |
Subject |
Signature |
Announcement |
Chamber documents |
Signature |
Announcement |
Note |
|
modification |
2012 |
2012 |
||||||
|
modification |
2004 |
2004 |
||||||
|
new-arrangement |
1998 |
1998 |
||||||
Comments
1) The date of entry into force is set under application of Article 16 of the Temporary Referendum Act.