4.5.1 Framework Directive
Directive 2002/21/EC on a common regulatory framework for electronic communications networks and services (Framework Directive), as amended by Directive 2009/140/EC and Regulation 544/2009, deals with data breach notifications in its Article 13, which states that
"Member States shall ensure that undertakings providing public communications networks or publicly available electronic communications services notify the competent national regulatory authority of a breach of security or loss of integrity that has had a significant impact on the operation of networks or services.
Where appropriate, the national regulatory authority concerned shall inform the national regulatory authorities in other Member States and the European Network and Information Security Agency (ENISA). The national regulatory authority concerned may inform the public or require the undertakings to do so, where it determines that disclosure of the breach is in the public interest.
Once a year, the national regulatory authority concerned shall submit a summary report to the Commission and ENISA on the notifications received and the action taken in accordance with this paragraph".
Article 2 provides some definitions that are adopted in other directives as well, such as the ePrivacy Directive. For clarity and convenience the most relevant ones are reported below:
'Electronic communications network' means transmission systems and, where applicable, switching or routing equipment and other resources, including network elements which are not active, which permit the conveyance of signals by wire, radio, optical or other electromagnetic means, including satellite networks, fixed (circuit and packet-switched, including Internet) and mobile terrestrial networks, electricity cable systems, to the extent that they are used for the purpose of transmitting signals, networks used for radio and television broadcasting, and cable television networks, irrespective of the type of information conveyed;
'Electronic communications service' means a service normally provided for remuneration which consists wholly or mainly in the conveyance of signals on electronic communications networks, including telecommunications services and transmission services in networks used for broadcasting, but excludes services providing, or exercising editorial control over, content transmitted using electronic communications networks and services; it does not include information society services, as defined in Article 1of Directive 98/34/EC, which do not consist wholly or mainly in the conveyance of signals on electronic communications networks;
'Public communications network' means an electronic communications network used wholly or mainly for the provision of electronic communications services available to the public which support the transfer of information between network termination points.
Download the preliminary release of the Cloud Accountability Reference Architecture and the relevant A4Cloud Toolkit.