German Government Adopts Security Breach Notification Requirement in Telecommunications Act
Time 2 Minute Read

On March 2, 2011, the German Federal government adopted a draft law revising certain sector-specific data protection provisions in the German Telecommunications Act.  The draft law addresses the implementation of data breach notification requirements in the European e-Privacy Directive by introducing a breach notification obligation for telecommunications companies.

According to the proposal, telecommunications companies must report data breaches to the Federal Network Agency (the Bundesnetzagentur or “BNetzA”), and the Federal Commissioner for Data Protection and Freedom of Information.  In the event the rights or protected interests of subscribers or other persons are affected by the data breach, such individuals also must be notified without undue delay.  Notification is not necessary, however, if the telecommunications provider can demonstrate that it had in place a security plan to protect the potentially-affected personal data by appropriate technical means, such as encryption.  Notwithstanding this exception, the BNetzA will have the authority to require any telecommunications company to provide notification to individuals regardless of information security protections in place at the time of the breach.

The law also contains detailed content requirements for the notifications that must be sent to data subjects and the two authorities.  In addition, telecommunications companies will be required to maintain records of data breaches in accordance with specific provisions set forth in the law.

The revised data protection provisions also require providers of location-based telecommunications services to send text messages informing users whenever their mobile devices are being tracked based on location.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page