German Ministry Publishes Draft Law for Cybersecurity Breach Notification
Time 1 Minute Read

On March 5, 2013, the German Federal Ministry of the Interior published proposed amendments (in German) to the German Federal Office for Information Security Law. These proposed amendments are significant because they establish a new duty to notify the German Federal Office for Information Security in the event of a cybersecurity breach.

The proposed amendments apply only to operators of critical infrastructure in the energy, IT and telecommunications, transport and traffic, health, water, food, finance and insurance sectors. These operators, which will be specifically identified in secondary legislation, would be required to immediately inform the German Federal Office for Information Security in the event their IT systems, components or processes suffer a significant adverse impact caused by a cybersecurity breach.

Other proposed amendments to the German Federal Office for Information Security Law seek to embed IT security obligations into German online privacy and telecommunications laws.

The German proposal is similar to the notification requirement described in the European Commission’s cybersecurity strategy and draft network and information security directive. At this stage, the German federal government still needs to agree to the proposal before it is sent on to the German Parliament for further discussion and an eventual vote.

You May Also Be Interested In

Time 2 Minute Read

On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit held that the 2024 amendment to Illinois’ Biometric Information Privacy Act, limiting damages, applies retroactively to pending cases.

Time 1 Minute Read

As reported on the Hunton Employment & Labor Perspectives blog, SB 574 is a California bill that would set specific duties for attorneys who use generative artificial intelligence and would restrict how arbitrators may use such tools in decision-making.

Time 3 Minute Read

SB 574 is a California bill that would set specific duties for attorneys who use generative artificial intelligence and would restrict how arbitrators may use such tools in decision-making. It would amend provisions in the Business and Professions Code and the Code of Civil Procedure to address confidentiality, accuracy, bias, and citation verification for attorneys, and to prohibit delegation of arbitral decision-making to AI while adding disclosure and responsibility requirements for arbitrators.

Time 2 Minute Read

On March 3, 2026, the European Commission published draft guidelines intended to clarify the application of the Cyber Resilience Act and opened a public consultation to gather feedback from stakeholders.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page