UK ICO Publishes New Breach Notification Guidance for Telecom Operators and ISPs
Time 2 Minute Read

On September 26, 2013, the UK Information Commissioner’s Office (“ICO”) published new breach notification guidance (the “Guidance”), applicable to telecom operators, Internet service providers (“ISPs”) and other public electronic communications service (“ECS”) providers.

The UK Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”) implement the revised e-Privacy Directive 2009/136/EC, and contain wide-ranging rules on marketing and advertising by telephone, fax, email and text message, as well as rules relating to cookies and security breaches. The breach notification requirements contained in the PECR apply to ECS providers (e.g., telecom providers and ISPs). In the event of a data breach, these entities must notify the ICO within 24 hours of becoming aware of the basic facts of the breach.

The Guidance sets out the breach requirements that must be provided to the ICO. A secure online form for all notifications is now available; previously service providers were expected to complete a breach notification form and email it to the ICO. The form is high-level and anticipates that notifying organizations may be awaiting further details from an internal investigation. Organizations submitting an initial breach notification form are expected to submit a second notification form containing further details of the breach within three days. If a data breach is likely to adversely affect individuals, the organization must notify those individuals “without undue delay” in addition to notifying the ICO. Data breach logs also must be maintained and submitted to the ICO on a monthly basis. The ICO provides a template log to help service providers understand what information needs to be submitted to the ICO.

The Guidance follows new technical implementing measures for data breach notification issued by the European Commission in June, which took effect in August 2013.

You May Also Be Interested In

Time 2 Minute Read

On March 25, 2026, the UK Information Commissioner’s Office and the UK Office of Communications released a joint statement addressing the intersection of online safety and data protection in relation to age assurance.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On March 3, 2026, the European Commission published draft guidelines intended to clarify the application of the Cyber Resilience Act and opened a public consultation to gather feedback from stakeholders.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page