EU wants to regulate customers data leaks processes
- Published: June 27, 2013, 4:12 p.m.
On 24th June the European Commission has released the digital agenda about new rules for cases when customers data is lost or stolen. It is based on several exist documents which were declared last decade. The rules describe what should do telecoms and Internet Service Providers (ISPs) in a situation when they recognise leaks of customers data. Also there are recommendations for preventing of such breaches, e. g. using of VPN connection.
The document leads to make equal conditions of confidential data insurance for all businesses and simple internet customers on whole EU territory. Actually it is not a low but recomendation for saving all interests.
Since 2011 telecoms and ISPs should inform national authorities and subscribers if breaches of users data is detected. Such obligation was made because many users keep a lot of personal information inside internet applications such as contact data, credit cards information, bank account credentials and so on. If even small part of such information is stolen, it can bring big troubles as for separate Internet customers as for business companies. So early informing about detected personal data leaks can prevent spreading of harmful effect.
Current rules provide ways for early informing of concerned parties. For example, company which detects personal data breach should inform the competent national authority in 24 hours after the finding. Also company should start activity to prevent further loss of personal data.
To prevent fake alerts of subscribers it is recommended to make assessing real scope of made harm and which type of data can be damaged or copied by detected actions. So if data leak is very little and isn’t relative to any confidential information then there is no sense to make notification which can really cause panic without a reason.
Another recommendation is to use standard form of notification which is used in whole EU. This can help to save time during notes creation.
For preventing compromise of data European Commission strongly recommends to use encryption of data. So even stolen encrypted information will not bring any benefit and will be useless. It is much harder to steal both data and encryption key. Also strong safety of data is provided by using VPN.
The rules were discussed with appropriate European community members and studied by European Parliament and Council. They will get force in two months after their publication in the EU Official Journal.