Dutch Legislation

Article 11.3

in force

Protection of personal data and privacy

Telecommunications Act · Chapter 11 · In force since 2012-06-05

Source
1.

The providers referred to in Article 11.2 shall, in the interest of the protection of personal data and the protection of the privacy of subscribers and users, take appropriate technical and organisational measures for the security and safety of the networks and services offered by them. Taking into account the state of the art and the costs of implementation, the measures shall guarantee a level of security appropriate to the risk concerned.

2.

The measures referred to in the first paragraph shall in any event include:

a.

ensure that only authorised personnel have access to personal data for legally permitted purposes,

b.

the protection of stored or transmitted personal data against unintended or unauthorised storage, processing, access, disclosure, alteration, loss, destruction, and

c.

the implementation of a security policy regarding the processing of personal data.

3.

The providers referred to in Article 11.2 shall ensure that subscribers are informed about:

a.

specific risks to the breach of the safety or security of the offered network or the offered service;

b.

any means by which the risks referred to under (a) may be mitigated, insofar as these concern measures other than those which the provider is obliged to take pursuant to the first paragraph, as well as an indication of the expected costs.

4.

By or pursuant to an Order in Council, further obligations and restrictions may be imposed upon the providers referred to in Article 11.2, in the interest of the protection of personal data and the protection of the privacy of subscribers and users, for the benefit of the safety and security of the networks and services offered by them.

1.

De in artikel 11.2 bedoelde aanbieders treffen in het belang van de bescherming van persoonsgegevens en de bescherming van de persoonlijke levenssfeer van abonnees en gebruikers passende technische en organisatorische maatregelen ten behoeve van de veiligheid en beveiliging van de door hen aangeboden netwerken en diensten. De maatregelen garanderen, rekening houdend met de stand van de techniek en de kosten van de tenuitvoerlegging, een passend beveiligingsniveau dat in verhouding staat tot het desbetreffende risico.

2.

De maatregelen als bedoeld in het eerste lid omvatten in elk geval:

a.

waarborgen dat slechts daartoe gemachtigd personeel voor wettelijk toegestane doeleinden toegang heeft tot de persoonsgegevens,

b.

de bescherming van opgeslagen of verzonden persoonsgegevens tegen onbedoelde of niet toegestane opslag, verwerking, toegang, verstrekking, wijziging, verlies, vernietiging, en

c.

de invoering van een veiligheidsbeleid met betrekking tot de verwerking van persoonsgegevens.

3.

De in artikel 11.2 bedoelde aanbieders dragen er zorg voor dat de abonnees worden geïnformeerd over:

a.

bijzondere risico's voor de doorbreking van de veiligheid of de beveiliging van het aangeboden netwerk of de aangeboden dienst;

b.

de eventuele middelen waarmee de onder a bedoelde risico's kunnen worden tegengegaan, voor zover het andere maatregelen betreft dan die welke de aanbieder op grond van het eerste lid gehouden is te treffen, alsmede een indicatie van de verwachte kosten.

4.

Bij of krachtens algemene maatregel van bestuur kunnen de in artikel 11.2 bedoelde aanbieders in het belang van de bescherming van persoonsgegevens en de bescherming van de persoonlijke levenssfeer van abonnees en gebruikers nadere verplichtingen en beperkingen worden opgelegd ten behoeve van de veiligheid en beveiliging van de door hen aangeboden netwerken en diensten.