CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 19 (2013)

CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 19 (2013)

Prompt identification, notification, and remediation of the breach by the provider minimized the security risk and demonstrated compliance with statutory obligations under EU data protection law.

Citation
[2013] IEDPC 19
Parties
Regulator: Data Protection Commissioner; Data Controller: Unnamed Telecommunications Provider
Jurisdiction
Ireland
Procedural Posture
Data Protection Breach Notification / Post Breach Investigation and Resolution
Outcome
Breach resolved; no further regulatory action required.
Legal Topics
Personal Data Security Breach, Breach Notification, Data Controller Obligations

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 1 Authorities cited 1 Party arguments 2 Amounts and remedies 1
Sign in to unlock

Parties

Data Protection Commissioner

Regulator

Unnamed Telecommunications Provider

Data Controller

Procedural Posture

Data Protection Breach Notification / Post Breach Investigation and Resolution

  1. 1 Whether the telecommunications provider complied with its obligations under Commission Regulation (EU) No 611/2013 to notify the Data Protection Commissioner of a personal data security breach.
  2. 2 Whether the provider took appropriate remedial action to address the breach and prevent recurrence.

Ratio Decidendi

Prompt identification, notification, and remediation of the breach by the provider minimized the security risk and demonstrated compliance with statutory obligations under EU data protection law.

Court Disposition

Breach resolved; no further regulatory action required.

Orders

  • Provider to notify all affected individuals.
  • Provider to implement measures to prevent recurrence of similar incidents.