CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 19 (2013)
Prompt identification, notification, and remediation of the breach by the provider minimized the security risk and demonstrated compliance with statutory obligations under EU data protection law.
- Citation
- [2013] IEDPC 19
- Parties
- Regulator: Data Protection Commissioner; Data Controller: Unnamed Telecommunications Provider
- Jurisdiction
- Ireland
- Procedural Posture
- Data Protection Breach Notification / Post Breach Investigation and Resolution
- Outcome
- Breach resolved; no further regulatory action required.
- Legal Topics
- Personal Data Security Breach, Breach Notification, Data Controller Obligations
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
Data Protection Commissioner
Regulator
Unnamed Telecommunications Provider
Data Controller
Procedural Posture
Data Protection Breach Notification / Post Breach Investigation and Resolution
Legal Issues
- 1 Whether the telecommunications provider complied with its obligations under Commission Regulation (EU) No 611/2013 to notify the Data Protection Commissioner of a personal data security breach.
- 2 Whether the provider took appropriate remedial action to address the breach and prevent recurrence.
Ratio Decidendi
Prompt identification, notification, and remediation of the breach by the provider minimized the security risk and demonstrated compliance with statutory obligations under EU data protection law.
Court Disposition
Breach resolved; no further regulatory action required.
Orders
- Provider to notify all affected individuals.
- Provider to implement measures to prevent recurrence of similar incidents.
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment