GDPR and ePrivacy interplay, October 2020
Abstract: Data breach notifications were firstly introduced in 2009 by means of amendments to the E-Privacy Directive, where such data breaches occurred in connection with the provision of publicly available electronic communications service. Further on, GDPR extended data breach notification obligation to all industries. The initial scope was to have a single notification regime, as E-Privacy Directive was intended to be replaced by E-Privacy Regulation, whenGDPR became applicable. SinceE-Privacy Regulation has a long way until enteringinto force, an electronic communications provider has difficulties in navigating through two regulatory regimes when it comes todata breach notifications.