Breach notification
Loi n°007/PR/2015, obligation de notification des violations de données à l'ANSICE
Loi n°007/PR/2015 du 10 février 2015, art. 61Loi n°007/PR/2015 du 10 février 2015, official text archived from the telecommunications and digital-economy regulator ARCEP's website
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 4, 2020. Publisher's page: https://arcep.td/sites/default/files/Loi-N%C2%B007-PR-2015.pdfIn force since 10 February 2015. Binds public and private bodies.
What this law does
Article 61 requires the controller, or its subcontractor, to notify both ANSICE and the affected data subject, without delay, of any security breach affecting that person's personal data.
This duty sits alongside article 59's confidentiality obligation and article 60's list of required technical and organizational security measures against alteration, damage, or unauthorized third-party access, and a controller or subcontractor who fails to meet the article 59 through 61 obligations is separately subject to criminal penalty.
What it requires