首页> 外文期刊>International Review of Law Computers & Technology >Don't tell them now (or at all) - responsible disclosure of security incidents under NIS Directive and GDPR
【24h】

Don't tell them now (or at all) - responsible disclosure of security incidents under NIS Directive and GDPR

机译:现在不要告诉他们(或全部) - 在NIS指令和GDPR下负责安全事件的负责披露

获取原文
获取原文并翻译 | 示例
           

摘要

In this article, we critically analyse the timeline for notifications of third parties under the NIS Directive and the GDPR in the case of security and privacy incidents from a legal and technical perspective. While a need to mitigate an immediate risk of damage for an individual would call for prompt notification of data subjects, there are scenarios which may justify a delay in communication, for instance where a service provider needs to analyse the current attack to prevent further attacks and assess the full impact. Further, we argue that notification duties in the GDPR and NISD have different protection goals which may conflict in the context of a given incident. Since they are triggered by the same incident, they may contain redundancies, which bears potential for synergies which should be capitalised by the competent authorities.
机译:在本文中,我们根据法律和技术视角的安全和隐私事件的情况下,在NIS指令和GDPR下批判分析了第三方通知的时间表。 虽然需要缓解个人损坏的直接风险将呼叫提示对数据主体的通知,有方案可以证明通信延迟,例如服务提供商需要分析当前攻击以防止进一步攻击和 评估完全影响。 此外,我们认为GDPR和NISD中的通知职责具有不同的保护目标,可能在给定事件的背景下冲突。 由于它们被同一事件引发,因此他们可能包含冗余,这持有应由主管当局资本化的协同作用的潜力。

著录项

相似文献

  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号