UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP
The UK government continues to progress amend - ments to the CMA, as commentators have long stated that the CMA has failed to keep pace with the cyber - security landscape. Commentators highlight issues with the ambiguity around the meaning of “authorisa - tion” and its subsequent impact on cybersecurity pro - fessionals, as well as issues with the current jurisdic - tional scope of the CMA, given the international nature of many cybersecurity incidents. In November 2023, the UK government published responses to a con - sultation on proposed CMA reforms, noting that work will continue on engagement with private and public sector organisations to understand further impacts and mitigations in this area before it is considered for legislation. In December 2025, the UK government confirmed plans to amend the CMA by introducing a statutory defence for cybersecurity professionals conducting legitimate vulnerability research. PECR and CA 2003 Regulation 5 (1A) of the PECR requires service pro - viders to: • restrict access to personal data to only authorised personnel for legally authorised purposes; • protect personal data against “accidental or unlaw - ful destruction, accidental loss or alteration, and unauthorised or unlawful storage, processing, access or disclosure”; and • implement a security policy with regard to the pro - cessing of personal data. Service providers are also required to retain a log of personal data breaches under Regulation 5A(8) of the PECR. Guidance on Security Requirements published by Ofcom in relation to the CA 2003 states that it is nec - essary to establish “clear lines of accountability, up to and including board or company director level, and sufficient technical capability to ensure that poten - tial risks are identified and appropriately managed”. The guidance further states that “a level of internal security expertise, capacity, and appropriate account - ability mechanisms, sufficient to provide proper man - agement of (security risks)” must be maintained. The guidance also references the following:
• the importance of internal risk assessments; • the need for sufficient oversight of networks and services to enable fast identification of significant security incidents; • a requirement to put in place security measures that exceed those in the Cyber Essentials scheme; and • the importance of intelligence-led vulnerability test - ing to manage cyber-risks. Regulation 2 (1) of the PECR defines a “personal data breach” as a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of – or access to – personal data transmitted, stored or otherwise processed in connection with the provision of a public electronic communications service. The security and breach notification requirements under Regulation 5 of the PECR apply to personal data. Under Regulation 5A(2) of the PECR, service provid - ers are required to notify the ICO of a personal data breach; such notification must be made, where fea - sible, no later than 72 hours after becoming aware of the breach. A notification to the ICO is not required where an organisation is responsible for delivering part of the service but does not have a direct con - tractual relationship with end users. In such cases, the organisation must notify the organisation that has the contractual relationship with end users and that organisation must then notify the ICO. The service pro - vider is also required to notify (without undue delay) the concerned subscriber or user where the breach is likely to adversely affect their personal data or pri - vacy, unless the service provider can demonstrate to the ICO that the data has been rendered unintelligible (eg, encrypted). The security breach notification requirements under Section 105K(1)(a) of the CA 2003 apply to public electronic communications networks and systems: network and service providers must notify Ofcom of security breaches that have a significant impact on the operation of a public electronic communica - tions network. Section 105 (A) of the CA 2003 broadly defines a “security compromise” as including “any - thing that compromises the availability, performance or functionality of the network or service”. In deter -
451 CHAMBERS.COM
Powered by FlippingBook