Hide metadata

dc.date.accessioned2013-03-12T10:15:13Z
dc.date.available2013-03-12T10:15:13Z
dc.date.issued2011en_US
dc.date.submitted2011-12-01en_US
dc.identifier.citationArguello, Victor Manuel Polit. FROM RAISING BARRIERS TO RAISING ALARMS. Masteroppgave, University of Oslo, 2011en_US
dc.identifier.urihttp://hdl.handle.net/10852/19673
dc.description.abstractABSTRACT The Directive 2009/136/EC required the implementation of a Personal data breach notifications regime. This notification is a complement to the already existing Information Security Provisions. Information Security traditional function is to prevent the unauthorized access or disclosure of personal data. As modern technology was adopted into the processing of personal data, the risks inherent to such technology threaten the personal data being processed. The responsibility was placed over the controllers and processors, but as data breaches were more commonly related to Identity theft cases, other measures were necessary to prevent the controller to remain silent if affected by a breach. California was the first jurisdiction to implement a mandatory regime of personal data breach notifications. In Europe, Spain and Germany implemented such notifications before the reforms to the E-Privacy Directive where adopted. As this date Personal Data Breach Notification Provisions are mandatory throughout the territory of the EU. These notifications have as main function to give notice to the data subjects about the occurrence of a data breach that affects or its believed have affected, their personal data. The providers of publicly available electronic communication services in the Telecommunication sector are the only controllers who are obligated to perform the notification to both the National Data Protection Authorities or to the data subjects. The present thesis reviews these provisions and analyses them in the context of the information security measures provisions. Discusses the threshold for appropriateness and develop on the traditional function that the information security had: to prevent unlawful access to or disclosure of personal information. Since the model of the notification provision resembles the one applied in California, reference to this framework will be made. Also the national provisions in Germany, Ireland, the United Kingdom and Spain will be taken as reference to compare the different approach that member states have taken to comply with the implementation of the reforms that unsaturated the notification regime. Finally, notes to consider for future reforms will be presented.  eng
dc.language.isoengen_US
dc.titleFROM RAISING BARRIERS TO RAISING ALARMS : A review of Data Breach notifications in the context of Information Security Provisionsen_US
dc.typeMaster thesisen_US
dc.date.updated2012-04-13en_US
dc.creator.authorArguello, Victor Manuel Politen_US
dc.subject.nsiVDP::340en_US
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:dissertation&rft.au=Arguello, Victor Manuel Polit&rft.title=FROM RAISING BARRIERS TO RAISING ALARMS&rft.inst=University of Oslo&rft.date=2011&rft.degree=Masteroppgaveen_US
dc.identifier.urnURN:NBN:no-30762en_US
dc.type.documentMasteroppgaveen_US
dc.identifier.duo145675en_US
dc.contributor.supervisorDr. Tobias Mahleren_US
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/19673/1/Data_Security_Breach_Notification.pdf


Files in this item

Appears in the following Collection

Hide metadata