PECRUK · S.I. 2003/2426
Digiphile

Regulations

Regulation 5Security of public electronic communications services

(1) Subject to paragraph (2), a provider of a public electronic communications service (“the service provider”) shall take appropriate technical and organisational measures to safeguard the security of that service.
(1A) [F1 The measures referred to in paragraph (1) shall at least—
  • (a)
    ensure that personal data can be accessed only by authorised personnel for legally authorised purposes;
  • (b)
    protect personal data stored or transmitted against accidental or unlawful destruction, accidental loss or alteration, and unauthorised or unlawful storage, processing, access or disclosure; and
  • (c)
    ensure the implementation of a security policy with respect to the processing of personal data.]
(2) If necessary, the measures required by paragraph (1) may be taken by the service provider in conjunction with the provider of the electronic communications network by means of which the service is provided, and that network provider shall comply with any reasonable requests made by the service provider for these purposes.
(3) Where, notwithstanding the taking of measures as required by paragraph (1), there remains a significant risk to the security of the public electronic communications service, the service provider shall inform the subscribers concerned of—
  • (a)
    the nature of that risk;
  • (b)
    any appropriate measures that the subscriber may take to safeguard against that risk; and
  • (c)
    the likely costs to the subscriber involved in the taking of such measures.
(4) For the purposes of paragraph (1), a measure shall only be taken to be appropriate if, having regard to—
  • (a)
    the state of technological developments, and
  • (b)
    the cost of implementing it,

it is proportionate to the risks against which it would safeguard.

(5) Information provided for the purposes of paragraph (3) shall be provided to the subscriber free of any charge other than the cost to the subscriber of receiving or collecting the information.
(6) F2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Amended text

This Regulation is shown as amended by the Data (Use and Access) Act 2025 (c. 18), among other instruments (see the annotations below) (commenced provisions as at 19 September 2026, ELI), as incorporated in the text in force on 19 September 2026 as published on legislation.gov.uk.