Regulations
Regulation 5Security of public electronic communications services
- (a)ensure that personal data can be accessed only by authorised personnel for legally authorised purposes;
- (b)protect personal data stored or transmitted against accidental or unlawful destruction, accidental loss or alteration, and unauthorised or unlawful storage, processing, access or disclosure; and
- (c)ensure the implementation of a security policy with respect to the processing of personal data.]
- (a)the nature of that risk;
- (b)any appropriate measures that the subscriber may take to safeguard against that risk; and
- (c)the likely costs to the subscriber involved in the taking of such measures.
- (a)the state of technological developments, and
- (b)the cost of implementing it,
it is proportionate to the risks against which it would safeguard.
Amended text
This Regulation is shown as amended by the Data (Use and Access) Act 2025 (c. 18), among other instruments (see the annotations below) (commenced provisions as at 19 September 2026, ELI), as incorporated in the text in force on 19 September 2026 as published on legislation.gov.uk.
Annotations
Textual Amendments
- F1 Reg. 5(1A) inserted (26.5.2011) by The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 (S.I. 2011/1208), regs. 1(1), 4(1)
- F2 Reg. 5(6) omitted (5.2.2026) by virtue of Data (Use and Access) Act 2025 (c. 18), ss. 115(2), 142(1); S.I. 2026/82, reg. 2(y) (with regs. 8-11)
https://pecr.digiphile.law/article/article-5.html
Text as at 19 September 2026.
This is an unofficial convenience version of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.