Section 5A(6)
The notification referred to in paragraph (3) is not required if the service provider has demonstrated, to the satisfaction of the Information Commissioner that— it has implemented appropriate technological protection measures which render the data unintelligible to any person who is not authorised to access it, and that those measures were applied to the data concerned in that breach.
← 5 · All articles · 7 →
Source: legislation.gov.uk · retrieved 2026-09-04