xmlns:atom="http://www.w3.org/2005/Atom" xmlns:atom="http://www.w3.org/2005/Atom"

Part 2U.K.Networks, services and the radio spectrum

Chapter 1U.K.Electronic communications networks and services

[F1Security of public electronic communications networks and servicesU.K.

Textual Amendments

[F2105A.Duty to take security measuresU.K.

(1)The provider of a public electronic communications network or a public electronic communications service must take such measures as are appropriate and proportionate for the purposes of—

(a)identifying the risks of security compromises occurring;

(b)reducing the risks of security compromises occurring; and

(c)preparing for the occurrence of security compromises.

(2)In this Chapter “security compromise”, in relation to a public electronic communications network or a public electronic communications service, means—

(a)anything that compromises the availability, performance or functionality of the network or service;

(b)any unauthorised access to, interference with or exploitation of the network or service or anything that enables such access, interference or exploitation;

(c)anything that compromises the confidentiality of signals conveyed by means of the network or service;

(d)anything that causes signals conveyed by means of the network or service to be—

(i)lost;

(ii)unintentionally altered; or

(iii)altered otherwise than by or with the permission of the provider of the network or service;

(e)anything that occurs in connection with the network or service and compromises the confidentiality of any data stored by electronic means;

(f)anything that occurs in connection with the network or service and causes any data stored by electronic means to be—

(i)lost;

(ii)unintentionally altered; or

(iii)altered otherwise than by or with the permission of the person holding the data; or

(g)anything that occurs in connection with the network or service and causes a connected security compromise.

(3)But in this Chapter “security compromise” does not include anything that occurs as a result of conduct that—

(a)is required or authorised by or under an enactment mentioned in subsection (4);

(b)is undertaken for the purpose of providing a person with assistance in giving effect to a warrant or authorisation that has been issued or given under an enactment mentioned in subsection (4);

(c)is undertaken for the purpose of providing a person with assistance in exercising any power conferred by or under prison rules; or

(d)is undertaken for the purpose of providing assistance to a constable or a member of a service police force (acting in either case in that capacity).

(4)The enactments are—

(a)the Investigatory Powers Act 2016;

(b)Part 1 of the Crime and Courts Act 2013;

(c)the Prisons (Interference with Wireless Telegraphy) Act 2012;

(d)the Regulation of Investigatory Powers Act 2000;

(e)the Regulation of Investigatory Powers (Scotland) Act 2000;

(f)the Intelligence Services Act 1994;

(g)any other enactment (whenever passed or made) so far as it—

(i)makes provision which is in the interests of national security;

(ii)has effect for the purpose of preventing or detecting crime or of preventing disorder; or

(iii)makes provision which is in the interests of the economic well-being of the United Kingdom so far as those interests are also relevant to the interests of national security.

(5)In this section—

Textual Amendments

F2Ss. 105A, 105B substituted for ss. 105A-105D and ss. 105C, 105D re-inserted (17.11.2021 for specified purposes, 1.10.2022 in so far as not already in force) by Telecommunications (Security) Act 2021 (c. 31), ss. 1(2), 2, 28(1)(a)