Glossary · Duties and incidents

Customer notification

Definition

Customer notification is a new duty in the Cyber Security and Resilience Bill requiring data centre operators, relevant digital service providers and relevant managed service providers to tell UK customers likely to be adversely affected by a reportable incident. It applies as soon as reasonably practicable after the 72-hour full notification, under regs 11C, 12C and 14G.

What exactly must the provider do?

After giving the full incident report, the provider must, as soon as reasonably practicable, take reasonable steps to establish which of its customers in the United Kingdom are likely to be adversely affected by the incident, and then notify those customers.

The notification must give details of the nature of the incident and explain why the provider considers the customer is likely to be adversely affected. There is no fixed hour count and no prescribed form in the Bill.

How does a provider decide which customers are affected?

The provider must take reasonable steps to identify affected customers, which means knowing which customers rely on which systems before an incident happens. Regulations 11C(3), 12C(2) and 14G(2) list the same three factors, adjusted for the service:

  • the extent of any actual or likely disruption to the service provided to that customer;
  • whether the confidentiality, authenticity, integrity or availability of any data relating to the customer is likely to be compromised;
  • any other impact on the network and information systems of the customer.

Why does this matter for customers?

Many customers of a relevant managed service provider, relevant digital service provider or data centre service are regulated themselves. A hospital trust or energy company whose provider is compromised may face its own 24-hour clock. The customer duty gives them a legal route to the facts, though it only arises after the provider's full notification, so customers should also agree faster contractual notice.

The duty covers only customers in the United Kingdom. It sits alongside other laws, so a provider may also have to tell individuals about a personal data breach under UK GDPR.

Incident notification rules compared: OES, data centre, RDSP and RMSP

RuleOES (non-data centre)Data centre OESRDSPRMSP
RegulationReg 11Reg 11AReg 12AReg 14E
Who you notifyDesignated competent authority for the OESDesignated competent authority (Ofcom, cl.4(2))Information CommissionInformation Commission
What makes it reportableHas affected or is affecting the operation or security of the systems, and impact has been, is or is likely to be significant (reg 11(3)-(4))Could have had, has had, is having or is likely to have a significant impact (reg 11A(3))Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 12A(2)-(3))Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 14E(2)-(3))
24-hour initial notificationFrom first awareness (reg 11(6)(a))From first awareness (reg 11A(5)(a))From first awareness (reg 12A(5)(a))From first awareness (reg 14E(5)(a))
72-hour full notificationFrom the same moment of first awareness (reg 11(6)(b))From the same moment (reg 11A(5)(b))From the same moment (reg 12A(5)(b))From the same moment (reg 14E(5)(b))
Customer notification dutyNone in the BillYes, reg 11CYes, reg 12CYes, reg 14G
Copy to the CSIRT (NCSC)At the same time, reg 11(8)At the same time, reg 11A(7)At the same time, reg 12A(7)At the same time, reg 14E(7)

Where it appears in the Bill

  • Cl.16(2), new reg 11CData centre operators must notify affected UK customers.
  • Cl.16(3), new reg 12CRDSPs must notify affected UK customers.
  • Cl.16(4), new reg 14GRMSPs must notify affected UK customers.
  • New reg 18(11)Failures under 11C(2)(b) and (4), 12C(1)(b) and (3), 14G(1)(b) and (3) are in the higher band.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

How quickly must customers be told?

The Bill sets no hour count. The provider must act as soon as reasonably practicable after giving its full notification to the regulator, which itself is due within 72 hours of first awareness. It must first take reasonable steps to identify affected UK customers, then notify them. Customers who need faster notice should secure it in their contracts.

Do operators of essential services have to notify customers?

Only data centre operators. Regulation 11C applies to an OES so far as it provides a data centre service. Other operators of essential services, such as energy or transport operators, have no customer notification duty under the Cyber Security and Resilience Bill, although other laws such as UK GDPR may still require them to tell people about personal data breaches.

What must a customer notification say?

It must give details of the nature of the incident and explain why the provider considers that the customer is likely to be adversely affected. The Bill does not prescribe a form. In deciding who is affected, the provider must consider service disruption, likely compromise of the customer's data, and any other impact on the customer's own systems.

Related guidance

Official sources

More in Duties and incidents

Full glossary