Deutschland Digital service providers are obligated, in addition to the existing regulations for telecommunication service providers in the Telecommunications Act (TKG), to inform their users about disruptions (Paragraph 5) or specific threats (Paragraph 6) emanating from one of their services.
Act to Strengthen Cybersecurity (Article 4 – Amendment to Section 19 of the Telecommunications, Digital Services Data Protection Act)
With the newly introduced Paragraphs 5 and 6 of Section 19 of the Telecommunications, Digital Services Data Protection Act (TDDG), digital service providers are required to inform their users about disruptions (Paragraph 5) or specific threats (Paragraph 6) arising from one of their services, and to pass on information from the Federal Office for Information Security (BSI) about specific threats affecting the providers’ customers to their users, insofar as this information is known and notification is possible.
Paragraphs 5 and 6 only cover those disruptions or threats emanating from a service during the user´s use of that service. This refers to cases where a user, for example, uses a hosting service to operate a website or email service, and the website or email service for which they are responsible is compromised and misused in order to distribute malware or phishing emails. It therefore concerns disruptions and threats that affect a user when they are using a service. Possible examples of relevant disruptions include a compromised email account used to send spam; a compromised server used for DDoS attacks; or a compromised website used to distribute malware.
The purpose of this obligation is to prevent damage caused by vulnerable or already compromised services. This kind of damage can occur to the user themselves as well as to other internet users if they are attacked via the affected services (e.g. malware, phishing or DDoS attacks). In addition, digital service providers are obligated to notify those users whose use of the services are causing a disruption or for whom there is a threat – insofar as this is known – and to forward to these users any information transmitted by the Federal Office for Information Security (BSI)