Take advantage of our expertise!
Under the Telecommunications Act (TKG), network operators and service providers are required to take technical and organizational measures
- to protect personal data and the confidentiality of telecommunications
- to protect the telecommunications infrastructure from disruptions and risks
- and to ensure the availability of telecommunications services
and to describe them in a conceptual framework. This is done in accordance with Section 166 of the TKG as a so-called security concept. This security concept must be submitted to the Federal Network Agency (BNetzA) for review, or may be requested by the BNetzA for review. Violations of this obligation, the reporting requirement, or breaches of telecommunications secrecy or the protection of personal data may result in substantial fines, which should be avoided.
We have many years of proven expertise in this area, successfully obtaining approval from the BNetzA. Thanks to our structured approach to developing a security concept, the effort required on your part is minimal.
The requirements of the Telecommunications Act mentioned above are further specified by the BNetzA in a so-called catalog of security requirements. The latest edition requires a “clear and defined organizational and procedural structure” to achieve the protection objectives (see above). This means that, in addition to the actual security concept, the company’s organizational structure must also be professionally regulated. With our sample organizational concept, we can offer you—as a network operator or service provider—quick and straightforward solutions.
In addition to the Telecommunications Act, legislation on critical infrastructure also mandates corresponding security concepts and measures. Depending on their size and significance, telecommunications companies may be considered critical infrastructure in their own right and, under the NIS-2 Implementation Act, are classified at a minimum as “important” entities and, where applicable, as “particularly important entities.” The KRITIS Umbrella Act may also contain additional requirements if it is relevant to a telecommunications company based on the number of “residents to be served.”
We are happy to assist you, as needed, in developing or updating your security concept and implementing all legal requirements.
Do you have any questions? We’d be happy to answer all your questions regarding security concepts.
In the German telecommunications market, there are four key obligations for providers of telecommunications services. These are:
- Obligation to report to the Federal Network Agency (BNetzA)
- The obligation to appoint a security officer
- Obligation to develop and implement a security plan
- The obligation to submit the security plan to the BNetzA
For network operators, it can generally be stated that all of these obligations must be fulfilled. However, the situation is more nuanced for service providers. The new Telecommunications Act, which took effect on December 1, 2021, has redefined telecommunications services. Service providers that were classified as so-called “over-the-top providers” were previously not subject to the regulatory framework of the TKG. This article first addresses the obligations under Section 166 of the TKG (formerly Section 109—Security Officer and Security Policy) and Section 165 (Technical and Organizational Security Measures), as well as the reporting obligation to the Federal Network Agency (BNetzA).
How is a telecommunications service defined? The new TKG provides some important clarifications on this point:
Section 3, “Definitions,” states:
61. “Telecommunications services” means services generally provided for a fee via telecommunications networks, which—with the exception of services that offer content via telecommunications networks and services or exercise editorial control over such content—include the following services:
a) Internet access services,
b) interpersonal telecommunications services, and
c) services that consist entirely or predominantly of the transmission of signals, such as transmission services used for machine-to-machine communication and for broadcasting;
Furthermore, paragraph 24 of this section states the following:
24. “person-to-person telecommunications service” means a service, usually provided for a fee, that enables a direct, person-to-person, and interactive exchange of information via telecommunications networks between a finite number of persons, whereby the recipients are determined by the persons initiating the telecommunications or participating in it; This does not include services that merely enable interpersonal and interactive telecommunications as a subordinate ancillary function inseparably linked to another service;
According to our understanding, telecommunications services thus include all Internet access services, all interpersonal telecommunications services that do not constitute a subordinate ancillary function, and certain signal transmission services.
Consequently, there is no longer an exemption for so-called “over-the -top services”—such as email services—which are essentially provided via the networks of network operators but are not themselves classified as service providers (as is the case, for example, with Google’s email service).
The only exception that remains is when the telecommunications service can be classified as “a subordinate ancillary function inseparably linked to another service.” This is the case, for example, when a chat service is offered as a secondary function within an online game and is inseparably linked to the main function—the game itself.
What obligations now apply to the providers of these telecommunications services with regard to reporting requirements, security policies/security officers, and the requirement to submit the security policy to the Federal Network Agency (BNetzA)?
Pursuant to Section 166 of the Telecommunications Act (TKG), the operator of a telecommunications network and the provider of a publicly available telecommunications service (see above) must, among other things, appoint a security officer and develop a security plan.
Pursuant to Section 166, this obligation applies to network operators. Service providers must maintain a security plan and may be required by the BNetzA to submit it.
The requirement to report the “commencement, modification, and termination of their activities, as well as changes to their name or business name, legal form, and address” pursuant to Section 5 of the Telecommunications Act (TKG) applies to all network operators and providers of telecommunications services “that are not number-independent interpersonal telecommunications services.” Thus, this provision again applies without exception to network operators as well as certain service providers. The exception for service providers therefore applies to number-independent interpersonal telecommunications services, such as messenger services that operate independently of national or international numbering plans.