system of critical information infrastructure, in their information system of essential service or in their important information system. Section 8 Cyber security incident reporting (1) Public authorities and legal or natural persons specified in Section 3, letters b) to f) are obliged to report cyber security incidents in their important network, in their information or communication system of critical information infrastructure, or in their important information system immediately after their detection; this shall not affect their obligation to provide information according to another legal regulation3) or directly applicable European Union regulation governing personal data protection11). If the cyber security incident has a significant impact on the continuity of the provision of an essential service, the essential service operator shall inform the Agency of this fact. (2) A digital service provider is obliged to report a cyber security incident with a significant impact on the provision of their services without undue delay if they have access to the information for the assessment of the importance of the incident. (3) Public authorities and legal or natural persons specified in 3, letters b) and h) shall report cyber security incidents to the operator of the national CERT. (4) Public authorities and legal or natural persons specified in Section 3, letters c) to g) shall report cyber security incidents to the Agency. (5) The obligation according to paragraph 1 is also fulfilled by the operator of an information or communication system of a critical information infrastructure, or the operator of an important information system, when a cyber security incident is reported by the administrator of this system. The administrator of the information or communication system of a critical information infrastructure or the administrator of an important information system shall inform the operators of this system of the reported cyber security incidents without undue delay. (6) Public authorities and legal or natural persons not specified in Section 3 may report cyber security incidents to the operator of the national CERT or to the Agency. (7) The implementing legal regulation shall set out the following: a) The type, category and assessment of the importance of a cyber security incident b) Requirements and the method of cyber security incident reporting (8) If a cyber security incident that affected a digital service provider has a significant impact on the continuity of an essential service provision, the operator of the essential service is obliged to inform the Agency of this fact. Record keeping Section 9 (1) The Agency keeps a cyber security incident record (hereinafter “the incident record”) which contains: a) A cyber security incident report

Select target paragraph3