the deadline for the limitation of service provision specified in this clause expire at weekends or
on public holidays, the proposal (offering) shall be submitted no later than the next business day
or the next day after a public holiday. If a judge delivers a reasoned verdict whereby the
legitimacy or reasonableness of the actions specified in the proposal is not approved, the order
shall be immediately suspended;
4) has the right to issue an order to the provider of public communications networks and
or public digital communications service provider, digital information hosting service provider
and digital service provider to preserve information related to the services provided by them
which might help detect the type of communications service used, technical measures which
were applied and the times of usage, identify the recipient of services, mail address, geographical
location address, phone or any other access number, information about accounts and payments
made on the basis of service agreement and other information which is available in the location
where communications equipment is installed, on the basis of the existing service contract or
agreement, get this information, and with the court ruling substantiated available, to receive the
data of service recipients’ flow and control the content of transferred information specified
herein.
CHAPTER III
OBLIGATIONS OF CYBER SECURITY ENTITIES
Article 11. General duties of cyber security entities
1. Cyber security entities:
1) are responsible for cyber security of communications and information service they
manage and of services they provide, ensure their compliance with the organisational and
technical cyber security requirements imposed on cyber security entities;
2) conduct risk assessment in accordance with the procedure established in the
description of organisational and technical cyber security requirements imposed on cyber
security entities as well as implement other technical and organisational cyber security measures
based on the latest technology developments proportionate to the identified risk;
3) notify the National Cyber Security Centre of cyber incidents which occur in
communications and information systems controlled and/or managed by them as well as of
applied cyber indecent management measures in accordance with the terms and conditions as
well as with the procedure laid down in the National Cyber Incidents Management Plan;
4) provide the Police with information required for the prevention and investigation of
infringements of the law which have constituent elements of criminal offences in cyber space in
accordance with the procedure established by the Police Commissioner General as well as