The NIS2 Directive does not exist in isolation, but is part of a broader EU regulatory framework, interacting with other regulations, in particular the General Data Protection Regulation (GDPR).
The documents highlight several key aspects of this interaction:
1. Explicit recognition of the GDPR’s preeminence:
- Article 1, paragraph 1: The main objective of the Directive is to establish a high and common level of cybersecurity within the EU “in order to improve the functioning of the internal market.” This approach emphasizes that the cybersecurity objectives of NIS2 must not compromise other fundamental EU principles, including data protection.
- Article 6, paragraph 12: Explicitly establishes that NIS2 applies “without prejudice” to numerous existing EU regulations, mentioning the GDPR first and foremost. This clear language establishes a precise hierarchy, stating that the principles of the GDPR regarding data protection take priority in the event of a conflict or overlap with NIS2.
2. Data processing within the scope of NIS2 subject to the GDPR:
- Article 8, paragraph 14: Emphasizes that any data processing activity carried out in the context of NIS2, whether by entities or competent authorities, must comply with the GDPR. This provision highlights that cybersecurity measures must be implemented in such a way as to respect the data protection rights of individuals.
- Article 8, paragraph 14 (emphasis added): Specifically addresses data processing by providers of public electronic communications services or publicly available electronic communications networks under NIS2. It establishes that such processing must comply with the broader EU regulatory framework regarding data protection and confidentiality, specifically citing Directive 2002/58/EC (ePrivacy Directive).
3. Cooperation between competent authorities and data protection authorities:
- Article 29, paragraph 3: Recognizes that cybersecurity incidents may also involve personal data breaches covered by the GDPR. To ensure coordinated and effective management of such incidents, this provision requires close cooperation between the competent authorities responsible for NIS2 and the data protection authorities (supervisory authorities under the GDPR).
- Clarification of roles: While requiring cooperation, Article 29, paragraph 3 clarifies that this interaction must not compromise the respective powers and tasks of each authority. GDPR supervisory authorities maintain their primary oversight role in enforcing data protection rules, even in cases involving cybersecurity implications.
- Article 35: Further strengthens the link between NIS2 and the GDPR by outlining a specific procedure for situations where competent authorities detect potential personal data breaches during the supervision or enforcement of NIS2 obligations.
4. Data sharing and confidentiality:
- Limited disclosure of confidential information: Article 2, paragraph 13 recognizes that sharing cybersecurity information could involve the disclosure of information protected by other EU or national regulations, such as trade secrets. It allows the sharing of such information with the Commission and other competent authorities solely for the purposes of enforcing the Directive and only to the extent necessary.
- Protection of confidential information: When information is shared, Article 2, paragraph 13 imposes safeguards to protect the confidentiality of the shared information and protect the commercial interests of the entities involved.
5. Implications for cybersecurity practices:
- Data protection by design and by default: Although not explicitly mentioned, the interaction between NIS2 and the GDPR reinforces the importance of integrating data protection considerations into cybersecurity measures from the outset. Entities starting a structured NIS2 Directive compliance path should adopt a “data protection by design and by default” approach when implementing cybersecurity risk management practices.
- Data minimization: The GDPR’s data minimization principle is also relevant in the context of NIS2. Entities should ensure that any collection and processing of personal data for cybersecurity purposes is limited to what is strictly necessary and proportionate to the identified risks.
In summary, the NIS2 Directive recognizes and respects the importance of data protection. It clearly establishes that its provisions do not override the GDPR and mandates cooperation between competent cybersecurity and data protection authorities. This interaction underscores the need for a balanced approach, ensuring that cybersecurity measures are implemented in a way that effectively mitigates risks while safeguarding the data protection rights of individuals. To learn more about the overall regulatory framework, it is useful to consult what the main objective of the NIS2 Directive is and the operational deadlines related to the ACN list.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
