The NIS2 Directive and the GDPR represent two pillars of European digital regulation, each with distinct but complementary objectives. While the GDPR protects the fundamental rights of natural persons regarding their personal data, NIS2 aims to ensure a high and uniform level of cybersecurity within the European Union. Understanding how these regulations interact is essential for organizations that must comply with both regulatory frameworks.
Different objectives, complementary scopes
The GDPR focuses on personal data protection: it establishes principles for the lawful, transparent, and secure processing of information that identifies or makes a natural person identifiable. Cybersecurity is one of the tools to ensure this protection, but it is not the sole objective of the regulation.
The NIS2 Directive, on the other hand, has the primary goal of strengthening the cyber resilience of critical infrastructure and essential services. Its focus is on operational continuity and the ability to prevent, detect, and respond to security incidents that could compromise the functioning of the European internal market.
Despite this difference in objectives, the two regulations overlap in several areas: a cybersecurity incident may also involve a personal data breach, and the technical and organizational measures required by NIS2 contribute directly to the data protection required by the GDPR.
The primacy of the GDPR in the regulatory framework
The NIS2 Directive explicitly recognizes the primacy of the GDPR. Article 6, paragraph 12, states that NIS2 applies “without prejudice” to numerous existing EU regulations, mentioning the GDPR first and foremost. This means that in the event of a conflict or overlap, the principles of the GDPR regarding data protection take priority.
Furthermore, Article 8, paragraph 14, clarifies that any data processing activity carried out in the context of NIS2 – whether by entities subject to the directive or by competent authorities – must comply with the GDPR. This also applies to providers of electronic communications services, who must comply with the broader EU regulatory framework regarding data protection and confidentiality, including the ePrivacy Directive.
Incident management: coordination between authorities
One of the most relevant aspects of the interaction between NIS2 and the GDPR concerns security incident management. A cyberattack can indeed result in both a significant incident under NIS2 and a personal data breach under the GDPR.
Article 29, paragraph 3 of NIS2 mandates close cooperation between the competent authorities responsible for the directive and the data protection authorities (the supervisory authorities under the GDPR). This cooperation is fundamental to ensuring a coordinated and effective management of incidents, avoiding duplication or gaps in the response.
However, cooperation does not compromise their respective competencies: the GDPR supervisory authorities maintain their primary role of oversight in the application of data protection rules, even in cases involving cybersecurity implications. Article 35 of NIS2 outlines a specific procedure for situations where competent authorities detect potential personal data breaches while supervising the directive’s obligations.
Information sharing and confidentiality
NIS2 promotes the sharing of cybersecurity information between entities, competent authorities, and other Member States. However, this sharing must take place in compliance with data protection and confidentiality regulations.
Article 2, paragraph 13 of NIS2 recognizes that sharing cybersecurity information could involve the disclosure of information protected by other regulations, such as trade secrets or personal data. The directive allows the sharing of such information with the Commission and other competent authorities exclusively for the purposes of applying NIS2 and only to the extent necessary, imposing safeguards to protect the confidentiality and commercial interests of the entities involved.
Practical implications for organizations
Data protection by design
Although NIS2 does not explicitly mention the “privacy by design” and “privacy by default” principles of the GDPR, the interaction between the two regulations reinforces the importance of integrating data protection considerations into cybersecurity measures from the outset. Entities subject to both regulations should adopt an integrated approach, ensuring that cybersecurity risk management practices respect the principles of the GDPR.
Data minimization
The GDPR’s data minimization principle is particularly relevant in the context of NIS2. Organizations must ensure that any collection and processing of personal data for cybersecurity purposes is limited to what is strictly necessary and proportionate to the identified risks. For example, security monitoring systems should be configured to collect only the data essential for detecting and responding to incidents, avoiding the indiscriminate collection of personal information.
Integrated governance
Organizations subject to both regulations must develop an integrated governance that takes into account both the cybersecurity obligations of NIS2 and the data protection requirements of the GDPR. This includes:
- Coordination between the Chief Information Security Officer (CISO) and the Data Protection Officer (DPO)
- Unified procedures for incident management that consider both NIS2 and GDPR notification obligations
- Risk assessments that integrate both cybersecurity risks and risks to the rights and freedoms of natural persons
- Training programs that cover both regulatory areas
What a company subject to NIS2 and GDPR must do
For organizations that fall within the scope of both regulations, it is essential to adopt a structured approach that ensures compliance with both regulatory frameworks:
- Map regulatory obligations: identify which NIS2 and GDPR requirements apply to the organization, highlighting areas of overlap and any differences in notification, documentation, and governance obligations.
- Integrate risk assessments: develop a risk assessment process that considers both cybersecurity risks (availability, integrity, confidentiality of systems) and risks to the rights and freedoms of natural persons resulting from personal data processing.
- Define unified incident management procedures: establish workflows that ensure timely notification to both the competent authorities for NIS2 and the data protection authorities in the event of a data breach, respecting the different timelines and methods provided by the two regulations.
- Implement integrated technical and organizational measures: adopt security controls that meet both NIS2 and GDPR requirements, applying the principles of privacy by design and data minimization.
- Ensure cooperation between functions: ensure that the cybersecurity team and the DPO collaborate closely, sharing relevant information and coordinating compliance activities.
- Document choices and measures taken: maintain up-to-date documentation that demonstrates compliance with both regulations, including risk assessments, security policies, records of processing activities, and incident management procedures.
Useful insights
To better understand the regulatory framework and specific obligations, these articles offer complementary insights:
- What are the main differences between the NIS1 and NIS2 directives? – Discover how NIS2 expands the scope and strengthens obligations compared to the previous directive.
- NIS2: are there exemptions or waivers? – Check if your organization is among the entities subject to the directive or can benefit from exemptions.
- What are the requirements for CSIRTs to ensure high levels of availability in their services? – Delve into the technical and organizational requirements for incident response teams provided by NIS2.
ISGroup supports organizations on their path to NIS2 compliance through NIS2 Compliance services, which include assessment of implemented measures, risk analysis, and customized training paths. To ensure the protection of personal data in accordance with the GDPR, ISGroup also offers GDPR Compliance services, with audits of measures, risk analysis, and continuous training.
Frequently asked questions
- Does NIS2 replace the GDPR regarding data security?
- No, NIS2 does not replace the GDPR. The two regulations have different and complementary objectives. The GDPR protects the fundamental rights of natural persons regarding their personal data, while NIS2 aims to ensure the cyber resilience of critical infrastructure. In the event of a conflict, the GDPR takes precedence regarding personal data protection.
- Must a cybersecurity incident be notified to both NIS2 authorities and GDPR authorities?
- It depends on the nature of the incident. If the incident also involves a personal data breach, it must be notified to both the competent authorities for NIS2 and the data protection authority under the GDPR. The timelines and methods of notification may differ between the two regulations, so it is important to know both requirements.
- Are the security measures required by NIS2 sufficient for GDPR compliance?
- The security measures required by NIS2 contribute to GDPR compliance, but they are not automatically sufficient. The GDPR also requires compliance with specific principles such as data minimization, privacy by design, transparency, and the legal basis for processing. An integrated approach that considers both regulatory frameworks is necessary.
- Who coordinates the response to incidents involving both NIS2 and the GDPR?
- Within the organization, it is essential that the cybersecurity team and the Data Protection Officer (DPO) collaborate closely. At the authority level, NIS2 provides for cooperation between cybersecurity competent authorities and data protection authorities, while each maintains its specific competencies.
- Is the sharing of cybersecurity information provided by NIS2 compatible with the GDPR?
- Yes, NIS2 provides that the sharing of cybersecurity information must take place in compliance with the GDPR and other confidentiality regulations. Sharing is permitted only to the extent necessary for the application of the directive and with safeguards to protect the confidentiality of information and the interests of the entities involved.
The interaction between NIS2 and the GDPR requires organizations to adopt an integrated approach to cybersecurity and data protection. Understanding how these regulations complement each other is the first step toward developing an effective compliance strategy that protects both critical infrastructure and the fundamental rights of individuals.
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
