Glossary · Cross-regulation
GDPR Overlap
The interplay between NIS2 and GDPR — one incident can trigger both a CSIRT report and a personal data breach notification, on different clocks and to different authorities.
Explained in depth: NIS2 incident reporting timeline
NIS2 and GDPR regulate different things: NIS2 protects the security and continuity of services; GDPR protects personal data. But a single incident, say ransomware that both halts operations and exfiltrates customer records, can trigger both regimes at once: an early warning to the CSIRT within 24 hours under NIS2 Article 23, and a personal data breach notification to the data protection authority (IMY in Sweden) within 72 hours under GDPR Article 33, plus, in high-risk cases, notification of the affected individuals. The regimes stay separate: different recipients, different content requirements, different assessment criteria (service impact vs risk to individuals). NIS2 provides that where a NIS2 fine has been imposed for an infringement, a GDPR administrative fine should not be imposed for the same conduct where the breaches stem from the same behaviour, but the notification duties themselves both stand.
Why it matters
Incident response plans need a dual-track notification matrix: who assesses NIS2 significance, who assesses GDPR breach risk, and who files what, where, by when. Discovering the overlap during a live incident guarantees a missed deadline.
