Comparison

GDPR vs NIS2 — privacy incident or cyber incident?

Published Reviewed

GDPR protects people in personal-data processing. NIS2 protects network and information systems supporting covered services.

Side by side

Dimension GDPR NIS2
Scope Controllers and processors of personal data. Essential and important entities under national NIS2 law.
Incident trigger A breach of confidentiality, integrity or availability of personal data. A significant incident affecting covered network and information systems.
Early clock Normally supervisory notification within 72 hours when risk is not unlikely. Early warning within 24 hours, then incident notification within 72 hours under the directive.
Authority Data-protection supervisory authority and sometimes affected people. CSIRT or competent national NIS authority and sometimes service recipients.

How they combine

Treat the event once and assess it twice. A ransomware incident can trigger both regimes, with different thresholds, recipients, facts, and follow-up reports.

A quick self-check

Are you ready?

  • Does the incident form capture both legal triggers?
  • Can the team meet 24- and 72-hour work in parallel?
  • Are no-report decisions documented for each regime?

This comparison is general information about public law and standards, not legal advice, and does not create a client relationship. Rules change and apply differently by situation. Verify the current official sources and seek qualified advice where needed.