Recital 106
Digital Operational Resilience Act · UE 2022/2554
| (106) | The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (29) and delivered an opinion on 10 May 2021 (30), |
In Luxembourg, the CSSF and the CNPD have signed an information exchange protocol allowing cross-transmission of incident notifications between the two authorities. Concretely, a major ICT incident notification to the CSSF can be relayed to the CNPD if it reveals a personal data breach, and vice versa. The law of 1 August 2018 organising the National Data Protection Commission and the law of 23 December 2016 on the financial sector frame this inter-authority cooperation.
Luxgap practice: we recommend Luxembourg financial entities prepare a unified notification anticipating questions from both authorities, and designate a single point of contact (often a pooled DPO-CISO) to avoid discourse divergences between CSSF and CNPD.