Recital 106

Recital 106

Digital Operational Resilience Act · UE 2022/2554

(106)

The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (29) and delivered an opinion on 10 May 2021 (30),

Luxembourg specificity
loi luxembourgeoise du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees

In Luxembourg, the CSSF and the CNPD have signed an information exchange protocol allowing cross-transmission of incident notifications between the two authorities. Concretely, a major ICT incident notification to the CSSF can be relayed to the CNPD if it reveals a personal data breach, and vice versa. The law of 1 August 2018 organising the National Data Protection Commission and the law of 23 December 2016 on the financial sector frame this inter-authority cooperation.

Luxgap practice: we recommend Luxembourg financial entities prepare a unified notification anticipating questions from both authorities, and designate a single point of contact (often a pooled DPO-CISO) to avoid discourse divergences between CSSF and CNPD.