Recital 103
Directive on the security of network and information systems · UE 2022/2555
| (103) | Where applicable, essential and important entities should communicate, without undue delay, to their service recipients any measures or remedies that they can take to mitigate the resulting risks from a significant cyber threat. Those entities should, where appropriate and in particular where the significant cyber threat is likely to materialise, also inform their service recipients of the threat itself. The requirement to inform those recipients of significant cyber threats should be met on a best efforts basis but should not discharge those entities from the obligation to take, at their own expense, appropriate and immediate measures to prevent or remedy any such threats and restore the normal security level of the service. The provision of such information about significant cyber threats to the service recipients should be free of charge and drafted in easily comprehensible language. |
In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the competent authority overseeing the duty to inform recipients. The Law of 28 July 2023 on cybersecurity, as amended by the Law of 28 July 2025, transposes this requirement and allows the ILR to formally instruct an essential or important entity to inform its customers of a specific threat. Luxembourg's multilingualism (FR/DE/LU/EN/PT) reinforces the intelligibility requirement: a notice issued only in English to a resident customer base will be treated as non-compliant.
Luxgap practice: pre-build multilingual customer notice templates (FR/DE/LU/EN/PT) validated by your DPO and legal counsel, so that communication can be triggered within 4 hours of threat qualification by the SOC.