Recital 108

Recital 108

Directive on the security of network and information systems · UE 2022/2555

(108)

Personal data are in many cases compromised as a result of incidents. In that context, the competent authorities should cooperate and exchange information about all relevant matters with the authorities referred to in Regulation (EU) 2016/679 and Directive 2002/58/EC.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) entrusts the ILR with NIS 2 incident notifications, while the CNPD remains competent for article 33 GDPR data breaches. Both authorities have formalised information exchange channels, making any narrative divergence immediately detectable during an audit.

Luxgap practice: prepare a single notification playbook that triggers both ILR and CNPD forms in parallel with a shared factual narrative, and trace everything in a timestamped incident register admissible before both authorities.