Recital 128
Directive on the security of network and information systems · UE 2022/2555
| (128) | This Directive does not require Member States to provide for criminal or civil liability with regard to natural persons with responsibility for ensuring that an entity complies with this Directive for damage suffered by third parties as a result of an infringement of this Directive. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (as amended by the law of 28 July 2025) does not create personal criminal or civil liability of directors towards third parties, in line with recital 128. However, article 1382 of the Luxembourg Civil Code (tort liability), articles 59 and 192-1 of the law of 10 August 1915 on commercial companies (management fault, liability towards shareholders and third parties) and article 418 of the Criminal Code (involuntary harm by negligence where an incident causes physical impact) remain fully applicable on an individual basis. The ILR retains administrative sanctioning power against the essential or important entity.
Luxgap practice: require timestamped minutes for each board approval of article 20 measures, file cyber delegations of authority with the RCS when they modify statutory powers, and verify that your D&O policy explicitly covers NIS 2 sanctions and consequential civil claims.