The classic trap
Recital 136 forces cooperation between the ILR (Luxembourg NIS 2 authority) and the CNPD (GDPR authority) on incidents involving personal data. In practice, many essential entities notify the ILR within 24h for a NIS 2 incident, then forget the CNPD notification within 72h under GDPR article 33, or vice versa. Both authorities now exchange their findings: an incomplete notification on the ILR side can trigger a CNPD investigation on the same facts, with a possible cumulation of NIS 2 sanctions (up to 10M EUR or 2% of turnover) and GDPR sanctions (up to 20M EUR or 4% of turnover).
Dual notification: one incident, two regimes, two clocks
Recital 136 does not merge the regimes, it coordinates them. Concretely, the same ransomware on an essential entity triggers three distinct notifications with deadlines that do not align:
- Early warning to ILR within 24h (NIS 2 article 23).
- Incident notification to ILR within 72h with initial assessment (NIS 2 article 23).
- Notification to CNPD within 72h if personal data is affected (GDPR article 33).
- Final report to ILR within 1 month (NIS 2 article 23).
- Communication to data subjects without delay if high risk (GDPR article 34).
The trap: IR teams fill a single internal form and let lawyers infer obligations afterwards. As a result, the CNPD clock often starts too late, because nobody qualifies the incident as a personal data breach in the first hours.
How Luxgap automates this risk
Our Luxgap Dual-Track Incident Orchestrator eliminates the risk of forgetting one authority by piloting both clocks (ILR and CNPD) in parallel from the moment the incident is detected. The tool integrates natively with Microsoft Sentinel, CrowdStrike Falcon, Wazuh and your SIEM to ingest the technical alert, then a specialised LLM agent automatically qualifies the incident under both regimes by cross-referencing IOCs, affected systems and the processing mapping declared in your article 30 register.
- Detects from the SIEM alert whether the incident affects a system containing personal data, based on your processing mapping and M365 Purview classification tags.
- Triggers two distinct timers (ILR 24h/72h/1 month and CNPD 72h) with Teams or Slack reminders at H-12, H-6 and H-2 on each deadline.
- Automatically generates both pre-filled forms: ILR incident notification in the expected format and CNPD breach notification in the Luxembourg format, avoiding duplication of common fields.
- Synchronises both files: an update on the ILR side (new scope, new compromised data) propagates the information into the CNPD file with cryptographic timestamping.
- Produces a sealed PDF report opposable to both authorities, demonstrating consistency between the two notifications and compliance with recital 136.
- Archives everything in a digital vault hosted in Luxembourg (eBRC or LuxConnect) for evidence in case of a cross-inspection.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request your demonstration and our teams prepare a simulation exercise on a real ransomware scenario, with a free white audit within 48h to measure the current maturity of your dual notification process.