Recital 14
Directive on the security of network and information systems · UE 2022/2555
| (14) | Union data protection law and Union privacy law applies to any processing of personal data under this Directive. In particular, this Directive is without prejudice to Regulation (EU) 2016/679 of the European Parliament and of the Council (8) and Directive 2002/58/EC of the European Parliament and of the Council (9). This Directive should therefore not affect, inter alia, the tasks and powers of the authorities competent to monitor compliance with the applicable Union data protection law and Union privacy law. |
In Luxembourg, the coexistence of the ILR (NIS 2 competent authority designated by the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025) and the CNPD (GDPR authority) requires an effective dual notification for any security incident involving personal data. The Luxembourg transposition law applies the NIS 2 deadlines (early warning 24h, notification 72h, final report 1 month) without derogating from the GDPR 72h deadline applied in parallel.
Luxgap practice: build a single incident procedure that triggers both ILR and CNPD notifications from the same event, with a shared field mapping to avoid contradictions between both files (which are cross-checked during inspections).