Recital 143

Recital 143

Directive on the security of network and information systems · UE 2022/2555

(143)

This Directive respects the fundamental rights, and observes the principles, recognised by the Charter, in particular the right to respect for private life and communications, the protection of personal data, the freedom to conduct a business, the right to property, the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence. The right to an effective remedy extends to the recipients of services provided by essential and important entities. This Directive should be implemented in accordance with those rights and principles.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, recital 143 takes a particular dimension as the ILR (NIS 2 cybersecurity) and the CNPD (GDPR) have signed a cooperation protocol: an ILR audit may trigger a CNPD investigation if deployed security measures infringe employee or client rights. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, requires essential and important entities to document the articulation between NIS 2 obligations and fundamental rights, including the right to remedy of service recipients.

Luxgap practice: for each major security measure, we build a cross-ILR / CNPD / ITM (Labour Inspectorate) file demonstrating proportionality and preserving the right to remedy, opposable in case of joint audit.