Recital 45

Recital 45

Directive on the security of network and information systems · UE 2022/2555

(45)

Given the importance of international cooperation on cybersecurity, the CSIRTs should be able to participate in international cooperation networks in addition to the CSIRTs network established by this Directive. Therefore, for the purpose of carrying out their tasks, the CSIRTs and the competent authorities should be able to exchange information, including personal data, with the national computer security incident response teams or competent authorities of third countries provided that the conditions under Union data protection law for transfers of personal data to third countries, inter alia those of Article 49 of Regulation (EU) 2016/679, are met.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, GOVCERT.LU (governmental CSIRT) and CIRCL (private CSIRT, operator of the world-leading MISP platform) are the officially designated CSIRTs under the law of 28 July 2023 on cybersecurity. Since CIRCL operates MISP, a major hub for international IOC exchange, it must in practice apply Article 49 GDPR conditions for every outbound flow to a non-EU partner, under joint oversight of the CNPD and the ILR.

Luxgap practice: if you are a Luxembourg essential or important entity connected to MISP CIRCL, document your own legal basis for sharing (you remain controller of your IOCs), and require an Article 28 GDPR compliance statement from CIRCL itself.