Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
EDPB / EDPS March 19, 2026 6 min

One single point to notify breaches: what the EDPB and EDPS asked for on the cybersecurity package

Joint opinion of 19 March 2026 on the Cybersecurity Act 2 proposal and the amendments to the NIS2 Directive. Inside is the thing every controller has been waiting years for

In short

On 19 March 2026 the European Data Protection Board and the European Data Protection Supervisor adopted a joint opinion on the Cybersecurity Act 2 proposal and on the targeted amendments to the NIS2 Directive. The package had been published by the Commission on 20 January 2026, which the following day formally requested the opinion under Article 42(2) of Regulation (EU) 2018/1725.

The single entry point, the part that concerns you every time

In line with their joint opinion on the Digital Omnibus, the Board and the Supervisor support establishing a single entry point for the notification of personal data breaches, as it would reduce the administrative burden for notifying organisations without affecting the level of protection for individuals.

Anyone who has managed an incident knows why this matters. Today the same event can trigger notification to the data protection authority within seventy-two hours, to the cybersecurity authority on a different clock, and in regulated entities several more filings besides: different formats, different portals, fields asking the same thing in different words, all during the hours when you should be containing the damage. It is not a theoretical problem, it is why first statements come out imprecise.

The limits on ENISA

The opinion supports strengthening the role of the EU Agency for Cybersecurity and facilitating uptake of certification, and welcomes that ENISA's advice would be issued upon prior request from the Board, keeping responsibilities clearly divided. It suggests adding the European Supervisor among those who can request that advice.

  • If ENISA's Management Board adopts measures necessary for the application of the EU data protection regulation, those decisions should be limited to very technical details, with prior consultation of the Supervisor
  • The scope of the European Cybersecurity Certification Framework and its relationship with GDPR certification should be further clarified
  • Before adopting a certification scheme relating to the security of processing personal data, ENISA should consult the Board
  • Schemes for products and services likely to be used in processing operations should take into account security controls that help demonstrate GDPR compliance

The sentence worth keeping

"While cybersecurity supports the protection of personal data by limiting the risks of unwanted access, modification or unavailability of data, it is crucial to ensure that security controls are implemented in a way that does not undermine individuals' fundamental rights and freedoms."
— Anu Talus, Chair of the European Data Protection Board

It is the argument to use when a vendor proposes a security measure that collects far more than needed: full keystroke logging, cameras over workstations, inspection of communication content. Security is not a legal basis that absorbs everything else.

On the NIS2 amendments

The Board and the Supervisor welcome designating providers of European Digital Identity Wallets and European Business Wallets as 'essential entities'. That choice has practical consequences: whoever runs those wallets enters the stricter regime of the directive, with the risk management and notification duties that follow.

On skills, the opinion recommends that the European Cybersecurity Skills Framework should not be limited to cybersecurity professionals but also include a general workforce profile. Translated: security is not the trade of a few people inside the company, and training cannot stop at the IT department.

What to do with it now

The single entry point is a proposal, not a rule: nothing changes in today's procedures. What you can do straight away is check whether your clients' notification procedure has one person filling different forms for different authorities, and whether that person has in front of them a list of who must be told and on what clock. The day the single point arrives, that list will get shorter; until then it is the only thing holding the statements together.

Official source:EDPS - EDPB and EDPS support strengthening EU's cybersecurity and easing compliance while protecting individuals' personal data (19 marzo 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

EDPB / EDPS
171paragraphs, and one of them is about your records

"We keep it for research purposes": the EDPB explains why that is not an answer

On 15 April 2026 the EDPB adopted draft Guidelines 1/2026 on scientific research. The public consultation closed on 25 June and the final text is not out yet. Anyone who maintains records should read the retention chapter: a research purpose, on its own, does not justify an open-ended period.

Apr 15, 2026New 7 min
EDPB / EDPS
12-14gli articoli sotto esame

In 2026 every European authority is looking at the same thing: privacy notices

Each year the EDPB picks a topic and every national authority checks it together, in the same period, through questionnaires and inspections. For 2026 the topic is transparency: how controllers tell people what happens to their data. In scope are Article 13, where data comes from the data subject, and Article 14, where it comes from elsewhere. The Czech authority has already written the theme into its inspection plan.

Aug 10, 2026New 6 min
EDPB / EDPS
28 agotermine per candidarsi

Competition and data protection: the EDPB opens the table, and there is a deadline

After the DSA and before the DMA and the AI Act, the fourth piece of the European regulatory mosaic concerns the relationship between competition and data protection. This is not theoretical: it touches data as a market asset, mergers, and the position of those who process data because they dominate a market. The EDPB and the Commission are asking for input before they write, and this time the deadline is close.

Jul 30, 2026New 6 min