In short
On 19 March 2026 the European Data Protection Board and the European Data Protection Supervisor adopted a joint opinion on the Cybersecurity Act 2 proposal and on the targeted amendments to the NIS2 Directive. The package had been published by the Commission on 20 January 2026, which the following day formally requested the opinion under Article 42(2) of Regulation (EU) 2018/1725.
The single entry point, the part that concerns you every time
In line with their joint opinion on the Digital Omnibus, the Board and the Supervisor support establishing a single entry point for the notification of personal data breaches, as it would reduce the administrative burden for notifying organisations without affecting the level of protection for individuals.
Anyone who has managed an incident knows why this matters. Today the same event can trigger notification to the data protection authority within seventy-two hours, to the cybersecurity authority on a different clock, and in regulated entities several more filings besides: different formats, different portals, fields asking the same thing in different words, all during the hours when you should be containing the damage. It is not a theoretical problem, it is why first statements come out imprecise.
The limits on ENISA
The opinion supports strengthening the role of the EU Agency for Cybersecurity and facilitating uptake of certification, and welcomes that ENISA's advice would be issued upon prior request from the Board, keeping responsibilities clearly divided. It suggests adding the European Supervisor among those who can request that advice.
- If ENISA's Management Board adopts measures necessary for the application of the EU data protection regulation, those decisions should be limited to very technical details, with prior consultation of the Supervisor
- The scope of the European Cybersecurity Certification Framework and its relationship with GDPR certification should be further clarified
- Before adopting a certification scheme relating to the security of processing personal data, ENISA should consult the Board
- Schemes for products and services likely to be used in processing operations should take into account security controls that help demonstrate GDPR compliance
The sentence worth keeping
"While cybersecurity supports the protection of personal data by limiting the risks of unwanted access, modification or unavailability of data, it is crucial to ensure that security controls are implemented in a way that does not undermine individuals' fundamental rights and freedoms."
It is the argument to use when a vendor proposes a security measure that collects far more than needed: full keystroke logging, cameras over workstations, inspection of communication content. Security is not a legal basis that absorbs everything else.
On the NIS2 amendments
The Board and the Supervisor welcome designating providers of European Digital Identity Wallets and European Business Wallets as 'essential entities'. That choice has practical consequences: whoever runs those wallets enters the stricter regime of the directive, with the risk management and notification duties that follow.
On skills, the opinion recommends that the European Cybersecurity Skills Framework should not be limited to cybersecurity professionals but also include a general workforce profile. Translated: security is not the trade of a few people inside the company, and training cannot stop at the IT department.
What to do with it now
The single entry point is a proposal, not a rule: nothing changes in today's procedures. What you can do straight away is check whether your clients' notification procedure has one person filling different forms for different authorities, and whether that person has in front of them a list of who must be told and on what clock. The day the single point arrives, that list will get shorter; until then it is the only thing holding the statements together.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free