All news
Regulation May 15, 2026 11 min

NIS2 and GDPR: how to orchestrate them operationally after Italian Decree 138/2024. The DPO checklist for the NIS Operator

Italian NIS2 transposition (Legislative Decree 138/2024, effective October 16, 2024): the DPO does not directly manage NIS2 but must interface with the security structure to avoid compliance gaps

TL;DR for the DPO

If your client is an 'essential entity' or 'important entity' under NIS2 (e.g. healthcare, energy, banks, transport, cloud providers, online platforms), you MUST coordinate with the Security Manager/CISO on incident management processes. NIS2 requires initial notification within 24h to ACN; GDPR requires notification within 72h to the DPA. Same incident may trigger both regimes - the flow must be unified to avoid contradictions in statements.

What changes with Legislative Decree 138/2024

Legislative Decree 138/2024 of September 4, 2024 transposed in Italy the NIS2 Directive (EU 2022/2555). It is effective since October 16, 2024 but sanctions apply from January 1, 2026. The Italian National Cybersecurity Agency (ACN) is the competent authority for entity registration and incident notification reception. The new aspect vs NIS1: scope expanded to 18 sectors, including cloud platforms, datacenters, ICT-managed services, social networks.

18
NIS2 essential and important sectors
24h
Initial ACN notification
72h
GDPR DPA notification
10MEUR
Max essential sanction

The NIS2-GDPR relationship

  • NIS2: protects SECURITY OF NETWORK AND INFORMATION SYSTEMS. Focus on availability and integrity of essential services
  • GDPR: protects PERSONAL DATA of data subjects. Focus on confidentiality, integrity and accountability of natural persons' processing
  • Overlap: a security incident affecting personal data activates BOTH regimes. E.g. ransomware encrypting customer DB = NIS2 (availability compromised) + GDPR (data breach)
  • Cumulative sanctions: NIS2 up to 10M EUR / 2% turnover for essentials; GDPR up to 20M / 4%. CAN be cumulated for same event
  • Different authorities: ACN for NIS2, DPA for GDPR. They must coordinate but don't always do so timely

Operational checklist if your client is a NIS2 entity

  • Verify scope: is the client essential or important under Decree 138/2024?
  • ACN registration: has the client registered on the ACN portal?
  • Contact point: who is the NIS Coordinator? Is the appointment in writing?
  • Incident management policy: does it exist? Does it include a 'DPO coordination' chapter? Timing: within 4h of internal trigger the DPO must also be notified
  • Notification templates: have ACN and DPA notification templates been prepared? Are they consistent?
  • Tabletop exercise: has a multi-regime simulated incident been done in the last year?
  • Supplier chain: has the client mapped NIS2-critical suppliers (cloud, MSP, ICT) with appropriate contractual clauses?
  • Training: has management completed mandatory NIS2 training (art. 23)?

In DPO Workspace

The Events/Workflow section includes a 'Multi-regime NIS2 Incident' template that triggers automatically when a NIS2-flagged client reports an incident. Generates 24h ACN + 72h DPA checklist with separate but coordinated timing.

Official source:Italian Legislative Decree 138/2024 - NIS2 transpositionOfficial source:ACN - Italian National Cybersecurity Agency

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min