TL;DR for the DPO
If your client is an 'essential entity' or 'important entity' under NIS2 (e.g. healthcare, energy, banks, transport, cloud providers, online platforms), you MUST coordinate with the Security Manager/CISO on incident management processes. NIS2 requires initial notification within 24h to ACN; GDPR requires notification within 72h to the DPA. Same incident may trigger both regimes - the flow must be unified to avoid contradictions in statements.
What changes with Legislative Decree 138/2024
Legislative Decree 138/2024 of September 4, 2024 transposed in Italy the NIS2 Directive (EU 2022/2555). It is effective since October 16, 2024 but sanctions apply from January 1, 2026. The Italian National Cybersecurity Agency (ACN) is the competent authority for entity registration and incident notification reception. The new aspect vs NIS1: scope expanded to 18 sectors, including cloud platforms, datacenters, ICT-managed services, social networks.
The NIS2-GDPR relationship
- NIS2: protects SECURITY OF NETWORK AND INFORMATION SYSTEMS. Focus on availability and integrity of essential services
- GDPR: protects PERSONAL DATA of data subjects. Focus on confidentiality, integrity and accountability of natural persons' processing
- Overlap: a security incident affecting personal data activates BOTH regimes. E.g. ransomware encrypting customer DB = NIS2 (availability compromised) + GDPR (data breach)
- Cumulative sanctions: NIS2 up to 10M EUR / 2% turnover for essentials; GDPR up to 20M / 4%. CAN be cumulated for same event
- Different authorities: ACN for NIS2, DPA for GDPR. They must coordinate but don't always do so timely
Operational checklist if your client is a NIS2 entity
- Verify scope: is the client essential or important under Decree 138/2024?
- ACN registration: has the client registered on the ACN portal?
- Contact point: who is the NIS Coordinator? Is the appointment in writing?
- Incident management policy: does it exist? Does it include a 'DPO coordination' chapter? Timing: within 4h of internal trigger the DPO must also be notified
- Notification templates: have ACN and DPA notification templates been prepared? Are they consistent?
- Tabletop exercise: has a multi-regime simulated incident been done in the last year?
- Supplier chain: has the client mapped NIS2-critical suppliers (cloud, MSP, ICT) with appropriate contractual clauses?
- Training: has management completed mandatory NIS2 training (art. 23)?
In DPO Workspace
The Events/Workflow section includes a 'Multi-regime NIS2 Incident' template that triggers automatically when a NIS2-flagged client reports an incident. Generates 24h ACN + 72h DPA checklist with separate but coordinated timing.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free