Many companies treat GDPR and cybersecurity as two entirely separate agendas: GDPR as a legal matter, security as an IT issue. This approach is inefficient and in fact counterproductive. GDPR and cybersecurity share a common foundation, data protection, and a large part of the technical measures meet the requirements of both regulations simultaneously.
Properly coordinated cooperation between the DPO (Data Protection Officer) and the CISO (Chief Information Security Officer) can dramatically reduce duplicate work for a company while simultaneously raising the overall level of data protection.
GDPR Article 32: Technical and organisational measures
From a cybersecurity perspective, the key provision of the GDPR is Article 32: Processing Security. The administrator and the processor are obliged to "implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
Article 32 explicitly mentions as examples of suitable measures:
- Pseudonymisation and encryption personal data
- Permanent confidentiality, integrity, availability and resilience systems and processing services
- Capability restore availability and access to personal data in a timely manner (backups, DRP)
- Regular testing, assessment and evaluation effectiveness of the measures taken
This wording is deliberately technology-neutral: the GDPR does not specify particular tools, but principles. At the same time, it is a call to action: without cybersecurity, Article 32 cannot be met. Firewalls, disk encryption, access management, backups, penetration testing, all of these are both GDPR measures and security measures at once.
Principle of proportionality and risk-based approach
It is important that GDPR does not require absolute security. It requires appropriate security. proportionate to the risk. This includes taking into account: the state of the art, implementation costs, the nature and scope of processing, and the likelihood and severity of risks to the rights of data subjects. The same risk-based approach applies to NIS2. Companies that conduct a formal risk analysis for GDPR can use the same methodology (with minor adjustments) for NIS2 compliance.
NIS2 vs GDPR: Where they differ and where they complement each other
The NIS2 Directive and GDPR are two distinct regulations with different objectives, but they share overlapping areas and can reinforce each other.
GDPR protects the rights of natural persons in relation to the processing of their personal data. It applies to practically all organisations processing personal data of individuals in the EU. Penalties up to 20 million EUR or 4% of global annual turnover.
NIS2 protects the security of networks and information systems in critical and important sectors. Applies to specific categories of entities (defined by law). Penalties up to 10 million EUR or 2% of global turnover for basic entities.
Key intersections of both regulations
- Risk management - both regulations require systematic risk management
- Technical measures - encryption, access control and patch management contribute to compliance with both
- Supply chain - GDPR: contracts with processors; NIS2: security of critical service suppliers
- Incident reporting - both regulations require reporting incidents (to different authorities, within different deadlines)
- Documentation and Audit - both require documented proof of measures taken
An organisation that builds its security programme correctly from the ground up can cover a substantial part of the requirements of both regulations with one set of technical measures and one set of processes.
Data breach notification: 72-hour deadline and what it means in practice
One of the most discussed GDPR obligations is obligation to report personal data security breaches (data breach). Article 33 stipulates: the controller is obliged to report the breach to the supervisory authority (in the Czech Republic, the Office for Personal Data Protection, ÚOOÚ). without undue delay, no later than within 72 hours from the moment it becomes aware of the breach, if the breach is likely to result in a risk to the rights and freedoms of natural persons.
72 hours is an extremely short deadline, especially if the organisation does not have a prepared Incident Response plan. In practice, this means:
- Attack or leak must be quickly detected - without monitoring and SIEM/SOC, it takes an average of 197 days (IBM Cost of Data Breach Report)
- It must exist internal escalation procedure - who receives the information, who decides, who reports
- The Data Protection Officer must be informed immediately. and must assess whether the reporting obligation applies to the given incident
- Must be prepared notice template for ÚOOÚ: form with required information
- If the incident also affects NIS2 entities, simultaneously reported by NÚKIB (with varying deadlines and formats)
If the risk to individuals is high, an additional obligation applies. inform the directly concerned data subjects (article 34 of the GDPR) - without undue delay.
How to prepare for a data breach
Preparation includes: a defined Incident Response plan with clear responsibilities, regular exercises (tabletop exercises), prepared templates for reporting to ÚOOÚ and communicating with relevant entities, and recording all incidents including those not requiring notification (internal records).
DPO and CISO Collaboration: How to Set It Up Effectively
DPO (Data Protection Officer) and CISO are distinct roles with different focuses, but their work naturally overlaps in the area of data protection. Without cooperation, duplication or blind spots arise.
Pseudonymisation and encryption as an intersection of both areas
Encryption you can count on it and during transmission it is a technical security measure that simultaneously reduces the risk under GDPR. If stolen data are encrypted and the attacker does not have the key, the risk to data subjects is minimal, and reporting a data breach may not be mandatory. Encryption is therefore an investment with dual value.
Pseudonymisation (replacing identifiers with pseudonyms) reduces risk and regulatory burden: pseudonymised data remains personal data under GDPR but carries a lower risk profile. A breach has a lesser impact.
Setting up effective collaboration between GDPR compliance and cybersecurity so that the company fulfils both regulations efficiently and without unnecessary duplication is precisely what SecureOn does. SecureOn.cz assists: whether as CISOaaS, in preparation for an audit, or when setting up Incident Response processes.