Skip to content

GDPRNIS2 crosswalk

A control-by-control mapping between General Data Protection Regulation (EU 2016/679) and NIS2 Directive (EU 2022/2555). 4 mappings.

GDPRNIS2RelationshipNotes
Art. 25
Data protection by design and by default
Art. 21(2)(a)
Risk analysis and information system security policies
RelatedCurated
Gouvernance et politique de sécurité
Art. 32
Security of processing
Art. 21(2)(h)
Cryptography and encryption
PartialCurated
Cryptographie et protection des données
Art. 33
Notification of a personal data breach to the supervisory authority
Art. 21(2)(b)
Incident handling
RelatedCurated
Réponse aux incidents et notification des violations
Art. 33
Notification of a personal data breach to the supervisory authority
Art. 23
Reporting obligations
RelatedCurated
Réponse aux incidents et notification des violations

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.