Two Clocks, One Incident: The DPO’s Decision Tree for NIS2 Article 23 (24h) vs. GDPR Article 33 (72h)
A ransomware attack locks your systems and exfiltrates customer records. Your incident response team declares it a critical event at 09:00. By 09:15, you are running two parallel regulatory obligations — NIS2 Article 23 and GDPR Article 33 — but they do not start from the same moment, they do not go to the same authority, and they are not satisfied by the same information. This guide maps the exact interaction, gives you a decision tree to triage every incident in under five minutes, and defines what the DPO owns versus what the board must sign.
The Awareness Gap: When NIS2’s Clock Starts Before GDPR’s
Both NIS2 Article 23 and GDPR Article 33 use the phrase “becoming aware” as the trigger. The language looks identical. The legal standard is not.
Under NIS2, Article 23(4) starts the 24-hour early warning clock from the moment your organisation has reasonable grounds to believe a significant incident is occurring or has occurred [1]. The directive does not require confirmation. Suspicion is enough — and that interpretation aligns with NIS2’s broader emphasis on proactive threat response. If a security analyst flags anomalous exfiltration behaviour at 09:00 and escalates it as a suspected incident, the NIS2 clock has started.
Under GDPR, the European Data Protection Board’s Guidelines 9/2022 interpret “becoming aware” as requiring a reasonable degree of certainty that a security incident has occurred and that personal data has been compromised [4]. That higher evidential standard means your GDPR clock may not start until your incident response team has confirmed that personal data was actually affected — which could be hours after the NIS2 clock started.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
This gap has a concrete consequence: you may legally owe your CSIRT a NIS2 early warning at Hour 23 while you are still inside your triage window for determining whether GDPR Article 33 applies at all. Running these two assessments simultaneously, on separate tracks, is not optional — it is how the legislation was designed. NIS2 Recital 14 confirms the two frameworks operate in parallel, with NIS2 explicitly “without prejudice” to GDPR [6].
The mechanism behind the gap: NIS2’s early warning exists to give the CSIRT operational intelligence quickly — it is an alert, not a formal breach determination. GDPR’s notification is a legal finding that personal data rights have been compromised. These serve different regulatory purposes, which is why their evidentiary thresholds differ.
The Decision Tree: GDPR Article 33, NIS2 Article 23, or Both
Every significant incident at an NIS2-covered entity requires a four-question assessment to determine which notification obligations apply. Work through the questions in order — first match determines the track.
| Question | Yes | No |
|---|---|---|
| Q1. Is your organisation in NIS2 scope? (Annex I or II sector, medium-sized or larger — or in a size-exempt category such as DNS, trust services, or public comms networks) [5] | Continue to Q2 | NIS2 Art.23 does not apply. Assess only GDPR Art.33. |
| Q2. Has the incident caused — or is it capable of causing — severe operational disruption of your services, financial loss for your entity, or considerable material/non-material damage to other persons? [1] | NIS2 Art.23 notification required. Continue to Q3. | NIS2 significance threshold not met. Assess only GDPR Art.33. |
| Q3. Does the incident involve accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data? | Continue to Q4 | NIS2 Art.23 only. No personal data breach — CSIRT notification only. |
| Q4. Is the breach likely to result in a risk to the rights and freedoms of natural persons? [3] | Both Art.23 and Art.33 triggered. Run the dual-track workflow. | NIS2 Art.23 only. Document the GDPR low-risk assessment under Art.33(5) [3]. |
Three common incident types fall cleanly into a single track. A DDoS attack that disrupts your service without touching personal data is NIS2 Art.23 only. A customer data leak at a small retailer below NIS2 size thresholds is GDPR Art.33 only. A ransomware attack at a hospital encrypting both clinical systems and patient records is both — and that dual trigger is where DPO and CISO coordination becomes critical. Note that Q2’s “capable of causing” language means a contained incident that did not actually cause damage can still be significant if the potential was present [1].
Running Both Tracks: The Parallel Notification Workflow
When both obligations are triggered, the two tracks run in parallel from the moment of detection. They share the same underlying incident data but file to different authorities, on different timelines, with different content requirements. Both notifications will be compared by regulators — inconsistencies between the NIS2 incident notification and the GDPR breach notification create enforcement risk beyond what either filing alone would generate.
| Timepoint | NIS2 Track → CSIRT/NCA | GDPR Track → DPA |
|---|---|---|
| Hour 0 Detection |
NIS2 clock starts at suspicion. CISO and DPO alerted. Incident log opened. | DPO begins GDPR scope assessment. Is personal data involved? What data categories? |
| Hours 0–24 | DPO + CISO draft early warning to CSIRT: suspected malicious cause (yes/no) + cross-border impact potential (yes/no). Filed before Hour 24 [1]. | If personal data confirmed compromised with risk to individuals: GDPR 72h clock starts at that moment of certainty. DPA notification draft begins [3] [4]. |
| Hours 24–72 | NIS2 72h update prepared: severity assessment, indicators of compromise, preliminary root cause, containment actions taken [1]. | GDPR notification filed to DPA: breach nature, data categories and approximate subject count, likely consequences, measures taken or proposed [3]. Phased reporting permitted under Art.33(4) if full details not yet available. |
| 1 Month | NIS2 final report: full incident description, confirmed root cause, mitigation measures applied and ongoing, cross-border impact documentation [1]. | No GDPR equivalent final report, but Art.33(5) documentation continues: remediation evidence, data subject notifications under Art.34 if applicable, DPA follow-up correspondence. |
The GDPR clock and the NIS2 clock may not start at the same moment. If personal data scope is unclear at Hour 0, the NIS2 early warning can legally fire at Hour 23 while you are still inside the GDPR assessment window. GDPR’s phased reporting provision (Article 33(4)) exists precisely for this scenario: file what you know within 72 hours of GDPR awareness, then supplement without undue further delay. Waiting for a complete picture before filing is the most common Art.33 compliance failure.
A unified incident register that records both tracks in a single document — with timestamped entries for each escalation, each filing, and each authority response — is the most audit-resistant structure for managing this parallel process [7]. The register becomes your Art.33(5) documentation simultaneously.
The DPO’s Role: What You Own vs. What the Board Signs
NIS2 creates no equivalent of the GDPR Data Protection Officer. Article 20 places accountability for cybersecurity risk management with the management body — the board or a delegated executive — who must approve the NIS2 risk management measures and take responsibility for incident notifications. The DPO’s mandate is a GDPR construct, derived from Articles 37–39.
In a dual-trigger incident, the DPO’s work divides into three distinct responsibilities:
Sole owner: GDPR Art.33 threshold determination. The DPO is accountable for completing Questions 3 and 4 of the decision tree. Only the DPO should certify whether personal data is involved and whether the risk-to-individuals threshold has been met. This determination drives whether the GDPR track opens at all.
Mandatory signatory: DPA contact point. GDPR Art.33(3)(b) requires the breach notification to include the DPO’s name and contact details. The DPO is the supervisory authority’s formal contact for follow-up questions, requests for additional information, and enforcement correspondence. In practice, this means the DPO must be reachable for the full duration of the DPA’s investigation — not just the initial 72 hours.
Coordination role: NIS2 consistency check. The DPO should review the NIS2 incident notification content to confirm the personal data dimension is described consistently with the GDPR filing. The DPO does not sign the NIS2 notification — that is the board’s responsibility — but misalignment between the two filings generates the highest post-incident enforcement risk. Under NIS2 Article 35, the CSIRT may alert the DPA directly (see next section), meaning the DPA may receive the NIS2 filing content before the GDPR notification arrives.
Under Art.33(5), the DPO also owns the internal documentation obligation. Every incident — including those where Art.33 notification to the DPA was not required — must be documented with the facts of the breach, its effects, and the remedial action taken. For dual-trigger incidents where the GDPR threshold was not met, the documentation must include the reasoning for the no-notification decision. Regulators examine this record during supervisory reviews [3].
NIS2 Article 35: The Provision That Connects Both Authorities
Most dual-compliance guidance stops at the entity level: file two reports to two authorities within two timelines. NIS2 Article 35 adds a third dimension — the authorities coordinate with each other — and that coordination directly affects the DPO’s enforcement exposure.
Article 35(1): Authority-to-authority notification. When the NIS2 competent authority discovers that a NIS2 violation could constitute a personal data breach under GDPR Art.4(12), it must inform the relevant GDPR supervisory authority without undue delay [2]. This means your CSIRT, upon receiving your NIS2 early warning, may proactively alert the DPA before you file your GDPR Art.33 notification. You have no control over this. What you can control is whether both filings are consistent from the moment the CSIRT receives the NIS2 early warning.
Article 35(2): The no-double-penalty rule. If the GDPR supervisory authority has already imposed an administrative fine for conduct that also constitutes a NIS2 violation, the NIS2 competent authority may not stack an additional NIS2 administrative fine for the same conduct [2]. This reduces maximum financial penalty exposure for dual-trigger incidents. The reduction applies only to administrative fines — NIS2 enforcement measures such as binding remedial orders, corrective action instructions, compliance audits, and operational restrictions remain fully available regardless of any GDPR fine already imposed.
To put the penalty context in numbers: GDPR fines reach EUR 20 million or 4% of global annual turnover for the most serious violations, while NIS2 fines reach EUR 10 million or 2% of global annual turnover for essential entities. Article 35(2) prevents the totals from being added when both authorities target the same conduct — a meaningful protection for the largest dual-trigger incidents.
Article 35(3): Cross-border coverage. When the NIS2 competent authority is in one Member State but the relevant DPA is in another — common for multinational entities subject to GDPR’s lead supervisory authority mechanism — the NIS2 authority still notifies its own Member State’s DPA, who then coordinates through GDPR’s cross-border consistency framework [2].
The practical implication: you cannot treat NIS2 and GDPR notifications as independent documents prepared by different teams without coordination. Once the NIS2 early warning is received, Article 35(1) means the DPA may be alerted within hours. Ensuring both tracks are internally consistent before the first CSIRT filing is the point in the workflow where the DPO’s coordination role matters most.
The Processor Cascade: Building the 12-Hour Buffer
If your organisation processes personal data on behalf of another controller, GDPR Art.33(2) requires you to notify the controller “without undue delay” after becoming aware of a breach [3]. In a dual-trigger scenario where your client is a NIS2-covered entity, that processor notification must arrive in time for the controller to run both the NIS2 24-hour early warning and the GDPR 72-hour notification in sequence.
The arithmetic creates pressure. If the controller needs two hours to assess both dimensions and draft the CSIRT early warning, your notification must arrive by Hour 22 at the latest. National data protection authority guidance and standard industry practice specify a processor notification window of 12 to 24 hours from the processor’s own moment of awareness [7]. That contractual specificity matters: “without undue delay” is interpreted differently by different DPAs, and a vague obligation cannot be enforced when a dual-track deadline expires.
Review your current data processing agreements and confirm three things: the notification window is specified in hours (not left to “without undue delay”), the window accounts for the 24-hour NIS2 deadline your controller clients face, and the notification format covers both the personal data dimension (enabling GDPR triage) and the operational impact dimension (enabling NIS2 significance assessment) in a single communication.
Looking Ahead: The Digital Omnibus Single Entry Point
The European Commission’s Digital Omnibus package, proposed in 2025, includes a proposed Article 23bis that would create a single entry point for incidents simultaneously triggering NIS2 and GDPR reporting obligations, managed by ENISA. Under the proposal, one notification to the unified portal would satisfy obligations to both the competent authority/CSIRT and the DPA — eliminating the parallel-track structure described in this guide.
That proposal has not been ratified at the time of publication. No confirmed entry-into-force date exists. Until it becomes law, the dual-track approach remains the legal standard. The preparation work is not wasted: the underlying incident data required for both the NIS2 and GDPR notifications is identical. Organisations that build a unified incident register now will transition to the single-entry-point system without restructuring their documentation.
Frequently Asked Questions
Can the DPO also serve as the NIS2 operational point of contact?
There is no legal prohibition, but GDPR Article 38 requires the DPO to operate free of instructions regarding the exercise of their tasks and to have no conflict of interest. A DPO who also manages NIS2 operational response in a line-management capacity risks that independence. The most common structure separates the NIS2 operational contact (typically CISO or IT lead) from the GDPR contact (DPO), with a defined handshake protocol for dual-trigger incidents.
What if the GDPR Art.33 risk threshold is not met but NIS2 Art.23 is triggered?
File the NIS2 Art.23 notification to the CSIRT. Document the GDPR Art.33 non-notification decision under Art.33(5), including the risk assessment that supported it. Under Article 35(1), the CSIRT may still inform the DPA of the incident. A documented, reasoned no-notification decision is your protection if the DPA subsequently enquires [3].
What information can the DPO share with the CSIRT under GDPR?
The DPO may provide operational details — attack vector, systems affected, service disruption — without restriction. Sharing personal data categories, affected subject counts, or breach-specific personal details with the CSIRT requires a legal basis under GDPR, typically legitimate interests or legal obligation depending on jurisdiction and data type. The NIS2 early warning template was designed to capture operational impact without requiring personal data fields.
Does the NIS2 24-hour early warning need to be a complete assessment?
No. Article 23(4) explicitly contemplates an early warning containing only the information available at that point. The required fields are: suspected malicious or unlawful cause (yes/no) and potential for cross-border impact (yes/no). Accuracy matters — do not include unverified claims — but a two-field early warning filed at Hour 23 is legally compliant. The 72-hour notification carries the substantive content [1].
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- European Union. Article 23: Reporting Obligations — Directive (EU) 2022/2555 (NIS2). nis-2-directive.com.
- European Union. Article 35: Coordination with Data Protection Supervisory Authorities — Directive (EU) 2022/2555 (NIS2). nis-2-directive.com.
- European Union. Article 33 GDPR — Notification of a personal data breach to the supervisory authority. gdpr-info.eu.
- European Data Protection Board. Guidelines 9/2022 on personal data breach notification under GDPR, Version 2.0 (April 2023). edpb.europa.eu.
- European Union. Article 2: Scope — Directive (EU) 2022/2555 (NIS2). nis-2-directive.com.
- European Union. Recital 14 — Directive (EU) 2022/2555 (NIS2). streamlex.eu/laws/nis2-en-recitals/.
- ISMS.online. NIS2 vs GDPR Reporting: Overlaps, Deadlines, and Board-Level Risks Explained. isms.online.
- IAPP. NIS2 Directive: Mapping the Interplays with the GDPR. iapp.org.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
