Let's talk about your project
01 / Knowledge hub

GDPR and NIS2: how they affect your company and how to prepare

GDPR governs the protection of personal data, and NIS2 sets the cybersecurity obligations of organisations in important sectors; both are European Union rules. Both can concern not only EU companies but also companies that serve people in the EU or supply organisations there. In this guide we explain the security side of the two regulations and the steps to prepare; it is not a substitute for a legal assessment.

  1. 01

    The short answer

    If you offer goods or services to people in the EU or monitor their behaviour, GDPR may apply to you too. NIS2 directly covers medium-sized and large organisations in certain sectors; even if you are out of scope, your EU customers may ask you, as a supplier, for similar security measures. Whether you are in scope is a matter for a legal assessment; the security measures, however, can be planned starting today.

  2. 02

    The security side of GDPR

    GDPR expects organisations that process personal data to take technical and organisational measures appropriate to the risk (Article 32): limiting access rights, encryption, backup and restore, logging and regular testing of the measures. When a personal data breach is discovered, the supervisory authority is notified within 72 hours where required (Article 33). In Turkey, KVKK sets out similar security obligations.

  3. 03

    Who NIS2 covers

    NIS2 (EU Directive 2022/2555) covers, as “essential” and “important” entities, generally medium-sized and large organisations in sectors such as energy, transport, banking, health, digital infrastructure, cloud and data centre services, managed IT services, food, manufacturing and postal services. The directive is applied through national law in each EU country, so the details can vary from country to country.

  4. 04

    The measures NIS2 expects

    Article 21 of the directive lists risk-based measures: risk analysis and information security policies, incident handling, business continuity and backups, supply chain security, security in the development and maintenance of systems including vulnerability handling, assessing the effectiveness of the measures, basic cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. The management body is responsible for approving these measures and overseeing their implementation.

  5. 05

    Incident reporting: 24 hours, 72 hours, one month

    An organisation in scope of NIS2 must submit an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month. These deadlines can only be met with an incident response plan written in advance, named owners and monitoring that can detect the incident. The 72-hour breach notification under GDPR benefits from the same preparation.

  6. 06

    Where preparation starts

    The first step is a gap analysis that compares the current state with the target framework: which measures exist, which exist in part and which are missing. Then come the asset and data inventory, access rights, a backup and restore test, the incident response plan and the supplier list. Policies should be short enough for the team to actually follow; a document that stays on paper helps neither in an incident nor in an audit.

  7. 07

    How we work at Doki

    We provide readiness consulting for the technical and organisational security measures GDPR and NIS2 expect: gap analysis, a roadmap to close the gaps, policy and procedure drafts, an incident response and notification plan, penetration testing and monitoring. Doki is not a law firm; legal matters such as whether you are in scope, data processing agreements and privacy notices are handled with your lawyer. Official audits and certification decisions are made by the competent bodies; we get you ready for that day.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.