NIS2

Directive (EU) 2022/2555

Directive on measures for a high common level of cybersecurity across the Union

In force since October 18, 2024

Who it applies to

  • Essential and important entities in eighteen sectors, including energy, transport, health, digital infrastructure and public administration
  • Generally medium and large enterprises, with some size-independent categories

Consumer rights

  • Access / know — not granted
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — not granted

Obligations

Consent model
Mixed
Universal opt-out signal
Not required
Risk assessments
Required for higher-risk processing
Data protection officer
Not required
Records of processing
Not required
Processor contract
Required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
Recipients of services must be informed where an incident is likely to affect them
To the regulator
Early warning within 24 hours, incident notification within 72 hours, final report within one month
What triggers it
A significant incident affecting the provision of services

Penalties

Headline
Up to €10 million or 2% of worldwide turnover for essential entities
Private right of action
No — enforcement is by the regulator only
Notes
Notable for reaching management personally: senior managers can be held liable and temporarily barred from management functions for non-compliance.

Exemptions

Entities

  • Most micro and small enterprises, outside the size-independent categories

Sources