NIS2
Directive (EU) 2022/2555Directive on measures for a high common level of cybersecurity across the Union
In force since October 18, 2024
Who it applies to
- Essential and important entities in eighteen sectors, including energy, transport, health, digital infrastructure and public administration
- Generally medium and large enterprises, with some size-independent categories
Consumer rights
- Access / know — not granted
- Correction — not granted
- Deletion / erasure — not granted
- Portability — not granted
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — not granted
Obligations
- Consent model
- Mixed
- Universal opt-out signal
- Not required
- Risk assessments
- Required for higher-risk processing
- Data protection officer
- Not required
- Records of processing
- Not required
- Processor contract
- Required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
Breach notification
- To individuals
- Recipients of services must be informed where an incident is likely to affect them
- To the regulator
- Early warning within 24 hours, incident notification within 72 hours, final report within one month
- What triggers it
- A significant incident affecting the provision of services
Penalties
- Headline
- Up to €10 million or 2% of worldwide turnover for essential entities
- Private right of action
- No — enforcement is by the regulator only
- Notes
- Notable for reaching management personally: senior managers can be held liable and temporarily barred from management functions for non-compliance.
Exemptions
Entities
- Most micro and small enterprises, outside the size-independent categories
Sources
- PrimaryRegulationDirective (EU) 2022/2555 — NIS2 text