NIS2 compliance and data processing: new challenges in practice

The introduction of the NIS2 Directive brings not only cyber security and IT controls into the life of organisations, but also has significant consequences for data processing. During compliance, a number of new or strengthened measures are introduced that directly affect the processing of employees’ personal data. In many cases, these measures appear as mandatory, audited requirements, meaning that companies must reconsider certain aspects of their operations not only from a technical perspective, but also from a legal and data protection perspective.

This is particularly evident in the area of identity verification. Hungarian legislation – for example, Decree 1/2025 (31 January) of the SZTFH on the procedure for conducting cyber security audits and on the maximum fee for cyber security audits – sets out detailed audit requirements in relation to access to IT systems. One of the central elements of these requirements is that users may only be granted access if their identity has been properly verified. In practice, this means that organisations must ensure that user identifiers can be clearly linked to a specific individual, and that the identity of the persons behind the access rights is properly verified and documented.

The requirements set out in the decree also provide that it is not sufficient merely to collect evidence relating to the verification of identity. Such evidence must also be authenticated, checked and validated, and the methods applied must be determined in advance. In certain cases, identification in person or multi-channel confirmation may also be required. Taken together, this results in organisations handling identification-related data in a more structured and detailed manner than before, including, for example, data from identity documents, information related to identification processes, or audit logs.

These measures clearly create new purposes for data processing, for which an appropriate basis must also be ensured from a GDPR perspective. In most cases, the legal basis for the processing will be a legal obligation; however, this alone is not sufficient: companies must precisely define the purpose, scope and duration of the processing, while also ensuring compliance with the principles of proportionality and necessity. NIS2 compliance does not exempt organisations from complying with data protection rules; on the contrary, in many cases it requires their even stricter and more conscious application.

All of this also generates significant documentation tasks. Organisations must review and update their privacy notices, particularly those addressed to employees. In addition, internal policies must be amended, for example IT security and access management policies, and records of processing activities (ROPA) must also be clarified and updated. Particular attention should also be paid where central IT or security functions operate within a group of companies: in such cases, it is essential to have appropriate data processing agreements in place that comply with Article 28 GDPR and regulate in detail the categories of data processed, the purpose of the processing, and the rules on instructions.

NIS2 compliance also brings noticeable changes at employee level. Stricter identification requirements, enhanced logging, and the monitoring of access rights are all elements that become part of day-to-day operations. It is therefore particularly important that employees receive appropriate and clear information about what data their employer processes about them, for what purpose, and with what safeguards.

Overall, it can be said that NIS2 is not merely a cyber security compliance exercise, but a complex set of requirements that also fundamentally affects data processing practices. Organisations that treat this not as an isolated IT project, but as a comprehensive legal and data protection issue, will not only be able to ensure compliance, but can also establish more transparent and auditable operations in the longer term.