NIS2 compliance and data processing: new challenges in practice

The introduction of the NIS2 Directive brings not only cyber security and IT controls into the life of organisations, but also has significant consequences for data processing. During compliance, a number of new or strengthened measures are introduced that directly affect the processing of employees’ personal data. In many cases, these measures appear as mandatory, audited requirements, meaning that companies must reconsider certain aspects of their operations not only from a technical perspective, but also from a legal and data protection perspective.