When a company suffers a cyberattack, technical action to contain the incident is not enough. It must also quickly establish whether the event needs to be notified, to which authority and on what terms.
The regulatory framework is set out in Regulation (EU) 2016/679 (hinc, “GDPR”) and Directive (EU) 2022/2555 (hinc, “NIS2 Directive”), transposed into Italian law by Legislative Decree No. 138 of 4 September 2024.
The two regimes may apply at the same time, but they govern different matters.
Cyber incident and data breach: the difference
Cyber incident
NIS2 Directive
An event that compromises the availability, authenticity, integrity or confidentiality of data, or of the services offered by network and information systems.
ExampleAn attack that makes a service unavailable, without affecting personal data.
Data breach
GDPR
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
ExamplePersonal data sent to the wrong recipient, with no cyberattack involved.
⇄The two cases do not coincide: they may occur separately or together, and in the latter case the conditions must be assessed independently.
A cybersecurity incident is an event that compromises the availability, authenticity, integrity or confidentiality of data or of the services offered by network and information systems.
A data breach, by contrast, specifically concerns personal data and consists of a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, such data.
The two concepts therefore do not necessarily coincide. An attack that makes a service unavailable may constitute a cyber incident without involving a personal data breach. Conversely, sending personal data to the wrong recipient may amount to a data breach even in the absence of a cyber attack.
Data breach: obligations under the GDPR
Where the breach concerns personal data, Articles 33 and 34 GDPR apply.
If the data breach poses a risk to the rights and freedoms of natural persons, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
In Italy, the competent authority is the Garante per la protezione dei dati personali.
Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must also communicate it to data subjects without undue delay.
A processor who becomes aware of the breach must, in turn, inform the controller without delay.
Significant incident · NIS2 → CSIRT Italia
Early warning
From becoming aware of the significant incident.
Notification
Information available on the incident and initial assessment of severity and impact.
Final report
Detailed description of the incident, its causes and the measures taken. The deadline runs from the 72-hour notification.
Data breach · GDPR → Garante and data subjects
Notification to the supervisory authority
Without undue delay and, where feasible, within 72 hours of becoming aware of it, if the breach poses a risk to the rights and freedoms of natural persons.Art. 33 GDPR
Communication to data subjects
Where the breach is likely to result in a high risk to the rights and freedoms of natural persons.Art. 34 GDPR
Incident reporting and NIS2
The NIS2 Directive imposes different obligations on entities operating in sectors deemed critical or highly critical, including energy, transport, banking and finance, healthcare, digital infrastructure, ICT services, public administration, water, waste management, postal services, etc.
Article 25 of Legislative Decree No. 138/2024 sets out a multi-stage incident reporting procedure for significant incidents.
In particular, the following must be submitted to the Computer Security Incident Response Team (CSIRT) Italia:
- within 24 hours of becoming aware of the significant incident, an early warning;
- within 72 hours, a notification containing the available information on the incident and an initial assessment of its severity and impact;
- within one month of the 72-hour notification, a final report containing a detailed description of the incident, its causes and the measures taken.
The particularly short deadlines make it essential for the company to have internal procedures in place before an incident occurs.
When GDPR and NIS2 overlap
A single cyberattack can trigger both regimes.
This is the case, for example, with ransomware that not only compromises the IT systems of an entity subject to NIS2 but also results in the exfiltration of personal data.
In such a case, the conditions under each regime must be assessed separately: on the one hand, those relating to notification of the significant incident to CSIRT Italia; on the other, those concerning notification of the data breach to the Garante and, where applicable, communication to data subjects.
The obligations are therefore not necessarily mutually exclusive.
Internal responsibilities
The speed required by the legislation makes it essential to establish in advance who must do what within the organisation. The IT (Information Technology) function must detect and contain the incident and gather the necessary technical information. The Chief Information Security Officer (CISO) must assess its significance from a cybersecurity standpoint, while the Data Protection Officer (DPO), where appointed under the GDPR, must be involved in assessing any personal data breach.
IT
Detects and contains the incident, and gathers the necessary technical information.
CISO
Assesses the significance of the event from a cybersecurity standpoint.
DPO
If appointed, is involved in assessing any personal data breach.
Legal and management
Check the applicable obligations and ensure notification deadlines are met.
→Escalation procedures are needed to carry information from technical functions to decision-makers within the required deadlines.
Finally, the legal function and management must verify the applicable regulatory obligations and ensure that notification deadlines are met.
It is therefore necessary to put in place escalation procedures that allow information to pass quickly from technical functions to those responsible for taking decisions
Cybersecurity compliance: preparing before the incident
Handling a cyberattack properly cannot be organised in the middle of the emergency.
Effective cybersecurity compliance requires incident response procedures, clearly defined roles, internal information flows and contractual arrangements with suppliers that ensure incidents are reported promptly.
In this context, the distinction between a cybersecurity incident and a data breach is of fundamental importance: not every cyber incident constitutes a personal data breach, and not every breach triggers the same notification obligations.
The aim is to enable the organisation to detect, classify and manage the incident and, where necessary, make the notifications required by the GDPR and NIS2 within the statutory deadlines.
Domande frequenti
Must a cyberattack always be notified to the Garante and CSIRT Italia?
No. The obligations depend on the nature of the incident and on the organisation involved. The GDPR requires notification to the Garante when a personal data breach is likely to result in a risk to the rights and freedoms of natural persons; NIS2, by contrast, sets specific obligations for significant incidents affecting entities within its scope. If a single event meets both sets of conditions, the two assessments must be carried out separately and may result in more than one notification.
How can Bliss help after a cyber crisis?
Bliss can support the organisation on governance, crisis management and communication with the market and stakeholders. A cyberattack can, in fact, have reputational consequences as well as technical and regulatory ones. Bliss operates under an ISO/IEC 27001-certified information management system and can work alongside management in defining processes, responsibilities and the reputational response to the crisis. Strictly legal obligations, however, require the involvement of the relevant professionals.
What does Studio Legale Zaccagnini do in the cyber field?
Studio Legale Zaccagnini also assists companies and managers in cybercrime and corporate criminal law. In the event of a cyber incident, the technical dimension may therefore be accompanied by legal issues relating to unlawful conduct, the organisation's liability and any criminal consequences. The firm has operated since 2001, with offices in Rome and Milan.

