When data protection is discussed, the first reflex is often to think about GDPR. That is understandable: the regulation has, for several years now, structured the way organisations collect, process and protect personal data. It requires personal data to be processed in a way that ensures an appropriate level of security, including confidentiality, integrity, and protection against unauthorised access or misuse. Source
Today, however, the issue can no longer be addressed only from a privacy perspective. With NIS2, cybersecurity takes on a broader dimension: it also concerns organisational resilience, business continuity, risk management, and the ability to cope with a major incident. NIS2 aims to strengthen the overall level of cybersecurity across the European Union by requiring risk-management measures and incident-reporting obligations for a wide range of entities. Source
In other words, being GDPR-compliant does not automatically mean being ready for NIS2. GDPR focuses on the protection of personal data. NIS2, by contrast, looks more broadly at the security of network and information systems, incident prevention, detection, response, recovery, and impact mitigation. The directive also explicitly states that security must cover stored, transmitted, and processed data. Source
This distinction matters because an organisation may have implemented certain GDPR-related obligations while still being insufficiently prepared from an operational point of view. In practice, protecting data confidentiality is not only about defining rules on paper. It also means ensuring that the systems hosting the data are resilient, that access is properly controlled, that backups are reliable, that teams know how to react, and that operations can continue despite an incident. Source Source
NIS2 specifically encourages organisations to adopt a true culture of risk management. The directive stresses a risk-based approach and the implementation of measures that are appropriate to the organisation’s actual exposure. It does not require everything to be protected in the same way, but rather calls for a clear understanding of what is critical, what is exposed, and what needs to be prioritised. Source
Another important development is that cybersecurity is no longer seen as a purely technical matter. NIS2 reinforces the responsibility of management bodies when it comes to cyber governance. This means that issues related to confidentiality, data integrity, and business continuity can no longer be left solely to IT teams. They need to be understood, governed, and monitored at management level. Source
n this context, data confidentiality should be viewed as an operational outcome, not simply as a compliance box to tick. Confidential data is only truly protected if an organisation is able to control access to it, limit its exposure, detect compromise, respond quickly, and restore its systems without long-term disruption to its operations. This reflects both the spirit of GDPR and that of NIS2, albeit with different and complementary points of focus. Source Source
In practice, this means moving beyond a purely documentary view of compliance. Internal policies are necessary, but they are not enough. Effective data protection also relies on concrete measures: disciplined access management, basic cyber hygiene, user awareness, monitoring, updates, segmentation, backups, crisis preparedness, and recovery capability. NIS2 explicitly refers to a broad approach that takes into account systems, data, human factors, and even the physical environment. Source
The right question, therefore, is not only: are we compliant? The real question is rather: are we truly able to protect our data, absorb an incident, and continue operating? This is where NIS2 brings valuable perspective. It does not replace GDPR, but it does require organisations to look further: governance, resilience, continuity, preparedness, and response capability. Source Source
Ultimately, GDPR and NIS2 pursue a common objective: strengthening trust. The former protects individuals and their personal data. The latter pushes organisations to structure cybersecurity as an essential function of governance and continuity. Together, they send a simple message: data confidentiality can no longer be treated as an isolated issue. It is part of a broader challenge of robustness, accountability, and reliability. Source Source