The average DPO has plenty on their plate: reviewing Data Protection Impact Assessments (DPIAs), checking data processing agreements, coordinating data breach notifications, and squeezing in conversations with marketing about cookie use. That's not always because the DPO deliberately set it up that way, sometimes other people in the organisation simply don't know enough about handling personal data. Either way, as the DPO you are the in-house expert for anything involving personal data.
Since 15 August, the Cyber Security Act (CSA), the Dutch implementation of the NIS2 Directive, has entered the picture. Does that land on the same plate?
The DPO's job description appears in Article 39 GDPR. Tasks include monitoring GDPR compliance and data-protection policy, and keeping the organisation informed of new developments. More concretely, the DPO advises on DPIAs and ensures awareness across the organisation remains up to standard. Where necessary, the DPO liaises with the Dutch Data Protection Authority (AP).
Sharp-eyed readers will have noticed (or long since known) that the job description does not stop at the GDPR's contents. Your remit as a DPO extends to supervising and advising on "data-protection provisions", and that does not end at Article 99 GDPR. Although the CSA is, strictly speaking, not a data-protection law but rather legislation on the resilience of network and information systems (with its own duty of care, notification obligation and supervisory authority), it can still touch on data protection.
Nowhere does it say the DPO must oversee full CSA compliance. That falls outside your role: an information-security officer or CISO sits on that. But the DPO who assumes the CSA is "someone else's problem" may miss the spots where the law trips them up anyway.
During an incident, first and foremost. The same systems that process personal data often fall under the new duty of care at a CSA-obligated organisation. Perform only the GDPR assessment and you may overlook a second clock ticking: an early warning within 24 hours and a notification within 72 hours, submitted to an entirely different authority than the AP. Note that this clock starts only for a significant incident, broadly defined as one causing serious operational disruption, substantial financial damage, or substantial (threatened) harm to other parties. You need not file that notification yourself, but you do want to know whether your organisation falls under the CSA and whether the incident procedure is set up accordingly.
And with the board. The GDPR arranges accountability at organisational level (Articles 5(2) and 24), but the CSA places it squarely on the board: directors must approve the measures and are themselves required to attend training. For essential entities, the supervisory authority can even ask a court to suspend a director in cases of serious negligence. For you as DPO, strange as it sounds, that's good news. A board personally accountable for security suddenly listens far more attentively to advice that used to gather dust. Seize that momentum: your case for appropriate security lands nowhere better than with a director who has just read that suspension is on the table.
Both points are worth knowing. Neither, though, changes what you actually do on an ordinary Tuesday. The third intersection moves a little closer to that day-to-day reality.
For the third intersection we arrive at Article 32 GDPR, an odd one out. Where the GDPR attempts to lay down clear rules in many areas, Article 32 is an open norm, and deliberately so. Article 32 requires appropriate security measures. Had the legislator specified precisely which measures qualify, we would have been back at the negotiating table for an update almost immediately after the law took effect. Until now, you largely had to argue what "appropriate" means yourself (armed, admittedly, with helpful guidance from supervisory authorities and bodies such as the EDPB). The CSA elaborates those same kinds of measures in the Cyber Security Decree and in sectoral regulations: encryption, access management, testing frequency and supply-chain security.
And no, that elaboration won't be outdated in a few months. The measures remain risk-driven: your own risk analysis is the starting point, and the content must move with the state of the art and with relevant European and international standards. What's more, the detailed provisions deliberately sit in lower-level regulations, which can be amended faster than the Act itself. That way the bar keeps pace with the threat landscape.
When assessing whether a processing operation's security is 'appropriate', use the CSA framework as a benchmark. Not because the CSA requires it, but because the legislator actually spells out what it expects in practice, something the GDPR never does. That makes your role as DPO, and your advice on this topic, just a bit more concrete.
Formally, monitoring the CSA is not your job. Nor should it be. In practice, though, you cannot avoid it. Not during an incident. Not in conversations with the board. And certainly not when the question arises of what 'appropriate' actually means.
Connect now with the information-security officer or CISO in your organisation. Ask what the CSA incident procedure looks like and where it diverges from the GDPR procedure. And ask straight away which measures from the Cyber Security Decree are already in place. Take that list with you as new benchmarks for Article 32, and make your organisation a little more resilient in the process.
Armed with these insights, you know the right questions to ask. We help you translate the answers into action. Get in touch and we will look together at what is already in place, what is missing, and what the next step is.