Expanded ENISA role welcomed alongside clearer oversight boundaries.
In a landmark move for the European Union’s cybersecurity landscape, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have backed proposals aimed at enhancing the EU cybersecurity law while ensuring robust protection for personal data. This joint opinion tackles significant reforms to the Cybersecurity Act and brings vital updates to the NIS2 Directive, which collectively set a stronger foundation for data security across member states.
The advice provided by these two authoritative bodies calls for explicit limitations on the processing of personal data. It emphasizes the necessity for prior consultations on any technical regulations that could impact individual privacy. This proactive approach ensures that privacy remains central to cybersecurity initiatives. Furthermore, any certification schemes developed under the new regulations should align closely with the General Data Protection Regulation (GDPR). This alignment will assist organizations in demonstrating compliance and enhancing trust among consumers.
In addition to these significant recommendations, the agencies are advocating for broader training in cybersecurity skills across the EU. This training is essential as the landscape of cybersecurity continues to evolve rapidly, requiring skilled professionals who are well-versed in the latest technologies and threats. They also propose the establishment of a single EU entry point for personal data breach notifications. This centralized system would streamline the reporting process, ensuring that incidents are managed swiftly and effectively. Among other changes, the proposals aim to classify digital identity wallet providers as essential entities under the EU security rules, highlighting their importance in the landscape of digital security.
Would you like to learn more about AI, tech and digital diplomacy? If so,
ask our Diplo chatbot
!

