Cybersecurity Policy Report, EU Privacy Officials: EC’s Cyber Law Revamp Shouldn’t Overlook Privacy Concerns, (Mar 20, 2026)
A plan by the European Commission to revamp Europe’s cybersecurity law should account for data privacy issues that are intertwined with cybersecurity, according to a joint opinion from the European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS).
“The relationship between data protection and cybersecurity is double-sided. On the one hand, cybersecurity serves the protection of personal data by limiting the risks of unwanted access, modification or unavailability of that data. On the other hand, some cybersecurity measures can interfere with individuals’ rights and freedoms, in particular the rights to privacy and data protection,” the opinion says.
The European Union’s General Data Protection Regulation (GDPR), for example, “recognises that cybersecurity measures involving the processing of personal data constitute a legitimate interest of the data controller concerned, while underlining at the same time that the measures should be strictly necessary and proportionate for the purposes of ensuring network and information security,” it says.
“As a result, cybersecurity measures should not only be guided by considerations of effectiveness, but also consider whether their impact on fundamental rights remains limited to what is necessary and proportionate,” the opinion adds.
In April the EC proposed updates to the EU’s 2019 Cybersecurity Act and the Directive on Security of Network and Information Systems (NIS 2 Directive). The EC proposed stronger measures to secure Europe’s information and communications technology (ICT) supply chains, including ways to keep untrustworthy equipment out of Europe’s telecom networks (CPR, Jan. 20).
The EDPB and EDPS endorsed the ICT supply chain proposal, which they said focused on “non-technical risks such as geopolitical, legal, ownership, dependency and strategic interference factors affecting ICT supply chains in sectors of high criticality and other critical sectors.”
“While such supply chain security measures aim primarily to address risks which are not directly related to data protection, they may also have a beneficial impact on the protection of fundamental rights by limiting the foreign interference with the data of EU data subjects through activities such as espionage and surveillance,” according to the opinion.
They also reiterated their support for a single EU point-of-contact for data breach reports. They “strongly support the objective of the establishment of a single-entry point for the notification of personal data breaches, as it would reduce the administrative burden for organisations without affecting the level of protection for data subjects,” the opinion says.
They expressed concerns, however, about the handling of cyber attack data by the European Union Agency for Cybersecurity (ENISA), which would have an expanded role under the EC proposal.
“ENISA would expand its role as a central hub for operational cooperation, including the processing of substantial amounts of threat intelligence information. As a result, one could infer that the information processed by ENISA as part of its role may include personal data, such as IP addresses, user credentials, user logs, financial exchanges or details of compromised accounts,” the opinion says.
“While taking note of the fact that ENISA would collect and further process mainly aggregated non-personal data, the EDPB and EDPS nevertheless recall that if the future tasks of ENISA as information hub would require processing of personal data to a substantial degree, this should be spelled out explicitly in the provisions of the basic act governing the respective tasks, including the essential elements of any large-scale processing and the appropriate safeguards,” it says.
“Conversely, if the aim is to enable ENISA to collect and further process mainly aggregated non-personal data, this should also be clarified, at least by way of a recital,” it adds.
“While maximizing the effectiveness of cybersecurity measures is vital, we must ensure that the processing of personal data remains limited to what is strictly necessary. We welcome the reinforced role of ENISA to promote digital resilience; our hope is that this new mandate fosters the synergies needed to create a robust ecosystem where security and privacy go hand in hand,” EDPS Wojciech Wiewiórowski said in a news release.
“The relationship between data protection and cybersecurity is reciprocal and deeply interconnected,” EDPB Chair Anu Talus said. “While cybersecurity supports the protection of personal data by limiting the risks of unwanted access, modification or unavailability of data, it is crucial to ensure that security controls are implemented in a way that does not undermine individuals’ fundamental rights and freedoms.”
News: InternationalLegislation DataPrivacy DataSecurity GDPR