16th IFIP Summer School on Privacy and Identity Management

The EnCaViBS team hosts the 16th IFIP Summer School on Privacy and Identity Management in Belval. The school is interactive in character: the aim is to encourage young academic and industry entrants to the privacy and identity management world to share their own ideas, build up a network, test presentation skills, and potentially publish a … Continued

Comments on the NIS 2.0 Proposal

The proposal for a NIS 2.0 Directive was welcomed at large. Since the publication of the proposal in December 2020, a variety of stakeholders have issued statements or have been responding directly to the Commission initiative. For some, the proposal reaches too far, while others stress a need to alignment with further initiatives in the … Continued

New Publication: Synergies in Cybersecurity Incident Reporting – The NIS Cooperation Group Publication 04/20 in Context

A central element of EU cybersecurity legislation is the reporting of security breaches. Mandatory reporting to national authorities promotes a culture of risk management, while also providing for the sharing of information about vulnerabilities. In this line, the GDPR introduced reporting obligations for data controllers based on the assumption that security challenges and relevant mitigation … Continued

BILETA Conference 2021: Taken by Surprise: (Re-)Constituting the Critical in an Age of Digital and Pandemic

14 – 16 April 2021 We are present at the annual conference of the British and Irish Law Education and Technology Association and present the following papers: Sandra Schmitz/Stefan Schiffner: “Every Student Can Learn, just not on the same Day” –  Data Protection and Cybersecurity Challenges for E-Learning Platforms Abstract When George Evans stated that … Continued

New Research Article published: Don’t tell them now (or at all) – responsible disclosure of security incidents under NIS Directive and GDPR

In this article, we critically analyse the timeline for notifications of third parties under the NIS Directive and the GDPR in the case of security and privacy incidents from a legal and technical perspective. While a need to mitigate an immediate risk of damage for an individual would call for prompt notification of data subjects, … Continued