New Publication: Synergies in Cybersecurity Incident Reporting – The NIS Cooperation Group Publication 04/20 in Context

A central element of EU cybersecurity legislation is the reporting of security breaches. Mandatory reporting to national authorities promotes a culture of risk management, while also providing for the sharing of information about vulnerabilities. In this line, the GDPR introduced reporting obligations for data controllers based on the assumption that security challenges and relevant mitigation … Continued

BILETA Conference 2021: Taken by Surprise: (Re-)Constituting the Critical in an Age of Digital and Pandemic

14 – 16 April 2021 We are present at the annual conference of the British and Irish Law Education and Technology Association and present the following papers: Sandra Schmitz/Stefan Schiffner: “Every Student Can Learn, just not on the same Day” –  Data Protection and Cybersecurity Challenges for E-Learning Platforms Abstract When George Evans stated that … Continued

New Research Article published: Don’t tell them now (or at all) – responsible disclosure of security incidents under NIS Directive and GDPR

In this article, we critically analyse the timeline for notifications of third parties under the NIS Directive and the GDPR in the case of security and privacy incidents from a legal and technical perspective. While a need to mitigate an immediate risk of damage for an individual would call for prompt notification of data subjects, … Continued

The EU’s Cybersecurity Strategy for the Digital Decade

Guest author: Pier Giorgio CHIARA On 16 December 2020, the European Commission and the High Representative of the Union for Foreign Affairs and Security Policy presented a new EU Cybersecurity Strategy (JOIN(2020) 18 final). The new strategy lays down the framework within which the Proposal for a NIS 2.0 and the Proposal for a Directive … Continued

Proposal for NIS 2.0

On 16 December, the European Commission adopted a Proposal for a Directive on Measures for High Common Level of Cybersecurity across the Union (COM(2020) 823 final). Undoubtedly the NIS Directive contributed to a significant change in the regulatory approach to cybersecurity in many Member States. However, increased digitisation of the internal market and digital transformation … Continued

Open letter on crypto and recent attacks

Recently a Resolution by the Council of the EU has been leaked titled “Encryption — Security through encryption and security despite encryption“. Beside the unsettling play with different interpretations of “Security”, the resolution requires “Competent authorities must be able to access data in a lawful and targeted manner [..]”. While not explicitly requiring backdoors or … Continued