EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data
EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data
19 March 2026
The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a Joint Opinion on the European Commission’s proposal for a Cybersecurity Act 2 (CSA2) and the proposal on amendments to the Network and Information Security 2 (NIS2) Directive.
On 20 January 2026, the Commission published a cybersecurity package proposal to further strengthen cybersecurity in Europe while making compliance with cybersecurity laws easier for organisations. In their joint opinion, issued at the request of the Commission, the EDPB and the EDPS address the proposed revision of the CSA and the targeted amendments to the NIS2 Directive.
“The relationship between data protection and cybersecurity is reciprocal and deeply interconnected. While cybersecurity supports the protection of personal data by limiting the risks of unwanted access, modification or unavailability of data, it is crucial to ensure that security controls are implemented in a way that does not undermine individuals’ fundamental rights and freedoms,” said EDPB Chair Anu Talus.
“While maximizing the effectiveness of cybersecurity measures is vital, we must ensure that the processing of personal data remains limited to what is strictly necessary. We welcome the reinforced role of ENISA to promote digital resilience; our hope is that this new mandate fosters the synergies needed to create a robust ecosystem where security and privacy go hand in hand,” said European Data Protection Supervisor, Wojciech Wiewiórowski
Read more here
