FractionalDataArchitect
Book a discovery call

EU Reg Overlap Decision Aid

EU Reg Overlap Decision Aid
EU Reg Overlap Decision Aid

We mapped NIS2, DORA and GDPR incident duties for one client. One incident record fed all three.

Three EU regulations can claim the same security incident. GDPR wants the personal-data angle within 72 hours. NIS2 wants an early warning within 24. DORA adds its own clock if you’re in financial services.

Most SMEs I talk to treat these as three separate compliance projects, usually owned by three different people. The duplication shows up mid-incident.

The required facts overlap heavily: what happened, when, what’s affected, who’s impacted, what you did about it. Deadlines and thresholds differ. The underlying record mostly doesn’t.

The decision aid I use asks three questions. Are you in NIS2 scope? Do you process personal data at scale? Are you a financial entity? Every “yes” adds a regulator, and one shared incident table covers the union of their fields.

Legal review per regulator still applies. Capturing the facts once, in one place with one owner, is the part you control before anything goes wrong.

Who owns incident reporting at your company: security, legal, or whoever’s on call that day?

Written by Thomas Nys

Fractional Data Architect helping startups and scaleups build data platforms that scale.

More about Thomas Nys →

Recognise the problem? Let's talk about it.