A smart-city vendor treats NIS 2 incident rules as identical to GDPR personal-data breach rules. Which statement correctly separates the regimes?
Select an answer to reveal the explanation.
Short Explanation
Two fire alarms on the same building can ring for different reasons. NIS 2 is the cyber-resilience alarm for covered entities; GDPR breach rules are the personal-data alarm when people’s information is compromised. A smart-city outage might trigger one, the other, or both—but the checklists are not copy-paste twins.
Full Explanation
NIS/NIS 2 instruments impose cybersecurity risk-management and incident-reporting obligations on designated entities in the European framework. The GDPR separately defines personal-data breaches and notification/communication duties when personal data is affected. Treating the regimes as identical collapses distinct legal triggers, audiences, and remedies. Cookie consent is primarily an ePrivacy/GDPR interaction issue, not the core of NIS 2, and neither regime is limited to deceased persons.