A port authority asks why GDPR, ePrivacy, and NIS obligations can all apply to one operational incident. Which explanation is correct?
Select an answer to reveal the explanation.
Short Explanation
One messy dockside outage can trip three different rulebooks at once—personal data (GDPR), communications/cookies-style overlays (ePrivacy), and cyber entity duties (NIS/NIS 2). European law stacks layers; it does not hand you a single “pick only one statute” coupon.
Full Explanation
A single operational scenario may simultaneously engage GDPR personal-data obligations, ePrivacy rules concerning electronic communications or terminal equipment, and NIS/NIS 2 cybersecurity duties for covered entities. Concurrent applicability follows from distinct material scopes that can overlap on the facts. EU law does not generally void later instruments or confine overlap exclusively to US state privacy regimes.