%0 Conference Proceedings %T Don’t Put the Cart Before the Horse – Effective Incident Handling Under GDPR and NIS Directive %+ Université du Luxembourg (Uni.lu) %A Schmitz-Berndt, Sandra %A Schiffner, Stefan %Z Part 1: Tutorial Paper %< avec comité de lecture %( IFIP Advances in Information and Communication Technology %B 15th IFIP International Summer School on Privacy and Identity Management (Privacy and Identity) %C Maribor, Slovenia %Y Michael Friedewald %Y Stefan Schiffner %Y Stephan Krenn %I Springer International Publishing %3 Privacy and Identity Management %V AICT-619 %P 3-17 %8 2020-09-21 %D 2020 %R 10.1007/978-3-030-72465-8_1 %Z Computer Science [cs]Conference papers %X This paper serves as notes to a lecture given at the IFIP summer school of privacy and identity management 2020. We discussed notification requirements in the NIS directive and the GDPR in the case of security and privacy incidents form legal and technical perspective. In particular, we discuss timing. While a need to mitigate an immediate risk of damage for an individual would call for prompt communication with data subjects, there are scenarios which may justify a delay in communication to a wider public, e.g. a large user base. This might be advisable, for instance, where a service provider needs to analyse the current attack to prevent further attacks and assess the full impact. In the latter, any delay in communication should fulfil the requirement of “without undue delay”. Further, we discuss why the concurrent reporting under both regimes is needed and conclude with a call for more cooperation of the respective competent authorities. %G English %Z TC 9 %Z TC 11 %Z WG 9.2 %Z WG 9.6 %Z WG 11.7 %Z WG 11.6 %2 https://inria.hal.science/hal-03703760/document %2 https://inria.hal.science/hal-03703760/file/498598_1_En_1_Chapter.pdf %L hal-03703760 %U https://inria.hal.science/hal-03703760 %~ IFIP %~ IFIP-AICT %~ IFIP-TC %~ IFIP-WG %~ IFIP-TC9 %~ IFIP-TC11 %~ IFIP-WG9-2 %~ IFIP-WG9-6 %~ IFIP-WG11-7 %~ IFIP-WG11-6 %~ IFIP-AICT-619 %~ IFIP-PRIVACY-AND-IDENTITY