# Infringements entailing a personal data breach — NIS2 — context bundle

> Focused context for a single provision, curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/laws/nis2/art-35
> Every item cites its source. Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

## Provision

### Infringements entailing a personal data breach — Infringements entailing a personal data breach

*NIS2, nis2-art-35-en — https://overview.legal/laws/nis2/art-35*

1. Where the competent authorities become aware in the course of supervision or enforcement that the infringement by an essential or important entity of the obligations laid down in Articles 21 and 23 of this Directive can entail a personal data breach, as defined in Article 4, point (12), of Regulation (EU) 2016/679 which is to be notified pursuant to Article 33 of that Regulation, they shall, without undue delay, inform the supervisory authorities as referred to in Article 55 or 56 of that Regulation.

2. Where the supervisory authorities as referred to in Article 55 or 56 of Regulation (EU) 2016/679 impose an administrative fine pursuant to Article 58(2), point (i), of that Regulation, the competent authorities shall not impose an administrative fine pursuant to Article 34 of this Directive for an infringement referred to in paragraph 1 of this Article arising from the same conduct as that which was the subject of the administrative fine under Article 58(2), point (i), of Regulation (EU) 2016/679. The competent authorities may, however, impose the enforcement measures provided for in Article 32(4), points (a) to (h), Article 32(5) and Article 33(4), points (a) to (g), of this Directive.

3. Where the supervisory authority competent pursuant to Regulation (EU) 2016/679 is established in another Member State than the competent authority, the competent authority shall inform the supervisory authority established in its own Member State of the potential data breach referred to in paragraph 1.

## Guidance

### Guidelines on processing of personal data through blockchain technologies

*EDPB — https://overview.legal/posts/125668*

Guidelines 02/2025 on processing of personal data through blockchain technologies Version 2.0 Adopted on 07 July 2026 1 | Adopted Version history Version Date Adoption information version 1.1 08 April 2025 adoption of the guidelines before public consultation version 2.0 07 July 2026 adoption of the guidelines after public consultation 3 | Adopted 4 | Adopted The European Data Protection Board Having regard to Article 70 (1)(e) of the Regulation 2016/679/EU of the European Parliament and of the…

### Template for Cross-Regulatory Cooperation Agreements

*EDPB — https://overview.legal/posts/125669*

1 | Adopted Template for Cross-Regulatory Cooperation Agreements Adopted by the EDPB on July 7 th 2026 2 | Adopted Explanatory note Cross-regulatory cooperation between data protection supervisory authorities (DPAs) and other national and EU competent authorities has become increasingly important as legal and practical challenges emerge at the intersection of different regulatory fields. Cooperation agreements can be an important basis to organise and strengthen cooperation and dialogue between…

### Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group

*EDPB — https://overview.legal/posts/125670*

Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group

*EDPB — https://overview.legal/posts/125671*

Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group

*EDPB — https://overview.legal/posts/125672*

Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

## Related topics

- **Data Breaches** — https://overview.legal/topics/datalekken
  ## Legal Framework
- **Notification Obligation** — https://overview.legal/topics/meldplicht
  ## Legal Framework
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  ## Legal Framework

---
Generated by overview.legal · https://overview.legal/laws/nis2/art-35 · 2026-08-22
