# Infringements entailing a personal data breach 35(1) — NIS2 — provision context

> Focused context for a single provision (35(1)), curated from overview.legal on 2026-10-06. Canonical: https://overview.legal/laws/nis2/art-35#par-1
> Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

Part of **Infringements entailing a personal data breach** (NIS2, full article: https://overview.legal/laws/nis2/art-35).

## Provision text

### 35(1)

Where the competent authorities become aware in the course of supervision or enforcement that the infringement by an essential or important entity of the obligations laid down in Articles 21 and 23 of this Directive can entail a personal data breach, as defined in Article 4, point (12), of Regulation (EU) 2016/679 which is to be notified pursuant to Article 33 of that Regulation, they shall, without undue delay, inform the supervisory authorities as referred to in Article 55 or 56 of that Regulation.


## Topics on this provision

- **Data Breaches** — https://overview.legal/topics/datalekken
  Security incidents involving unauthorized access to personal data
- **Notification Obligation** — https://overview.legal/topics/meldplicht
  Duty to report data breaches to authorities and affected individuals
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

## Cited by (exact-provision citations)

- **Guidelines 04/2022 on the calculation of administrative fines under the GDPR** (guidance) — https://overview.legal/posts/38068
- **Guidelines 04/2022 on the calculation of administrative fines under the GDPR** §29 (guidance, EDPB) — https://overview.legal/posts/38068

---
Generated by overview.legal · https://overview.legal/laws/nis2/art-35#par-1 · 2026-10-06
