Cross-regulation map
Where the laws touch
Four acts, and every place in their official texts where one names another. A citation is not decoration: it is where one law tells you which other law applies, or gives way, or supplies the definition. Click any arc to read the passage that makes the link.
What the overlap actually decides
The questions that come up when these acts meet, each answered next to the passage that settles it. Study aid, not legal advice.
- Does DORA override NIS2 for financial entities?
Yes, for what the two overlap on. DORA calls itself lex specialis with regard to NIS2, so for a financial entity the DORA rules on ICT risk management, incident reporting, resilience testing, information sharing and ICT third-party risk apply instead of the NIS2 ones. NIS2 says the same thing from its own side. The financial entity stays inside the NIS2 ecosystem for cooperation and information flow, and its supervisors still talk to the NIS2 authorities.
DORAcitesNIS2Consequently, this Regulation constitutes lex specialis with regard to Directive (EU) 2022/2555.
- Does NIS2 replace the GDPR, or do both apply?
Both apply. NIS2 states in its own scope article that it applies without prejudice to the GDPR, so the two run cumulatively: NIS2 governs the security of your network and information systems, and the GDPR governs the personal data those systems process. Where NIS2 requires entities and authorities to process personal data, it points at the GDPR for the lawful basis rather than creating its own.
NIS2citesGDPRThis Directive applies without prejudice to Regulation (EU) 2016/679, Directive 2002/58/EC, Directives 2011/93/EU (27) and 2013/40/EU (28) of the European Parliament and of the Council and Directive (EU) 2022/2557.
- Can one incident be fined twice, under NIS2 and under the GDPR?
No, not for the same conduct. If the GDPR supervisory authority has already imposed an administrative fine, the NIS2 competent authority must not impose a NIS2 fine for an infringement arising from the same conduct. The duties still stack, and the authorities must inform each other when an infringement looks like it also entails a personal data breach, but the penalty for that one course of conduct does not land twice.
NIS2citesGDPRWhere the supervisory authorities as referred to in Article 55 or 56 of Regulation (EU) 2016/679 impose an administrative fine pursuant to Article 58(2), point (i), of that Regulation, the competent authorities shall not impose an administrative fine pursuant to Article 34 of this Directive for an infringement referred to in paragraph 1 of this Article arising from the same conduct as that which was the subject of the administrative fine under Article 58(2), point (i), of Regulation (EU) 2016/679.
- Does the EU AI Act change the GDPR?
No. The AI Act says it does not affect the GDPR, and leaves data protection law standing underneath it, with two narrow exceptions it names in its own text. In practice the AI Act leans on the GDPR rather than displacing it: it borrows the GDPR definitions of personal data, profiling and special categories, and it points deployers of high-risk systems at the GDPR data protection impact assessment.
EU AI ActcitesGDPRThis Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680, without prejudice to Article 10(5) and Article 59 of this Regulation.
- Where does the EU AI Act get its definition of special category data?
From the GDPR. The AI Act's own definitions article defines special categories of personal data by reference to GDPR Article 9(1), together with the equivalent provisions of the law enforcement directive and the EU institutions regulation. That is why biometric categorisation is treated the way it is: the newest act in the family is built on the oldest one's terms.
EU AI ActcitesGDPRon, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data; (37) ‘special categories of personal data’ means the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725; (38) ‘sensitive operational data’ means operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the di
- Does a GDPR impact assessment cover the AI Act one?
It contributes to it, and does not replace it. The AI Act says that where an obligation of the fundamental rights impact assessment is already met by a data protection impact assessment carried out under GDPR Article 35, the fundamental rights assessment complements that assessment. Two instruments, one evidence base, and the AI Act one is still owed.
EU AI ActcitesGDPRIf any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment.
- Which authority supervises a financial entity that is also a critical ICT provider?
Both regimes reach it, and they are made to coordinate rather than choose. NIS2 requires the competent authorities to inform the DORA Oversight Forum when they exercise supervisory or enforcement powers over an essential entity that has been designated a critical ICT third-party service provider under DORA. The designation does not remove the NIS2 supervision; it adds a party that has to be told.
NIS2citesDORAIn particular, Member States shall ensure that their competent authorities under this Directive inform the Oversight Forum established pursuant to Article 32(1) of Regulation (EU) 2022/2554 when exercising their supervisory and enforcement powers aimed at ensuring compliance of an essential entity that is designated as a critical ICT third-party service provider pursuant to Article 31 of Regulation (EU) 2022/2554.
Source texts: the Official Journal, through the Publications Office. Study aid, not legal advice.
GDPR 32016R0679NIS2 32022L2555DORA 32022R2554EU AI Act 32024R1689
A citation on this map means one act names another in its text. It does not mean the two obligations are equivalent, and it is not advice about which applies to you.
Want the reasoning behind each of the four texts? Read them one at a time in the GDPR, NIS2 and DORA explorers, or in the EU AI Act Explorer.