GDPR and NIS2 in plain language

Two European rules determine how your business handles data and security. The legal texts are long and technical. What they actually expect from an SME fits on this page.

GDPR and NIS2

The difference in two sentences

GDPR is about personal data: anything that can be traced back to a person. Those rules apply to every business, including you alone with a laptop.

NIS2 is about the cybersecurity of businesses that keep society running. Those rules apply to only some organisations. But those that fall outside still get them, through their customers.

GDPR: applies to every business

Does this really apply to me?

Yes. There is no lower limit. As soon as you have one employee, one customer, one supplier or one newsletter address, you process personal data. A sole trader with a customer list in Outlook is covered just as much as a bank. What differs is not whether the rules apply, but how much is expected of you: the law asks for measures that match your size and the risk.

What you need to have in place

  1. A record of your processing activities. An overview of what data you keep, about whom, why, for how long, and who gets to see it. There is an exemption for organisations under 250 employees, but it falls away as soon as processing is regular, and payroll administration and a customer database are regular. So assume you need one. A table in Excel will do.
  2. A reason for every processing activity. Every use of data must rest on one of six legal bases: consent, performance of a contract, a legal obligation, a legitimate interest, and two that rarely apply. A newsletter to your own customers can rest on legitimate interest; one to purchased addresses cannot.
  3. A privacy statement that is accurate. On your website, in plain language: who you are, what you keep, why, for how long, who you share it with and what rights people have. A text copied from another site is not a privacy statement, because it does not describe what you do.
  4. An answer to people’s requests, within one month. Anyone may ask what data you hold about them, and have it corrected, erased or transferred. You have one month to reply. Make sure such a request reaches someone who knows what to do, rather than sitting in a general mailbox.
  5. Data processing agreements with your suppliers. Everyone who processes data on your behalf, such as your IT partner, your accountant, your payroll office or your cloud provider, must have a contract with you about how that is done. That is a legal obligation, not a formality.
  6. Security that matches the risk. The law prescribes no products, but a result: data must be protected against loss, theft and unauthorised access. In practice that means tested backups, multi-factor authentication, timely updates, limited access rights and encrypted laptops.
  7. A plan for a data breach. If something goes wrong, a stolen laptop, a file sent to the wrong person, ransomware, you have 72 hours to report it to the Data Protection Authority, unless the risk is negligible. Where the risk is high you must also inform the people affected. Those 72 hours start when you know, not when you have finished investigating. Knowing who to call on a Saturday evening then saves you a full day.
  8. A point of contact. A formal data protection officer, a DPO, is only mandatory for public authorities and for those who monitor behaviour on a large scale or process sensitive data. Most SMEs therefore do not need one. They do need someone internally who follows the subject and knows where the record is kept.

What it costs to do nothing

The fines you read about, up to 20 million euro or 4 per cent of worldwide turnover, are for the large cases. For an SME the real risk looks different: a complaint from a former employee or a customer to the Data Protection Authority, a request to produce your record, and a file that runs for months. And after a breach without a usable backup, the fine is rarely your biggest cost.

NIS2: certain sectors, but far more businesses affected

NIS2 is a European directive on cybersecurity, implemented in Belgium by the Act of 26 April 2024, in force since 18 October 2024. Where GDPR is about people’s data, NIS2 is about the continuity of services society depends on. The supervisory authority is the Centre for Cybersecurity Belgium, the CCB.

Are you covered? Two questions

The first question is your sector.

Highly critical sectorsOther critical sectors
Energy, transport, banking, financial markets, health, drinking water, waste water, digital infrastructure, management of ICT services between businesses, public administration, spacePost and courier services, waste management, chemicals, food, manufacturing of among others medical devices, electronics, machinery and vehicles, digital providers such as marketplaces and social networks, research

The second question is your size.

  • Fewer than 50 employees and less than 10 million euro turnover: in principle you are not covered. With a few exceptions, such as providers of DNS, top-level domain registries and trust services: those are covered regardless of size.
  • From 50 employees or 10 million euro: you are an important entity.
  • From 250 employees or 50 million euro, in a highly critical sector: you are an essential entity, under stricter supervision.

Note the entry “management of ICT services between businesses”. That is a sector in its own right. An IT service provider with sixty people is covered, even if it only serves other businesses.

And if you are not covered?

You are not off the hook, and that surprises most SMEs. NIS2 obliges the organisations that are covered to secure their supply chain. Your customer in healthcare, food or energy must be able to show that its suppliers are not a weak link. That translates into questionnaires, contract clauses on security and incident reporting, and sometimes a request for a certificate.

For most SMEs, NIS2 therefore arrives as an e-mail from their largest customer, not as a letter from the government. Those with a clear answer ready keep the contract.

What to do if you are covered

  1. Register with the CCB, through the Safeonweb@work portal. This was due by 18 March 2025. If you missed it, register anyway.
  2. Take measures. The law lists them: a risk analysis and a security policy, incident handling, backups and business continuity, supply chain security, secure acquisition and development of systems, checking whether your measures work, cyber hygiene and training, encryption, human resources and access management, and multi-factor authentication.
  3. Report incidents in three steps: an early warning within 24 hours, a full notification within 72 hours, and a final report within one month.
  4. The board carries the responsibility. The management body must approve the measures, follow training on them and can be held personally liable. This cannot be passed on to “the IT person”.

Fines run up to 10 million euro or 2 per cent of worldwide turnover for essential entities, and up to 7 million or 1.4 per cent for important entities.

CyberFundamentals: the Belgian way to demonstrate it

The CCB published a practical framework, CyberFundamentals or CyFun, with four levels: Small, Basic, Important and Essential. It translates the law into concrete measures, and a verified declaration counts as a presumption of conformity. If you fall under NIS2, that is the clearest path. If you do not, the Small or Basic level is an excellent checklist and an answer you can show your customers.

The good news: it is largely the same work

GDPR and NIS2 start from a different concern, but technically ask for almost the same thing. Anyone who has the following in order meets most of both.

What the law asksWhat that means in practice
Protect data against lossBackups that are tested, including of Microsoft 365
Prevent unauthorised accessMulti-factor authentication, an individual account per employee, as few administrators as possible
Close vulnerabilitiesUpdates that happen automatically and on time
Detect and handle incidentsProtection on every device that raises an alarm, and someone who acts on it
Make people resilientPhishing training, and knowing who to warn
Be able to show what you doA record, a written policy, logs that are kept
Secure the chainData processing agreements and clear arrangements with suppliers

Where to start

Take the IT check. Ten questions, ten minutes, and they are about exactly the points above. Whatever you cannot answer with “yes” is your first job, for the law and for your business.

This page is an explanation in plain language, not legal advice. For a definitive assessment of your situation, and certainly for the question of whether you fall under NIS2, consult a lawyer. We take care of the technical and organisational part. Updated 30 September 2026.