Reporting obligations for IT security incidents: who must report what, when and to whom

13 min

There is no single uniform reporting obligation for IT security incidents. Instead, several legal acts may apply in parallel or at the same time. Which obligation applies in a specific case depends on the company’s role, the sector affected, whether personal data are involved and whether the incident is relevant to a product. We show which six regimes are most important in practice and answer the key questions for each: who must report, to whom, and within what reporting deadline.

Arrange a no-obligation initial consultation

Which reporting obligations apply in the event of an IT security incident?

In the event of an IT security incident, data protection, cybersecurity, sector-specific and product safety reporting obligations may apply at the same time. They do not arise from a single uniform set of rules, but from several interlocking legal acts.

For the legal assessment, you should therefore first clarify the regulatory context in which your company and the incident fall. For practical handling, two points are particularly important: who is subject to the reporting obligation and who is the correct recipient of the report.

The following table provides a quick overview of reporting entities, recipients, reporting deadlines and fine ranges under the six regimes that are most relevant in practice. The details and requirements are explained in the respective sections.

Regime Who reports Recipient First deadline Fine range
GDPR Controller Data protection supervisory authority Without undue delay, where feasible within 72 hours Up to EUR 10 million / 2% of annual turnover
NIS2 / BSIG Important or particularly important entity BSI and BBK, joint reporting office 24-hour initial notification Up to EUR 10 million / 2% of annual turnover
DORA Financial entity Competent supervisory authority, BaFin MVP portal 4 hours after classification, maximum 24 hours Under sector-specific legislation, plus supervisory measures
TKG Telecommunications provider / network operator Federal Network Agency and BSI 24-hour initial notification Up to EUR 100,000
eIDAS Trust service provider Competent supervisory body, e.g. BNetzA 24 h Up to EUR 20,000 under Section 19 VDG
CRA, from 09/2026 Manufacturer Single Reporting Platform 24-hour early warning Up to EUR 15 million / 2.5% of annual turnover

Depending on the situation, a reporting obligation may arise under several rows of this table at the same time. The decisive factor is always a role-, sector-, data- and product-specific assessment of the particular incident.

Newsletter

For your Inbox

Current updates and important information on topics such as data law, information security, technology, artificial intelligence, and much more. (only in German)

What is the sum of 8 and 2?

By clicking on the button, you consent to the sending of our newsletter and the aggregated usage analysis (opening rate and link clicks). You can revoke your consent at any time, e.g. via the unsubscribe link in the newsletter. More information: Privacy policy.

GDPR: when is a personal data breach reportable?

Under Article 33 GDPR, a reporting obligation exists whenever there is a personal data breach and this is likely to result in a risk to the rights and freedoms of natural persons. Only if no risk is likely may notification to the supervisory authority be omitted.

A breach already exists where a security breach leads accidentally or unlawfully to the destruction, loss, alteration, unauthorised disclosure of or unauthorised access to personal data. Fault is not required. You determine the risk by assessing the likelihood of occurrence and the possible severity of harm.

The obligation applies to the controller, typically the company that determines the systems, purposes and means of processing. A processor is not the addressee of the authority notification, but must inform the controller without undue delay as soon as it becomes aware of such an incident.

The notification to the supervisory authority essentially contains:

  • the nature of the breach
  • the categories and approximate number of affected persons and data records
  • the likely consequences of the incident
  • remedial measures taken and planned
  • a contact point for queries, such as the data protection officer

Where a high risk is likely, Article 34 GDPR also requires communication to the affected persons in plain language. Regardless of whether a notification obligation exists, every personal data breach must be comprehensively documented, even if you exceptionally conclude that no notification obligation applies. Infringements fall within the fine framework of Article 83(4) GDPR: up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher.

As soon as personal data are affected and a risk arises, the 72-hour deadline starts running for the controller.

NIS2 and BSIG: which reporting obligations apply to important and particularly important entities?

Important and particularly important entities under the German Federal Office for Information Security Act, the BSIG, must report significant security incidents to the Federal Office for Information Security, BSI, and the Federal Office of Civil Protection and Disaster Assistance, BBK. The German legislator has implemented the European NIS2 Directive primarily in the BSIG.

An incident is significant in particular where it affects the availability, confidentiality or integrity of data or IT services and may thereby cause significant operational disruption, financial losses or damage. Reporting takes place via the joint reporting office of the two authorities. The reporting obligation lies with the affected entity itself; in the case of critical facilities, with the operator.

Reporting follows a staged process:

  • 24 hours from awareness: early initial notification as an early warning, including an initial assessment of whether unlawful or malicious acts caused the incident and whether cross-border effects are likely
  • 72 hours: follow-up notification with updated findings and a preliminary assessment of severity and impact
  • 1 month: detailed final report; if the incident is still ongoing, a progress report

In addition, the BSI may order you to inform recipients of your services about the incident. In certain sectors, such as finance, digital infrastructure, ICT service management and digital services, a balancing of interests must be carried out for this purpose. Section 65 BSIG sanctions infringements as administrative offences: up to EUR 10 million for particularly important entities and up to EUR 7 million for important entities.

If a GDPR fine has already been imposed for the same conduct, an additional BSIG fine for the same infringement is excluded.

Anyone falling within the scope of the BSIG must report significant incidents within 24 hours via the joint reporting office, in three stages.

Financial entities report major ICT-related incidents under the separate regime of the Digital Operational Resilience Act, DORA, not under the general NIS2 regime. The key provision is Article 19(1) DORA.

A major ICT-related incident has a significant adverse impact on the network and information systems that support critical or important functions of the financial entity. Classification is based on the criteria in Article 18 DORA and the supplementary Regulatory Technical Standards, RTS. The reporting obligation applies to the entities covered by Article 2 DORA, such as credit institutions, payment and e-money institutions, investment firms and insurance undertakings.

Here too, a staged procedure applies via BaFin’s MVP portal:

  • 4 hours after classification as major, and no later than 24 hours after becoming aware: initial notification
  • 72 hours: intermediate report with updated information
  • 1 month after the intermediate report: final report after resolution and root-cause analysis

If the incident affects customers’ financial interests, you must inform them without undue delay about the incident and the measures taken. In Germany, fines are imposed via the respective sector-specific legislation; supervisory measures and publications under Articles 50 et seq. and 54 DORA may also apply.

The initial notification deadline of four hours after classification is the shortest deadline across all regimes, which is why financial entities must complete their classification processes particularly quickly.

TKG: which reporting obligations apply to telecommunications providers?

Providers of publicly available telecommunications services and operators of public telecommunications networks must report significant security incidents under Section 168 TKG to the Federal Network Agency and the BSI. In addition, Section 169 TKG contains a separate data-protection-related reporting obligation that must be assessed separately.

A security incident is significant if it causes or may cause serious operational disruption or financial losses for the provider, or if it affects other persons through significant material or non-material damage. Reporting under Section 168 TKG is staged:

  • 24 hours after awareness: early initial notification, in particular concerning possible unlawful or malicious triggers and any cross-border effects
  • 72 hours: further notification with an initial assessment of the incident and, where applicable, indicators of compromise
  • 1 month: final report

If the incident creates a particular and significant risk, you must also inform users.

It is important to distinguish this from Section 169 TKG: anyone providing publicly available telecommunications services must, in the event of a personal data breach, notify the Federal Network Agency and the Federal Commissioner for Data Protection and Freedom of Information without undue delay. This obligation applies independently of Article 33 GDPR and independently of whether the incident significantly affects the security of the network or service.

Providers must also maintain a register of personal data breaches. A breach of the reporting obligation may result in fines of up to EUR 100,000 under Section 228 TKG.

In the telecommunications sector, Section 168 and Section 169 TKG establish two different reporting obligations side by side: one security-related and one data-protection-related.

eIDAS: what must trust service providers report?

Trust service providers must report any breach of security or loss of integrity that has a significant impact on the trust service or on the personal data contained in it. Under Article 19(2) of the eIDAS Regulation, this obligation applies to both qualified and non-qualified providers. The decisive question is therefore whether your company acts as a trust service provider.

A trust service is an electronic service, usually provided for remuneration. Under Article 3(16) of the eIDAS Regulation, this includes, for example, the creation, verification and validation of electronic signatures, seals, time stamps and electronic registered delivery services, certificates for website authentication, and the preservation of such signatures, seals or certificates.

Notification must be made without undue delay and in any event within 24 hours of becoming aware. Depending on the severity and scope of the incident, different bodies must be involved:

  • the competent supervisory body, such as the Federal Network Agency, and, where applicable, further bodies such as the data protection authority
  • the affected person, if the incident is likely to adversely affect them
  • the supervisory bodies of other Member States and ENISA, if several Member States are affected
  • the public, if the supervisory body determines that there is a public interest

Infringements may be sanctioned as administrative offences under Section 19 VDG with fines of up to EUR 20,000. In addition, supervisory measures up to and including prohibition of operation may be considered.

Trust service providers must report significant security breaches to the supervisory body within 24 hours; in cross-border cases, ENISA is involved.

Cyber Resilience Act: which reporting obligations will apply to manufacturers from 2026?

From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents under Article 14(1) of the Cyber Resilience Act, CRA. The CRA creates product-safety-related reporting obligations for the first time.

Covered manufacturers are those who develop products with digital elements, or have them developed or manufactured, and market them under their own name or trademark. Whether an incident is severe depends on its impact, scope and exploitability. The affected manufacturer is subject to the reporting obligation. The deadlines follow the same staged model as the other regimes:

  • 24 hours after awareness: early warning
  • 72 hours: more detailed information on the vulnerability or incident, the nature of the exploitation and corrective or risk-mitigating measures taken or possible
  • for vulnerabilities: 14 days after a corrective measure has been made available; for incidents: 1 month after notification: final report

Reports are submitted via a central European Single Reporting Platform, SRP, from which the information is forwarded to the competent bodies. In addition, under Article 14(8) CRA, you must inform affected users and, where applicable, all users of the product about the vulnerability or incident and available countermeasures.

Infringements may result in fines of up to EUR 15 million or 2.5% of worldwide annual turnover, as well as measures such as sales bans, recalls or restrictions on product availability.

From September 2026, reporting obligations will also apply to pure product manufacturers, with a dedicated platform and a particularly high fine framework. In practice, this example shows what applies to all regimes: a single incident can trigger several of them at the same time.

What should you do if several reporting obligations apply at the same time?

If more than one reporting obligation applies to an IT security incident, never assess them in isolation. Instead, allocate the incident to all relevant regimes at the same time. A single incident may trigger several regimes in parallel: a ransomware attack, data exfiltration or a compromised software component may affect data protection, cybersecurity, financial supervisory and product safety obligations at both European and national level.

An additional complication is that the reporting deadlines differ between regimes.

You must distinguish between reports to different authorities, notifications to affected persons, follow-up and final reports, as well as internal documentation obligations. Your first legal assessment should therefore not only capture the technical cause, but also the company’s role, the sector affected, the personal data dimension, the product relevance and any existing outsourcing or supply-chain relationships.

Anyone wishing to report incidents in a legally robust way needs resilient structures:

  • comprehensive regulatory mapping of the organisation’s own roles and obligations
  • reliable incident matrices with thresholds and recipients
  • clear escalation and decision-making channels
  • suitable contractual arrangements with service providers and throughout the supply chain
  • a robust audit and evidence structure

Only when legal assessment, operational incident response and information flows interlock will you be able to meet all applicable reporting obligations on time.

Conclusion: reporting obligations for IT security incidents can only be managed as an integrated whole

There is no single reporting obligation for IT security incidents that applies uniformly to all situations. Which requirements apply depends on the company’s role, the sector affected, the type of incident and the regulatory interest protected by the respective regime.

Anyone required to report a security incident often has only 24 hours or less, depending on the regime. Depending on the regime, this period begins when the incident becomes known or when it is classified. The decisive factor is therefore to know your own roles and obligations before an emergency occurs and to be able to assign an incident quickly to the correct regime in a crisis. Those who have prepared this gain, at the decisive moment, the time that the law does not give them.

Frequently asked questions

#1 Do I have to report an IT security incident even if no personal data are affected?

Yes, a reporting obligation may also exist without any personal data being involved. The GDPR only applies to personal data, but the BSIG, DORA, the TKG, eIDAS and the CRA are linked to sector, function or product and may require a report independently of any personal data.

#2 Which reporting deadline applies to an IT security incident?

The reporting deadline depends on the applicable regime and is usually 24 hours from awareness for the initial notification. Under the GDPR, it is up to 72 hours; under DORA, it is as early as four hours after classification as major. The initial notification is usually followed by a follow-up notification after 72 hours and a final report after approximately one month.

#3 From when will the reporting obligations under the Cyber Resilience Act apply?

The Cyber Resilience Act reporting obligations for manufacturers will apply from 11 September 2026. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents via the Single Reporting Platform.

#4 Can both a GDPR fine and a BSIG fine be imposed for the same incident?

No. Double fines for the same conduct are excluded. Under Section 65(11) BSIG, no additional BSIG fine may be imposed if a GDPR fine has already been imposed for the same conduct.

#5 Who must report if an external service provider is affected by the incident?

Under data protection law, the controller remains subject to the reporting obligation, not the processor. However, the processor must inform the controller without undue delay as soon as it becomes aware of a personal data breach, so that the controller can meet the deadline vis-à-vis the supervisory authority.

#6 What must an initial notification contain at a minimum?

An initial notification typically describes the nature of the incident, an initial assessment of the cause and impact, and a contact point for queries. Depending on the regime, information on possible malicious triggers, cross-border effects or affected groups of persons may also be required; later notifications then provide more detail.

Schedule your initial consultation

Describe your situation to us in a no-obligation phone call, and our lawyers will work with you to find the best solution.

Schedule consultation