Introduction

Cyberattacks no longer target IT systems alone: they also reach intellectual property assets, trade secrets, customer files and trademark databases. Facing this growing threat, French and European lawmakers have built, over recent years, a demanding framework: the GDPR, the NIS2 Directive, and the recommendations issued by the CNIL and ANSSI. Yet many companies still do not know whether these obligations apply to them, and above all what they must concretely put in place. This article reviews the cybersecurity policies to adopt, the measures authorities expect, and the reporting deadlines that apply in the event of an incident.

A legal framework that depends on the company's status

The intensity of cybersecurity obligations depends primarily on the status of the organization concerned. French law broadly distinguishes between two categories of actors.

Entities of essential importance

Certain organizations engaged in critical activities are subject to enhanced cybersecurity requirements.

  • Operators of vital importance are designated from among those entities whose unavailability or destruction could seriously affect the nation’s security, economy, defense, or the lives of its citizens.
  • Essential service operators, on the other hand, are identified when an incident affecting their networks or information systems could seriously disrupt the provision of a service essential to the functioning of society or the economy.

These operators must, in particular, implement measures related to security governance, the protection of systems and access, the detection and handling of incidents, as well as business continuity and crisis management. They may also be subject to specific obligations to report incidents to ANSSI.

Data controllers and processors

For any organisation, public or private, that processes personal data, article 32 of the GDPR requires the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity and availability of processing systems, the ability to restore access to data in the event of a technical incident, and a process for regularly testing and evaluating security measures. These same requirements are echoed and detailed by the CNIL.

Summary table of obligations by company status

Company status Reporting authority Deadline Reference text
Operator of vital importance (OIV) ANSSI Without delay / per sector-specific order Defence Code, article L1332-7
Operator of essential services (OES) ANSSI Without delay NIS Directive, French transposition
Data controller / processor CNIL 72 hours maximum, where feasible GDPR, articles 33 and 34
Essential and important entities (upcoming) ANSSI 24 hours (early warning) then 72 hours Directive (EU) 2022/2555 (NIS2)

The security measures authorities expect from companies

The CNIL and the ANSSI have published practical guidance. The reported incidents show that effective protection depends as much on the implementation of appropriate technical measures as it does on internal organization and staff awareness.

The essential baseline

  • keep software and systems up to date in order to promptly address known vulnerabilities;
  • require strong and unique credentials for each user account;
  • strengthen the security of professional email accounts;
  • regularly raise employees’ awareness of the main cybersecurity risks and fraud attempts;
  • implement frequent backups, ensuring that at least one copy is kept isolated from systems accessible online.

Advanced protective measures

  • implement multi-factor authentication for sensitive access, particularly remote access;
  • assign individual accounts to employees, partners, and service providers in order to avoid credential sharing;
  • restrict network access to devices that have been previously authorized or authenticated;
  • deploy monitoring mechanisms to quickly detect unusual behavior or connections.

Documenting every incident: an obligation too often overlooked

The GDPR requires data controllers to keep a record of every data breach, its effects and the remedial measures taken (articles 33(5) and 34). This record allows supervisory authorities to verify compliance in the event of an audit. Processors, for their part, must assist the controller and keep appropriate internal documentation. The law does not set a precise retention period: in practice, the record should be kept for as long as the legal risk exists.

Reporting a breach or incident: to whom, and within what deadlines?

To the CNIL, for personal data

Three types of incidents must be reported: a confidentiality breach (unauthorised disclosure of or access to data), an availability breach (loss or destruction of data), and an integrity breach (unauthorised alteration of data). Notification must occur within 72 hours of the company becoming aware of the breach, where feasible, via the CNIL's online notification service.

To ANSSI, for entities of essential importance

Operators of vital importance must report any incident affecting their vital information systems, following the procedures set out in the relevant sector-specific order (OIV incident reporting form).

Operators of essential services must, in turn, report any incident likely to have a significant impact on the continuity of their services (OES incident reporting form).

Shorter deadlines ahead under the NIS2 Directive

Directive (EU) 2022/2555, known as NIS2, not yet transposed into French law at the time of writing, requires essential and important entities to submit an initial notification, known as an 'early warning', without undue delay and within 24 hours of becoming aware of a significant incident, followed by a full notification within 72 hours. These timelines may be further specified by the national implementing measures.

Checklist: the first 5 actions in the event of an incident

  • Qualify the incident: does it affect confidentiality, availability or integrity of the data?
  • Identify whether the company is a controller, a processor, an OIV or an OES.
  • Start the clock: 24 hours (NIS2 early warning) or 72 hours (GDPR).
  • Document the facts, effects and remedial measures in a dedicated register.
  • Notify the competent authority using the appropriate form, then inform data subjects if the risk is high.

Informing data subjects and the public

Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, the company must also inform the data subjects directly, unless the CNIL considers that appropriate measures have rendered the data unintelligible to any unauthorised third party. This communication may take several forms: direct messaging (email, SMS), a prominent website banner or notification, postal mail, or an announcement in the print media.

Conclusion

Putting the right cybersecurity policies in place is no longer optional: depending on its status, a company is subject to the GDPR, to reinforced sector-specific obligations, or soon to the NIS2 Directive. The essential measures remain within reach of any organisation, regardless of size. In the event of an incident, how quickly it is qualified and reported largely determines the scale of the legal and reputational consequences.

Dreyfus Law Firm assists its clients in managing complex intellectual property matters by providing tailored advice and comprehensive operational support to ensure the full protection of intellectual property rights.

Dreyfus Law Firm works in partnership with a global network of intellectual property attorneys.

Nathalie Dreyfus, with the assistance of the entire Dreyfus team.

Q&A

What happens if a company fails to report a breach on time?

It may face CNIL fines of up to €20 million or 4% of global annual turnover, in addition to potential compensation claims from affected individuals.

Do these obligations apply to small businesses too?

Yes. The size of a company does not exempt it from its obligations under the GDPR where it processes personal data. However, certain enhanced obligations depend on the nature of its activities, the types of processing carried out, or the status of the organization.

Is appointing a Data Protection Officer mandatory?

The appointment is mandatory for public authorities and bodies, for organizations whose core activities involve regular and systematic monitoring of individuals on a large scale, and for those that process sensitive data or data relating to criminal convictions and offences on a large scale.

Does the 72-hour deadline still apply if the incident occurs at a service provider or processor?

Yes, the processor must alert the controller without undue delay upon becoming aware of the incident, so the controller can still meet the CNIL notification deadline.

Does missing the 72-hour deadline automatically trigger a penalty?

No, the CNIL assesses the circumstances of each case; a justified and documented delay is treated differently from a complete failure to notify.

Should a company maintain an out-of-hours on-call rotation to meet these deadlines?

It is not an explicit legal requirement, but it is strongly advisable in practice, since regulatory deadlines run continuously, including weekends and public holidays.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.