Incident reporting
QTSPs must report incidents fast: NIS2 (24h warning, RDI/NCSC), GDPR breach notification (72h) - eIDAS's own Article 19 duty was repealed in 2024.
Incident reporting (also called breach notification) is the legal duty for regulated digital services such as QTSPs to notify security incidents to their supervisor. NIS2 and the GDPR each set their own triggers and deadlines. eIDAS's own incident-notification duty has been narrowed rather than abolished: NIS2's Article 42 deleted the former Article 19 - which required all trust service providers, qualified and non-qualified alike, to report a breach of security or loss of integrity with significant impact to the supervisory body within 24 hours - in its entirety, with effect from 18 October 2024, while a new Article 19a inserted at the same time keeps an equivalent 24-hour notification duty in place specifically for non-qualified trust service providers. The practical effect is that qualified trust service providers lost their standalone eIDAS notification duty, and instead pick up an equivalent one under NIS2 itself once the Cyberbeveiligingswet - the law transposing NIS2, approved by the Eerste Kamer and due to enter into force on 15 August 2026 - applies to them; see that entry for how the transition works in the meantime. NIS2's own lex specialis rule (Article 4) - a rule letting a more specific law take precedence over a general one - separately lets other Union acts such as DORA set equivalent sector-specific reporting duties instead of NIS2, though no such carve-out was needed for eIDAS once QTSPs' Article 19 duty was removed.
NIS2 sets a three-stage regime for significant incidents: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report one month after that 72-hour notification (with an intermediate report in between if the CSIRT or competent authority asks for one). Reports go to the national CSIRT (the NCSC in the Netherlands); once the Cyberbeveiligingswet enters into force they will also go to the competent supervisor - the RDI for trust services - rather than to the CSIRT alone. Entities must inform affected users of a significant incident that is likely to adversely affect the provision of their service, and the competent authority can require, or itself proceed with, public disclosure where this serves the public interest; cross-border incidents are coordinated between the CSIRTs and competent authorities of the member states involved.
eIDAS 2.0 also adds a breach duty specific to the EUDI Wallet: if the security of a wallet solution is compromised in a way that affects its reliability or harms users, the wallet provider must suspend the wallet or the affected function without delay, inform users and relying parties, and may only resume the service once the risk has been remedied.
Where personal data is involved, the GDPR adds a further duty: a personal data breach that is likely to result in a risk to individuals' rights and freedoms must be reported to the privacy regulator - the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) in the Netherlands - without undue delay and, where feasible, within 72 hours, and - where the risk is high - affected individuals must also be informed directly under GDPR Article 34. Not every incident meets this threshold, but where it does, one event can trigger multiple notification duties in parallel - which is why incident response plans and rehearsals are a fixed part of a QTSP's audited operations.