DORA and GDPR: when both apply to the same incident
DORA does not replace GDPR and is not lex specialis in relation to it. DORA focuses on the digital operational resilience of the financial entity; GDPR protects people and their personal data. When the same system, provider or incident engages both, both regimes must be assessed.
The short answer
Different rules, different objects
| Question | GDPR | DORA |
|---|---|---|
| What it protects | Personal data and the rights and freedoms of individuals | The digital operational resilience of the financial entity and the continued delivery of financial services |
| Who it applies to | Controllers and processors within the Regulation’s scope | Financial entities listed in Article 2; ICT providers are mainly affected through contracts, with direct EU oversight for providers designated as critical |
| Relevant incident | A personal data breach: a security breach affecting the confidentiality, integrity or availability of personal data | A major ICT-related incident under DORA’s classification rules, whether or not personal data is involved |
| Main regulatory recipient | The competent data-protection supervisory authority, commonly the CPDP in Bulgaria, subject to the GDPR lead-authority rules | The competent financial supervisory authority for the entity and its licence |
| First headline deadline | Without undue delay and, where feasible, within 72 hours after awareness, unless the breach is unlikely to result in a risk to people | Within 4 hours after classification as major and no later than 24 hours after awareness of the ICT-related incident |
Why neither regime absorbs the other
DORA contains no rule making it apply instead of GDPR. Its Article 56 expressly requires the European Supervisory Authorities and competent authorities to process personal data in accordance with GDPR or the data-protection regulation for EU institutions. For the financial entity, any personal-data processing needed for incident management, evidence or supplier oversight still needs a GDPR basis, purpose, minimisation, retention rule and protection of data-subject rights.
Where the two regimes overlap
Security controls
GDPR Article 32 requires measures appropriate to the risk to personal data. DORA Chapter II requires a broader ICT risk-management framework for the systems and data supporting financial services. A control can be shared, but the risk assessment and evidence must answer both purposes.
ICT providers and contracts
GDPR Article 28 governs processors, instructions, security, subprocessors and return or deletion of personal data. DORA Articles 28–30 govern ICT third-party risk, the register of information and contractual provisions on matters including service locations, security, audit, incident assistance, continuity and exit.
Incidents
An outage with no personal-data impact may engage DORA but not GDPR breach notification. A personal-data leak may engage GDPR even when it is not a major DORA incident. Ransomware affecting a critical service and customer records may trigger both.
Threat-information sharing
DORA Article 45 permits financial entities to exchange cyber-threat information within trusted arrangements. If the information contains personal data, GDPR still requires a lawful basis, necessity, minimisation and appropriate safeguards.
One supplier contract may need both sets of clauses
A cloud or managed-service agreement often needs a GDPR data-processing agreement and the DORA provisions required for the ICT service. Recording where data is processed or stored for DORA does not replace the GDPR rules for transfers to third countries. Remote access or a subprocessor outside the EEA may still require an adequacy decision, standard contractual clauses or another Chapter V mechanism and the related assessment.
One event can start two clocks
| Scenario | DORA assessment | GDPR assessment |
|---|---|---|
| A critical system is unavailable, but personal data is not compromised | Classify under DORA and report if the major-incident criteria are met | No Article 33 notification merely because the service is unavailable, unless the event is also a personal data breach that meets the notification test |
| Customer data is disclosed, but the DORA major-incident thresholds are not met | Record and assess under DORA; major-incident reporting may not be triggered | Notify the supervisory authority unless the breach is unlikely to result in a risk to people; communicate to affected people if the high-risk test in Article 34 is met |
| Ransomware disrupts a critical service and exposes customer records | The DORA reporting sequence may apply | The GDPR controller-notification and, where relevant, data-subject communication duties may also apply |
The roles are connected but not interchangeable
The data protection officer advises and monitors compliance with data-protection law. The functions responsible for ICT risk and security manage operational resilience and technical risk. The same people may contribute evidence and decisions, but any combination of responsibilities must preserve independence, capacity and the absence of conflicts of interest.
The registers are also different
GDPR Article 30 record
Describes processing activities involving personal data: purposes, categories, recipients, transfers, retention and security measures.
DORA register of information
Describes contractual arrangements for ICT services and supports oversight of ICT third-party risk.
A practical joint playbook
- Classify under DORAIs this a major ICT-related incident? Record the criteria, classification time, financial recipient and DORA reporting deadlines.
- Assess the personal data breachWere personal data affected? Is there a risk to people? Record the Article 33 decision and whether Article 34 communication is required.
- Check the provider routeApply the DORA contract and, where the provider is a processor, its duty to notify the controller without undue delay under GDPR Article 33(2).
- Use one fact recordMaintain one verified chronology, affected assets, data, people, services and actions, with separate DORA and GDPR decision fields.
- Control external communicationsEnsure reports to financial, cyber and data-protection authorities remain consistent while answering their different legal tests.
Three misleading shortcuts
“DORA absorbs GDPR security for banks.”
It does not. A control may support both regimes, while the personal-data risk and GDPR evidence remain separate.
“The DPO is the ICT risk function.”
The roles have different legal purposes. Cooperation is necessary; substituting one for the other can create gaps and conflicts.
“The DORA register replaces the GDPR Article 30 record.”
The two registers describe different objects and should be linked where the same ICT service processes personal data.
In one sentence
Read how DORA and NIS2 differ → · DORA → · Regulatory reference →
This article provides general information, not legal advice. The obligations for a specific incident or contract depend on the entity, licence, processing roles, affected data, risk to individuals, service impact and applicable supervisory arrangements.