Article · published 13 September 2026

DORA and GDPR: when both apply to the same incident

DORA does not replace GDPR and is not lex specialis in relation to it. DORA focuses on the digital operational resilience of the financial entity; GDPR protects people and their personal data. When the same system, provider or incident engages both, both regimes must be assessed.

The short answer

Use one operational response, but make two legal assessments. The same technical control or incident record can support both regimes, while the purpose, threshold, recipient and deadline remain different.

Different rules, different objects

QuestionGDPRDORA
What it protectsPersonal data and the rights and freedoms of individualsThe digital operational resilience of the financial entity and the continued delivery of financial services
Who it applies toControllers and processors within the Regulation’s scopeFinancial entities listed in Article 2; ICT providers are mainly affected through contracts, with direct EU oversight for providers designated as critical
Relevant incidentA personal data breach: a security breach affecting the confidentiality, integrity or availability of personal dataA major ICT-related incident under DORA’s classification rules, whether or not personal data is involved
Main regulatory recipientThe competent data-protection supervisory authority, commonly the CPDP in Bulgaria, subject to the GDPR lead-authority rulesThe competent financial supervisory authority for the entity and its licence
First headline deadlineWithout undue delay and, where feasible, within 72 hours after awareness, unless the breach is unlikely to result in a risk to peopleWithin 4 hours after classification as major and no later than 24 hours after awareness of the ICT-related incident

Why neither regime absorbs the other

DORA contains no rule making it apply instead of GDPR. Its Article 56 expressly requires the European Supervisory Authorities and competent authorities to process personal data in accordance with GDPR or the data-protection regulation for EU institutions. For the financial entity, any personal-data processing needed for incident management, evidence or supplier oversight still needs a GDPR basis, purpose, minimisation, retention rule and protection of data-subject rights.

Where the two regimes overlap

Security controls

GDPR Article 32 requires measures appropriate to the risk to personal data. DORA Chapter II requires a broader ICT risk-management framework for the systems and data supporting financial services. A control can be shared, but the risk assessment and evidence must answer both purposes.

ICT providers and contracts

GDPR Article 28 governs processors, instructions, security, subprocessors and return or deletion of personal data. DORA Articles 28–30 govern ICT third-party risk, the register of information and contractual provisions on matters including service locations, security, audit, incident assistance, continuity and exit.

Incidents

An outage with no personal-data impact may engage DORA but not GDPR breach notification. A personal-data leak may engage GDPR even when it is not a major DORA incident. Ransomware affecting a critical service and customer records may trigger both.

Threat-information sharing

DORA Article 45 permits financial entities to exchange cyber-threat information within trusted arrangements. If the information contains personal data, GDPR still requires a lawful basis, necessity, minimisation and appropriate safeguards.

One supplier contract may need both sets of clauses

A cloud or managed-service agreement often needs a GDPR data-processing agreement and the DORA provisions required for the ICT service. Recording where data is processed or stored for DORA does not replace the GDPR rules for transfers to third countries. Remote access or a subprocessor outside the EEA may still require an adequacy decision, standard contractual clauses or another Chapter V mechanism and the related assessment.

One event can start two clocks

ScenarioDORA assessmentGDPR assessment
A critical system is unavailable, but personal data is not compromisedClassify under DORA and report if the major-incident criteria are metNo Article 33 notification merely because the service is unavailable, unless the event is also a personal data breach that meets the notification test
Customer data is disclosed, but the DORA major-incident thresholds are not metRecord and assess under DORA; major-incident reporting may not be triggeredNotify the supervisory authority unless the breach is unlikely to result in a risk to people; communicate to affected people if the high-risk test in Article 34 is met
Ransomware disrupts a critical service and exposes customer recordsThe DORA reporting sequence may applyThe GDPR controller-notification and, where relevant, data-subject communication duties may also apply
A report to the financial supervisor does not replace a required GDPR notification. A GDPR notification does not replace DORA reporting. The facts and technical evidence can be shared internally, but each decision and deadline should be recorded separately.

The roles are connected but not interchangeable

The data protection officer advises and monitors compliance with data-protection law. The functions responsible for ICT risk and security manage operational resilience and technical risk. The same people may contribute evidence and decisions, but any combination of responsibilities must preserve independence, capacity and the absence of conflicts of interest.

The registers are also different

GDPR Article 30 record

Describes processing activities involving personal data: purposes, categories, recipients, transfers, retention and security measures.

DORA register of information

Describes contractual arrangements for ICT services and supports oversight of ICT third-party risk.

A practical joint playbook

  1. Classify under DORAIs this a major ICT-related incident? Record the criteria, classification time, financial recipient and DORA reporting deadlines.
  2. Assess the personal data breachWere personal data affected? Is there a risk to people? Record the Article 33 decision and whether Article 34 communication is required.
  3. Check the provider routeApply the DORA contract and, where the provider is a processor, its duty to notify the controller without undue delay under GDPR Article 33(2).
  4. Use one fact recordMaintain one verified chronology, affected assets, data, people, services and actions, with separate DORA and GDPR decision fields.
  5. Control external communicationsEnsure reports to financial, cyber and data-protection authorities remain consistent while answering their different legal tests.

Three misleading shortcuts

“DORA absorbs GDPR security for banks.”

It does not. A control may support both regimes, while the personal-data risk and GDPR evidence remain separate.

“The DPO is the ICT risk function.”

The roles have different legal purposes. Cooperation is necessary; substituting one for the other can create gaps and conflicts.

“The DORA register replaces the GDPR Article 30 record.”

The two registers describe different objects and should be linked where the same ICT service processes personal data.

In one sentence

DORA asks whether the financial service can withstand and recover from an ICT disruption; GDPR asks what happened to people and their personal data. When the same event engages both, run one coordinated response and complete both legal assessments.

Read how DORA and NIS2 differ → · DORA → · Regulatory reference →

This article provides general information, not legal advice. The obligations for a specific incident or contract depend on the entity, licence, processing roles, affected data, risk to individuals, service impact and applicable supervisory arrangements.

Primary sources

All articles →