惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
爱范儿
爱范儿
MongoDB | Blog
MongoDB | Blog
腾讯CDC
aimingoo的专栏
aimingoo的专栏
月光博客
月光博客
Engineering at Meta
Engineering at Meta
C
Check Point Blog
N
Netflix TechBlog - Medium
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
B
Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
WordPress大学
WordPress大学
博客园 - 司徒正美

Privacy & Cybersecurity Law Blog

FTC Rescinds 2021 Policy Statement on Health App Data Breaches EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan EDPB Opens Public Consultation on New Personal Data Breach Notification Template
European Commission Refers Four Member States to CJEU Ove...
2026-07-09 · via Privacy & Cybersecurity Law Blog

European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays

On July 8, 2026, the European Commission announced that it had referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union (“CJEU”) for failing to notify the Commission that they had fully transposed Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the European Union (the “NIS2 Directive”) into national law.  

The NIS2 Directive is intended to strengthen cybersecurity across the EU by imposing risk management and incident reporting requirements on entities operating in critical sectors, including health, energy, transport, and the public sector. EU Member States were required to transpose the NIS2 Directive into their national laws by October 17, 2024.

According to the Commission, the four EU Member States have not yet notified the Commission that they have completed the required transposition. The Commission sent letters of formal notice on November 28, 2024, and sent reasoned opinions on May 7, 2025, before referring the matter to the CJEU.

The Commission has requested the CJEU to impose financial sanctions, including lump-sum amounts and daily penalties, on the EU Member States until full transposition is notified. The referrals reflect the Commission’s view that timely implementation of the NIS2 Directive is important to improving cybersecurity resilience and incident response capacity across the EU.

The decision comes as the Commission continues to refine the EU’s cybersecurity framework. As part of a broader cybersecurity package released in January 2026, the Commission proposed targeted amendments to the NIS2 Directive intended to provide greater legal clarity and make compliance more manageable for companies operating in the EU. Read more about the Commission’s January 2026 proposals here.

Read the press release here.