NCA or SDAIA? Same Incident, Two Separate Tracks
A parallel track, not a substitute
Notifying NCA about a cybersecurity incident is a fully separate track from notifying SDAIA about a personal-data incident. Filing one doesn’t satisfy the other. The same incident can require both at once.
So who’s legally on the hook
Executing the cybersecurity controls falls to the CISO’s team. But the legal accountability to SDAIA for whether those controls were sufficient sits with the Controller itself, not the CISO alone. That means the DPO and CISO genuinely need a clear coordination line, not two jobs running in parallel without talking to each other.
See where your own data actually stands → free scan