GUTcert has informed the relevant data protection authority about the incident and is continuing to assess which individuals and data may have been affected, with updates provided as new facts emerge. Organizations should independently review whether the breach triggers reporting duties under BSIG, NIS2, DORA, or critical infrastructure rules, especially if sensitive security-related information may have been exposed. #GUTcert #BSIG #NIS2 #DORA
Keypoints
- GUTcert has submitted a preliminary notice to the data protection authority.
- The company is still investigating which individuals and data were affected.
- Customers were first informed about the incident on 14.09.2026.
- Organizations under BSIG or NIS2 should quickly assess possible reporting obligations.
- Critical infrastructure operators and financial entities may face additional sector-specific requirements.
Read More: https://www.gut-cert.de/de/service/sicherheitsvorfall