In this episode of the PrivacyRules Privacy Espresso Series, Alessandro Di Mattia is joined by Wout Platteau (Timelex, Belgium) to discuss the relationship between two key European regulatory frameworks: NIS2 and the Critical Entities Resilience (CER) Directive.
While NIS2 has received significant attention from organizations focused on cybersecurity compliance, the CER Directive remains less widely understood. Wout explains how the two frameworks work together to strengthen the resilience of critical infrastructure operators, with NIS2 focusing on cybersecurity and information systems, and CER addressing physical resilience, including preparedness for natural disasters, accidents, sabotage, and other disruptions.
The discussion explores:
🔹 The key differences and similarities between NIS2 and CER;
🔹 Why the CER Directive is often overlooked despite its importance;
🔹 Governance and board-level responsibilities under both frameworks;
🔹 The relationship between cybersecurity resilience and physical resilience;
🔹 Whether compliance with one framework automatically supports compliance with the other;
🔹 Practical steps organizations should take to align their resilience efforts.
One clear takeaway: this decision is not only about OpenAI. It sets a precedent that affects every organization processing personal data at scale — and signals that Canada’s privacy legislation is overdue for reform.
Wout also shares a key recommendation for critical infrastructure operators: ensuring there is clear ownership and coordination of resilience across both cyber and physical security functions before an incident occurs.

