One incident log for GDPR and NIS2

A personal data breach and a security incident go in the same register, on the same form. Record what happened and what you did about it, attach the documentation that proves it, delegate the follow-up, and export the lot when somebody asks six months later.

Unlimited users  •  Free onboarding and support  •  No commitment

One open register panel holding several incident rows, with evidence cards and a follow-up card gathered onto it rather than scattered around it
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
The incident log in .legal, listing three registered incidents with the type of incident, a severity and the date and time each one started, above buttons to create an incident or download the log

One incident log Meridian's incidents stopped living in a mailbox

Anders Krogh is CISO at Meridian Nordic, an energy group with entities in Denmark, Sweden and Germany, and NIS2, ISO 27001 and GDPR all live at the same time. Sofie Bruhn, the group DPO, sits with her own half of the same job. Incidents used to be handled in an email thread and written up in a Word file afterwards, if anybody got round to it. Now the two of them register in the same log: what happened, when it started, what caused it, what was done about it, and who was told. The documentation is attached to the record, and the follow-up is a task with somebody's name and a date on it.

  • One register for both jobs, so a personal data breach and an operational security incident go the same way.
  • Cause, nature, potential consequences and the measures implemented, captured while people still remember them.
  • Whether it was reported, when the report was made, and whether the affected individuals were notified.
  • One incident exports as a zip with a PDF summary, and the whole log exports as Excel.

  • One log, two regimes

    A personal data breach and an operational security incident are registered in the same place, on the same form, by the same drill.

  • Evidence on the record

    Attach the extract, the email receipt and the supplier's reply to the incident itself, while you create it or at any point after.

  • Follow-up with a name on it

    Create a task straight from the incident with a responsible person, a business area and a deadline, linked back automatically.

  • It leaves the platform

    One incident as a zip of its documents plus a PDF summary, the whole log as Excel, whenever somebody asks to see it.

Four separate mail trays each holding a different version of the same account, with loose evidence cards lying between them and nothing joining them up

One incident log Incidents that live in a mailbox

The incident itself is rarely the hard part six months later. The hard part is that the account of it is spread across four inboxes and one person's memory.

  • Everybody who handled it wrote it down somewhere different, and nothing says which version is the account of record.
  • The evidence, the extract, the receipt, the supplier's reply, sits wherever it happened to land.
  • When somebody asks what you actually did about it, the answer is a search rather than a document.
The create-incident form in .legal, with fields for the name, the date and time it started, the cause, tags, the nature of the incident, the types of personal data affected and the severity

One incident log One drill, two regimes

Anders and Sofie do not need two systems and two habits. The incident log is one standard form with fixed fields, and both of them fill in the same one.

  • What happened and when it started, the cause, the nature of it, and the potential consequences for individuals, for the company and for the services.
  • Which types of personal data were involved, when it is that kind of incident.
  • The measures you implemented to deal with it and to limit the damage.
One incident open on its documents tab in .legal, with two files attached to the record, above the fields recording the date and time, the type of incident, the personal data affected and whether it was reported to the data protection authority

One incident log Reported, notified, and the proof attached

The two questions that come back later are whether you told the authority and whether you told the people affected. Both sit on the record, and so does what proves it.

  • Whether the incident was reported to the data protection authority, and when the report was made.
  • Whether the affected individuals were notified.
  • The documentation attached to the incident itself, an extract from another system or an email receipt for the notification. Files can go on while you create the incident or at any point after.
The tasks tab on one incident in .legal, holding a single follow-up task to write up the incident, with its status and the colleague responsible for it

One incident log What happens next gets a name and a date

Registering the incident is half the job. The other half is the work that follows it, and that is the half that quietly stalls.

  • Create a task straight from the incident page with a name, a responsible person, a business area and a deadline.
  • The task links back to the incident automatically, so the follow-up and the account of what happened stay together.
  • Mention a colleague in a task comment or in the incident's own cause field, and the discussion stays with the record instead of in a chat thread.
One incident record closing into a single sealed bundle beside a wider sheet drawn from the whole register

One incident log When somebody asks to see it

This is what the log is for. Somebody asks months later, and you want one artefact rather than a reconstruction.

  • A single incident downloads as a zip of its uploaded documents plus a PDF summary of the incident.
  • The full log exports as Excel, for an internal review, a report or an audit.
  • Incidents by severity is one of the fixed widgets on the Compliance Dashboard, for the group as a whole or drilled down to one company.
A tall record panel with empty rows, and one figure filling a row in by hand — no dial, no counter and nothing on the panel that counts down

One incident log We hold the record of the reporting. You do the reporting.

Two boundaries, said plainly, because they are the two things everybody assumes. Better read here than discovered during your first incident.

  • There is no countdown. The platform does not track the statutory deadlines, not the ones under NIS2 and not the 72-hour one under GDPR, and nothing on an incident counts down.
  • Nothing is filed for you. There is no submission to a supervisory authority and no receipt handling. You report where you have always reported, and the log holds the record that you did.
  • The platform is the record, not the detector. It does not scan and it never derives a status from breaches found automatically, so it is not a SIEM, and spotting the incident is still your job.
.legal in practice

Features for one incident log

A standard incident form

Fixed fields, the same for everybody: what happened and when it started, the cause, the nature of it, the potential consequences and the measures you implemented.

Reported and notified, on the record

Whether the incident was reported to the data protection authority and when the report was made, and whether the affected individuals were notified.

Documentation on the incident

Upload files while you create the incident or afterwards, an extract from another system or an email receipt for the notification, all gathered on the record.

Tasks straight off the incident

Create the follow-up from the incident page with a name, a responsible person, a business area and a deadline. The task links back to the incident automatically.

Export one incident or the whole log

A single incident downloads as a zip of its uploaded documents plus a PDF summary. The full log exports as Excel for an internal review, a report or an audit.

Incidents by severity on the dashboard

One of the fixed widgets on the Compliance Dashboard shows how registered incidents distribute by severity, for the whole group or drilled down to one company.

One incident log Frameworks this covers

One log, and the two regimes that send people looking for it.

  • icon-framework-GDPR

    GDPR

    Articles 33 and 34 are a documentation job: what happened, whether it had to be reported, whether the people affected were told, and what proves it. The fields on the incident log are shaped around exactly that.

    Read about GDPR
  • icon-framework-NIS2

    NIS2

    Incident handling is one of the risk-management measures behind the services you deliver. .legal holds the NIS2 framework and the controls beneath it, and the log is where you document your own handling. Reporting to an authority happens outside the platform.

    Read about NIS2
.legal compliance platform

Keep one incident log with...

Do you need one register for both regimes? We recommend the following modules for that task.

GDPR / Data Protection

Where the incident log sits alongside the record of processing, the processing activities, the assets and the annual wheel (årshjul).

Explore GDPR

Information Security Management

Where your security documentation and controls live, so incident registration sits next to the controls that ask for it. The frameworks themselves, NIS2 and ISO 27001 among them, are run in the Frameworks module.

Explore Information Security Management

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
Use cases

Find the job you need done

Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.

Book demo

12 use cases

Compliance & GRC lead

Run awareness training that reaches every colleague

Send out training and policies, chase the stragglers automatically, and prove every colleague completed it. You bring the material, we run the rails.
See awareness training
Compliance & GRC lead

Manage compliance across a group of companies

Run every company in the group from one platform, document once at group level, and still report entity by entity. Delivered by the Group Companies add-on.
See group compliance
Legal counsel

Run due diligence on your vendors

Classify a vendor on your own criteria, get the answers and documents you need with no login for them, and move the approved ones straight into contracts.
See vendor due diligence
Compliance & GRC lead

Multi-framework compliance: do the work once

Do a control once and it counts across every framework it maps to, with a simulated score on the ones you haven't started yet.
See multi-framework compliance
CISO & IT security

Get NIS2-ready without starting from scratch

Build on the ISO 27001 work you've already done, switch NIS2 on, and let a simulated score show how far ahead you already are.
See NIS2 readiness
DPO

From twelve spreadsheets to one record of processing

Your GDPR documentation already exists, it just lives in spreadsheets. Export what you have and we structure it in .legal for you, typically inside two weeks.
See the move off spreadsheets
Compliance & GRC lead

Build one risk register for the whole organisation

One register across GDPR, NIS2, AI and information security, where each risk area keeps its own matrix, scale and appetite. Delivered by the Enterprise Risk Management add-on.
See the risk register
Executive & board

Give the board a risk picture it can act on

One management report across every risk area: entities assessed, risks above appetite, exposure now and once the open plans are done. Export it with your own comment on it.
See board risk reporting

Frequently Asked Questions about incident registration

Does .legal track the NIS2 and GDPR reporting deadlines?

No, and we would rather say it here than let you find out during an incident. There is no countdown on an incident, no 24-hour or 72-hour timer, no one-month reminder, and nothing tells you that a clock has started running. What the log does is hold the decision and the proof: whether the incident had to be reported, whether it was, when the report was made, and whether the affected individuals were notified. We hold the record of the reporting. You do the reporting.

Can we submit a report to an authority from the platform?

No. There is no submission, no form generated for a supervisory authority and no receipt handling. You report the way you report today, and then the log records that it happened, when it happened and what proves it, an email receipt for example. The point is that afterwards the account and the evidence sit in the same place instead of in somebody's inbox.

Is this a GDPR log or a NIS2 log?

One log, and the history behind it is worth knowing. It was built for GDPR, so the fields are shaped around Articles 33 and 34, with the types of personal data involved and the notification of the individuals concerned. There are no NIS2-specific fields and no separate NIS2 incident form. In practice the same register carries both, because the questions asked afterwards are the same ones: what happened, what did you do about it, who did you tell, and can you show it.

Getting NIS2-ready without starting from scratch

Does .legal detect incidents?

No. The platform is the record, not the detector. It does not scan anything and it never derives a status from security breaches found automatically, which is exactly what a SIEM does. Spotting the incident out there is still your job, and registering it is a person filling in a form. If what you need is a SIEM, you need to buy one somewhere else, because this does not replace it.

How the management system runs day to day

What can we get out of it when an auditor asks?

Two things. A single incident downloads as a zip of its uploaded documents together with a PDF summary of the incident itself. The whole log exports as Excel, for an internal review, a report or an audit. Both have been in the product since March 2025, so this is not a new promise.

Keeping your records of processing audit-ready

Can we see incidents across the group?

Yes, at dashboard level. Incidents by severity is one of the fixed widgets on the Compliance Dashboard, showing how registered incidents distribute by severity, for the whole group or drilled down to a single company. Read it as an operational overview of where the pressure is, not as a management report and not as a status on your compliance.

Can we link an incident to the system or the supplier it affected?

Not as a relationship in the data model, and we would rather be exact about that than let you assume it. You can name the system or the supplier in the incident's cause field, where you can also @-mention the colleague who deals with it, and you can put a tag on the incident so it groups with everything else you tag that way. Both are useful. Neither is a connection you could report on. If a structured link matters to your process, raise it on a demo rather than read it into this page.

Can we add our own fields to the incident form?

Not today. The incident log is a standard form with fixed fields, the same ones for everybody. Custom fields do exist elsewhere in the platform, as an add-on, so if that is a requirement for you it belongs on the table in a demo rather than being assumed either way.

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell