The IT Security Act is to be seen as a synopsis of various regulations. Thus, unlike data protection law with the General Data Protection Regulation (GDPR), there is no fundamental norm for IT security. The central difference between data protection law and IT security law is that data protection law contains material processing restrictions and procedural requirements that go widely beyond the security of processing.  Consequently, the concept of IT security is narrower than that of data protection.