Data Centres: European Cybersecurity and Technology Law
Data Centres: European Cybersecurity and Technology Law
This marketing material was produced for the Eversheds Sutherland Data Centre Breakfast Forum, held exclusively for data centre clients on 29 April 2026.
Cybersecurity and operational resilience requirements are converging quickly - with real consequences for governance, incident response, and customer expectations. The European Union places particular focus on the second Network and Information Security Directive (“NIS2”), the Directive on the Resilience of Critical Entities (“CER”), as well as the Digital Operational Resilience Act (“DORA”).
NIS2 minimum cybersecurity standards
EU harmonisation: NIS2 introduces a new minimum harmonisation of cybersecurity. EU member states are at various implementation stages.
ICT risk-management: The Directive requires data centres to adopt an all-hazards approach and sound ICT risk-management. This includes registration requirements, incident reporting to the supervisory authority (24h, 72h, 1 month) and supply chain management.
Personal liability of management: The management body must undertake mandatory NIS2 training and will be personally liable for its implementation.
Data centre specific: As part of the digital infrastructure, data centres are subject to higher standards under the EU Commission implementing standards for cybersecurity risk-management measures. They are also subject to the main establishment rule.
DORA’s direct and indirect effects
Evolving beyond outsourcing: Requirements for services to regulated customers in the EU have increased for ICT third-party risk, specifically in the financial and insurance sectors.
Contractual uplift: Customers are required to uplift their agreements to the new DORA standards, including specific termination and audit rights, business contingency measures, incident support, specific forms of penetration testing (TLPT) and significant subcontractor, and supply chain requirements.
Direct DORA oversight: ICT services which supply a majority of the EU financial sector have been designated as critical under the oversight framework. Currently 19 suppliers are under the direct supervision of the European financial authorities (e.g., Equinix and InterXion, NTT, Google, AWS, Microsoft).
Other European technology developments
CER for critical entities: CER introduces physical and environmental security and registration requirements, currently being implemented by EU member states. The relationship to NIS2 obligations should be closely assessed due potential precedence in certain respects.
EU AI Act: AI systems are subject to increased scrutiny under the EU AI Act where they are classified as “high-risk”. This should be assessed in particular where data centres provide and/or deploy AI systems intended to be used as safety components in the management or operation of their facilities that qualify as critical infrastructure.
Data sovereignty under increased political and customer focus: The EU explicitly frames “digital sovereignty” as a strategic priority. While DORA and NIS2 place emphasis on visibility of locations in the supply chain, sovereignty‑related requirements at this stage primarily translate to obligations for customers looking to qualify as an EU sovereign cloud.
Data protection: EU supervisory authorities place increasing emphasis on employee and visitor personal data, such as CCTV, access control, visitor logs and employee monitoring.
In an era increasingly defined by AI deployment, hyperscale infrastructure and data driven business models, compliance is no longer a purely defensive exercise for data centre providers. As cybersecurity, operational resilience and digital governance frameworks continue to converge at EU level, regulatory readiness has become a core element of trust, resilience and commercial differentiation. Providers that proactively embed compliance into their strategies are notably better positioned to meet increasing customer expectations and support long term growth in Europe. In this environment, compliance is a decisive competitive advantage, not only mitigating regulatory risk but also enabling new business opportunities with customers subject to stringent regulatory requirements.
Eversheds Sutherland’s cross jurisdictional data centre and privacy, cyber and tech teams specialise in this precise sector with practical, business focused advice. For more details and bespoke legal advice, please reach out to your contacts below.
"Eversheds Sutherland" imasi visų deramų atsargumo priemonių, siekiant užtikrinti, kad "Eversheds Sutherland" interneto svetainėje pateikiama medžiaga, informacija ir dokumentai, įskaitant, bet neapsiribojant straipsniais, naujienlaiškiais, pranešimais ir tinklaraščio įrašais ("Medžiaga"), yra tiksli ir išsami. Tačiau, Medžiaga yra pateikiama tik kaip bendra informacija. Tokios informacijos pateikimas negali būti siejamas su teisinės pagalbos teikimu, ir tokia informacija nebūtinai atitinka dabartiniu metu galiojančius įstatymus ir teisės aktus. Medžiaga neturėtų būti interpretuojama kaip teisinė pagalba bet kokiu klausimu.
Medžiaga gali neatspindėti naujausių pokyčių teisės srityje. Medžiagos turinys ir interpretavimas ir Medžiagoje aptariami teisės aktai turi būti patikrinti. Nesuteikiami jokie pareiškimai arba aiškiai išreikštos ar numanomos garantijos dėl Medžiagos tikslumo ir išsamumo, todėl Medžiaga neturėtų būti pasikliaunama. "Eversheds Sutherland" neprisiima jokios atsakomybės dėl veiksmų, kurie buvo įvykdyti arba neįvykdyti remiantis bet kokiu ir visu Medžiagoje pateiktu turiniu, kiek tai leidžiama pagal įstatymus. Medžiaga negali būti laikoma išsamia arba joje nepateikiami patarimai, kuriais jūs galėtumėte remtis. Bet kokiu konkrečiu teisės klausimu, jūs visuomet turėtumėte pasikonsultuoti su tinkamą kvalifikaciją turinčiu teisininku/ advokatu.
Medžiagoje išreikšta bet kokia nuomonė yra asmeninė autoriaus nuomonė ir gali nesutapti su "Eversheds Sutherland" arba bet kokio kito individualaus teisininko/ advokato nuomone.