Data Centres: European Cybersecurity and Technology Law
Data Centres: European Cybersecurity and Technology Law
This marketing material was produced for the Eversheds Sutherland Data Centre Breakfast Forum, held exclusively for data centre clients on 29 April 2026.
Cybersecurity and operational resilience requirements are converging quickly - with real consequences for governance, incident response, and customer expectations. The European Union places particular focus on the second Network and Information Security Directive (“NIS2”), the Directive on the Resilience of Critical Entities (“CER”), as well as the Digital Operational Resilience Act (“DORA”).
NIS2 minimum cybersecurity standards
EU harmonisation: NIS2 introduces a new minimum harmonisation of cybersecurity. EU member states are at various implementation stages.
ICT risk-management: The Directive requires data centres to adopt an all-hazards approach and sound ICT risk-management. This includes registration requirements, incident reporting to the supervisory authority (24h, 72h, 1 month) and supply chain management.
Personal liability of management: The management body must undertake mandatory NIS2 training and will be personally liable for its implementation.
Data centre specific: As part of the digital infrastructure, data centres are subject to higher standards under the EU Commission implementing standards for cybersecurity risk-management measures. They are also subject to the main establishment rule.
DORA’s direct and indirect effects
Evolving beyond outsourcing: Requirements for services to regulated customers in the EU have increased for ICT third-party risk, specifically in the financial and insurance sectors.
Contractual uplift: Customers are required to uplift their agreements to the new DORA standards, including specific termination and audit rights, business contingency measures, incident support, specific forms of penetration testing (TLPT) and significant subcontractor, and supply chain requirements.
Direct DORA oversight: ICT services which supply a majority of the EU financial sector have been designated as critical under the oversight framework. Currently 19 suppliers are under the direct supervision of the European financial authorities (e.g., Equinix and InterXion, NTT, Google, AWS, Microsoft).
Other European technology developments
CER for critical entities: CER introduces physical and environmental security and registration requirements, currently being implemented by EU member states. The relationship to NIS2 obligations should be closely assessed due potential precedence in certain respects.
EU AI Act: AI systems are subject to increased scrutiny under the EU AI Act where they are classified as “high-risk”. This should be assessed in particular where data centres provide and/or deploy AI systems intended to be used as safety components in the management or operation of their facilities that qualify as critical infrastructure.
Data sovereignty under increased political and customer focus: The EU explicitly frames “digital sovereignty” as a strategic priority. While DORA and NIS2 place emphasis on visibility of locations in the supply chain, sovereignty‑related requirements at this stage primarily translate to obligations for customers looking to qualify as an EU sovereign cloud.
Data protection: EU supervisory authorities place increasing emphasis on employee and visitor personal data, such as CCTV, access control, visitor logs and employee monitoring.
In an era increasingly defined by AI deployment, hyperscale infrastructure and data driven business models, compliance is no longer a purely defensive exercise for data centre providers. As cybersecurity, operational resilience and digital governance frameworks continue to converge at EU level, regulatory readiness has become a core element of trust, resilience and commercial differentiation. Providers that proactively embed compliance into their strategies are notably better positioned to meet increasing customer expectations and support long term growth in Europe. In this environment, compliance is a decisive competitive advantage, not only mitigating regulatory risk but also enabling new business opportunities with customers subject to stringent regulatory requirements.
Eversheds Sutherland’s cross jurisdictional data centre and privacy, cyber and tech teams specialise in this precise sector with practical, business focused advice. For more details and bespoke legal advice, please reach out to your contacts below.
Eversheds Sutherland prend toutes les précautions raisonnables et nécessaires pour s'assurer que les informations et les documents, y compris, mais sans s'y limiter, les articles, les bulletins d'information, les rapports, les enquêtes et les blogs ("matériel") sur le site Web d'Eversheds Sutherland sont exacts et complets. Toutefois, ces documents sont fournis à titre d'information générale uniquement, et non dans le but de fournir des conseils juridiques, et ne reflètent pas nécessairement la législation ou la réglementation en vigueur. Ces documents ne doivent pas être interprétés comme des conseils juridiques sur quelque sujet que ce soit.
Les documents peuvent ne pas refléter les développements juridiques les plus récents. Le contenu et l'interprétation des documents, ainsi que la législation qui y est abordée, peuvent faire l'objet de révisions.
Aucune déclaration ou garantie, expresse ou implicite, n'est faite quant à l'exactitude ou à l'exhaustivité de la documentation et il convient donc de ne pas s'y fier. Eversheds Sutherland décline toute responsabilité en ce qui concerne les mesures prises ou non prises sur la base de tout ou partie du contenu des documents, dans toute la mesure permise par la loi. Les documents n'ont pas vocation à être exhaustifs ou à inclure des conseils sur lesquels vous pouvez vous appuyer. Vous devez toujours consulter un juriste/avocat dûment qualifié pour toute question juridique spécifique.
Les opinions exprimées dans les documents sont celles de leur auteur et ne reflètent pas nécessairement celles d'Eversheds Sutherland ou de tout autre avocat.