27.12.2022
EN
Official Journal of the European Union
L 333/83
(12)
Postal service providers as defined in Directive 97/67/EC of the European Parliament and of the Council (7),
including providers of courier services, should be subject to this Directive if they provide at least one of the steps in
the postal delivery chain, in particular clearance, sorting, transport or distribution of postal items, including pick-up
services, while taking account of the degree of their dependence on network and information systems. Transport
services that are not undertaken in conjunction with one of those steps should be excluded from the scope of postal
services.
(13)
Given the intensification and increased sophistication of cyber threats, Member States should strive to ensure that
entities that are excluded from the scope of this Directive achieve a high level of cybersecurity and to support the
implementation of equivalent cybersecurity risk-management measures that reflect the sensitive nature of those
entities.
(14)
Union data protection law and Union privacy law applies to any processing of personal data under this Directive. In
particular, this Directive is without prejudice to Regulation (EU) 2016/679 of the European Parliament and of the
Council (8) and Directive 2002/58/EC of the European Parliament and of the Council (9). This Directive should
therefore not affect, inter alia, the tasks and powers of the authorities competent to monitor compliance with the
applicable Union data protection law and Union privacy law.
(15)
Entities falling within the scope of this Directive for the purpose of compliance with cybersecurity risk-management
measures and reporting obligations should be classified into two categories, essential entities and important entities,
reflecting the extent to which they are critical as regards their sector or the type of service they provide, as well as
their size. In that regard, due account should be taken of any relevant sectoral risk assessments or guidance by the
competent authorities, where applicable. The supervisory and enforcement regimes for those two categories of
entities should be differentiated to ensure a fair balance between risk-based requirements and obligations on the one
hand, and the administrative burden stemming from the supervision of compliance on the other.
(16)
In order to avoid entities that have partner enterprises or that are linked enterprises being considered to be essential
or important entities where this would be disproportionate, Member States are able to take into account the degree
of independence an entity enjoys in relation to its partner or linked enterprises when applying Article 6(2) of the
Annex to Recommendation 2003/361/EC. In particular, Member States are able to take into account the fact that an
entity is independent from its partner or linked enterprises in terms of the network and information systems that
that entity uses in the provision of its services and in terms of the services that the entity provides. On that basis,
where appropriate, Member States are able to consider that such an entity does not qualify as a medium-sized
enterprise under Article 2 of the Annex to Recommendation 2003/361/EC, or does not exceed the ceilings for a
medium-sized enterprise provided for in paragraph 1 of that Article, if, after taking into account the degree of
independence of that entity, that entity would not have been considered to qualify as a medium-sized enterprise or
to exceed those ceilings in the event that only its own data had been taken into account. This leaves unaffected the
obligations laid down in this Directive of partner and linked enterprises which fall within the scope of this Directive.
(17)
Member States should be able to decide that entities identified before the entry into force of this Directive as
operators of essential services in accordance with Directive (EU) 2016/1148 are to be considered to be essential
entities.
(7) Directive 97/67/EC of the European Parliament and of the Council of 15 December 1997 on common rules for the development of
the internal market of Community postal services and the improvement of quality of service (OJ L 15, 21.1.1998, p. 14).
(8) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with
regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data
Protection Regulation) (OJ L 119, 4.5.2016, p. 1).
(9) Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and
the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)
(OJ L 201, 31.7.2002, p. 37).