L 194/10
EN
Official Journal of the European Union
19.7.2016
depend on whether the network and information systems are physically located in a given place; the presence
and use of such systems do not, in themselves, constitute such main establishment and are therefore not criteria
for determining the main establishment.
(65)
Where a digital service provider not established in the Union offers services within the Union, it should designate
a representative. In order to determine whether such a digital service provider is offering services within the
Union, it should be ascertained whether it is apparent that the digital service provider is planning to offer
services to persons in one or more Member States. The mere accessibility in the Union of the digital service
provider's or an intermediary's website or of an email address and of other contact details, or the use of
a language generally used in the third country where the digital service provider is established, is insufficient to
ascertain such an intention. However, factors such as the use of a language or a currency generally used in one or
more Member States with the possibility of ordering services in that other language, or the mentioning of
customers or users who are in the Union, may make it apparent that the digital service provider is planning to
offer services within the Union. The representative should act on behalf of the digital service provider and it
should be possible for competent authorities or the CSIRTs to contact the representative. The representative
should be explicitly designated by a written mandate of the digital service provider to act on the latter's behalf
with regard to the latter's obligations under this Directive, including incident reporting.
(66)
Standardisation of security requirements is a market-driven process. To ensure a convergent application of
security standards, Member States should encourage compliance or conformity with specified standards so as to
ensure a high level of security of network and information systems at Union level. ENISA should assist
Member States through advice and guidelines. To this end, it might be helpful to draft harmonised standards,
which should be done in accordance with Regulation (EU) No 1025/2012 of the European Parliament and of the
Council (1).
(67)
Entities falling outside the scope of this Directive may experience incidents having a significant impact on the
services they provide. Where those entities consider that it is in the public interest to notify the occurrence of
such incidents, they should be able to do so on a voluntary basis. Such notifications should be processed by the
competent authority or the CSIRT where such processing does not constitute a disproportionate or undue burden
on the Member States concerned.
(68)
In order to ensure uniform conditions for the implementation of this Directive, implementing powers should be
conferred on the Commission to lay down the procedural arrangements necessary for the functioning of the
Cooperation Group and the security and notification requirements applicable to digital service providers. Those
powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of
the Council (2). When adopting implementing acts related to the procedural arrangements necessary for the
functioning of the Cooperation Group, the Commission should take the utmost account of the opinion of
ENISA.
(69)
When adopting implementing acts on the security requirements for digital service providers, the Commission
should take the utmost account of the opinion of ENISA and should consult interested stakeholders. Moreover,
the Commission is encouraged to take into account the following examples: as regards security of systems and
facilities: physical and environmental security, security of supplies, access control to network and information
systems and integrity of network and information systems; as regards incident handling: incident-handling
procedures, incident detection capability, incident reporting and communication; as regards business continuity
management: service continuity strategy and contingency plans, disaster recovery capabilities; and as regards
monitoring, auditing and testing: monitoring and logging policies, exercise contingency plans, network and
information systems testing, security assessments and compliance monitoring.
(70)
In the implementation of this Directive, the Commission should liaise as appropriate with relevant sectoral
committees and relevant bodies set up at Union level in the fields covered by this Directive.
(1) Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation,
amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC,
2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council
Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12).
2
( ) Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general
principles concerning mechanisms for control by Member States of the Commission's exercise of implementing powers (OJ L 55,
28.2.2011, p. 13).