L 194/12
EN
Official Journal of the European Union
19.7.2016
(d) establishes security and notification requirements for operators of essential services and for digital service providers;
(e) lays down obligations for Member States to designate national competent authorities, single points of contact and
CSIRTs with tasks related to the security of network and information systems.
3.
The security and notification requirements provided for in this Directive shall not apply to undertakings which are
subject to the requirements of Articles 13a and 13b of Directive 2002/21/EC, or to trust service providers which are
subject to the requirements of Article 19 of Regulation (EU) No 910/2014.
4.
This Directive applies without prejudice to Council Directive 2008/114/EC (1) and Directives 2011/93/EU (2)
and 2013/40/EU (3) of the European Parliament and of the Council.
5.
Without prejudice to Article 346 TFEU, information that is confidential pursuant to Union and national rules,
such as rules on business confidentiality, shall be exchanged with the Commission and other relevant authorities only
where such exchange is necessary for the application of this Directive. The information exchanged shall be limited to
that which is relevant and proportionate to the purpose of such exchange. Such exchange of information shall preserve
the confidentiality of that information and protect the security and commercial interests of operators of essential
services and digital service providers.
6.
This Directive is without prejudice to the actions taken by Member States to safeguard their essential State
functions, in particular to safeguard national security, including actions protecting information the disclosure of which
Member States consider contrary to the essential interests of their security, and to maintain law and order, in particular
to allow for the investigation, detection and prosecution of criminal offences.
7.
Where a sector-specific Union legal act requires operators of essential services or digital service providers either to
ensure the security of their network and information systems or to notify incidents, provided that such requirements are
at least equivalent in effect to the obligations laid down in this Directive, those provisions of that sector-specific Union
legal act shall apply.
Article 2
Processing of personal data
1.
Processing of personal data pursuant to this Directive shall be carried out in accordance with Directive 95/46/EC.
2.
Processing of personal data by Union institutions and bodies pursuant to this Directive shall be carried out in
accordance with Regulation (EC) No 45/2001.
Article 3
Minimum harmonisation
Without prejudice to Article 16(10) and to their obligations under Union law, Member States may adopt or maintain
provisions with a view to achieving a higher level of security of network and information systems.
(1) Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the
assessment of the need to improve their protection (OJ L 345, 23.12.2008, p. 75).
(2) Directive 2011/93/EU of the European Parliament and of the Council of 13 December 2011 on combating the sexual abuse and sexual
exploitation of children and child pornography, and replacing Council Framework Decision 2004/68/JHA (OJ L 335, 17.12.2011, p. 1).
(3) Directive 2013/40/EU of the European Parliament and of the Council of 12 August 2013 on attacks against information systems and
replacing Council Framework Decision 2005/222/JHA (OJ L 218, 14.8.2013, p. 8).