19.7.2016
EN
Official Journal of the European Union
L 194/23
Article 17
Implementation and enforcement
1.
Member States shall ensure that the competent authorities take action, if necessary, through ex post supervisory
measures, when provided with evidence that a digital service provider does not meet the requirements laid down in
Article 16. Such evidence may be submitted by a competent authority of another Member State where the service is
provided.
2.
For the purposes of paragraph 1, the competent authorities shall have the necessary powers and means to require
digital service providers to:
(a) provide the information necessary to assess the security of their network and information systems, including
documented security policies;
(b) remedy any failure to meet the requirements laid down in Article 16.
3.
If a digital service provider has its main establishment or a representative in a Member State, but its network and
information systems are located in one or more other Member States, the competent authority of the Member State of
the main establishment or of the representative and the competent authorities of those other Member States shall
cooperate and assist each other as necessary. Such assistance and cooperation may cover information exchanges between
the competent authorities concerned and requests to take the supervisory measures referred to in paragraph 2.
Article 18
Jurisdiction and territoriality
1.
For the purposes of this Directive, a digital service provider shall be deemed to be under the jurisdiction of the
Member State in which it has its main establishment. A digital service provider shall be deemed to have its main
establishment in a Member State when it has its head office in that Member State.
2.
A digital service provider that is not established in the Union, but offers services referred to in Annex III within the
Union, shall designate a representative in the Union. The representative shall be established in one of those
Member States where the services are offered. The digital service provider shall be deemed to be under the jurisdiction
of the Member State where the representative is established.
3.
The designation of a representative by the digital service provider shall be without prejudice to legal actions which
could be initiated against the digital service provider itself.
CHAPTER VI
STANDARDISATION AND VOLUNTARY NOTIFICATION
Article 19
Standardisation
1.
In order to promote convergent implementation of Article 14(1) and (2) and Article 16(1) and (2), Member States
shall, without imposing or discriminating in favour of the use of a particular type of technology, encourage the use of
European or internationally accepted standards and specifications relevant to the security of network and information
systems.
2.
ENISA, in collaboration with Member States, shall draw up advice and guidelines regarding the technical areas to
be considered in relation to paragraph 1 as well as regarding already existing standards, including Member States'
national standards, which would allow for those areas to be covered.