19.7.2016
EN
Official Journal of the European Union
L 194/9
(56)
This Directive should not preclude Member States from adopting national measures requiring public-sector
bodies to ensure specific security requirements when they contract cloud computing services. Any such national
measures should apply to the public-sector body concerned and not to the cloud computing service provider.
(57)
Given the fundamental differences between operators of essential services, in particular their direct link with
physical infrastructure, and digital service providers, in particular their cross-border nature, this Directive should
take a differentiated approach with respect to the level of harmonisation in relation to those two groups of
entities. For operators of essential services, Member States should be able to identify the relevant operators and
impose stricter requirements than those laid down in this Directive. Member States should not identify digital
service providers, as this Directive should apply to all digital service providers within its scope. In addition, this
Directive and the implementing acts adopted under it should ensure a high level of harmonisation for digital
service providers with respect to security and notification requirements. This should enable digital service
providers to be treated in a uniform way across the Union, in a manner proportionate to their nature and the
degree of risk which they might face.
(58)
This Directive should not preclude Member States from imposing security and notification requirements on
entities that are not digital service providers within the scope of this Directive, without prejudice to
Member States' obligations under Union law.
(59)
Competent authorities should pay due attention to preserving informal and trusted channels of informationsharing. Publicity of incidents reported to the competent authorities should duly balance the interest of the public
in being informed about threats against possible reputational and commercial damage for the operators of
essential services and digital service providers reporting incidents. In the implementation of the notification
obligations, competent authorities and the CSIRTs should pay particular attention to the need to keep
information about product vulnerabilities strictly confidential, prior to the release of appropriate security fixes.
(60)
Digital service providers should be subject to light-touch and reactive ex post supervisory activities justified by the
nature of their services and operations. The competent authority concerned should therefore only take action
when provided with evidence, for example by the digital service provider itself, by another competent authority,
including a competent authority of another Member State, or by a user of the service, that a digital service
provider is not complying with the requirements of this Directive, in particular following the occurrence of an
incident. The competent authority should therefore have no general obligation to supervise digital service
providers.
(61)
Competent authorities should have the necessary means to perform their duties, including powers to obtain
sufficient information in order to assess the level of security of network and information systems.
(62)
Incidents may be the result of criminal activities the prevention, investigation and prosecution of which is
supported by coordination and cooperation between operators of essential services, digital service providers,
competent authorities and law enforcement authorities. Where it is suspected that an incident is related to serious
criminal activities under Union or national law, Member States should encourage operators of essential services
and digital service providers to report incidents of a suspected serious criminal nature to the relevant law
enforcement authorities. Where appropriate, it is desirable that coordination between competent authorities and
law enforcement authorities of different Member States be facilitated by the European Cybercrime Centre (EC3)
and ENISA.
(63)
Personal data are in many cases compromised as a result of incidents. In this context, competent authorities and
data protection authorities should cooperate and exchange information on all relevant matters to tackle any
personal data breaches resulting from incidents.
(64)
Jurisdiction in respect of digital service providers should be attributed to the Member State in which the digital
service provider concerned has its main establishment in the Union, which in principle corresponds to the place
where the provider has its head office in the Union. Establishment implies the effective and real exercise of
activity through stable arrangements. The legal form of such arrangements, whether through a branch or
a subsidiary with a legal personality, is not the determining factor in this respect. This criterion should not