Source: OJ L, 2024/2690, 18.10.2024

Current language: FR

Article 8 Incidents importants concernant les fournisseurs de services de centres de données


Summary What does Article 8 of the Cybersecurity measures and significant incidents for relevant entities say?

This article forms part of a series of sector-specific articles (Articles 5 to 14) that build on the general significance criteria established in Article 3, tailoring them to particular entity types.

Article 8 applies those thresholds specifically to data centre service providers, defining the conditions under which an incident must be treated as significant.

Notably, the criteria here are comparatively strict — for example, any complete unavailability of a data centre service triggers significance regardless of duration, and even a limited availability disruption lasting more than one hour qualifies.

Important points:

  • Data centre service providers must treat any complete unavailability of their service as a significant incident, with no minimum duration threshold required.
  • Report an incident where availability is limited for more than one hour, data integrity or confidentiality is compromised through a suspectedly malicious action, or physical access to the data centre is compromised.
  • The physical access criterion is distinctive to this article and reflects the critical infrastructure nature of data centres, where on-site security is treated as equally important as digital availability.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

En ce qui concerne les fournisseurs de services de centres de données, un incident est considéré comme important au sens de l’article 3, paragraphe 1, point g), lorsqu’il remplit un ou plusieurs des critères suivants:

  1. un service d’un centre de données exploité par le fournisseur est totalement indisponible;

  2. la disponibilité d’un service d’un centre de données exploité par le fournisseur est limitée pendant plus d’une heure;

  3. l’intégrité, la confidentialité ou l’authenticité des données stockées, transmises ou traitées liées à la fourniture d’un service de centre de données est compromise par une action suspectée d’être malveillante,

  4. l’accès physique à un centre de données exploité par le fournisseur est compromis.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod