Source: OJ L, 2024/2690, 18.10.2024

Current language: SV

Artikel 8 Betydande incidenter när det gäller leverantörer av datacentraltjänster


Summary What does Article 8 of the Cybersecurity measures and significant incidents for relevant entities say?

This article forms part of a series of sector-specific articles (Articles 5 to 14) that build on the general significance criteria established in Article 3, tailoring them to particular entity types.

Article 8 applies those thresholds specifically to data centre service providers, defining the conditions under which an incident must be treated as significant.

Notably, the criteria here are comparatively strict — for example, any complete unavailability of a data centre service triggers significance regardless of duration, and even a limited availability disruption lasting more than one hour qualifies.

Important points:

  • Data centre service providers must treat any complete unavailability of their service as a significant incident, with no minimum duration threshold required.
  • Report an incident where availability is limited for more than one hour, data integrity or confidentiality is compromised through a suspectedly malicious action, or physical access to the data centre is compromised.
  • The physical access criterion is distinctive to this article and reflects the critical infrastructure nature of data centres, where on-site security is treated as equally important as digital availability.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

När det gäller leverantörer av datacentraler ska en incident anses som betydande enligt artikel 3.1 g om den uppfyller ett eller flera av följande kriterier:

  1. En datacentraltjänst hos en datacentral som drivs av leverantören är helt otillgänglig.

  2. Tillgången till en datacentraltjänst hos en datacentral som drivs av leverantören är begränsad under en period av mer än en timme.

  3. Integriteten, konfidentialiteten eller autenticiteten hos lagrade, överförda eller behandlade uppgifter i samband med tillhandahållandet av en datacentraltjänst har komprometterats till följd av en misstänkt skadlig handling.

  4. Den fysiska tillgången till en datacentral som drivs av leverantören har komprometterats.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod