Recital 116

Recital 116

Directive on the security of network and information systems · UE 2022/2555

(116)

Where a DNS service provider, a TLD name registry, an entity providing domain name registration services, a cloud computing service provider, a data centre service provider, a content delivery network provider, a managed service provider, a managed security service provider or a provider of an online marketplace, of an online search engine or of a social networking services platform, which is not established in the Union, offers services within the Union, it should designate a representative in the Union. In order to determine whether such an entity is offering services within the Union, it should be ascertained whether the entity is planning to offer services to persons in one or more Member States. The mere accessibility in the Union of the entity’s or an intermediary’s website or of an email address or other contact details, or the use of a language generally used in the third country where the entity is established, should be considered to be insufficient to ascertain such an intention. However, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering services in that language, or the mentioning of customers or users who are in the Union, could make it apparent that the entity is planning to offer services within the Union. The representative should act on behalf of the entity and it should be possible for the competent authorities or the CSIRTs to address the representative. The representative should be explicitly designated by a written mandate of the entity to act on the latter’s behalf with regard to the latter’s obligations laid down in this Directive, including incident reporting.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority to receive the designated representative's contact details and verify the reality of its mandate. The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, provides that a representative established in Luxembourg must be reachable by the ILR and the CSIRT (GovCERT.lu / CIRCL depending on the sector) within the incident reporting deadlines (24h early warning, 72h notification). Failure to designate is sanctionable on the same footing as a substantive breach of risk management measures.

Luxgap practice: if you are a non-EU cloud, DNS or MSSP provider serving Luxembourg customers, designate your representative before your first reportable incident, because the ILR will require proof of the written mandate from the first post-incident contact.