Recital 35

Recital 35

Directive on the security of network and information systems · UE 2022/2555

(35)

Services offered by data centre service providers may not always be provided in the form of a cloud computing service. Accordingly, data centres may not always constitute a part of cloud computing infrastructure. In order to manage all the risks posed to the security of network and information systems, this Directive should therefore cover providers of data centre services that are not cloud computing services. For the purposes of this Directive, the term ‘data centre service’ should cover provision of a service that encompasses structures, or groups of structures, dedicated to the centralised accommodation, interconnection and operation of information technology (IT) and network equipment providing data storage, processing and transport services together with all the facilities and infrastructures for power distribution and environmental control. The term ‘data centre service’ should not apply to in-house corporate data centres owned and operated by the entity concerned, for its own purposes.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the competent authority to designate data centre service providers as essential or important entities under the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025). Luxembourg hosts an exceptional concentration of targeted operators (LuxConnect, eBRC, POST Telecom, Datacenter Luxembourg) and the ILR applies a strict reading of the in-house exemption of recital 35: an intragroup data centre serving several legally distinct group entities is qualified as a service within the meaning of NIS 2.

Luxgap practice: if your group operates a technical room in Bissen, Bettembourg, Kayl or Roost serving even a single distinct subsidiary, anticipate the registration with the ILR rather than waiting for it, as ex officio designation exposes you to administrative fines up to EUR 7M or 1.4% of global turnover for important entities.