Skip to content
NIS2 Recital 114 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this law. Contains: the full text of every article, recital and provision of this law. Everything links back to its source on overview.legal — legal information, not advice.

Recital 114 — single Member State jurisdiction for digital service providers

In force — consolidated2022-12-27 · CELEX 02022L2555-20221227 · ELI ↗
Version history 1
  • 2022-12-27in force CELEX 02022L2555-20221227

In order to take account of the cross-border nature of the services and operations of DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms, only one Member State should have jurisdiction over those entities. Jurisdiction should be attributed to the Member State in which the entity concerned has its main establishment in the Union. The criterion of establishment for the purposes of this Directive implies the effective exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect. Whether that criterion is fulfilled should not depend on whether the network and information systems are physically located in a given place; the presence and use of such systems do not, in themselves, constitute such main establishment and are therefore not decisive criteria for determining the main establishment. The main establishment should be considered to be in the Member State where the decisions related to the cybersecurity risk-management measures are predominantly taken in the Union. This will typically correspond to the place of the entities’ central administration in the Union. If such a Member State cannot be determined or if such decisions are not taken in the Union, the main establishment should be considered to be in the Member State where cybersecurity operations are carried out. If such a Member State cannot be determined, the main establishment should be considered to be in the Member State where the entity has the establishment with the highest number of employees in the Union. Where the services are carried out by a group of undertakings, the main establishment of the controlling undertaking should be considered to be the main establishment of the group of undertakings.

Related across sources

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Jan 28, 2020 Personal Data Privacy by Design & Default Processing
Guidelines 02/2024 Article 48 GDPR Article 48 GDPR provides that: ' Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to… Guidelines ·EDPB Jun 5, 2025 Controllers Privacy Shield International Transfer
C-507/17 Google LLC v CNIL C-507/17 (Google Territorial Scope) CJEU Sep 24, 2019 Territorial scope (GDPR) Right to be Forgotten Direct Marketing
Guidelines 3/2018 territorial scope of the GDPR (Article 3) Guidelines on the territorial scope of the GDPR Guidelines ·EDPB Nov 12, 2019 Territorial scope (GDPR) IP Address Processors