Blog

New digital legislation imposes additional rights and obligations on many IT customers

The digital transformation brings valuable innovations, but undeniably poses new challenges for organizations. In sectors considered vital to the functioning of our society - think healthcare, energy supply, transportation and government - the interconnectedness with digital service providers is greater than ever. With this is also the vulnerability to cyber threats and the risk of [...]

The digital transformation brings valuable innovations, but undeniably poses new challenges for organizations.
to new challenges. In sectors considered vital to the functioning of
our society - think healthcare, energy supply, transportation and government - the interconnectedness
with digital service providers is greater than ever. With this is also the vulnerability to cyber threats
and the potential for supply chain disruption has increased exponentially: an incident
at one service provider can disrupt the continuity of an entire (vital) service.

Digital chain care under pressure

Against this background, we see and foresee that in the IT field two European laws will have a major impact in the coming period:

  • the NIS2 directive (hereafter: NIS2); and
  • the Data Regulation.

On the one hand, NIS2 obliges sectors to demonstrate supply chain security and risk management; customers must therefore start managing parties in their IT chain more actively. On the other hand, the Data Regulation makes switching between IT vendors providing data processing services easier, which also allows effective chain management and reduces "vendor lock-in.

This article focuses on the practical interplay between these two European frameworks, with an emphasis on how, in practice, buyers can strengthen their contractual position, enforce compliance and thereby increase their digital resilience.

Data Regulation

The Data Regulation, formally Regulation (EU) 2023/2854, is the European Union’s response to the growing role of data as a strategic business asset. The regulation, which has been in effect since September 2025, facilitates fair access to and use of data for both businesses and consumers. The goal is to give users more control over the data they generate with connected products—that is, products connected to the internet, such as a smart thermostat or refrigerator.[1] The Data Regulation not only covers data generated by connected products (and related services) but also includes rules for so-called data processing services. In short, these are virtually all digital services offered via cloud or edge technology, including SaaS, IaaS, and PaaS services.[2] For example, a SaaS platform used by an energy provider to process and analyze meter readings and consumption data qualifies as a data processing service within the meaning of the Data Regulation, and the IT provider is considered the provider of such a data processing service.

Core obligations: data portability, switching and minimum contractual agreements

Although facilitating fair access to and use of data is the most publicized aspect of the General Data Protection Regulation (GDPR), the regulation also contains provisions that have a broad impact on IT suppliers who qualify as data processing service providers. This is because the Data Regulation enshrines the right to data portability and the ability to switch providers in contractual terms. IT suppliers are required to transfer data smoothly and without technical or legal obstacles when a customer wishes to switch to another provider or to its own infrastructure. This promotes competition, prevents long-term dependence on a single IT supplier (vendor lock-in), and ultimately serves the public interest in reliable and accessible digital services.[3] This aspect will be explained in more detail later.

At the same time, the Data Regulation requires IT suppliers to enter into more detailed contractual agreements with customers regarding how the IT supplier will ensure interoperability, continue service provision during migration, and safeguard their customers’ business continuity. For customers, this regulation means that IT contracts must not only address the IT supplier’s performance or prices, but must also give thorough consideration to data ownership, portability, and contractual guarantees.[4]

If no explicit agreements are made in the contract about interoperability, migration or guarantees of business continuity, as prescribed in the Data Regulation, the mandatory provisions of the Data Regulation are read into the contract by operation of law. As a result, the statutory minimum obligations - including the guarantee of switching options, the prevention of barriers to switching and a maximum notice period - apply in full. This additional effect of the Data Ordinance particularly restricts the IT supplier's freedom of contract in appropriate cases, as these provisions cannot be deviated from to the detriment of the customer and violation can result in significant penalties.

NIS2 Directive

NIS2, formally Directive (EU) 2022/2555, builds upon the earlier NIS Directive,[5] but raises the bar substantially. NIS2 is currently being implemented in the Netherlands through the Cybersecurity Act (hereinafter: CBW) and expands both the scope and the severity of the existing obligations.[6] Organizations classified as essential or important will, effective as of the CBW, be explicitly responsible for the security of their entire network and information systems, including the (IT) supply chain.

Core obligations: duty of care and notification

Not only must the customer’s own security be in order, but its direct IT suppliers and service providers must also operate in accordance with the prescribed (stricter) security standards. The focus thus shifts from internal governance alone to a system of supply chain governance. This broader responsibility does not, however, mean that the customer must take on the entire implementation of the security measures. However, the customer remains ultimately responsible for governance, responsibilities, and control mechanisms throughout the entire supply chain, with the contract with the IT suppliers serving as one of the most important tools.[7]

In addition, NIS2 imposes reporting and information obligations on all essential and important organizations. If a significant incident occurs at the organization in question that (among other things) leads to an operational disruption of its services, the organization must inform its customers in a timely manner and submit an initial report to the National Cyber Security Center (NCSC) no later than 24 hours after the incident.[8]

With the advent of NIS2, customers face the challenge of not only determining the security level of their own processes and systems, but also enforcing that their external (IT) suppliers do so. This must then be enshrined in a robust contractual foundation.

Risk analysis, contract requirements and compliance

Article 21 of NIS2 (and the CBW) explicitly requires customers to take appropriate and proportionate technical, operational, and organizational measures to manage supply chain risks.[9] This requires not only the establishment of measures, but also policies and procedures through which the customer regularly assesses the effectiveness of those measures. To ensure that the effectiveness assessment truly reflects actual practice, it is advisable to also regularly analyze the underlying risks, at least in the event of relevant changes within the customer’s organization (such as a change in IT supplier or internal system) and following incidents. This analysis must include not only the customer’s IT suppliers and subcontractors, but also the supply chain partners of those partners on whom the service provision depends.[10] The results of this analysis form the basis for new or amended contractual agreements regarding, among other things, access control, data storage, authentication, and monitoring. The customer should therefore not rely on empty guarantees or “standard” security certificates, but must set specific requirements and ensure compliance with them through demonstrable contractual safeguards.

Governance and enforcement

Compliance monitoring and the explicit authority to intervene if an IT supplier fails to meet the requirements are also integral parts of the NIS2 regulations. This makes it possible to respond to incidents or new threats without having to accept dependence on a single supplier every time. Establishing audit rights, interim review points, and the right to tighten obligations ensure that supply chain security does not remain a one-time or reactive issue.[11]

It is also important that managerial responsibility within the customer’s organization be clearly assigned. Under NIS2, directors bear additional responsibilities: they must actively assess information security risks and approve the organization’s corresponding security measures to ensure compliance with Article 21 of NIS2. This also means that directors must complete mandatory training on cybersecurity. By completing this training, organizations can demonstrate that they possess sufficient knowledge and skills to carry out the aforementioned assessments and make the necessary decisions.[12] The consequences of ignoring this obligation are significant: fines, reputational damage, or even director liability are real risks in the event of negligence.[13] A passive role in risk management and contract management is therefore no longer acceptable, especially now that the RDI, together with eight sector-specific regulators, is setting clear expectations and actively focusing on enforcement.[14]

All in all, for companies in critical and important sectors, NIS2 brings with it not only weighty internal, but especially external, contractually enforceable obligations. Enforcing compliance within the supply chain requires legally detailed contracting practices, active governance, and consistent enforcement toward suppliers. In practice, conflict and resistance can arise among IT suppliers, which emphasizes all the more the importance of clear legal and contractual tools and leveraging legal means that can enforce compliance.

The unique nature of the Data Regulation is clearly evident in Chapter VI: data processing services (a category that includes many IT providers) are required to always offer customers the option to transfer their data without hindrance to an alternative data processing service provider or an on-premises solution. In doing so, IT providers must actively cooperate in the data export, ensure the preservation of functionality during the migration, provide technical documentation, and support the migration process. Furthermore, the migration must be able to take place without excessive costs or unnecessary delays—requirements that are legally enforceable under the General Data Protection Regulation.[15]

Practical tips for practice

Contracts: make security, changes and transition enforceable

Organization: ensure governance and engage in dialogue

Ensure that the board is structurally involved in compliance and that there are clear procedures for incidents, changes and changeover scenarios. Facilitate regular meetings between procurement, IT, legal and security officers to keep contractual agreements current and continuously aligned with changing risks. In addition, conduct discussions with IT vendors about the specific requirements from NIS2 and the Data Regulation. This should include questions such as: are the requirements known, can data actually be transferred in a timely, secure and complete manner, are migration options prepared, and are liabilities, penalties and reporting obligations adequately regulated?

Suppliers: focus on supply chain risks and security standards

Preferably select suppliers on their willingness and ability to comply with the most up-to-date security standards where the basis is often ISO27001, possibly supplemented by specific sector standards (such as NEN7510 for healthcare). In international collaborations, pay extra attention to the extraterritorial aspects of data storage, transfer and compliance. Passivity is the biggest risk: organizations that invest now in robust contracts, effective collaboration across disciplines and chain-based governance will be more resilient to future incidents, audits and market changes.

Looking ahead: supply chain resilience starts now

NIS2 and the Data Regulation set a new market standard. NIS2 sets tough requirements for chain responsibility, while the Data Regulation is a tool that also facilitates chain governance. Organizations must invest in chain-based governance, robust contracts and effective collaborations between departments as well as IT vendors, simply to meet the standards imposed by law.

This article was written by Lauren Wendrich and Frank Rutgers and previously appeared in Juridisch up to Date.

Open this article as a PDF file [LINK]


[1] C.A. Janssen, “Lexplicatie, commentary on the Data Protection Regulation Implementation Act,” InView; European Commission, “Explanation of the Data Protection Regulation,” https://digital-strategy.ec.europa.eu/nl/factpages/data-act-explained.

[2] IaaS stands for Infrastructure-as-a-Service, PaaS stands for Platform-as-a-Service, and SaaS stands for Software-as-a-Service. This list of cloud services is not exhaustive; see recitals 80 and 81 of the General Data Protection Regulation (GDPR); Article 2(8) of the GDPR; see also recitals 80 and 81 of the GDPR.

[3] Chapter VI of the General Data Protection Regulation (GDPR), “Switching to Another Data Processing Service”; European Commission, “Explanation of the General Data Protection Regulation,” https://digital-strategy.ec.europa.eu/nl/factpages/data-act-explained.

[4] C.A. Janssen, “Lexplicatie, commentary on the Data Protection Regulation Implementation Act,” InView; European Commission, “Explanation of the Data Protection Regulation,” https://digital-strategy.ec.europa.eu/nl/factpages/data-act-explained. See recitals 90, 96, and 99 of the General Data Protection Regulation.

[5] Directive (EU) 2016/1148 ceased to be in force on October 17, 2024.

[6] The Cybersecurity Act is expected to take effect in Q2 of 2026.

[7] Chapter IV of NIS2, “Risk Management Measures and Reporting Obligations in the Area of Cybersecurity.” See also: footnotes 83 and 85 of NIS2.

[8] Article 23 of NIS2; recital 102 of NIS2; Articles 16, 26, and 27 of the CBW; NCSC, “Reporting Obligation,” ncsc.nl.

[9] Article 21, paragraph 1 and paragraph 2(d) of NIS2.

[10] Article 21(2)(f) of NIS2; Article 21(3)(f) of CBW; NCSC, “Duty of Care,” ncsc.nl.

[11] “Supply Chain and Cybersecurity,” rdi.nl.

[12] Article 24 of the Cybersecurity Act; Article 20 of NIS2; “The focus on digital threats is shifting toward executives,” ncsc.nl.

[13] Sections 92 and 93 of the Cybersecurity Act.

[14] National Inspectorate for Digital Infrastructure (RDI); “Sectors subject to RDI oversight,” rdi.nl; “RDI oversight of the Cybersecurity Act (Cbw),” rdi.nl.

[15] Articles 23 and 25 of the Data Protection Regulation; Parliamentary Documents II 2024/25, 36733, No. 3, p. 16 (Explanatory Memorandum).

Author

Expertises

Share this article

More blogs