Cloud Contracts Are Not Set-and-Forget: What NIS-2, DORA and the US Cloud Act Mean for European Organisations
Published on 10/08/2026 at 05:20 | Editorial boerse-global.de
Handing data to a cloud provider does not hand over the legal responsibility that comes with it. That principle runs through the emerging compliance landscape for banks, public bodies and any organisation large enough to fall under Europe's newer cybersecurity rules — and it is catching out those who assume an EU-based server rack settles the question.
The duty of oversight never leaves the building
For regulated sectors such as banking, the rule is blunt: institutions remain permanently accountable for choosing, steering and monitoring how their data is processed in the cloud. Moving workloads into data centres inside the European Union or the European Economic Area is not, on its own, sufficient. Remote access arrangements, support structures, sub-processors and the relevant laws of third countries all have to be examined and documented systematically.
Cross-border transfers bring their own checklist. Depending on the circumstances, organisations may need adequacy decisions, standard contractual clauses, binding corporate rules or supplementary safeguards. Where a US provider is involved, the specific coverage offered by the EU–US Data Privacy Framework must be verified.
Experts also flag a technicality that trips people up: standard contractual clauses used for transfers in a processor relationship do cover the requirements of Article 28 of the General Data Protection Regulation, but the clauses issued under paragraph 7 of that same article do not satisfy the demands placed on third-country transfers.
Encryption, access control and the limits of certificates
IT governance in this space includes technical measures such as encryption in which users manage or hold their own keys, alongside strict access controls. Holding an external certificate does not excuse an organisation from carrying out its own risk assessment.
Running in parallel, the Digital Operational Resilience Act (DORA) obliges financial institutions to operate comprehensive third-party risk management. Articles 28 to 30 of DORA require, among other things, due diligence, assessment of concentration risks, audit and access rights, and defined exit strategies.
If institutions ignore supervisory recommendations, the national supervisor can demand under Article 42 that a cooperation be suspended or terminated. For institutions in Switzerland, the regulation is not generally directly applicable, though it gains relevance through relationships into the EU area.
Registration is the organisation's own job
Beyond finance, the NIS-2 Directive is raising requirements across the board. Its provisions are anchored in Germany in the newly drafted Act on the Federal Office for Information Security (BSI-Gesetz), and affected entities must register themselves with the Federal Office for Information Security — nobody will do it for them.
The thresholds are concrete. Classification as an important entity applies from 50 employees, or more than 10 million euros in annual turnover and balance sheet total. Particularly important entities are generally companies with 250 or more employees, or turnover above 50 million euros together with a balance sheet total of more than 43 million euros.
Management is required to ensure and monitor risk management measures. Breaches carry fines of up to 10 million euros or 2 percent of worldwide annual turnover for particularly important entities, and up to 7 million euros or 1.4 percent for important entities — with the higher figure applying in each case.
Incident reporting follows a tight clock: an initial notification within 24 hours, an assessment within 72 hours, and a final report no later than one month after the notification.
Sovereignty, open interfaces and the long arm of the US Cloud Act
Beyond security measures themselves, specialists are calling for more digital freedom of choice through open interfaces and interoperable systems, particularly for municipalities. The aim is to prevent lock-in effects and keep data under control.
One driver is legislation such as the US Cloud Act, which can subject data held by US service providers to government access even when the servers sit inside Europe. In response, a growing number of organisations are turning to sovereign architectures built on open standards to head off losses of control.
