Regingada
Sector · Digital business

Cloud and hosting — intermediary duties plus NIS2

Sector profile · Source: Funk corpus (CELEX/ELI-anchored) · Status: 2026-08

Whoever stores customer content is a hosting service under the DSA, and that is true of a great many infrastructure businesses that never thought of themselves as platforms. The liability privilege that comes with the role is not a status but a condition: it holds only as long as the provider has no actual knowledge and acts once knowledge arrives. On top of that sits NIS2, because digital infrastructure and ICT service management are listed sectors with their own risk-management duties and their own reporting chain. As a rule the same business is also a processor under the GDPR, which means it acts on instructions and carries its own security duties. And since the Data Act became applicable, the chapter on switching between data processing services reaches directly into contracts, exit documentation and interfaces.

  • DSA · hosting service
  • NIS2 · digital infrastructure sector
  • GDPR · processor
  • Data Act · switching chapter
  • AI Act · not activated by hosting alone

Sector profile for orientation. It describes what the norms provide for a role of this shape. Whether they reach a concrete company, and in which role, is a legal assessment and belongs to a mandate — not to a sector page.

1 · Regime footprint

Four regimes on one stack

Infrastructure providers rarely have a classification problem — they have a coordination problem. Four regimes reach for the same systems, each with its own addressee, its own evidence and its own clock. The order below is the order in which they usually become urgent: first the intermediary duties that a single notice can trigger, then the security duties that an incident triggers, then the contractual duties that a customer triggers.

Regime footprint

Regime & norm Why it applies What to do first
DSA · Art. 6 The liability exemption for hosting is conditional: it depends on the absence of actual knowledge and on acting expeditiously to remove or disable access once knowledge is obtained. Define the internal path from notice to decision, with timestamps — the privilege is defended with records, not with intentions.
DSA · Art. 16 and Art. 17 Hosting services must operate notice-and-action mechanisms and give a statement of reasons for restrictions imposed on the basis of a notice or on their own initiative. Build the mechanism and the reasons template before the first notice arrives; both are visible artefacts that authorities can inspect.
DSA · Art. 11, 12, 13 Single points of contact for authorities and for recipients of the service, and — for providers without an establishment in the Union — a legal representative. Designate, publish and notify. These are the cheapest duties to satisfy and among the most visible when missing.
NIS2 · Art. 20 and Art. 21 Management bodies must approve and oversee the risk-management measures, and the measures themselves are enumerated: policies, incident handling, business continuity, supply-chain security, cryptography, access control and more. Maintain one control set and map it once — to NIS2, and to whatever customer questionnaires arrive on top of it.
NIS2 · Art. 23 Significant incidents run a staged reporting chain: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. Name the people who may start the 24-hour clock without waiting for a management decision, and rehearse it once.
GDPR · Art. 28 and Art. 32 Hosting customer data as a processor means acting on documented instructions, running a contract with the prescribed content, controlling the sub-processor chain and securing the processing. Inventory the processing agreements and the sub-processor chain before a customer audit asks for it.
Data Act · Art. 23 to Art. 31 Providers of data processing services must remove obstacles to switching, carry prescribed contractual terms, support the transfer of exportable data and digital assets, and observe the timetable under which switching charges are withdrawn from 12 January 2027. Read the standard contract and the exit documentation against the switching chapter — this is the duty that touches the commercial model, not just the security team.

Not activated by hosting alone: the AI Act. Renting GPU capacity or operating an inference endpoint on behalf of a customer does not make an infrastructure provider the provider of an AI system. That role arises where a system is developed and placed on the market under one's own name — a different question, asked separately.

2 · Where it gets expensive

Three seams that cost coordination

  • Two clocks, one incident

    A single security event can start the NIS2 chain towards the CSIRT and the competent authority and, where personal data is affected, the GDPR chain towards the supervisory authority — with a further duty running towards the controller, because a processor notifies its customer without undue delay. Different addressees, different deadlines, different content, all fed by the same facts under time pressure. Whoever builds three separate procedures discovers on the day of the incident that they contradict each other.

  • Switching duties meet running contracts

    The Data Act's switching chapter reaches into terms that were drafted long before it existed: notice periods, transition assistance, export formats, egress charges and the technical means by which a customer actually leaves. It is not a clause to be inserted but a set of duties that has to be true of the product. Contract, exit documentation and interfaces have to move together, because a well-drafted clause over an inaccessible export is worse than neither.

  • Notice-and-action against instruction-bound processing

    The DSA expects a hosting provider to act on illegal content once it knows about it. The GDPR expects a processor to act only on the controller's documented instructions. Where the hosted content is a customer's data, one duty asks for an intervention that the other appears to forbid, and the customer is the one whose service is interrupted. The boundary belongs in the contract and in the escalation path, settled before the first notice rather than during it.

The full map of the seams, across all regimes: the collision map.

3 · Providers without an EU establishment

Two appointments, two different reasons

An intermediary service without an establishment in the Union that has a substantial connection to it designates a legal representative under Art. 13 DSA, whose details have to be notified and made publicly available. Independently of that, NIS2 requires certain digital service providers without an EU establishment to designate a representative in a Member State in which they offer their services — and that designation also anchors which authority is competent. The two duties have different triggers, and neither of them settles the representative question under Art. 27 GDPR.

Where the duties come from and how they stack: EU representation overview and the representative compass. Regingada UG (haftungsbeschränkt) takes on appointed representative functions; whether a concrete company owes one, and under which act, is a legal assessment in a separate mandate.

4 · What the twin delivers

From four rulebooks to one working list

  • Obligation cockpit per roleThe hosting set of the DSA, the NIS2 duties for the sector classification that applies, and the processor duties of the GDPR — each entry with its source node, so the list reads back to the norm text instead of resting on trust.
  • Incident clocks side by sideThe staged NIS2 chain and the data-breach chain shown as what they are: separate deadlines on the same event, with the addressee named for each stage rather than merged into a single generic escalation.
  • Collision mapThe seams that this profile actually produces — reporting chains against each other, switching duties against contract terms, notice-and-action against instruction-bound processing — shown as explicit connections.
  • Radar watchChange entries tagged to the profile rather than a general newsfeed: implementing acts, national transposition of NIS2, guidance on the switching chapter. The radar reports the state of its watchlist with a date; it does not claim to be a live feed.
  • Deliverables, marked DRAFTObligation register, gap report, an outline for the notice-and-action procedure and a structure for the incident reporting chain. Everything the suite produces is a DRAFT: no signature, no assessment, no liability. It becomes an assessment when the law firm Theo Funk takes it into a mandate and signs it off.
5 · Step 2

Where the software stops

Everything above is orientation: a map of what a role of this shape reaches in EU digital law, drawn from a public corpus and readable back to its sources. It is structured self-assessment and decision support, not an evaluation of a specific company and not legal advice. Whether a service is an intermediary service, whether the entity is essential or important under NIS2, and how far the switching duties reach into a given contract is the second step and belongs to the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) builds the software and takes on appointed EU-representative functions; the firm does the legal work.

Worked through on a fictional demo profile: an intermediary at designation scale.

Disclaimer

Orientation, not legal advice

This sector page and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.