Under the recent amendments to the U.K. Network and Information System Regulations, digital service providers needed to appoint a NIS representative by March 31, 2021, in the U.K.

The NIS Directive (EU 2016/1148 – NISD) aims to achieve a high standard network and information systems security in the European Union, including the U.K. when initiated. It applies to two types of organizations: operators of essential services and DSPs.  

Due to its legal nature, the NIS Directive is different from the EU General Data Protection Regulation, as it is not directly applicable in the EU member states. It needed to be transposed into national law. Technically, there are 28 different NIS laws in force. It is important to note that the NISD or its transposition into national laws has extraterritorial scope like the GDPR, which means companies based outside the EU or U.K. can also be affected by these national laws. The core obligation arising from the extraterritorial scope is the requirement for companies located outside the EU/U.K. to appoint a NIS representative.

What is a DSP?

A DSP is any legal person that offers a digital service. However, not all digital services are subject to NIS, only specific services. The following DSPs are subject to NIS.

Online marketplaces: An online marketplace allows consumers and traders to conclude online sales or service contracts with traders and function as the destination for the conclusion of those contracts. Application stores, which operate as online stores enabling the digital distribution of applications or software programs from third parties, are understood as being a type of online marketplace.

They do not include online services that serve only as an intermediary to third-party services through which a contract can ultimately be concluded.

Online search engines: An online search engine allows the user to perform searches of websites based on a query on any subject. It can also be focused on websites in certain languages.

Search functions that are limited to the content of a specific website, even if the function is provided by an external search engine, are not subject to NIS. Online services that compare the price of products or services from different traders and then redirect the user to the preferred trader to purchase the product are also not included.

Cloud computing services: Cloud computing services allow access to a scalable and elastic pool of shareable computing resources, such as networks, servers or other infrastructure, storage, applications, and services. The NISD mentions three properties a cloud computing service must have to be qualified as a cloud service:

  • Scalable resources: Resources can be flexibly allocated by the cloud services provider irrespective of their geographical location to handle fluctuations in demand.
  • Elastic pool of resources: Computing resources that are provisioned and released according to demand to increase and decrease resources available depending on workload.
  • Shareable: Computing resources are provided to multiple users who share common access to the service, but the processing is carried out separately for each user even though it is provided from the same electronic equipment.

Included are different models, such as infrastructure as a service, platform as a service or software as a service.

As the NISD aims to improve network and information systems security, it applies to companies with a particular impact on such infrastructure; therefore, small businesses are exempt. Neither the EU NISD and its national transpositions nor the U.K. NIS Regulation applies to businesses with less than 50 staff members and an annual turnover or balance sheet of fewer than 10 million euros.

Assessing if the company offers services within the EU or UK

When it comes to assessing whether a DSP is offering its services to a certain market, the NISD seems to pursue a similar approach to the GDPR. The recitals of the NISD suggest it must be apparent the DSP is trying to offer its services to one or more member states in the EU, or in other words, evidence of "actively targeting" a particular market. When it comes to the U.K.'s NIS Regulation, they will likely follow a similar approach. 

Like with the scope of GDPR, the mere accessibility of a website or using a language typically used in different countries is not sufficient to ascertain the intention to target a specific market. However, here are some criteria to be considered that might suggest such intentions: 

  • Using a language or a currency used in one or more member states or the U.K.
  • The possibility of ordering services in those languages. 
  • The mentioning of customers or users who are in the EU or U.K.

Implications of Brexit on the requirement for a representative 

The NISD was transposed into U.K. law through the Network and Information System Regulations when the U.K. was still part of the EU. Brexit did not affect the NIS Regulation's validity; however, it has been amended to fit a U.K.-only application. At first, the U.K. NIS Regulation did not include the obligation to appoint a NIS representative. The Brexit amendments of the NIS Regulation introduced the obligation. Under the new regulations, non-U.K. companies must appoint a U.K. representative if: 

  • They are a DSP (online marketplace, online search engine or cloud computing service).
  • Their head office is not located in the U.K. 
  • They offer services in the U.K. 

The obligation to appoint a U.K. representative, even if the company has a branch in the U.K. that is not its headquarters, might be the most significant and hard-hitting difference between the NIS Regulation's and the GDPR's approach to appointing a representative.

If all of this applies, a company is considered a DSP under U.K. law and must comply with U.K. NIS Regulations. This means they should have appointed a representative before the March 31 deadline. Furthermore, DSPs should have appropriate and proportionate security measures to manage risks to the network and information systems that support their services. They must notify the U.K. Information Commissioner's Office in the event of incidents that substantially impact the provision of their services.

It needs to be highlighted that the U.K. NIS Regulation is not the GDPR's little sibling but an equal partner when it comes to the fines stipulated for noncompliance. According to the U.K. NIS Regulation, the ICO (as the relevant authority) may issue fines up to 17 million GBP in the most serious cases, like the fines stipulated in the GDPR.

NIS representation in the EU

Article 18 (2) of the NISD requires member states to provide national measures that oblige DSPs established outside the EU offering their services in the EU to appoint a European representative, which is similar to the obligation under Article 27 of the GDPR. However, this requirement was implemented differently in the various member states. Some, including the U.K. at first, did not implement such obligation at all. 

But does the March 31 deadline to appoint a U.K. representative also apply to a European representative's appointment? The answer is no since the deadline is U.K. specific, triggered by the fact that the U.K. only adopted their representative obligation with the recently introduced Brexit amendments. The amendments to the U.K. NIS Regulation provide for a three-month timeframe to appoint a representative, which began when the amendments came into force, Jan. 1, 2021. 

In the EU, the NISD introduced the obligation to appoint a representative and its transposition into national law. Therefore, it has already existed for quite some time. 

What companies should do now

There are certain impacts on DSPs arising from Brexit, which should be carefully assessed in view of the above. The key issue is that there are now two legal frameworks that might require companies to appoint a NIS representative. These frameworks apply to: 

  • DSPs that do not have headquarters in the U.K., which may be companies in or outside the EU.
  • U.K. DSPs and relevant DSPs without an establishment in the EU.  
  • DSPs without their headquarters in the U.K. and an establishment in the EU.

We have created a detailed FAQ about the NIS representative requirements for further guidance.

Companies that need an EU or U.K. NIS representative or both are very likely to need an Article 27 (U.K.GDPR representative. The NIS representative can be the same as the GDPR representative, so it is possible to have the same person or entity be your GDPR and NIS representative, which is probably the easiest and most favorable option, especially when it comes to data breaches.

Choosing the European representative does have implications on the jurisdiction to be applied to the DSP since it is under the member state jurisdiction where their representative is established. The DSP must comply with the domestic NIS law, which includes implementing technical and organizational measures to manage risks posed to the security of network and information systems and reporting obligations in case of incidents that substantially impact the provision of their service.

Photo by Rocco Dipoppa on Unsplash