When you ask managers at almost any company in the EU whether they are prepared for NIS2 and GDPR, most will answer: “We have a signed contract with our provider, so we are compliant.” It sounds reassuring. But it is only half the story...
This is where many managers start paying closer attention. A contract protects you only to the extent that your environment is actually configured exactly as the contract requires. The rest is your responsibility, and this is where the first problems arise.
Where your data is physically located
GDPR restricts transfers of personal data outside the EU and EEA unless appropriate safeguards are in place. It sounds like a legal issue, but in the cloud it is also a technical question: in which region is your resource actually located?
An enterprise contract with a provider does not automatically mean that your data stays in Europe. The location must be explicitly selected and configured. The good news is that the same rule can also be enforced technically: a policy can simply prevent resources from being created outside an approved region. This turns a legal requirement into something that cannot be violated accidentally.
Choosing a cloud region is not a random decision. Similarly, data replication between regions is not something that can always be easily changed later. Both need to be defined in advance by clear rules, otherwise you risk violating GDPR requirements.
Auditability and incident reporting
Both regulations have one thing in common: when something goes wrong, you need to be able to report it quickly. NIS2 requires an early warning within 24 hours, while GDPR generally requires notification of a personal data breach within 72 hours.
That sounds simple until you ask yourself: can you determine within an hour who accessed a particular system, when the problem occurred, and where the user logged in from?
Without an immutable record of every operation – who did what and when – the answer is a guess, not a fact. And guesses are not what you present to an auditor or regulator.
Retention is equally important. As a general rule, logs should be retained for at least a year, while records related to GDPR incidents may need to be kept for three to five years. When it comes to logging, a useful principle is simple: log everything that is relevant and practical. It is easier to work through a large amount of information than to investigate an incident with no information at all.
Encryption and access management as a foundation, not a bonus
Encryption of data both at rest and in transit should no longer be optional. It should be the default. The same applies to access management – who has access to what, and why.
Combining least-privilege access with multi-factor authentication supports the GDPR requirement for appropriate technical measures under Article 32. These are not optional security extras. They are specific controls that auditors are likely to examine.
The principle is simple: users should have access to exactly what they need to do their job – and nothing more.
NIS2 and what you bring in from outside
NIS2 goes beyond your own environment. It also requires organizations to address security risks related to their suppliers and service providers, including AI tools.
Who can access your data through a third party? Do you have a list of subcontractors or sub-processors with whom your provider may share your data? If you cannot answer these questions, the risk does not sit solely with the supplier. Your organization carries it as well.
What this means for you
Compliance is not a project that you complete once and check off a list. Requirements continue to evolve, and your company needs to meet them whenever changes are made to the environment.
It is a set of technical and organizational rules that must remain in place continuously, not only on the day of an audit. One of the best ways to understand where you actually stand is a simple gap analysis – comparing what the regulations require with what is currently implemented in your environment.
A question for you: Can you show an auditor today exactly where your customers' data is stored and who has accessed it over the past 90 days?
SP Software Solutions | Just Cloud IT
