3 min to read

MEPs vote strongly in favour of the proposed European Cybersecurity Directive

Date
02 October 2015

 

closeup of finger touching screen  on tablet-pc with shallow depth of field

The European Parliament today voted to approve the draft Network and Information Security Directive (known colloquially as the Cybersecurity Directive), which contains new rules designed to improve the cybersecurity of the European Union. The proposal was first published in February 2013. Our comments on the initial proposal can be found here.

MEPs were strongly in favour of the current draft of the new rules, with the ‘yes’ vote winning by 521 votes to 22. Now the current draft of the Directive has been approved by the European Parliament, it will be negotiated with the European Commission and the Council.

In the most recent draft of the Directive, the requirement for certain technology service providers (such as social networks, search engines, e-commerce platforms and online payment gateways) to notify breaches of their data systems to national authorities has been removed. Only those providers who own, operate or provide infrastructure which, if disrupted or destroyed, would have a significant impact on a Member State will be caught in the scope of the Directive. This was one of the most fiercely debated aspects of the drafting and its removal may have been the key to the success of the draft Directive in the European Parliament today.

See our analysis of the current draft of the Directive (published in February 2014) here.

The Directive is unlikely to complete the legislative process before the end of the current European Parliament term, meaning there is the possibility that the process will not be continued in the new Parliament starting in May 2014 although this is unlikely given the strong support of MEPs in this vote.

Simon Shooter, a partner in Bird & Bird’s Cyber Security Team comments:

“The European Parliament has recognised the critical importance of network and information systems in today’s society and the need to protect them against cyber threats. However, many in industry will be concerned that the proposed new rules will increase regulation and the associated cost of doing business without actually delivering the desired improvements in security.

As the only law firm sitting on the NIS Public-Private Platform working group formed by ENISA (the European Union Agency for Network and Information Security) to help implement the proposed new rules we’ve seen that businesses considered to be an ‘operator of critical infrastructure’ are particularly concerned that the rules requiring them to report security breaches in their systems will be inconsistently applied by different Member States leading to regulatory complexity in complying. This is compounded by uncertainty at present about who these reporting rules will actually apply to.
What does this mean for businesses? First an assessment should be made as to whether your business is likely to be affected by the resultant legislation. If it is you should start to implement measures now that will ease the task of compliance later.”

Author: Simon Shooter
Partner
Tel: +44 (0)20 7415 6000

Share
Written by
Clarity Admin
Clarity Admin
Related articles
Smart Contracts – Recognising and Addressing the Risks
4 min to read
29 December 2021
Smart Contracts – Recognising and Addressing the Risks
Smart contracts, where some or all of the contractual obligations are defined in and/or performed automatically by a computer program, are expected to have a significant impact on the way business is...
Technology Projects: Managing the Risks of Innovation and Change Part 3: Contract Reset and Dispute Resolution
Technology Projects: Managing the Risks of Innovation and Change Part 3: Contract Reset and Dispute Resolution
Customers in long-term technology projects can find that while they have been working towards their chosen solution a more advanced, cheaper, or simply more desirable technology has become available....
Digital dispute resolution rules to facilitate rapid and cost-effective resolution of disputes involving novel digital technologies
Digital dispute resolution rules to facilitate rapid and cost-effective resolution of disputes involving novel digital technologies
While some saw the development of products using blockchain technology leading to the demise of disputes, the reality is that disputes in the arena of digital technology are increasing in number. Lawtech’s...
Technology Projects: Managing the Risks of Innovation and Change Part 2: During the Life of the Project
Technology Projects: Managing the Risks of Innovation and Change Part 2: During the Life of the Project
Customers in long-term technology projects can find that while they have been working towards their chosen solution a more advanced, cheaper, or simply more desirable technology has become available....
Cookies
We use analytics cookies to help us understand if our website is working well and to learn what content is most useful to visitors. We also use some cookies which are essential to make our website work. You can accept or reject our analytic cookies (including the collection of associated data) and change your mind at any time. Find out more in our Cookie Notice.