How to choose a data center for NIS2, DORA and GDPR

Practical data center selection criteria for NIS2, DORA and GDPR: responsibility, ICT suppliers, incidents, backup, DR, logs, SLA, audit and exit planning.

Choosing an ICT and data center provider

How to choose a data center for NIS2, DORA and GDPR

A data center does not make an organisation compliant automatically. It should provide measurable services, a clear responsibility split and evidence the customer can use in its own risk, continuity and incident-management processes.

Service scope and responsibility

Contracts, SLA and documentation should separate customer, DataHouse and other supplier duties. Systems, locations, roles, contacts, escalation levels and support scope must be identified.

Business continuity

RPO, RTO, retention, restore tests, a second site and DR scenarios must follow the customer's process analysis. Having a backup alone does not prove successful recovery.

Incidents and evidence

Monitoring, logs, alerts, ticket history and an agreed escalation path help reconstruct an event. The customer remains responsible for classification and required regulatory reporting.

ICT providers and exit planning

Due diligence covers SLA, subcontractors, service locations, data access, auditability, concentration risk and a plan to move the service to another environment.

Access and data protection

MFA, administrator roles, restricted RDP/SSH, segmentation, physical access control, encryption and permission removal should form one coherent process.

Layered security

DDoS protection, firewall, monitoring, secure DNS, email, patching and vulnerability management reduce risk, but their scope must be selected and contracted for each service.

Requirement-to-evidence matrix

Use this as a technical due-diligence aid, not as legal advice or an automatic compliance declaration.

AreaCustomer responsibilityProvider contributionEvidence to retain
Assets and riskIdentify processes, criticality, data, dependencies and risk owners.Describe contracted services, locations, boundaries and technical dependencies.Asset inventory, architecture, supplier register, contracts and responsibility matrix.
IncidentsClassify events, make regulatory decisions and submit required notifications.Detect and escalate within the contracted scope; preserve agreed logs and timelines.Contact tree, ticket history, monitoring records, incident timeline and post-incident actions.
ContinuityApprove RPO/RTO, BCP/DR scenarios, recovery priorities and acceptance criteria.Deliver contracted backup, DR, infrastructure availability and technical support.Backup reports, restore-test results, DR runbooks, monitoring and SLA reports.
Suppliers and exitPerform due diligence, assess concentration, keep the ICT register and test exit plans.Document service locations, SLA, relevant subcontractors, data return and transition support.Due-diligence file, contractual register, audit evidence, exit plan and transition tests.

Responsibility split

Customer

  • legal qualification and governance
  • business-process and data classification
  • risk acceptance and budget
  • regulatory incident reporting
  • application and user-access security

DataHouse / eTop

  • contracted data center and network scope
  • physical access procedures
  • monitoring and support in the selected package
  • technical logs and service evidence
  • backup or administration only when ordered

Shared and agreed

  • emergency contacts and escalation
  • RPO/RTO and recovery tests
  • change and service-window procedure
  • incident cooperation and evidence transfer
  • exit and migration plan

Provider due-diligence checklist

  • service scope, location and data-processing locations
  • SLA, support hours, escalation and exclusions
  • relevant subcontractors and responsibility split
  • physical access and customer separation
  • network redundancy, DDoS protection and monitoring
  • backup, restore tests, RPO/RTO and DR options
  • logging, evidence retention and incident cooperation
  • certification scope and current documents
  • data return, deletion, transition period and exit support
  • regular review, tests and evidence owners

Polish KSC status in 2026

The amended Polish KSC Act entered into force on 3 April 2026. Official guidance indicates 3 October 2026 for registration of qualifying entities and 3 April 2027 for implementation of duties by entities that met the criteria on the effective date. Each organisation must verify its own status and deadlines.

Decision signals

Polish KSC status

The amended KSC Act entered into force on 3 April 2026; each organisation must assess its own status and applicable deadlines.

NIS2 and KSC

risk management, incidents, continuity, supply chain, access, assets, cryptography and security-effectiveness assessment

DORA

ICT-provider register, due diligence, SLA, locations, incidents, audit, continuity, concentration risk and a tested exit plan

GDPR

controller and processor roles, processing security, contracts, subprocessors, records and personal-data-breach handling

Technical evidence

service scope, logs, tickets, backup and restore reports, monitoring, physical access, changes, SLA and escalation contacts

Core services

Cloud Pro, dedicated servers, colocation, VPS, administration, backup, DR, DDoS protection, email and secure DNS

Frequently asked questions

Does DataHouse guarantee NIS2, KSC, DORA or GDPR compliance?

No. Duties depend on the organisation, sector, processes and contracts. DataHouse supplies agreed technical layers and evidence that support the customer's compliance programme.

What should be checked before contracting a data center?

Service scope and location, SLA, responsibility, subcontractors, physical security, network, backup and DR, monitoring, incidents, evidence access, audit terms and exit planning.

Who reports an incident to a CSIRT or regulator?

Regulatory responsibility remains with the relevant entity. The operator should provide agreed contacts, escalation and technical data needed for assessment and reporting.

Is an ISO certificate enough for provider due diligence?

No. It is one item of evidence. Review the actual service scope, SLA, locations, subcontractors, backup, DR, incidents, access, reports and termination conditions.

How do NIS2, DORA and GDPR fit together?

Their common core is assets, risk, access, suppliers, continuity, incidents and evidence. DORA adds detailed ICT third-party requirements, while GDPR covers personal-data processing duties.

Where should a regulated infrastructure project start?

Begin with process and system inventory, criticality, supplier map, RPO/RTO, responsibility, logs, access, backup, tests, emergency contacts and an exit plan.