Choosing an ICT and data center provider
How to choose a data center for NIS2, DORA and GDPR
A data center does not make an organisation compliant automatically. It should provide measurable services, a clear responsibility split and evidence the customer can use in its own risk, continuity and incident-management processes.
Service scope and responsibility
Contracts, SLA and documentation should separate customer, DataHouse and other supplier duties. Systems, locations, roles, contacts, escalation levels and support scope must be identified.
Business continuity
RPO, RTO, retention, restore tests, a second site and DR scenarios must follow the customer's process analysis. Having a backup alone does not prove successful recovery.
Incidents and evidence
Monitoring, logs, alerts, ticket history and an agreed escalation path help reconstruct an event. The customer remains responsible for classification and required regulatory reporting.
ICT providers and exit planning
Due diligence covers SLA, subcontractors, service locations, data access, auditability, concentration risk and a plan to move the service to another environment.
Access and data protection
MFA, administrator roles, restricted RDP/SSH, segmentation, physical access control, encryption and permission removal should form one coherent process.
Layered security
DDoS protection, firewall, monitoring, secure DNS, email, patching and vulnerability management reduce risk, but their scope must be selected and contracted for each service.
Requirement-to-evidence matrix
Use this as a technical due-diligence aid, not as legal advice or an automatic compliance declaration.
| Area | Customer responsibility | Provider contribution | Evidence to retain |
|---|---|---|---|
| Assets and risk | Identify processes, criticality, data, dependencies and risk owners. | Describe contracted services, locations, boundaries and technical dependencies. | Asset inventory, architecture, supplier register, contracts and responsibility matrix. |
| Incidents | Classify events, make regulatory decisions and submit required notifications. | Detect and escalate within the contracted scope; preserve agreed logs and timelines. | Contact tree, ticket history, monitoring records, incident timeline and post-incident actions. |
| Continuity | Approve RPO/RTO, BCP/DR scenarios, recovery priorities and acceptance criteria. | Deliver contracted backup, DR, infrastructure availability and technical support. | Backup reports, restore-test results, DR runbooks, monitoring and SLA reports. |
| Suppliers and exit | Perform due diligence, assess concentration, keep the ICT register and test exit plans. | Document service locations, SLA, relevant subcontractors, data return and transition support. | Due-diligence file, contractual register, audit evidence, exit plan and transition tests. |
Responsibility split
Customer
- legal qualification and governance
- business-process and data classification
- risk acceptance and budget
- regulatory incident reporting
- application and user-access security
DataHouse / eTop
- contracted data center and network scope
- physical access procedures
- monitoring and support in the selected package
- technical logs and service evidence
- backup or administration only when ordered
Shared and agreed
- emergency contacts and escalation
- RPO/RTO and recovery tests
- change and service-window procedure
- incident cooperation and evidence transfer
- exit and migration plan
Provider due-diligence checklist
- service scope, location and data-processing locations
- SLA, support hours, escalation and exclusions
- relevant subcontractors and responsibility split
- physical access and customer separation
- network redundancy, DDoS protection and monitoring
- backup, restore tests, RPO/RTO and DR options
- logging, evidence retention and incident cooperation
- certification scope and current documents
- data return, deletion, transition period and exit support
- regular review, tests and evidence owners
Polish KSC status in 2026
The amended Polish KSC Act entered into force on 3 April 2026. Official guidance indicates 3 October 2026 for registration of qualifying entities and 3 April 2027 for implementation of duties by entities that met the criteria on the effective date. Each organisation must verify its own status and deadlines.
Decision signals
Polish KSC status
The amended KSC Act entered into force on 3 April 2026; each organisation must assess its own status and applicable deadlines.
NIS2 and KSC
risk management, incidents, continuity, supply chain, access, assets, cryptography and security-effectiveness assessment
DORA
ICT-provider register, due diligence, SLA, locations, incidents, audit, continuity, concentration risk and a tested exit plan
GDPR
controller and processor roles, processing security, contracts, subprocessors, records and personal-data-breach handling
Technical evidence
service scope, logs, tickets, backup and restore reports, monitoring, physical access, changes, SLA and escalation contacts
Core services
Cloud Pro, dedicated servers, colocation, VPS, administration, backup, DR, DDoS protection, email and secure DNS
Related topics
Technical checks
Frequently asked questions
Does DataHouse guarantee NIS2, KSC, DORA or GDPR compliance?
No. Duties depend on the organisation, sector, processes and contracts. DataHouse supplies agreed technical layers and evidence that support the customer's compliance programme.
What should be checked before contracting a data center?
Service scope and location, SLA, responsibility, subcontractors, physical security, network, backup and DR, monitoring, incidents, evidence access, audit terms and exit planning.
Who reports an incident to a CSIRT or regulator?
Regulatory responsibility remains with the relevant entity. The operator should provide agreed contacts, escalation and technical data needed for assessment and reporting.
Is an ISO certificate enough for provider due diligence?
No. It is one item of evidence. Review the actual service scope, SLA, locations, subcontractors, backup, DR, incidents, access, reports and termination conditions.
How do NIS2, DORA and GDPR fit together?
Their common core is assets, risk, access, suppliers, continuity, incidents and evidence. DORA adds detailed ICT third-party requirements, while GDPR covers personal-data processing duties.
Where should a regulated infrastructure project start?
Begin with process and system inventory, criticality, supplier map, RPO/RTO, responsibility, logs, access, backup, tests, emergency contacts and an exit plan.