NIS2 – Impacts on the Supply Chain

Germany’s NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) is expected to come into force in spring 2025. This new regulation will have significant implications for service provider contracts and cybersecurity. Companies should not wait passively but actively prepare to comply with the legal requirements. This article outlines how NIS2 will affect future service provider contracts for regulated entities and what…

weiterlesen

NIS2: Who is affected, and what needs to be done?

After our first blog article (April 2024) on the new EU NIS2 Guidline dealt with the basics, differences to NIS1, and the legislative situation, we will this time focus on the following topics: What criteria are used to categorize companies that operate critical infrastructure? What sanctions are potentially possible? What measures, especially in the area…

weiterlesen

EU Regulation DORA – Contents and implementation tips

The EU Regulation DORA (Digital Operational Resilience Act) establishes a unified framework for the European financial sector to manage cybersecurity and ICT risks. Its goal is to strengthen the EU financial market by harmonizing requirements and standards in cybersecurity and ICT risk management, ensuring resilience and adaptability—operational resilience—of financial institutions during and after disruptions. Implementation…

weiterlesen
Data Privacy Framework - Datenschutzabkommen EU USA

New data protection agreement “Data Privacy Framework” between the EU and the US – All good things come in threes?

The Data Privacy Framework agreement has been in force since July 2023. Following Safe Harbor and the EU-US Privacy Shield, this is now the third attempt to establish a legally secure agreement for the transfer of personal data from the EU to the US. In the following article, we clarify the following questions in particular:…

weiterlesen