← Course outline
Aavistus Training · nis2 · NIS.08

Jurisdiction, registration and domain data

What you'll learn

Which Member State's rules apply (main-establishment rule and its exceptions), the ENISA registry for digital infrastructure entities, and the accuracy duties on domain-name registration data.

Regulation — cited to the current EU text

Default jurisdictional rule

Entities in scope of NIS 2 fall under the jurisdiction of the Member State in which they are established 32022L2555 Article 26@2022-12-27. This is the baseline rule. Three category-specific exceptions override it.

Exception 1 — Electronic communications providers

Providers of public electronic communications networks or publicly available electronic communications services fall under the jurisdiction of the Member State where they provide their services, regardless of where they are established 32022L2555 Article 26@2022-12-27.

Exception 2 — Main-establishment rule for digital infrastructure entities

A defined category of entities — comprising DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines and social networking services platforms — falls under the jurisdiction of the Member State where the entity has its main establishment in the Union 32022L2555 Article 26@2022-12-27.

Locating the main establishment follows a sequential three-step test. The primary criterion is the Member State where decisions on cybersecurity risk-management measures are predominantly taken. If that cannot be determined, or if such decisions are not taken anywhere in the Union, the fall-back is the Member State where cybersecurity operations are carried out. If that too is indeterminate, the main establishment defaults to the Member State where the entity has the establishment with the highest number of employees in the Union 32022L2555 Article 26@2022-12-27.

Exception 3 — Public administration entities

Public administration entities fall under the jurisdiction of the Member State that established them 32022L2555 Article 26@2022-12-27.

Entities with no Union establishment

A digital-infrastructure entity of the type described under Exception 2 that is not established in the Union but offers services within it must designate a representative in one of the Member States where those services are offered. Jurisdiction then attaches to the Member State of that representative. If no representative is designated, any Member State where the entity provides services may take legal actions against the entity for the infringement of this Directive 32022L2555 Article 26@2022-12-27. Designating a representative does not shield the entity itself from direct legal action 32022L2555 Article 26@2022-12-27.

The ENISA entity registry

ENISA creates and maintains a registry of the same digital-infrastructure entity categories listed under Exception 2, populated from information forwarded by Member States' single points of contact 32022L2555 Article 27@2022-12-27. Upon request, ENISA shall allow competent authorities access to the registry, while ensuring the confidentiality of information is protected where applicable 32022L2555 Article 27@2022-12-27.

The registration deadline for submitting information to national competent authorities was 17 January 2025 32022L2555 Article 27@2022-12-27. Required fields are: the entity's name; its sector, subsector and entity type under Annex I or II, where applicable; the address of its main establishment and any other Union establishments, or the representative's address if the entity is not Union-established; up-to-date contact details including email and telephone for the entity and any representative; the Member States in which services are provided; and the entity's IP ranges 32022L2555 Article 27@2022-12-27.

All submitted information except IP ranges is forwarded by the single point of contact to ENISA without undue delay 32022L2555 Article 27@2022-12-27. Entities must notify changes without delay and in any event within three months of the date of the change 32022L2555 Article 27@2022-12-27.

Domain-name registration data: accuracy duties

TLD name registries and entities providing domain name registration services must collect and maintain accurate and complete domain name registration data in a dedicated database, with due diligence and in compliance with Union data protection law for personal data 32022L2555 Article 28@2022-12-27.

The database must enable identification of, and contact with, domain name holders and the points of contact administering those names under the relevant TLD. Required data elements are: the domain name; the date of registration; the registrant's name, contact email address and telephone number; and, where different from the registrant's details, the contact email address and telephone number of the point of contact administering the domain name 32022L2555 Article 28@2022-12-27.

Policies and procedures ensuring data accuracy — including verification procedures — must be in place and made publicly available 32022L2555 Article 28@2022-12-27. Registration data that do not constitute personal data must be published without undue delay following registration 32022L2555 Article 28@2022-12-27.

Legitimate access seekers may submit lawful and duly substantiated requests for access to specific registration data, including personal data. Registries and registrars must provide such access in accordance with Union data protection law, respond without undue delay and in any event within 72 hours of receipt of the request, and make their disclosure policies publicly available 32022L2555 Article 28@2022-12-27. Compliance with these obligations shall not result in a duplication of collecting domain name registration data; to that end, TLD name registries and domain name registration service providers are required to cooperate with one another 32022L2555 Article 28@2022-12-27.

Your operations manual

This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The following are labeled illustrative context, not regulation.

No recent cases are cached for this topic.

Check your understanding

1. A provider of publicly available electronic communications services is established in Member State A but provides its services exclusively in Member State B. Under NIS 2, which Member State has jurisdiction over that provider?

2. When determining a cloud computing service provider's main establishment in the Union, which criterion is applied first in the sequential test?

3. A digital-infrastructure entity type subject to the main-establishment jurisdiction rule provides services within the Union but has no Union establishment and designates no representative. What does NIS 2 prescribe?

4. Which information element submitted to a national competent authority for the ENISA registry is explicitly NOT forwarded by the single point of contact to ENISA?

5. How quickly must a TLD name registry respond to a lawful and duly substantiated request for access to domain name registration data?