(1) By way of derogation from section 59, the BSI is competent for DNS service providers, Top Level Domain Name Registries, domain name registry service providers, providers of cloud computing services, providers of data centre services, operators of content delivery networks, managed service providers, managed security service providers, and providers of online marketplaces, online search engines or social networking services platforms, only where they have their main establishment in the European Union in the Federal Republic of Germany. Where this is the case, the BSI has centralised competence for the entity throughout the European Union.
(2) The main establishment in the European Union within the meaning of subsection (1) is deemed to be the Member State of the European Union in which the entity's decisions in connection with cybersecurity risk management measures are predominantly taken. Where such a Member State cannot be determined, or such decisions are not taken in the European Union, the main establishment is deemed to be the Member State in which the cybersecurity measures are carried out. Where such a Member State cannot be determined, the main establishment is deemed to be the Member State in which the entity concerned has the establishment with the highest number of employees in the European Union.
(3) Where an entity of the type of entity named in subsection (1), first sentence has no establishment in the European Union but offers services within the European Union, it is obliged to designate a representative. The representative must be established in a Member State of the European Union in which the entity offers the services. Where the representative is established in the Federal Republic of Germany, the BSI is competent for the entity. Where an entity of the type of entity named in subsection (1), first sentence has designated no representative within the meaning of this subsection in the European Union, the BSI may declare itself competent for the entity concerned.
(4) The designation of a representative by an entity of the type of entity named in subsection (1), first sentence does not affect legal steps that could be taken against the entity itself.
(5) Where the BSI has received a request for mutual assistance from another Member State of the European Union concerning an entity of the type of entity named in subsection (1), first sentence, the BSI is empowered to take, within the limits of that request, suitable supervisory and enforcement measures with regard to the entity concerned that offers services in the Federal Republic of Germany or operates an information technology system, an information technology component or an information technology process. The first sentence applies accordingly to a request for mutual assistance from another Member State of the European Union that is competent for an entity throughout the European Union, where the entity offers services in the Federal Republic of Germany or operates an information technology system, an information technology component or an information technology process.
Home› Cybersecurity & IT Security› BSIG-EN
Part 7 · Supervision › Section 60
Centralised competence in the European Union for particular types of entity
←→ also move between sections