{"id":3874,"date":"2025-02-09T23:00:00","date_gmt":"2025-02-09T23:00:00","guid":{"rendered":""},"modified":"2025-03-28T09:52:09","modified_gmt":"2025-03-28T09:52:09","slug":"urgent-contract-review-the-impacts-of-the-dora-regulation-on-the-financial-sector","status":"publish","type":"publicacion","link":"https:\/\/belzuz.com\/en\/publicacion\/urgent-contract-review-the-impacts-of-the-dora-regulation-on-the-financial-sector\/","title":{"rendered":"Urgent contract review: The Impacts of the DORA Regulation on the Financial Sector"},"content":{"rendered":"<p style=\"text-align: justify;\">(Regulation (EU) 2022\/2554 of the European Parliament and the Council, of December 14, 2022) entered into force on January 17, 2025, imposing new and stringent obligations on financial entities and ICT third-party service providers (e.g., cloud computing providers, software providers, and ICT infrastructure).<\/p>\n<p style=\"text-align: justify;\">Considering this new regulatory framework, an immediate and detailed analysis of existing contracts is required to review and update them.<\/p>\n<p style=\"text-align: justify;\">This is because, in addition to introducing structural obligations regarding the security and resilience of financial entities&#8217; systems, DORA Regulation creates a detailed regulatory framework governing contractual relations with so-called &#8220;ICT Third-Party Service Providers&#8221;, responding to the growing dependence of financial entities on external vendors to support their ICT functions and processes.<\/p>\n<p style=\"text-align: justify;\">One of the core elements of DORA is the management of risks associated with these third-party providers, establishing a <strong><span style=\"text-decoration: underline;\">minimum set of contractual obligations<\/span><\/strong> that both financial entities and providers must comply with, aimed primarily at ensuring <strong>(i)<\/strong> continuous monitoring of the services provided to ensure the financial entities&#8217; operational continuity and <strong>(ii)<\/strong> effective supervision by the competent authorities over ICT service providers, especially those supporting critical or important functions of financial entities.<\/p>\n<p style=\"text-align: justify;\">To ensure effective monitoring, operational continuity, and regulatory oversight, the European legislator, through Article 30 of DORA Regulation, has set forth that contracts between financial entities and ICT service providers must, <span style=\"text-decoration: underline;\"><strong>at a minimum<\/strong><\/span>, include the following provisions:<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; A detailed description of the ICT services to be provided, including the possibility and conditions for subcontracting;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Identification of the service delivery and data processing locations, with the obligation for prior notification in case of any changes;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Strict obligations on data treatment policies, ensuring availability, integrity, authenticity, and confidentiality, and compliance with the General Data Protection Regulation (GDPR);<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Access and data recovery procedures in case of cessation of activity or insolvency;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Service level agreements (SLAs), including periodic updates and revisions;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Mandatory assistance procedures in the event of ICT incidents;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Obligation to cooperate with competent authorities;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Termination clauses with minimum notice periods;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Conditions for participation in ICT security and digital operational resilience training programs.<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; When the ICT service providers support critical or important functions, contracts should also include:<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Full descriptions of service levels, with strict performance goals, including quantitative and qualitative targets;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Pre-notification obligations regarding any developments that may materially affect the ICT provider&#8217;s ability to effectively deliver services;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Contingency plans and robust security measures, regularly tested and adjusted to ensure regulatory compliance;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Mandatory participation in Threat-Led Penetration Testing (TLPT);<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Continuous monitoring rights, including inspections and audits;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">&#8211; Exit strategies and mandatory transition periods to ensure continuity or efficient migration of services.<\/p>\n<p style=\"text-align: justify;\">In response to these regulatory requirements, financial entities must adopt a proactive approach, implementing:<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">(a) A rigorous mapping process of internal processes relying on third-party ICT services, prioritizing those supporting critical or important functions;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">(b) A program for defining and managing priorities for contractual review;<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">(c) A strict schedule to ensure compliance with the regulations.<\/p>\n<p style=\"text-align: justify;\"><span style=\"text-decoration: underline;\">Entities must maintain an up-to-date record of all contracts with ICT service providers<\/span>, with a particular focus on those involving critical functions. This record must be available to the relevant authorities to enable quick and effective verification of regulatory compliance.<\/p>\n<p style=\"text-align: justify;\">Lastly, it is important to note that the competent authorities have the responsibility to oversee and monitor both financial entities and ICT providers, <span style=\"text-decoration: underline;\">with the power to impose financial penalties on non-compliant third-party ICT service providers<\/span>, reaching up to 1% of their average global daily turnover from the previous financial year.<\/p>\n<p style=\"text-align: justify;\">has experienced lawyers in the areas of Contracts, Compliance, and , and can provide legal advice in this field, effectively supporting the contractual review process.<\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">\n","protected":false},"featured_media":7871,"template":"","categories":[],"area-de-practica":[],"publicaciones":[],"idioma-publicacion":[71],"areas-practica-publicacciones":[],"class_list":["post-3874","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry","idioma-publicacion-ingles"],"acf":[],"_links":{"self":[{"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/publicacion\/3874","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/media\/7871"}],"wp:attachment":[{"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/media?parent=3874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/categories?post=3874"},{"taxonomy":"area-de-practica","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/area-de-practica?post=3874"},{"taxonomy":"publicaciones","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/publicaciones?post=3874"},{"taxonomy":"idioma-publicacion","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/idioma-publicacion?post=3874"},{"taxonomy":"areas-practica-publicacciones","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/areas-practica-publicacciones?post=3874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}