How this links to the Cyber Security and Resilience Bill
The Cyber Security and Resilience Bill extends the UK representative duty from digital service providers to managed service providers, tightens the deadlines and requires email and phone details. Because the Bill applies to providers whether or not they are established in the UK, many overseas cloud, marketplace and managed service firms will need a UK representative.
- Clause 14(4) rewrites reg 14A(1) so it applies to any relevant digital service provider whose principal office is outside the UK.
- Clause 14(5)-(6) adds email and telephone details, a three-month deadline and a seven-day duty to notify changes.
- Clause 14(9) inserts new reg 14D, which applies the same duty to a relevant managed service provider.
- The Information Commission or GCHQ may contact the representative instead of, or as well as, the provider.
- Failures sit in the standard maximum penalty band under new regulation 18.
Who has to nominate a UK representative?
Regulation 14A, as amended, applies to an RDSP that has its principal office outside the United Kingdom. New regulation 14D applies in the same way to an RMSP. Clauses 7(8) and 9(4) make both regimes apply to providers serving the UK whether or not they are established here, so an overseas cloud provider or managed service provider above the small enterprise ceiling will usually be caught.
Operators of essential services have a separate but similar duty. Regulation 8A requires an OES whose principal office is outside the UK to nominate a person to act on its behalf in the UK, and the Bill’s Schedule 2 aligns its change deadlines.
What must the provider do, and by when?
The duties under regulations 14A and 14D are the same:
- Nominate in writing a representative in the United Kingdom.
- Notify the Information Commission of the representative’s name and contact details, including an email address and telephone number.
- Do so within three months of section 14 coming into force, or within three months of becoming a provider to which the regulation applies.
- Notify any change within seven days: from the day it took effect for a new representative, or from the day the provider became aware for new contact details.
Does a representative take on the provider’s liability?
No. The representative is a point of contact. The Information Commission or GCHQ may contact the representative instead of, or in addition to, the provider when carrying out their functions. A nomination is without prejudice to any legal action that could be brought against the provider itself.
Under Part 5 of the Bill, notices and directions can be given to a representative a regulated person has appointed, so the representative must be able to pass them on quickly. Since the 24-hour incident clock runs from first awareness, delays in that chain are a real risk.
Where it appears in the Bill
- Clause 14(3)-(8)Amends NIS reg 14A for RDSPs: principal office test, contact details, deadlines.
- Clause 14(9)Inserts new regs 14C (registration) and 14D (RMSP representatives).
- Clause 7(6)Changes the definition of "representative" to refer to an RDSP.
- Schedule 2, para 7Amends reg 8A, the OES equivalent, including the seven-day change deadline.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
How long does an overseas provider have to nominate a UK representative?
Three months. A provider in scope when section 14 of the Cyber Security and Resilience Bill comes into force has three months from that day. A provider that comes into scope later has three months from the day it first becomes an RDSP or RMSP with a principal office outside the UK. Changes must then be notified within seven days.
What is the penalty for failing to nominate a UK representative?
Representative failures sit in the standard band under new regulation 18. The maximum is the greater of £10 million and 2% of the provider’s turnover. The Information Commission can also serve an enforcement notice first. The higher band, the greater of £17 million and 4%, is reserved for security duties, incident notification and failures to comply with directions and inspections.
Does the UK representative become liable for the provider’s breaches?
No. The representative is a contact point that the Information Commission or GCHQ can use instead of, or as well as, the provider. The Regulations state that a nomination is without prejudice to any legal action that could be brought against the provider itself, so the duties and liability stay with the regulated provider.