Many national regulations in EU jurisdictions applying to data centre operators are based on, or transpose, EU law. This chapter provides an overview of the principal EU-level legislation that forms the baseline for the national transpositions examined in the jurisdiction chapters that follow. Readers should treat this chapter as contextual reference material: where a national chapter references an EU directive or regulation, this chapter provides the underlying EU-level framework. The principal areas addressed are the internal electricity market framework, renewable energy and guarantees of origin, cybersecurity and physical resilience (NIS2 and the CER Directive), environmental and planning regulation (including the EIA Directive and the Industrial Emissions Directive), energy efficiency and eco-design requirements, corporate sustainability reporting (the CSRD), greenwashing and consumer protection, AI and supercomputing, and data protection and governance regimes.

The Internal Electricity Market Directive (Directive (EU) 2019/944) establishes common rules within the EU for the generation, transmission, distribution, energy storage, and supply of electricity. Of greatest relevance for data centre operators, the Directive stipulates the basic rules governing third-party access to the transmission and distribution grid. Such access must be based on published tariffs that apply to all customers, and must be applied objectively and without discrimination between grid users. A grid operator may refuse access only in defined circumstances, in particular where it lacks the necessary capacity. Under the Electricity Market Regulation (Regulation (EU) 2019/943), the European Commission is empowered to adopt delegated network codes which establish harmonised rules for the European wholesale electricity markets and the operation of grids, including, by way of example, a network code on demand connection.

The Renewable Energy Directive (Directive (EU) 2018/2001) establishes a common framework for the promotion of energy from renewable sources in the EU. It lays down rules on, among other things, financial support for electricity from renewable sources, consumption of such electricity, and accelerating permitting in “renewables acceleration areas”. It also establishes a scheme for guarantees of origin (“GOs”), which data centre operators may use to evidence their use of renewable energy to regulatory authorities, customers, and lenders. 

The NIS2 Directive (Directive (EU) 2022/2555) establishes a comprehensive cybersecurity framework for operators of essential and important entities in the EU, and was required to be transposed into national law by 17 October 2024 (although a number of Member States were late in completing transposition). Under NIS2, data centre providers are expressly identified as essential or important entities, depending on size, and EU Member States must ensure that data centre operators are able to prevent, manage, and report security incidents. Most notably, Member States must ensure that data centre operators take appropriate and proportionate technical, operational, and organisational measures to manage the risks posed to the security of their network and information systems, and to minimise the impact of incidents on the recipients of their services and on interconnected systems. These measures must be based on an “all-hazards approach” designed to protect network and information systems and the physical environment of those systems from incidents.

As at mid-2026, the substantial majority of Member States have completed transposition. The focus has now shifted from implementation to enforcement: national authorities have begun the first wave of supervisory activity, encompassing entity registration, incident-reporting compliance, supplier-risk management, and the personal accountability of designated senior managers. 

In addition, the Critical Entities Resilience Directive (Directive (EU) 2022/2557) (“CER Directive”) sets out requirements for the physical resilience of critical infrastructure and was required to be transposed by 17 October 2024. Digital infrastructure – including data centre service providers and certain cloud computing service providers – is one of the eleven sectors expressly within the scope of the CER Directive. However, where an entity is identified as a critical entity under the CER Directive, it will automatically be treated as an essential entity under NIS2, with the result that both the physical resilience obligations under the CER Directive and the cybersecurity obligations under NIS2 apply cumulatively. Member States retain discretion to impose stricter requirements at national level. 

A further resilience regime operates on the sector by indirect effect. The Digital Operational Resilience Act (Regulation (EU) 2022/2554) (“DORA”) applies to financial entities and their ICT third-party service providers. In November 2025, the European Supervisory Authorities designated the first cohort of critical ICT third-party providers – a list of nineteen that includes the principal hyperscale cloud platforms – subjecting them to direct EU-level oversight, on-site inspection rights, and daily penalties of up to 1% of average worldwide daily turnover for remediation failures. Data centre operators serving financial sector customers should expect its requirements – exit and substitutability planning, ICT risk registers, and audit and access rights – to flow through contractually into colocation and hosting arrangements, and should anticipate that financial tenants will negotiate accordingly.

The EU has adopted several directives on environmental regulation which are relevant for the planning and permitting of data centres. The Environmental Impact Assessment Directive (Directive 2011/92/EU) (“EIA Directive”) requires EU Member States to assess the likely significant effects on the environment of certain infrastructure projects before development consent is granted. This includes stakeholder and public participation requirements. These processes are a critical step in the development of a data centre, as they directly affect project timelines and permit decisions. Under the EIA Directive, data centres are not expressly listed in either Annex I (mandatory EIA) or Annex II (case-by-case screening). EU Member States therefore retain discretion as to whether, and on what thresholds, a data centre project (typically captured under Annex II categories such as “urban development projects” or “industrial estate development projects”) is subject to a full EIA. 

The Strategic Environmental Assessment Directive (Directive 2001/42/EC) (“SEA Directive”) applies to certain plans and programmes prepared and adopted by public authorities at national, regional, or local level, including those that set the framework for projects likely to have significant environmental effects. Under the SEA Directive, the competent authority must conduct a strategic EIA of any such plan or programme. Data centres are regularly accounted for in land-use and zoning plans prepared by local or regional authorities. As a result, the SEA may also impact the consenting environment for the development of a data centre. Furthermore, the Habitats Directive (Directive 92/43/EEC) and the Birds Directive (Directive 2009/147/EC) establish protection regimes for specific habitats and species which regulatory authorities consider in zoning and land-use plans (including, where required, an “appropriate assessment”). 

The Industrial Emissions Directive (Directive 2010/75/EU) (“IED”) commits EU Member States to control and reduce the impact of industrial emissions on the environment. It applies to combustion plants with a rated thermal input of 50 MW or above; for plants below that threshold, but with a rated thermal input of at least 1 MW, the Medium Combustion Plants Directive (Directive (EU) 2015/2193) (“MCPD”) applies instead. Both instruments are potentially relevant for data centres. A single emergency power generator – which would typically combust diesel, gas, or other fossil fuels – will rarely reach the 50 MW threshold that triggers the IED. However, the IED’s aggregation rules treat technically connected units operated by the same operator as a single installation for the purposes of calculating rated thermal output. This means that hyperscale facilities operating large generator fleets may nonetheless fall within its scope. For most data centre operators, the MCPD will be the operative instrument: it sets emission limit values for sulphur dioxide, nitrogen oxides, and particulate matter from fossil fuel combustion plants.

The Energy Efficiency Directive (Directive (EU) 2023/1791) (“EED”) recognises the economic importance of data centres while addressing their significant energy consumption. The EED and the supplementary Commission Delegated Regulation (EU) 2024/1364 impose reporting obligations on data centres with an IT power demand of at least 500 kW. The EED also obliges EU Member States to ensure that data centres with a total rated energy input exceeding 1 MW utilise waste heat recovery applications or supply waste heat to a district heating network, unless a cost-benefit analysis demonstrates that this is not technically or economically feasible. The Commission Implementing Regulation (EU) 2019/424 on Ecodesign Requirements for Servers and Data Storage Products sets energy and material efficiency requirements for certain servers and data storage products that are essential to data centre infrastructure.

The Commission’s Strategic Roadmap for Digitalisation and AI in the Energy Sector (COM(2026) 501 final) is a non-binding communication organised around three pillars – the sustainable integration of data centres into the energy system, the deployment of digital and AI solutions across it, and the supporting data-governance framework – and foreshadows both a model agreement between operators, energy actors, and public authorities (to be published in the second half of 2026), and, if voluntary coordination proves insufficient, a possible legislative proposal to secure that integration. 

Most significantly for operators, the Roadmap was accompanied by a Data Centre Energy Efficiency Package, the central element of which is a second Delegated Regulation establishing a common EU-wide sustainability rating scheme. The draft Regulation, published for consultation in March 2026 and scheduled for adoption in mid-2026, provides for electronic ratings to be issued automatically by the European database on data centres, rating facilities by reference to PUE and WUE classes calculated under a harmonised methodology, with the first ratings expected in 2027. The reporting cycle under Delegated Regulation (EU) 2024/1364 in respect of calendar year 2025 closed on 15 May 2026, and the data submitted in that cycle will form the baseline against which the rating scheme – and any future minimum performance standards – is calibrated. Operators should therefore treat the definitional and boundary choices made in their submissions as positioning decisions rather than merely being a compliance response: the rating may rapidly become a benchmark in procurement, financing, and leasing across the EU.

In addition to the reporting obligations under the EED, some data centre operators may be subject to reporting requirements set out in national regulations which implement the Corporate Sustainability Reporting Directive (Directive (EU) 2022/2464) (“CSRD”), as amended by the Omnibus Directive on Sustainability (Directive (EU) 2026/470). Under the CSRD, certain EU and non-EU companies must report on their environmental and climate impacts across their supply chain. Companies subject to the CSRD have to report according to the European Sustainability Reporting Standards (“ESRS”) that are currently in the process of being revised in view of the Omnibus Directive on Sustainability. With the amendments of the CSRD, as introduced by the Omnibus Directive on Sustainability, effective as of March 2026, the EU legislator drastically narrowed the CSRD's scope: only companies with over 1,000 employees and €450 million net turnover will be subject to mandatory CSRD reporting, effective from the financial year 2027. This removes approximately 90% of previously in-scope companies. Data centre operators will only be subject to the CSRD if they meet these high thresholds. 

The Directive on Empowering Consumers for the Green Transition (Directive (EU) 2024/825) prohibits general environmental claims – such as “climate neutral”, “eco-friendly”, or “green” – where these are not scientifically substantiated. Data centre operators must take this requirement into account when advertising their data centre as climate neutral to prevent greenwashing litigation. 

The AI Act (Regulation (EU) 2024/1689) has been in force since 1 August 2024 and classifies AI systems by risk level: unacceptable (use of which is prohibited), high (subject to extensive regulation), and limited (subject to additional transparency obligations). Many other AI systems pose only minimal risk and are subject to limited obligations (for example, AI literacy).

The Act is being implemented on a staged basis: the prohibitions and AI literacy obligations apply from 2 February 2025, the rules on general-purpose AI (“GPAI”) from 2 August 2025, and the transparency and enforcement rules from 2 August 2026. Following political agreement on the Digital Omnibus on AI, the obligations on high-risk AI systems have been postponed to 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in certain products. A grace period also applies to certain of the transparency rules.

Providers of general-purpose AI models trained using more than 1025 floating-point operations are presumed to have high-impact capabilities, which carry specific notification and risk-management duties. That threshold has rapidly become a commercial reference point in hyperscale compute procurement. Data centre operators hosting in-scope training or inference workloads may find that these obligations begin to flow through into hosting and colocation contracts as compute-related disclosure and data governance requirements, even where the operator itself owes no direct duty under the Regulation. For example, although the direct duty for data governance and quality is owed by the provider, the provider may require the operator’s assistance in producing supporting evidence, such as compute records or evidence of infrastructure resilience.

Data centre operators may also fall directly within the scope of the Act, particularly because one of the high-risk categories concerns AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, which could include data centres.

In addition, the EuroHPC Joint Undertaking pools EU and national resources to build world-class computing infrastructure across Europe. Two amendments have materially expanded its mandate: the 2024 amendment established AI Factories (compute clusters of approximately 25,000 AI-optimised processors linked to supercomputing centres to support AI experimentation, training, and startup access), and the January 2026 amendment (Council Regulation (EU) 2026/150, in force 20 January 2026) extended it to AI Gigafactories (state-of-the-art facilities of approximately 100,000 processors each, built on energy-efficient data centre infrastructure and covering the full AI lifecycle from development to large-scale inference), supported by the InvestAI facility targeting €20 billion in mobilised investment across up to five Gigafactory sites in the EU.

A major pending development is the proposed Cloud and AI Development Act (“CADA”), adopted by the Commission on 3 June 2026 as the centrepiece of its European Technological Sovereignty Package. That package pairs two legislative proposals – CADA and the proposed Chips Act 2.0 – with two policy instruments – the EU Open Source Strategy and the Strategic Roadmap for Digitalisation and AI in the Energy Sector – bringing cloud, compute, semiconductors, software, and energy-system integration into a single sovereignty programme. CADA aims to triple the EU’s data centre capacity within five to seven years, principally through each Member State’s designation of at least one data centre acceleration zone, in which qualifying projects benefit from streamlined, aggregated permitting, a 12-month consent deadline, and improved access to energy, land, water, and financing. The Commission may also designate individual projects as strategic, unlocking preferential access to EU funding, and CADA would establish an EU-wide framework for assessing the sovereignty of cloud and AI services procured by the public sector, with progressively stricter requirements for sensitive sectors.

The proposed framework is structured around four Union assurance levels, moving from EU-located infrastructure and data, through demonstrated independence from third-country control and software supply chain transparency, and EU ownership and control, to effective control over the entire software supply chain with no third-country interference. Its significance lies in its downstream reach: public sector bodies would assess which cloud and AI services suit particular use cases by reference to those levels, and essential entities under NIS2 may be drawn into the same logic – initially voluntarily and, through future secondary legislation, potentially as a binding requirement in designated sectors. For operators serving public sector or otherwise sensitive workloads, sovereignty would therefore become a procurement criterion in its own right, absorbing the cybersecurity-certification and data localisation requirements they already face and recasting them as gradations of a single sovereignty test.

The proposal now enters the ordinary legislative procedure, likely to run for one to three years. The most contested element is expected to be the sovereignty framework, on which the Council and Parliament are likely to divide, while the permitting provisions – more directly relevant to data centre development – engage competences that Member States guard closely. The direction of travel is not in doubt, however: because CADA would take effect as a directly applicable regulation, its acceleration-zone and consent-deadline obligations would overlay and, in time, reshape the national consenting regimes described in the jurisdiction chapters that follow.

The General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) is the principal data protection framework within the EU. It confers privacy rights on EU residents with regard to how their data is collected, used, stored, and processed. If data centre operators also operate the servers (i.e. process personal data on behalf of customers), they can qualify as data processors or data controllers and be subject to obligations under the GDPR. The EU Data Act (Regulation (EU) 2023/2854) complements the GDPR by setting specific obligations on data processing services – such as cloud and edge services typically operated from data centres – particularly in relation to switching between providers and removing contractual, commercial, and technical barriers to interoperability. For non-personal data, the Free Flow of Non-Personal Data Regulation prohibits unjustified localisation requirements, while preserving public authorities’ access to data stored or processed in either another Member State, or in the cloud. However, it does not displace sector-specific sovereignty, cybersecurity, or national security rules that may shape where sensitive workloads are hosted. 

The European Health Data Space Regulation (Regulation (EU) 2025/327) seeks to ensure the effective use of health data within the European Union, while guaranteeing a heightened level of protection for such sensitive data. For operators of hosting data centres, national implementation of the Regulation may give rise to a de facto obligation to store electronic health data within the EU, the EEA, or a specified Member State.

 

Back to homepage

This material is provided for general information only.
It does not constitute legal or other professional advice.