Source: OJ L 333, 27.12.2022, p. 1–79
EN
- Digital operational resilience act
Basic legislative acts
- DORA regulation
Article 3 Definitions
For the purposes of this Regulation, the following definitions shall apply:
‘digital operational resilience means the ability of a financial entity to build, assure and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service providers, the full range of ICT-related capabilities needed to address the security of the network and information systems which a financial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions;’ means the ability of a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; to build, assure and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service providers means an undertaking providing ICT services;, the full range of ICT-related capabilities needed to address the security of the network and information systems means: any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; which a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; uses, and which support the continued provision of financial services and their quality, including throughout disruptions;
‘network and information system means: any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972;’ means a network and information system means: any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; as defined in Article 6, point 1, of Directive (EU) 2022/2555;
‘legacy ICT system means an ICT system that has reached the end of its lifecycle (end-of-life), that is not suitable for upgrades or fixes, for technological or commercial reasons, or is no longer supported by its supplier or by an ICT third-party service provider, but that is still in use and supports the functions of the financial entity;’ means an ICT system that has reached the end of its lifecycle (end-of-life), that is not suitable for upgrades or fixes, for technological or commercial reasons, or is no longer supported by its supplier or by an ICT third-party service provider means an undertaking providing ICT services;, but that is still in use and supports the functions of the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;;
‘security of network and information systems means the ability of network and information systems to resist, at a given level of confidence, any event that may compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, those network and information systems;’ means security of network and information systems means the ability of network and information systems to resist, at a given level of confidence, any event that may compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, those network and information systems; as defined in Article 6, point 2, of Directive (EU) 2022/2555;
‘ICT risk means any reasonably identifiable circumstance in relation to the use of network and information systems which, if materialised, may compromise the security of the network and information systems, of any technology dependent tool or process, of operations and processes, or of the provision of services by producing adverse effects in the digital or physical environment;’ means any reasonably identifiable circumstance in relation to the use of network and information systems means: any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; which, if materialised, may compromise the security of the network and information systems means: any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972;, of any technology dependent tool or process, of operations and processes, or of the provision of services by producing adverse effects in the digital or physical environment;
‘information asset means a collection of information, either tangible or intangible, that is worth protecting;’ means a collection of information, either tangible or intangible, that is worth protecting;
‘ICT asset means a software or hardware asset in the network and information systems used by the financial entity;’ means a software or hardware asset in the network and information systems means: any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; used by the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;;
‘ICT-related incident means a single event or a series of linked events unplanned by the financial entity that compromises the security of the network and information systems, and have an adverse impact on the availability, authenticity, integrity or confidentiality of data, or on the services provided by the financial entity;’ means a single event or a series of linked events unplanned by the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; that compromises the security of the network and information systems means: any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972;, and have an adverse impact on the availability, authenticity, integrity or confidentiality of data, or on the services provided by the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;;
‘operational or security payment-related incident means a single event or a series of linked events unplanned by the financial entities referred to in Article 2(1), points (a) to (d), whether ICT-related or not, that has an adverse impact on the availability, authenticity, integrity or confidentiality of payment-related data, or on the payment-related services provided by the financial entity;’ means a single event or a series of linked events unplanned by the financial entitiesas defined in Article 2, points (a) to (t) referred to in Article 2(1), points (a), to (d), whether ICT-related or not, that has an adverse impact on the availability, authenticity, integrity or confidentiality of payment-related data, or on the payment-related services provided by the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;;
‘major ICT-related incident means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions of the financial entity;’ means an ICT-related incident means a single event or a series of linked events unplanned by the financial entity that compromises the security of the network and information systems, and have an adverse impact on the availability, authenticity, integrity or confidentiality of data, or on the services provided by the financial entity; that has a high adverse impact on the network and information systems means: any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance; an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; that support critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;;
‘major operational or security payment-related incident means an operational or security payment-related incident that has a high adverse impact on the payment-related services provided;’ means an operational or security payment-related incident means a single event or a series of linked events unplanned by the financial entities referred to in Article 2(1), points (a) to (d), whether ICT-related or not, that has an adverse impact on the availability, authenticity, integrity or confidentiality of payment-related data, or on the payment-related services provided by the financial entity; that has a high adverse impact on the payment-related services provided;
‘cyber threat means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;’ means ‘cyber threat means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;’ as defined in Article 2, point (8), of Regulation (EU) 2019/881;
‘significant cyber threat means a cyber threat which, based on its technical characteristics, can be assumed to have the potential to have a severe impact on the network and information systems of an entity or the users of the entity’s services by causing considerable material or non-material damage;’ means a cyber threat means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; the technical characteristics of which indicate that it could have the potential to result in a major ICT-related incident means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions of the financial entity; or a major operational or security payment-related incident means an operational or security payment-related incident that has a high adverse impact on the payment-related services provided;;
‘cyber-attack means a malicious ICT-related incident caused by means of an attempt perpetrated by any threat actor to destroy, expose, alter, disable, steal or gain unauthorised access to, or make unauthorised use of, an asset;’ means a malicious ICT-related incident means a single event or a series of linked events unplanned by the financial entity that compromises the security of the network and information systems, and have an adverse impact on the availability, authenticity, integrity or confidentiality of data, or on the services provided by the financial entity; caused by means of an attempt perpetrated by any threat actor to destroy, expose, alter, disable, steal or gain unauthorised access to, or make unauthorised use of, an asset;
‘threat intelligence means information that has been aggregated, transformed, analysed, interpreted or enriched to provide the necessary context for decision-making and to enable relevant and sufficient understanding in order to mitigate the impact of an ICT-related incident or of a cyber threat, including the technical details of a cyber-attack, those responsible for the attack and their modus operandi and motivations;’ means information that has been aggregated, transformed, analysed, interpreted or enriched to provide the necessary context for decision-making and to enable relevant and sufficient understanding in order to mitigate the impact of an ICT-related incident means a single event or a series of linked events unplanned by the financial entity that compromises the security of the network and information systems, and have an adverse impact on the availability, authenticity, integrity or confidentiality of data, or on the services provided by the financial entity; or of a cyber threat means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;, including the technical details of a cyber-attack means a malicious ICT-related incident caused by means of an attempt perpetrated by any threat actor to destroy, expose, alter, disable, steal or gain unauthorised access to, or make unauthorised use of, an asset;, those responsible for the attack and their modus operandi and motivations;
‘vulnerability means a weakness, susceptibility or flaw of ICT products or ICT services that can be exploited by a cyber threat;’ means a weakness, susceptibility or flaw of an asset, system, process or control that can be exploited;
‘threat-led penetration testinga framework that mimics the tactics, techniques and procedures of real-life threat actors perceived as posing a genuine cyber threat, that delivers a controlled, bespoke, intelligence-led (red team) test of the financial entity’s critical live production systems (TLPT(threat-led penetration testing) a framework that mimics the tactics, techniques and procedures of real-life threat actors perceived as posing a genuine cyber threat, that delivers a controlled, bespoke, intelligence-led (red team) test of the financial entity’s critical live production systems)’ means a framework that mimics the tactics, techniques and procedures of real-life threat actors perceived as posing a genuine cyber threat means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;, that delivers a controlled, bespoke, intelligence-led (red team) test of the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;’s critical live production systems;
‘ICT third-party risk means an ICT risk that may arise for a financial entity in relation to its use of ICT services provided by ICT third-party service providers or by subcontractors of the latter, including through outsourcing arrangements;’ means an ICT risk means any reasonably identifiable circumstance in relation to the use of network and information systems which, if materialised, may compromise the security of the network and information systems, of any technology dependent tool or process, of operations and processes, or of the provision of services by producing adverse effects in the digital or physical environment; that may arise for a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; in relation to its use of ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; provided by ICT third-party service providers means an undertaking providing ICT services; or by subcontractors of the latter, including through outsourcing arrangements;
‘ICT third-party service provider means an undertaking providing ICT services;’ means an undertaking providing ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services;;
‘ICT intra-group service provider means an undertaking that is part of a financial group and that provides predominantly ICT services to financial entities within the same group or to financial entities belonging to the same institutional protection scheme, including to their parent undertakings, subsidiaries, branches or other entities that are under common ownership or control;’ means an undertaking that is part of a financial group means a group as defined in Article 2, point (11), of Directive 2013/34/EU; and that provides predominantly ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; to financial entitiesas defined in Article 2, points (a) to (t) within the same group means a group as defined in Article 2, point (11), of Directive 2013/34/EU; or to financial entitiesas defined in Article 2, points (a) to (t) belonging to the same institutional protection scheme, including to their parent undertakings means a parent undertaking within the meaning of Article 2, point (9), and Article 22 of Directive 2013/34/EU;, subsidiaries means a subsidiary undertaking within the meaning of Article 2, point (10), and Article 22 of Directive 2013/34/EU;, branches or other entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; that are under common ownership or control;
‘ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services;’ means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services;
‘critical or important function means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law;’ means a function, the disruption of which would materially impair the financial performance of a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law;
‘critical ICT third-party service provider means an ICT third-party service provider designated as critical in accordance with Article 31;’ means an ICT third-party service provider means an undertaking providing ICT services; designated as critical in accordance with Article 31;
‘ICT third-party service provider established in a third country means an ICT third-party service provider that is a legal person established in a third-country and that has entered into a contractual arrangement with a financial entity for the provision of ICT services;’ means an ICT third-party service provider means an undertaking providing ICT services; that is a legal person established in a third-country and that has entered into a contractual arrangement with a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; for the provision of ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services;;
‘subsidiary means a subsidiary undertaking within the meaning of Article 2, point (10), and Article 22 of Directive 2013/34/EU;’ means a subsidiary means a subsidiary undertaking within the meaning of Article 2, point (10), and Article 22 of Directive 2013/34/EU; undertaking within the meaning of Article 2, point (10), and Article 22 of Directive 2013/34/EU;
‘group means a group as defined in Article 2, point (11), of Directive 2013/34/EU;’ means a group means a group as defined in Article 2, point (11), of Directive 2013/34/EU; as defined in Article 2, point (11), of Directive 2013/34/EU;
‘parent undertaking means a parent undertaking within the meaning of Article 2, point (9), and Article 22 of Directive 2013/34/EU;’ means a parent undertaking means a parent undertaking within the meaning of Article 2, point (9), and Article 22 of Directive 2013/34/EU; within the meaning of Article 2, point (9), and Article 22 of Directive 2013/34/EU;
‘ICT subcontractor established in a third country means an ICT subcontractor that is a legal person established in a third-country and that has entered into a contractual arrangement either with an ICT third-party service provider, or with an ICT third-party service provider established in a third country;’ means an ICT subcontractor that is a legal person established in a third-country and that has entered into a contractual arrangement either with an ICT third-party service provider means an undertaking providing ICT services;, or with an ICT third-party service provider established in a third country means an ICT third-party service provider that is a legal person established in a third-country and that has entered into a contractual arrangement with a financial entity for the provision of ICT services;;
‘ICT concentration risk means an exposure to individual or multiple related critical ICT third-party service providers creating a degree of dependency on such providers so that the unavailability, failure or other type of shortfall of such provider may potentially endanger the ability of a financial entity to deliver critical or important functions, or cause it to suffer other types of adverse effects, including large losses, or endanger the financial stability of the Union as a whole;’ means an exposure to individual or multiple related critical ICT third-party service providers means an ICT third-party service provider designated as critical in accordance with Article 31; creating a degree of dependency on such providers so that the unavailability, failure or other type of shortfall of such provider may potentially endanger the ability of a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; to deliver critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law;, or cause it to suffer other types of adverse effects, including large losses, or endanger the financial stability of the Union as a whole;
‘management body means a management body as defined in Article 4(1), point (36), of Directive 2014/65/EU, Article 3(1), point (7), of Directive 2013/36/EU, Article 2(1), point (s), of Directive 2009/65/EC of the European Parliament and of the Council (^31^), Article 2(1), point (45), of Regulation (EU) No 909/2014, Article 3(1), point (20), of Regulation (EU) 2016/1011, and in the relevant provision of the Regulation on markets in crypto-assets, or the equivalent persons who effectively run the entity or have key functions in accordance with relevant Union or national law; Directive 2009/65/EC of the European Parliament and of the Council of 13 July 2009 on the coordination of laws, regulations and administrative provisions relating to undertakings for collective investment in transferable securities (UCITS) (OJ L 302, 17.11.2009, p. 32).’ means a management body means a management body as defined in Article 4(1), point (36), of Directive 2014/65/EU, Article 3(1), point (7), of Directive 2013/36/EU, Article 2(1), point (s), of Directive 2009/65/EC of the European Parliament and of the Council (^31^), Article 2(1), point (45), of Regulation (EU) No 909/2014, Article 3(1), point (20), of Regulation (EU) 2016/1011, and in the relevant provision of the Regulation on markets in crypto-assets, or the equivalent persons who effectively run the entity or have key functions in accordance with relevant Union or national law; Directive 2009/65/EC of the European Parliament and of the Council of 13 July 2009 on the coordination of laws, regulations and administrative provisions relating to undertakings for collective investment in transferable securities (UCITS) (OJ L 302, 17.11.2009, p. 32). as defined in Article 4(1), point (36), of Directive 2014/65/EU, Article 3(1), point (7), of Directive 2013/36/EU, Article 2(1), point (s), of Directive 2009/65/EC of the European Parliament and of the Council (31)Directive 2009/65/EC of the European Parliament and of the Council of 13 July 2009 on the coordination of laws, regulations and administrative provisions relating to undertakings for collective investment in transferable securities (UCITS) (OJ L 302, 17.11.2009, p. 32)., Article 2(1), point (45), of Regulation (EU) No 909/2014, Article 3(1), point (20), of Regulation (EU) 2016/1011, and in the relevant provision of the Regulation on markets in crypto-assets, or the equivalent persons who effectively run the entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; or have key functions in accordance with relevant Union or national law;
‘credit institution means a credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013 of the European Parliament and of the Council (^32^); Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1).’ means a credit institution means a credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013 of the European Parliament and of the Council (^32^); Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1). as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013 of the European Parliament and of the Council (32)Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1).;
‘institution exempted pursuant to Directive 2013/36/EU means an entity as referred to in Article 2(5), points (4) to (23), of Directive 2013/36/EU;’ means an entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; as referred to in Article 2(5), points (4) to (23), of Directive 2013/36/EU;
‘investment firm means an investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU;’ means an investment firm means an investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU; as defined in Article 4(1), point (1), of Directive 2014/65/EU;
‘small and non-interconnected investment firm means an investment firm that meets the conditions laid out in Article 12(1) of Regulation (EU) 2019/2033 of the European Parliament and of the Council (^33^); Regulation (EU) 2019/2033 of the European Parliament and of the Council of 27 November 2019 on the prudential requirements of investment firms and amending Regulations (EU) No 1093/2010, (EU) No 575/2013, (EU) No 600/2014 and (EU) No 806/2014 (OJ L 314, 5.12.2019, p. 1).’ means an investment firm means an investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU; that meets the conditions laid out in Article 12(1) of Regulation (EU) 2019/2033 of the European Parliament and of the Council (33)Regulation (EU) 2019/2033 of the European Parliament and of the Council of 27 November 2019 on the prudential requirements of investment firms and amending Regulations (EU) No 1093/2010, (EU) No 575/2013, (EU) No 600/2014 and (EU) No 806/2014 (OJ L 314, 5.12.2019, p. 1).;
‘payment institution means a payment institution as defined in Article 4, point (4), of Directive (EU) 2015/2366;’ means a payment institution means a payment institution as defined in Article 4, point (4), of Directive (EU) 2015/2366; as defined in Article 4, point (4), of Directive (EU) 2015/2366;
‘payment institution means a payment institution as defined in Article 4, point (4), of Directive (EU) 2015/2366; exempted pursuant to Directive (EU) 2015/2366’ means a payment institution means a payment institution as defined in Article 4, point (4), of Directive (EU) 2015/2366; exempted pursuant to Article 32(1) of Directive (EU) 2015/2366;
‘account information service provider means an account information service provider as referred to in Article 33(1) of Directive (EU) 2015/2366;’ means an account information service provider means an account information service provider as referred to in Article 33(1) of Directive (EU) 2015/2366; as referred to in Article 33(1) of Directive (EU) 2015/2366;
‘electronic money institution means an electronic money institution as defined in Article 2, point (1), of Directive 2009/110/EC of the European Parliament and of the Council;’ means an electronic money institution means an electronic money institution as defined in Article 2, point (1), of Directive 2009/110/EC of the European Parliament and of the Council; as defined in Article 2, point (1), of Directive 2009/110/EC of the European Parliament and of the Council;
‘electronic money institution exempted pursuant to Directive 2009/110/EC means an electronic money institution benefitting from a waiver as referred to in Article 9(1) of Directive 2009/110/EC;’ means an electronic money institution means an electronic money institution as defined in Article 2, point (1), of Directive 2009/110/EC of the European Parliament and of the Council; benefitting from a waiver as referred to in Article 9(1) of Directive 2009/110/EC;
‘central counterparty means a central counterparty as defined in Article 2, point (1), of Regulation (EU) No 648/2012;’ means a central counterparty means a central counterparty as defined in Article 2, point (1), of Regulation (EU) No 648/2012; as defined in Article 2, point (1), of Regulation (EU) No 648/2012;
‘trade repository means a trade repository as defined in Article 2, point (2), of Regulation (EU) No 648/2012;’ means a trade repository means a trade repository as defined in Article 2, point (2), of Regulation (EU) No 648/2012; as defined in Article 2, point (2), of Regulation (EU) No 648/2012;
‘central securities depository means a central securities depository as defined in Article 2(1), point (1), of Regulation (EU) No 909/2014;’ means a central securities depository means a central securities depository as defined in Article 2(1), point (1), of Regulation (EU) No 909/2014; as defined in Article 2(1), point (1), of Regulation (EU) No 909/2014;
‘trading venue means a trading venue as defined in Article 4(1), point (24), of Directive 2014/65/EU;’ means a trading venue means a trading venue as defined in Article 4(1), point (24), of Directive 2014/65/EU; as defined in Article 4(1), point (24), of Directive 2014/65/EU;
‘manager of alternative investment funds means a manager of alternative investment funds as defined in Article 4(1), point (b), of Directive 2011/61/EU;’ means a manager of alternative investment funds means a manager of alternative investment funds as defined in Article 4(1), point (b), of Directive 2011/61/EU; as defined in Article 4(1), point (b), of Directive 2011/61/EU;
‘management company means a management company as defined in Article 2(1), point (b), of Directive 2009/65/EC;’ means a management company means a management company as defined in Article 2(1), point (b), of Directive 2009/65/EC; as defined in Article 2(1), point (b), of Directive 2009/65/EC;
‘data reporting service provider means a data reporting service provider within the meaning of Regulation (EU) No 600/2014, as referred to in Article 2(1), points (34) to (36) thereof;’ means a data reporting service provider means a data reporting service provider within the meaning of Regulation (EU) No 600/2014, as referred to in Article 2(1), points (34) to (36) thereof; within the meaning of Regulation (EU) No 600/2014, as referred to in Article 2(1), points (34) to (36) thereof;
‘insurance undertaking means an insurance undertaking as defined in Article 13, point (1), of Directive 2009/138/EC;’ means an insurance undertaking means an insurance undertaking as defined in Article 13, point (1), of Directive 2009/138/EC; as defined in Article 13, point (1), of Directive 2009/138/EC;
‘reinsurance undertaking means a reinsurance undertaking as defined in Article 13, point (4), of Directive 2009/138/EC;’ means a reinsurance undertaking means a reinsurance undertaking as defined in Article 13, point (4), of Directive 2009/138/EC; as defined in Article 13, point (4), of Directive 2009/138/EC;
‘insurance intermediary means an insurance intermediary as defined in Article 2(1), point (3), of Directive (EU) 2016/97 of the European Parliament and of the Council (^34^); Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (OJ L 26, 2.2.2016, p. 19).’ means an insurance intermediary means an insurance intermediary as defined in Article 2(1), point (3), of Directive (EU) 2016/97 of the European Parliament and of the Council (^34^); Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (OJ L 26, 2.2.2016, p. 19). as defined in Article 2(1), point (3), of Directive (EU) 2016/97 of the European Parliament and of the Council (34)Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (OJ L 26, 2.2.2016, p. 19).;
‘ancillary insurance intermediary means an ancillary insurance intermediary as defined in Article 2(1), point (4), of Directive (EU) 2016/97;’ means an ancillary insurance intermediary means an ancillary insurance intermediary as defined in Article 2(1), point (4), of Directive (EU) 2016/97; as defined in Article 2(1), point (4), of Directive (EU) 2016/97;
‘reinsurance intermediary means a reinsurance intermediary as defined in Article 2(1), point (5), of Directive (EU) 2016/97;’ means a reinsurance intermediary means a reinsurance intermediary as defined in Article 2(1), point (5), of Directive (EU) 2016/97; as defined in Article 2(1), point (5), of Directive (EU) 2016/97;
‘institution for occupational retirement provision means an institution for occupational retirement provision as defined in Article 6, point (1), of Directive (EU) 2016/2341;’ means an institution for occupational retirement provision means an institution for occupational retirement provision as defined in Article 6, point (1), of Directive (EU) 2016/2341; as defined in Article 6, point (1), of Directive (EU) 2016/2341;
‘small institution for occupational retirement provision means an institution for occupational retirement provision which operates pension schemes which together have less than 100 members in total;’ means an institution for occupational retirement provision means an institution for occupational retirement provision as defined in Article 6, point (1), of Directive (EU) 2016/2341; which operates pension schemes which together have less than 100 members in total;
‘credit rating agency means a credit rating agency as defined in Article 3(1), point (b), of Regulation (EC) No 1060/2009;’ means a credit rating agency means a credit rating agency as defined in Article 3(1), point (b), of Regulation (EC) No 1060/2009; as defined in Article 3(1), point (b), of Regulation (EC) No 1060/2009;
‘crypto-asset service provider means a crypto-asset service provider as defined in the relevant provision of the Regulation on markets in crypto-assets;’ means a crypto-asset service provider means a crypto-asset service provider as defined in the relevant provision of the Regulation on markets in crypto-assets; as defined in the relevant provision of the Regulation on markets in crypto-assets;
‘issuer of asset-referenced tokens means an issuer of asset-referenced tokens as defined in the relevant provision of the Regulation on markets in crypto-assets;’ means an issuer of asset-referenced tokens means an issuer of asset-referenced tokens as defined in the relevant provision of the Regulation on markets in crypto-assets; as defined in the relevant provision of the Regulation on markets in crypto-assets;
‘administrator of critical benchmarks means an administrator of ‘critical benchmarks’ as defined in Article 3(1), point (25), of Regulation (EU) 2016/1011;’ means an administrator of ‘critical benchmarks’ as defined in Article 3(1), point (25), of Regulation (EU) 2016/1011;
‘crowdfunding service provider means a crowdfunding service provider as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503 of the European Parliament and of the Council (^35^); Regulation (EU) 2020/1503 of the European Parliament and of the Council of 7 October 2020 on European crowdfunding service providers for business, and amending Regulation (EU) 2017/1129 and Directive (EU) 2019/1937 (OJ L 347, 20.10.2020, p. 1).’ means a crowdfunding service provider means a crowdfunding service provider as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503 of the European Parliament and of the Council (^35^); Regulation (EU) 2020/1503 of the European Parliament and of the Council of 7 October 2020 on European crowdfunding service providers for business, and amending Regulation (EU) 2017/1129 and Directive (EU) 2019/1937 (OJ L 347, 20.10.2020, p. 1). as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503 of the European Parliament and of the Council (35)Regulation (EU) 2020/1503 of the European Parliament and of the Council of 7 October 2020 on European crowdfunding service providers for business, and amending Regulation (EU) 2017/1129 and Directive (EU) 2019/1937 (OJ L 347, 20.10.2020, p. 1).;
‘securitisation repository means a securitisation repository as defined in Article 2, point (23), of Regulation (EU) 2017/2402 of the European Parliament and of the Council (^36^); Regulation (EU) 2017/2402 of the European Parliament and of the Council of 12 December 2017 laying down a general framework for securitisation and creating a specific framework for simple, transparent and standardised securitisation, and amending Directives 2009/65/EC, 2009/138/EC and 2011/61/EU and Regulations (EC) No 1060/2009 and (EU) No 648/2012 (OJ L 347, 28.12.2017, p. 35).’ means a securitisation repository means a securitisation repository as defined in Article 2, point (23), of Regulation (EU) 2017/2402 of the European Parliament and of the Council (^36^); Regulation (EU) 2017/2402 of the European Parliament and of the Council of 12 December 2017 laying down a general framework for securitisation and creating a specific framework for simple, transparent and standardised securitisation, and amending Directives 2009/65/EC, 2009/138/EC and 2011/61/EU and Regulations (EC) No 1060/2009 and (EU) No 648/2012 (OJ L 347, 28.12.2017, p. 35). as defined in Article 2, point (23), of Regulation (EU) 2017/2402 of the European Parliament and of the Council (36)Regulation (EU) 2017/2402 of the European Parliament and of the Council of 12 December 2017 laying down a general framework for securitisation and creating a specific framework for simple, transparent and standardised securitisation, and amending Directives 2009/65/EC, 2009/138/EC and 2011/61/EU and Regulations (EC) No 1060/2009 and (EU) No 648/2012 (OJ L 347, 28.12.2017, p. 35).;
‘microenterprise means a financial entity, other than a trading venue, a central counterparty, a trade repository or a central securities depository, which employs fewer than 10 persons and has an annual turnover and/or annual balance sheet total that does not exceed EUR 2 million;’ means a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;, other than a trading venue means a trading venue as defined in Article 4(1), point (24), of Directive 2014/65/EU;, a central counterparty means a central counterparty as defined in Article 2, point (1), of Regulation (EU) No 648/2012;, a trade repository means a trade repository as defined in Article 2, point (2), of Regulation (EU) No 648/2012; or a central securities depository means a central securities depository as defined in Article 2(1), point (1), of Regulation (EU) No 909/2014;, which employs fewer than 10 persons and has an annual turnover and/or annual balance sheet total that does not exceed EUR 2 million;
‘Lead Overseer means the European Supervisory Authority appointed in accordance with Article 31(1), point (b) of this Regulation;’ means the European Supervisory Authority appointed in accordance with Article 31(1), point (b) of this Regulation;
‘Joint Committee means the committee referred to in Article 54 of Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010;’ means the committee referred to in Article 54 of Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010;
‘small enterprise means a financial entity that employs 10 or more persons, but fewer than 50 persons, and has an annual turnover and/or annual balance sheet total that exceeds EUR 2 million, but does not exceed EUR 10 million;’ means a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; that employs 10 or more persons, but fewer than 50 persons, and has an annual turnover and/or annual balance sheet total that exceeds EUR 2 million, but does not exceed EUR 10 million;
‘medium-sized enterprise means a financial entity that is not a small enterprise and employs fewer than 250 persons and has an annual turnover that does not exceed EUR 50 million and/or an annual balance sheet that does not exceed EUR 43 million;’ means a financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; that is not a small enterprise means a financial entity that employs 10 or more persons, but fewer than 50 persons, and has an annual turnover and/or annual balance sheet total that exceeds EUR 2 million, but does not exceed EUR 10 million; and employs fewer than 250 persons and has an annual turnover that does not exceed EUR 50 million and/or an annual balance sheet that does not exceed EUR 43 million;
‘public authority means any government or other public administration entity, including national central banks.’ means any government or other public administration entity means an entity recognised as such in a Member State in accordance with national law, not including the judiciary, parliaments or central banks, which complies with the following criteria:, including national central banks.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.