What EU DORA Subcontracting Chain Provisions - ICT Third-Party Risk for Cloud and Managed Service Providers in Financial Services requires
Under Article 30(3) of EU DORA, financial entities must ensure their contractual arrangements with ICT third-party service providers, such as cloud providers, explicitly govern the entire subcontracting chain, requiring prior notification of any changes and granting the financial entity the right to object to or terminate the contract based on such changes.
Pillar: Cloud & SaaS · Authority: European Parliament and the Council of the European Union · Version: 1.0.0 · Last updated:
Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554
SHA-256 integrity: 20013e973fcbc1ac69e0f2fb04eb80ef0cae7378748b8d59c34da79b99534154
Primary Citations — 7 traced to source
- Regulation (EU) 2022/2554, Article 30(3): Main provisions on subcontracting
- Regulation (EU) 2022/2554, Article 30(3)(a): Requirement to specify locations of subcontracting
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/eu-dora-ict-third-party-cloud.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/eu-dora-ict-third-party-cloud.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/eu-dora-ict-third-party-cloud
- Back to registry: Browse all 10,085 compliance nodes