Regulation: from best effort to proof

European and Dutch rules are increasingly turning secure communication into an obligation you must be able to demonstrate. Here, in plain language, is what that means for your telephone contact.

NIS2 and the Dutch Cybersecurity Act

The Dutch implementation of the European NIS2 Directive makes digital resilience a legal duty of care for organisations in essential and important sectors, including healthcare, finance and government. Communication security falls within the mandatory risk management measures. Board members are personally responsible, and incidents must be reported within 24 hours.

DORA

The Digital Operational Resilience Act sets requirements for the digital operational resilience of financial institutions, including the reliability of the channels they use to communicate with customers.

PSD3 and the Payment Services Regulation

The new European payment rules provide for reimbursement of victims of spoofing fraud in which criminals pose as bank staff. That shifts the financial risk from the customer to the institution. If you can show that spoofed calls are technically ruled out, you are in a stronger position.

Digital Networks Act

With the Digital Networks Act, the European Commission aims to require telecom providers in all member states to take harmonised measures against number spoofing. Europol now calls caller ID spoofing a European security priority.

GDPR and ISO 27001

On the public network, personal data and call data travel through providers in different countries, with no guarantee of compliance. Within the Trusted Voice network, that processing remains controlled and auditable.

This page provides a general overview and is not legal advice. The status of European legislation may change.

Make your number mean something again.

In half an hour, we will show you what verified calling means for your organisation. No obligation.