Skip to content
Ditap®
Trust CenterCompliance

Regulatory compliance

Where we actually stand today on GDPR, ISO 27001 and NIS2 — no badges for certifications we don't hold.

GDPR — Reglamento (UE) 2016/679

Active compliance program

DITAP operates out of Italy and serves clients in the European Union, so the General Data Protection Regulation (GDPR) applies directly to our operations — it is not an aspirational goal, it is the legal basis for how we handle data today.

Our Privacy Policy (/privacy) documents what data we collect, under what legal basis, for how long, and which sub-processors are involved (see /trust/sub-processors). Rights of access, rectification, erasure, portability and objection can be exercised by writing to [email protected].

When DITAP acts as a data processor for a client (for example, managing a hotel's guest WiFi or IP cameras that capture personal data), we offer a project-specific Data Processing Agreement (DPA).

See sub-processors

ISO/IEC 27001

Alignment in progress — certification not yet obtained

Let's be direct: DITAP is not ISO 27001 certified today. We say this plainly because a "certified" badge that doesn't match reality is, to us, worse than no badge at all.

What we do is shape our information security practices — access control, asset management, vendor management, incident management, operational continuity — around the Annex A control domains of the standard. The detail of those practices is at /trust/security.

We are evaluating starting the formal certification process once enterprise client volume justifies it.

See security practices

NIS2 — Directiva (UE) 2022/2555

Directive relevant to our clients — DITAP supports compliance

The NIS2 Directive (EU 2022/2555) raises the minimum cybersecurity bar required across the European Union, already transposed into Italian law. It broadens the scope compared to the previous directive: it no longer covers only classic critical infrastructure (energy, healthcare, transport), but also sectors like digital service providers, managed service providers (MSPs) and managed security service providers (MSSPs) — once certain size thresholds are met — and it explicitly requires managing supply-chain risk (Article 21).

This has two implications for DITAP. First, many of our clients in hospitality, SMBs and remote operations in Italy may fall under NIS2 directly or indirectly (for example, as suppliers to an obligated entity), and they need their infrastructure and security provider — us — to demonstrate solid practices. Second, as an MSP, it's reasonable that DITAP itself could eventually fall in scope as it grows, so we're shaping our security posture (see /trust/security) with that standard in mind now, not only once it becomes mandatory.

We do not claim to be audited or certified under NIS2 — the directive does not define a third-party certification scheme the way ISO 27001 does. What we offer is concrete support to help our clients sustain their own compliance.

How we help our clients comply

  • Technical and organizational risk management over the infrastructure we operate (Art. 21.2.a).
  • Supply-chain security documentation ready for our clients' own audits (Art. 21.2.d).
  • Incident handling and notification procedures aligned with the timeframes NIS2 requires of obligated entities (Art. 23).
  • Continuity and disaster recovery plans for the managed infrastructure (Art. 21.2.c).
  • Security training and awareness for the teams operating our clients' infrastructure (Art. 21.2.g).

Does your legal or procurement team need more detail?

We share our Privacy Policy, the sub-processor list and, where applicable, a DPA draft.

Email [email protected]