EIOPA · DORA 193 - 3207
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 28
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2024-12-13
- Answered
- 2025-11-20
Question
Can Social Media usage (e.g. for public relations) be considered an ICT-service under DORA?
Background
Strictly going by the DORA criteria, this could arguably be the case. However, it is unlikely that Meta, X,… will adapt their terms and conditions to include the key contractual provisions of DORA Article 30. Therefore, agreeing that social media use constitutes an ICT-service might effectively ban financial entities from using them.
Answer
This question has been rejected because the matter falls within the scope of Q&A 030.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
ICT third-party risk management (DORA)
Answered 2025-08-08
ICT third-party risk management (DORA)
Answered 2025-11-21
ICT third-party risk management (DORA)
Answered 2025-08-08
ICT third-party risk management (DORA), Other DORA topics
Answered 2025-07-25
ICT third-party risk management (DORA)
Answered 2024-11-28
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.