Time
Click Count
On 27 April 2026, the European Commission launched a public consultation on a draft revision of the EU Cybersecurity Act, introducing mandatory data localization and new security certification requirements for public-facing interactive terminals—including kiosk technology, hotel self-check-in systems, and guestroom automation control panels. This development carries direct implications for suppliers in smart hospitality infrastructure, digital signage, and embedded terminal hardware—particularly those headquartered outside the EU.
On 27 April 2026, the European Commission published a draft revision of the EU Cybersecurity Act for stakeholder consultation. The proposal mandates that all user data processed by publicly accessible interactive terminals—including kiosk technology (Kiosk Tech), hotel self-service check-in devices, and guestroom automation control screens (Guestroom Automation)—must be stored exclusively on servers located within the European Union. In addition, such systems must undergo conformity assessment against the EN 303 645:2025 standard—a harmonized cybersecurity specification for consumer Internet-connected products. Non-compliant suppliers—including those from China without EU-based cloud infrastructure or EN 303 645:2025 certification—will be excluded from EU public procurement and tenders issued by major hotel chains operating in the region.
Manufacturers supplying guestroom automation systems (e.g., in-room tablets, HVAC/lighting controllers, voice-enabled interfaces) are directly impacted because their devices collect and process personal user data during guest stays. Under the draft rule, storing or routing such data—even temporarily—to non-EU cloud services or edge gateways would constitute non-compliance. Impact manifests as restricted market access, increased infrastructure costs, and potential redesign of data flow architecture.
Suppliers of self-service kiosks—including retail, transportation, and hospitality use cases—are affected due to the regulation’s broad definition of ‘public-facing interactive terminals’. These devices often rely on centralized cloud platforms for remote management, analytics, and firmware updates. The requirement to localize all user data (e.g., ID scans, payment tokens, session logs) necessitates re-architecting backend infrastructure and revising data processing agreements with EU clients.
Companies integrating third-party modules (e.g., biometric sensors, NFC readers, display controllers) into end-user terminals face cascading compliance obligations. As system integrators, they bear responsibility for full-stack conformity—including firmware, OS-level security, and data handling logic. Failure to verify EN 303 645:2025 alignment across all components may invalidate the final product’s eligibility for EU deployment.
The current draft is under public consultation; the final version—including scope definitions, enforcement timelines, and transitional provisions—has not yet been adopted. Stakeholders should track official updates via the European Commission’s Better Regulation Portal and national cybersecurity authorities (e.g., Germany’s BSI, France’s ANSSI), as implementation windows and grandfathering clauses remain unconfirmed.
Review live and planned deployments in the EU to identify data flows involving user inputs (e.g., name, contact details, ID images, preferences). Map where data is ingested, cached, processed, and persisted—including edge devices, regional gateways, and SaaS backends. Prioritize remediation for systems where data transits or resides outside the EU—even if anonymized or encrypted—as the draft text does not exempt such transfers.
Begin internal gap analysis against EN 303 645:2025’s core requirements: secure update mechanisms, vulnerability disclosure policies, default password removal, data protection in transit and at rest, and attack surface reduction. Engage accredited EU Notified Bodies early to clarify interpretation of clauses relevant to embedded systems (e.g., Section 6.2 on insecure communication channels) and prepare for formal testing cycles.
For vendors without existing EU-based infrastructure, assess feasibility of partnering with certified EU cloud providers (e.g., AWS EU regions with ISO/IEC 27001 + EN 303 645-aligned SLAs, Deutsche Telekom’s T-Systems) or establishing dedicated local hosting arrangements. Note that mere use of an EU-region data center is insufficient—data residency, administrative control, and audit rights must align with the draft’s intent.
Observably, this proposal signals a tightening of operational sovereignty requirements—not just for cloud services, but for physical-edge IoT devices deployed in public spaces. Analysis shows the emphasis on EN 303 645:2025 (a standard originally targeting consumer routers and smart speakers) reflects a broader regulatory shift toward baseline security accountability across all connected endpoints, regardless of form factor or deployment context. From an industry perspective, the draft is best understood not as an immediate ban, but as a clear policy signal: EU procurement and enterprise B2B demand will increasingly treat cybersecurity certification and data residency as non-negotiable prerequisites—not differentiators. Continued attention is warranted because final adoption timing, enforcement thresholds (e.g., whether ‘user data’ includes pseudonymized telemetry), and alignment with the upcoming EU AI Act remain open questions.

This development underscores how evolving cybersecurity governance is reshaping hardware-centric supply chains—not only in terms of compliance cost, but in architectural decision-making around data flow, firmware lifecycle, and partner selection. For affected vendors, the priority is not wholesale market exit or delay, but structured, evidence-based readiness planning grounded in the draft’s explicit technical and geographic requirements.
Main source: European Commission, Public Consultation on the Revision of the Cybersecurity Act (Ref. ARES(2026)2894112), published 27 April 2026.
Areas requiring ongoing observation: Final adoption date; inclusion of transitional periods; clarification of ‘user data’ scope under Article 4; alignment with GDPR derogations for processing in automated systems.
Recommended News
Join 50,000+ industry leaders who receive our proprietary market analysis and policy outlooks before they hit the public library.