IT and regulation
Which rules apply to the digital side of your building?
Fibre in new builds, mandatory building automation, stricter cybersecurity requirements. Regulation around digital infrastructure in real estate is growing fast. Here is what is happening, and what it means for your building.
From "nice to have" to "required"
For a long time, the digital infrastructure of a building was something the owner and tenant arranged between themselves. That is changing. The EU and national governments increasingly set requirements: for fibre in buildings, for smart building systems, for network security and for who may access the data from smart devices.
For owners, that means new obligations when building and renovating. For tenants, it means stricter requirements for the building they work in. And for investors, it is one of the risks you want to know about in advance.
This overview focuses on EU rules and on the Netherlands, where we are based. Rules may differ in other countries.
The rules at a glance
The most important rules for the digital infrastructure of commercial buildings. Correct as of 30 September 2026.
| Rule | What it involves | Who and from when | What it means for your building |
|---|---|---|---|
| Gigabit Infrastructure Act EU regulation | New buildings and major renovations must be fibre-ready: in-building infrastructure and cabling up to the connection point. Buildings that meet this can receive a "fibre-ready" label. | Has applied since 12 November 2025. The building requirement applies to permits applied for after 12 February 2026. | Include fibre and cabling in the design from the start. Adding them later costs much more. |
| Building automation (GACS) EU EPBD, in Dutch building regulations | A building automation and control system that continuously monitors installations and analyses energy use. | In the Netherlands: non-residential buildings with heating or cooling of 290 kW or more, since 1 January 2026. From 2030 the threshold is 70 kW. | The system runs on the network. It must be properly connected, integrated and secured. |
| Dutch Cybersecurity Act Dutch implementation of NIS2 | Duty of care, reporting obligation (report incidents within 24 hours) and registration obligation for organisations providing essential or important services. | In force since 15 August 2026. Applies to around 8,000 organisations in the Netherlands. | Tenants who fall under it will set requirements for the network and building systems. For example, separate networks and access management. |
| Data Act EU regulation | Users of connected products may request the data those products collect, and have it shared with others. | Has applied since 12 September 2025. | Agree who may access the data from sensors and building systems: the owner, the tenant or the supplier. That belongs in the IT Demarcation List. |
| Cyber Resilience Act EU regulation | Security requirements for products with digital elements, such as smart devices and sensors. Manufacturers must report vulnerabilities and provide updates. | Reporting obligation for manufacturers since 11 September 2026. The full requirements apply to products placed on the market from 11 December 2027. | When buying new IoT devices, check for updates and support. Older devices deserve extra attention. |
| GDPR Privacy law | Rules for processing personal data: a clear purpose, keeping data no longer than necessary, good security and informing people. | Already in force. | Cameras, access control, visitor registration and sometimes occupancy sensors process personal data. Set them up accordingly. |
| Energy label for offices Dutch building regulations | Offices in the Netherlands must have at least energy label C. | Since 1 January 2023. | Smart building systems help with sustainability. Read more on IT and sustainability. |
This overview is general and not legal advice. Rules and dates may change. Always check the official sources at the bottom of this page for your situation.
What does this mean for you?
As an owner
New requirements apply to new builds and renovations, such as fibre-ready infrastructure and building automation. Including them from the design stage avoids costly changes later. And a building that demonstrably complies is more attractive to tenants who have to meet strict rules themselves.
As a tenant
Do you fall under NIS2 legislation? Then you are responsible for the security of your network, even if part of it sits in someone else's building. So know in advance what is in place, who manages what and how it is protected. The IT-Label and the IT Demarcation List help with that.
As an investor
Regulation increasingly determines the future value of a building. A building that does not meet building automation requirements, or whose systems are set up insecurely, means extra costs. You map that with digital due diligence.
We keep track
Our experts closely follow developments in legislation and regulation around digital infrastructure in real estate, at EU and Dutch level.
New rules, new effective dates, new guidance from regulators: things move quickly. We keep track, so you do not have to. And we translate it into practice: what does this rule mean for this building, and what needs to happen?
- During a pre-inspection we include the rules that apply to your building in our advice. For example, whether your building falls under the building automation requirement, and whether the building systems are set up securely.
- During digital due diligence we map where a building does not comply, and what it costs to fix that.
- For new builds and renovations we help you think through what needs to be arranged now, so you do not have to break things open later.
The IT-Label audit itself follows the fixed IT-Label methodology. We apply our knowledge of the rules in the advice we give around it.
Questions
Does my building need to be fibre-ready?
For new builds and major renovations with a building permit applied for after 12 February 2026: yes, under the EU Gigabit Infrastructure Act. Existing buildings without a renovation are not subject to this obligation, but tenants increasingly expect it.
Does my building need a building automation system?
In the Netherlands, since 1 January 2026 this applies to non-residential buildings with a heating or cooling system of 290 kW or more. From 2030 the threshold drops to 70 kW. Not sure whether it applies to your building? We are happy to check it with you.
Does the Dutch Cybersecurity Act apply to property owners?
The Act applies to organisations that provide essential or important services. Whether you fall under it depends on your sector and size. Even if you do not, tenants who do may set requirements for the network and building systems.
Is this legal advice?
No. This page gives a general overview. For a legal assessment of your situation we recommend consulting a lawyer. We help with the technical side: what is in your building and what is needed.
Official sources
- Gigabit Infrastructure Act, summary (EUR-Lex)
- Building automation and control system (GACS) (RVO, in Dutch)
- Dutch Cybersecurity Act (NIS2) (NCSC, in Dutch)
- Data Act (European Commission)
- Cyber Resilience Act (European Commission)
- GDPR (Dutch Data Protection Authority)
Last checked: 30 September 2026.
Does your building meet today's rules?
During a pre-inspection we look at what is in place and which rules apply to your building.