At five this afternoon the consultation window closed on a draft Royal Decree that attaches conditions to the grid access permits of Spanish data centres. It has been on the urgent track since 25 August and the public consultation lasted two weeks, extension included. The title of the decree lists four subjects: energy sustainability, environmental sustainability, resilience and digital sovereignty. We went looking for the third one. It is in the heading of article 5. Read in full, that article creates not a single resilience requirement.
We read the draft on 30 August and already wrote about it — about the electrical side, which was what filled every wire story: the number that decides is not the 80 % renewable, it is a PUE of 1.15. We have filed no submissions and we are not going to pretend otherwise. A two-week public consultation, in August, on a text that can knock over a grid access permit, is one a lot of people miss. What we bring today is what we did not look at that day: the article carrying the word "resilience" in its heading.
First thing, and it works against the easy headline: this does not bind you
Article 2 sets the scope and it is a short read. The obligations apply to data centres with a grid access capacity of 1 MW or more, and to groups of centres on the same site and under the same ownership that reach that figure in aggregate. There is one exception going downwards: article 14, the reporting one, reaches anybody with 500 kW or more of information technology power, regardless of their grid access capacity. And centres used exclusively for defence, civil protection and public security are left out.
Translated into what we have in front of us every week: 1 MW of grid access capacity is a building. The cabinet in the plant room does not get there, the half dozen servers in the office do not either, and a small room with its own UPS and dedicated cooling does not either. If somebody tells you "there is new regulation for your servers", they are selling you something. This regulates whoever builds and operates data centres, not whoever has infrastructure inside one.
It is the same reading we did with the AI Act and what actually applies to you: the first question in front of a legal text is whom it binds.
The word that is in the title and not in the articles
Article 5 is titled "Resilience and digital sovereignty requirements". Its paragraph 2 lists the requirements in six lettered points, from a) to f), and all six are sovereignty: being established in the European Union; keeping the data, metadata and logs of the centre's operation inside the EU; controlling and tracing support or maintenance access performed from third countries; identifying and contractually supervising direct subcontractors; adopting measures against data access requests from third-country authorities that are contrary to Union or national law and not covered by an international agreement in force; and any additional voluntary commitment. Resilience, none.
Paragraph 4 says it plainly: resilience and cybersecurity requirements "shall be governed by the regulation applicable to each entity", and it closes by stating that entities within the scope of the NIS2 transposition remain under that regulation's supervision "without this article establishing any additional or parallel assessment on the same subjects".
Before going on, the objection that can be made to the above, because it exists and it is inside the text itself: article 4.1.a) calls that declaration one "relating to the resilience and digital sovereignty requirements", and the fifth transitional provision is headed "Application of the resilience and digital sovereignty requirements". Two more places where the word appears with nothing behind it. Paragraph 8 confirms rather than contradicts this: additional measures for critical or essential systems "must be provided for in that regulation or imposed by a decision of the competent sectoral authority". Always another norm. The closest thing to a resilience objective in the articles is the end of point c), and it is about access from third countries: that it must not "compromise its operational autonomy".
We are going to say something you would not expect from a post with this headline: we think it is right. Duplicating NIS2 inside a grid access decree would have created two authorities asking the same questions on different forms, which is exactly the kind of compliance that protects nothing. Paragraph 4 avoids that.
Resilience does come back once with legal effect, and it is worth looking at where: in the first final provision, which adds a paragraph to Royal Decree 1183/2020 so that the criteria of demand capacity tenders involving data centres include, "where applicable", resilience and digital sovereignty criteria. Two words, "where applicable", that make it discretionary. Which is to say: resilience enters the text as a criterion for allocating megawatts between projects, not as a guarantee anybody owes a customer.
The consequence is the one we have been repeating for years and that now has an official document behind it: nobody is going to hand you availability by decree. Not this one, not the next one. The failure of the power feed, the disk or the person is inevitable; the size of the outage is decided by you beforehand, when you choose architecture, contract and procedure. We wrote it three days ago with a case where the redundant pair was undone by a procedure, not by a fault, and it holds here too: resilience comes out of decisions you sign.
The centre's sovereignty is not your data's sovereignty
That the sovereignty label covers the building and not your workload is something we already argued on 30 August, quoting point b) of paragraph 2 — "without extending to its customers' systems, data or services over which it has neither access nor control" — and we are not going to run it again in full: it is in that post. What is worth adding is where that limitation comes from, because it is not our reading: paragraph 2 opens by fencing itself, "shall be limited to the elements under the direct or contractual control of the obliged party", and that sentence governs all six points.
Of the six points, the one that interests us most professionally is c): controlling and keeping traceability of access and support or maintenance operations carried out from third countries. That is the good old privileged management plane — who can get into the infrastructure, from where, and what gets logged — which is the same problem we already described from the inside when writing about the console that manages your machines. If the draft survives with that point intact, it will have achieved something sensible: making somebody write down on paper who holds the key and from which country they use it.
The clause that will reach you, and it will reach you by contract
Paragraph 3 of article 5 is the one to read twice. It forbids in-scope data centres from hosting National Security Framework (ENS) information systems that process data under public sector control, or linked to national security or defence, unless everything is processed, stored and transferred exclusively within the European Union. And that "everything" is spelled out: the data, the metadata, the telemetry, the logs, the replicas and the backups.
A legal text naming replicas and backups explicitly is unusual, and it is good news, because that is exactly where things break. Almost everybody knows where the primary data lives. Considerably fewer people know where the third copy ends up, in which region of whichever provider, and under which contract. We ask that in every review, and the answer takes, on average, longer than people expect.
The part that reaches you is in the next paragraph. Obliged parties "shall incorporate into their contracts the obligation to identify, before hosting, the systems and data subject to this paragraph, and to pass the prohibition set out in it on to customers, suppliers and subcontractors". No ambiguity there: it is a contractual cascade. If the text comes out like this, a new clause will appear in the hosting contract of a lot of people who have not read this decree and do not plan to.
And then comes the allocation of blame, the sentence to underline if you host public administration work: non-compliance shall not be attributable to the obliged party where it stems from information that a customer, supplier or subcontractor omitted or supplied inaccurately and could not have been detected with due diligence, and provided it can show it put the clause in its contracts and stopped the breach as soon as it knew. Read it backwards, which is how it will reach you: if you do not declare that system as ENS, the problem is yours.
The numbers that may end up in the price of your rack
We wrote up the electrical side in full on 30 August — the 1.15 PUE, the 0.1 WUE and the article 10 surcharge scale — so here we keep only what you need to see where the bill arrives from: article 4 makes the granting of grid access and connection permits conditional on demonstrating sovereignty, efficiency and renewables; article 10 can multiply the regulated part of the electricity bill sixfold; and article 11 allows things to end in the loss of the grid access and connection permits. The lever is the plug.
Our reading, and we flag it as a reading: those surcharges are not paid by the operator out of goodwill, they end up in the price of the kilowatt it passes on to you and therefore in the price of the rack. There is another detail that caught our eye more than the percentages: the second additional provision opens a six-month window to withdraw applications or permits not yet connected without the deposited guarantees being called in, while the third transitional provision gives projects holding a permit but not connected six months to demonstrate compliance, failing which the permits lapse with the guarantees called in. That is an orderly exit for projects that are not going to make it. How much announced capacity will leave through that door we do not know, and we are not going to invent a number.
One point in the text's favour, because it is not all burden: article 5.1 lets the operator include voluntary strategic digital sovereignty commitments, including reserving storage or compute capacity for Spanish or EU companies, with the percentage and the term. And those commitments count as a criterion in the capacity tenders. It is the only place in the draft where we found somebody winning megawatts by committing to keep room for you.
And with all this, it is not in force yet
Worth saying out loud, because it is the part the news coverage drops. It is a draft: the date of the Cabinet meeting that would approve it is written in the text as "XXX". The fifth final provision says it will enter into force twenty days after publication in the Official Gazette, and it has not been published. The third additional provision allows the renewable share, the PUE and WUE values and the coverage percentages to be changed by resolution. And there is one more layer of waiting: the fifth transitional provision defers the enforceability of article 5 except for two pieces: its paragraph 9 and the second subparagraph of its paragraph 1, which is precisely the declaration filed with the grid operator when applying for the permits and required by article 4. The rest waits for the ministerial order setting the template, and then there are six months to file. The bulk of digital sovereignty has no date; the prior declaration does.
So do not base any purchasing decision on this, and be wary of anybody who suggests you should. What you can do is prepare the questions, which do not expire even if the text changes.
Five things you can do without waiting for the Gazette
- Ask for the grid access capacity of the room you are in. Your provider knows that figure and you probably do not. It determines whether the whole decree applies to them or only the reporting part, and therefore what they will end up passing on to you.
- Ask for the PUE, and write the answer down. Today it is a commercial figure everybody frames as they please. Article 14 obliges those from 500 kW of IT power upwards to submit the Delegated Regulation (EU) 2024/1364 indicators before 15 May, and the Ministry to publish them on its portal. When that happens, you will have somewhere to check what you were told.
- If you touch the public sector, identify it yourself first. The draft says non-compliance is not attributable to the operator if the customer omitted the information. Make the list of which of your systems fall under the ENS before the form reaches you, not after.
- Find out where your third copy is. Not the first one, everybody knows that: the replica and the backup of the backup, with their region and their contract. The text names them explicitly, and it is the question that most often goes unanswered when we ask it.
- Do not mistake your provider's declaration for a guarantee about your service. Nothing in this decree speaks about your recovery time or your recovery point. Those two figures still come out of your design and your contract, and if you do not have them written down, you do not have them.
What we are not claiming
We are not lawyers and this is not legal advice: it is the reading of an operator that builds and maintains infrastructure, done on the PDF of the draft. We do not claim the final text will keep the 1 MW threshold, the surcharges or the PUE and WUE values, not least because the decree itself provides for changing them by resolution. We give no figure on how much this will push hosting prices up, because we do not have one. And we are not saying article 5 is wrong for not demanding resilience: we are saying that whoever reads the title and expects to find an availability guarantee there is in for a disappointment.
Do you know where your third copy is and who can walk into your room?
We run our own hardware in a data centre and have been doing colocation for years, so we ask ourselves these questions before we ask you. If you are left wondering what applies to you and what does not, the review is short: where each copy lives, who holds privileged access and from where, and what your contract says happens on the day of the outage. That is compliance and continuity with an operator's judgement, and if the conclusion is that you are fine where you are, we will tell you that too.
Talk to everyWANNote on sources
Everything this post asserts about the content of the regulation comes from two primary documents downloaded today, 10 September 2026, from the portal of the Spanish Ministry for the Ecological Transition and the Demographic Challenge, in the public consultation of the "Draft Royal Decree regulating the energy and environmental sustainability, resilience and digital sovereignty requirements applicable to data centres": the PDF of the draft decree and the resolution extending the deadline. Quotations from the norm are reproduced here in our translation; the original exists only in Spanish. From the draft come the scope in article 2 (1 MW of grid access capacity, aggregation by site and ownership, 500 kW of IT power for article 14, and the defence, civil protection and public security exclusions); the heading and the six lettered points of article 5.2, including its limitation to direct or contractual control and the express exclusion of customers' systems and data; article 5.3 with the National Security Framework prohibition, the enumeration of metadata, telemetry, logs, replicas and backups, the contractual cascade and the allocation of responsibility for omitted or inaccurate information; article 5.4 and its deferral to each entity's own regulation and to the NIS2 transposition; the voluntary strategic digital sovereignty commitments in article 5.1; article 6 and the fourth transitional provision (class "A", PUE 1.15, WUE 0.1 and serious non-compliance after two consecutive years); articles 7, 8 and 9 (renewable share, 80 % coverage, eighteen months since commissioning, hourly matching); article 10 with the 500, 400, 300 and 100 % surcharge scale and the 65 % with ten points per year; article 11 on loss of permits; article 14 on information publicity and the 15 May date; the second additional provision on withdrawal without calling in guarantees; the third additional provision on threshold changes; the third and fifth transitional provisions; and the first and fifth final provisions, including the "where applicable" of the paragraph added to Royal Decree 1183/2020. From the extension resolution come the dates: Cabinet agreement of 25 August 2026 authorising the urgent procedure, publication of the notice on 27 August, initial deadline of 4 September and extension to 10 September 2026 at 17:00. The following is OUR reading, not the document's: that the absence of resilience requirements of its own is sound legislative technique; that the surcharges end up passed through into hosting prices; that the withdrawal window is an orderly exit for projects that will not make it; and the five recommendations in the checklist. We give no market, price or capacity figures, and we assert nothing about the content of the final text, which does not exist yet. That everyWAN runs its own hardware in a data centre and provides colocation is our own information. The cover photograph is "Systems testing in the service switchgear room of a power substation located in Queens", by MTA Capital Construction Mega Projects, published on Wikimedia Commons under a Creative Commons BY 2.0 licence and cropped for this use.