Escrow agent and compliance: compliance with laws and regulations

How does an escrow agent help with compliance? Read how escrow services contribute to GDPR, DORA, and other continuity requirements.

Compliance around digital resilience increasingly revolves around demonstrability. Supervisors and auditors no longer want to hear only that an organisation is prepared for the failure of a critical supplier; they want to see how that preparation is structured. An escrow arrangement delivers exactly that: a contractually defined safeguard, executed by an independent party, that can be produced on request. This article explains how an escrow agent contributes to compliance with the GDPR, DORA, and NIS2, and which concrete pieces of evidence it provides.

GDPR: access to data during incidents

The General Data Protection Regulation requires organisations to safeguard the availability and resilience of processing systems. Any organisation that has personal data processed by an application from an external supplier must be able to demonstrate that access to that data is preserved even if the supplier runs into trouble.

An escrow arrangement makes that demonstrability concrete. The escrow agreement records that source code, documentation, and where relevant data models have been deposited, and under which conditions the organisation gains access to them. The registration and verification reports of the escrow agent additionally demonstrate that the deposit is current and usable. For an auditor, that is considerably stronger evidence than an internal memo stating that the organisation trusts the supplier to remain in business.

DORA: an exit strategy for critical ICT third parties

The Digital Operational Resilience Act obliges financial entities to maintain an exit strategy for critical or important ICT service providers: a documented plan for the event that the relationship with that provider ends, whatever the reason. DORA also requires contracts with critical providers to contain specific provisions on continuity and access to data.

An escrow arrangement is one of the few instruments that makes an exit strategy technically executable. The agreement defines release conditions that correspond to exit scenarios, such as bankruptcy or discontinuation of the service, and the escrow agent manages the material needed in such an exit. The periodic deposit registrations and verification reports from the escrow agent can serve directly as evidence within the operational resilience framework that DORA prescribes.

NIS2: continuity of critical software

NIS2 requires essential and important entities to take measures for the continuity of their operations, including the security of the supply chain. Any organisation dependent on critical third-party software must demonstrate how the availability of that software is safeguarded if the supplier fails.

Here too, the escrow agent provides concrete evidence. The escrow agreement shows which continuity measures have been contractually agreed, the deposit registrations show that the deposit is being maintained, and the verification reports show that the material to be released is actually usable. Together, these documents form a defensible file towards the supervisor.

What an escrow agent concretely delivers

In practice, escrow arrangements produce three categories of evidence for audits and supervision: the escrow agreement itself, recording the parties, the material, and the release conditions; the registration of each deposit, including date and scope; and the periodic verification and status reports of the escrow agent. Precisely because these documents are drawn up by an independent third party, they carry more weight than internal statements.

Frequently asked questions

Is an escrow arrangement legally required under GDPR, DORA, or NIS2? No, none of these regulations explicitly prescribes escrow. They do, however, require demonstrable continuity and exit measures, and an escrow arrangement is one of the most direct ways to meet that requirement.

Which documents from the escrow agent can I show an auditor? The escrow agreement, the deposit registrations, and the verification or status reports. These are drawn up by the escrow agent as a neutral party.

Does this also apply if my supplier is a large, stable party? Yes. The obligations under DORA and NIS2 apply regardless of the size of the supplier. Continuity can be at risk even with large suppliers, for example through product discontinuation or a takeover.