Cyprus Cap 113 + NIS2: The CEO-Director Personal Liability Framework
For the CEO-director of a Cyprus-registered tech, AI, or fintech company, personal liability for compliance failures sits on two foundations: Cap 113 sections 311, 197, and 43, plus NIS2 Art. 20(1) (management-body duty) and Art. 32(5)(b) (suspension power), as transposed into Cyprus law. Section 197 bars contracting the duty away.
In brief: Cyprus Companies Law Cap 113 section 311 lets the company sue a director personally for breach of duty of care. Section 197 voids exemption clauses. Section 43 attaches personal liability for untrue prospectus statements. NIS2 Art. 20(1) places cybersecurity risk-management oversight on the management body and Art. 32(5)(b) gives competent authorities the power to request court-ordered suspension of a named natural person — both routed through Cyprus's national transposition (Law 60(I)/2025). No named Cap 113 compliance case is publicly documented; the framework is live.
The pain: a Cyprus-registered CEO wears two hats
DailyMind LTD, the publisher of Compliance Glossary, is one example (HE 439959). A CEO-director of a Cyprus-incorporated company operates under a statutory framework that pre-dates the EU regulatory wave by decades — with EU directives layered on top.
AGP Law, in its Cap 113 analysis, states the s.311 route plainly:
"it is for the company or its liquidator and not for individual shareholders to sue the director in breach under section 311 of the Companies Act, Cap. 113." AGP Law — Liabilities of Directors under Cyprus Law (verbatim)
Section 311 is captioned "Responsibility for fraudulent trading" in the statute; AGP Law and Cyprus practitioners cite it as the procedural vehicle for derivative claims against directors for breach of duty — the company (not individual shareholders) is the proper plaintiff. On contracting the duty away, section 197 Cap 113 permits directors' liability insurance but voids any contract or articles-of-association clause that "attempts to exempt a director or indemnify a director who has been in breach of his duty of care and skill" (AGP Law, verbatim).
Three sections matter for a CEO-director who is also an EU regulatory addressee:
- Section 311. Company-led civil action. A board that has changed hands — after an acquisition or a bankruptcy administrator stepping in — can sue the outgoing CEO for breach of duty of care. Standard: common-law negligence plus statutory provisions.
- Section 197. Exemption and indemnity clauses are void. No articles of association, employment contract, or service agreement can contract this away.
- Section 43. Personal civil liability for untrue statements in a prospectus — an investor-facing duty attaching to the director who signed off.
On the EU layer, NIS2 Art. 20(1) places cybersecurity risk-management oversight on management bodies of essential and important entities, and Art. 32(5)(b) gives competent authorities of essential entities the power to request court-ordered suspension of a named natural person from exercising managerial functions. Personal-liability rules attach through national transposition — Cyprus transposed NIS2 via Law 60(I)/2025, amending Law 89(I)/2020. The national framework for a Cyprus-registered essential entity is Cap 113 plus the transposition.
What this costs the CEO personally
Statutory overlays on top of Cap 113 — each with its own liability standard:
- VAT Law — strict liability. AGP Law, verbatim: "Strict liability is imposed on directors in circumstances where it is proved that the directors have violated the provisions of VAT legislation." Intent not required.
- Stock Exchange Law ss.68-69 — intent-based criminal. Per AGP Law, directors who have "consented or collaborated in making false and misleading fraudulent statements are jointly or severally criminally liable."
- NIS2 Art. 20(1) (as transposed) — fault-based. The management-body oversight duty in Art. 20(1), routed through Cyprus's national transposition, can ground personal liability for the natural person responsible for a Cyprus-registered essential entity in case of breach of duties. Art. 32(5)(b) layers a court-ordered management-function-ban request power. Not strict liability.
AGP Law notes, verbatim, that "claims against directors for negligence are rare." The tail risk sits in the statutory overlays above — none of which can be waived under section 197.
The board meeting question
The 2026 diligence question for a Cyprus CEO is "what evidence of active director engagement with EU compliance obligations do you hold?" The KPMG 2025 CEO Outlook (n=1,350) found 69 percent of CEOs cite the pace of regulation as a barrier to success. The EY Responsible AI Pulse (August 2025) found only 14 percent of CEOs strongly agree their organization has appropriate AI controls in place — against 29 percent for the rest of the C-suite. In a Series A, a D&O reinsurance questionnaire, or an M&A data room, "I believe we are compliant" is a position; a time-stamped approval log is a document.
How terminology governance helps
Honest note: Compliance Glossary is not a legal shield. Cap 113 liability and any NIS2-derived personal liability (routed through national transposition of Art. 20(1)) are established by the court or supervisor on the facts. The product provides a governance artifact — a time-stamped, four-eyes-approved, version-controlled record supporting a reasonable-care defense.
- Four-eyes approval. Terms move to approved only when a second named person signs off. The CEO-director's approval becomes a timestamped record.
- Version history. How the management body interpreted a key term on a past date — a record, not a recollection.
- Audit trail with timestamps. Dated, attributable entry on every write — the artifact a duty-of-care defense relies on.
- Compliance scanner. Regex flags where Confluence pages diverge from approved terms.
- CSV export with full version history (PDF audit-package export on the 2026 roadmap). On demand for supervisor requests, a NIS2 investigation, a s.311 defense, or an M&A data room.
The economics
For current pricing, see the Atlassian Marketplace.
Frequently asked questions
Can a Cyprus CEO-director be sued personally under Cap 113?
Yes. Under Cap 113 section 311, the company can bring a civil claim against a director for breach of duty of care. Section 197 voids clauses that attempt to contract the duty away. Named compliance-failure enforcement cases are not publicly documented, but the framework is in force and is reinforced by Cyprus's national transposition of NIS2 Art. 20(1) (management-body duty) for Cyprus-registered essential entities.
What does NIS2 add for Cyprus-registered companies?
NIS2 Art. 20(1) places cybersecurity risk-management oversight on management bodies of essential and important entities, and Art. 32(5)(b) gives competent authorities of essential entities the power to request that courts temporarily prohibit a named natural person from exercising managerial functions. Both are subject to Cyprus's national transposition. For a Cyprus-registered CEO-director of an essential entity in energy, digital infrastructure, banking, or another NIS2 sector, this layers EU-derived duty on top of the existing Cap 113 common-law and statutory duty. Important entities fall under Article 33's parallel but more limited regime.
Can the CEO-director contract out of Cap 113 liability?
No. Section 197 voids provisions that exempt or indemnify a director against liability for negligence, default, breach of duty, or breach of trust. Shareholders cannot waive it. D&O insurance remains available but does not change the statutory duty.
Does a documented governance artifact reduce Cap 113 exposure?
It is not a legal shield. Cap 113 liability is established by the court on the facts. A time-stamped, version-controlled, four-eyes-approved record is, however, the kind of documentary evidence a director uses to show reasonable care. It is an artifact in a duty-of-care defense, not a defense by itself.
Install before your next Cyprus board meeting
For current pricing, see the Atlassian Marketplace.
Evaluate in Confluence Read the Security WhitepaperRelated reading
- Compliance for Confluence — approved terms, page scanning, and audit evidence for CEO-level compliance oversight in Confluence
- NIS2 Article 32: when a court can suspend the CEO — the EU-layer sibling to Cap 113 personal liability
- NIS2 Article 20: the CEO training duty that cannot be delegated — the other NIS2 personal obligation on management
- NIS2 Article 20: the CFO-angle on personal liability — cross-persona read for finance team
- SOX 302 and 906: CEO certification liability for US-listed companies — the US-listing sibling for Cyprus companies with a US listing path
- Security Whitepaper — Forge architecture, data residency, and vendor-assessment evidence