opinion parliamentary committee, 30 January 2023
On the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union
Document AFCO-AD-730186 · (COM(2022)0119 – C90121/2022 – 2022/0084(COD))
Committee on Constitutional Affairs · Rapporteur: Maite Pagazaurtundúa
AI:In short
The Committee on Constitutional Affairs gives its opinion on the proposed regulation on information security in the Union's institutions, bodies, offices and agencies. It proposes 52 amendments to the Commission proposal. The amendments add common minimum standards, an interinstitutional approach to sharing EUCI and sensitive non-classified information, and a Coordination Group that can adopt recommendations and monitor compliance. They require institutions to safeguard the integrity of EU democratic processes, vet contractors and terminate relationships that pose a risk to democratic processes. They set deadlines of one week for reporting breaches, require EUCI documents to go to the Historical Archives after 30 years, and require SNC information to be stored and processed exclusively in the Union.
Position. The Committee on Constitutional Affairs welcomes the proposal and proposes 52 amendments to strengthen common minimum standards, interinstitutional cooperation, monitoring by the Coordination Group, and protection against foreign interference.
Key points
- The committee calls on the Committee on Civil Liberties, Justice and Home Affairs, as committee responsible, to take into account its amendments.
- The amendments require an interinstitutional approach to sharing EUCI and sensitive non-classified information, with common categories and key handling principles, and simplified procedures.
- They state it is high time that effective rules ensuring a common level of information security in all Union institutions and bodies be laid down, with common minimum standards.
- They delete the recital excluding Euratom Classified Information from the regulation's scope.
- They require the Coordination Group to adopt recommendations and provisions to enhance policy coherence, set up subgroups, and take account of training for personnel.
- They require institutions to safeguard the integrity of EU democratic processes and adopt provisions in tender procedures to curb foreign interference, covering security infrastructure, vetting and staff clearance.
- They require the Coordination Group to monitor compliance through a yearly evaluation report and carry out risk assessments on foreign interference in EUCI.
- They require institutions to mark information 'PUBLIC USE', establish streamlined incident reporting procedures, and store and process SNC information exclusively in the Union.
- They set a consultation procedure between Parliament and the Commission when there is doubt about the confidential nature of information or its classification level.
- They require holders of EUCI to be legally responsible for its protection, including under the Treaties, relevant criminal law and the Staff Regulations.
- They require notification of breaches to the originator and competent authorities no later than one week after the Security Authority is informed.
- They require EUCI documents to be transferred to the Historical Archives after 30 years, with effective measures to protect them from unauthorised access prior to declassification.
Who is affected
- Union institutions and bodies: must apply common minimum information security rules and safeguard EU democratic processes.
- Contractors and third parties: subject to vetting in tender procedures and possible termination of relationships posing risks.
- National Security Authorities of member states: benefit from a common glossary and procedures in personnel security.
- European Parliament and Commission: must consult each other on classification doubts before transmitting documents.
Figures and deadlines
Written by AI from the full text · every figure comes from the text · ¶ opens the paragraph · 25 Sept 2026 · Report a problem
Full text
Jump to an amendment (52)
- Amendment 1
- Amendment 2
- Amendment 3
- Amendment 4
- Amendment 5
- Amendment 6
- Amendment 7
- Amendment 8
- Amendment 9
- Amendment 10
- Amendment 11
- Amendment 12
- Amendment 13
- Amendment 14
- Amendment 15
- Amendment 16
- Amendment 17
- Amendment 18
- Amendment 19
- Amendment 20
- Amendment 21
- Amendment 22
- Amendment 23
- Amendment 24
- Amendment 25
- Amendment 26
- Amendment 27
- Amendment 28
- Amendment 29
- Amendment 30
- Amendment 31
- Amendment 32
- Amendment 33
- Amendment 34
- Amendment 35
- Amendment 36
- Amendment 37
- Amendment 38
- Amendment 39
- Amendment 40
- Amendment 41
- Amendment 42
- Amendment 43
- Amendment 44
- Amendment 45
- Amendment 46
- Amendment 47
- Amendment 48
- Amendment 49
- Amendment 50
- Amendment 51
- Amendment 52
Short justification 215 paragraphs
Union institutions and bodies need to share between themselves ever-increasing amounts of sensitive non-classified and European Union classified information (‘EUCI’) in a landscape of dramatically increasing threat levels. As a result, the European administration is exposed to attack in all its areas of activity. The information handled by the Union institutions and bodies is very attractive for the threat actors and needs to be swiftly and appropriately protected. Currently, the Union institutions and bodies either have their own information security rules, based on their Rules of procedure or founding act, or they do not have information security rules at all.
The rapporteur thus welcomes this proposal, which is part of the EU Security Union Strategy adopted by the Commission on 24 July 2020 and which is aimed at streamlining the internal legal frameworks for information security in all Union institutions and bodies so as to protect our societies from the ever evolving threats targeting the information handled by institutions and bodies.
An efficient and independent administration relies on the security of its information. With a view to achieving their mission, the Union institutions and bodies shall benefit from a secure environment for the information they handle and store on a daily basis. In addition, providing a common baseline of standards mandatory for all would guarantee a high level of security, reduce the risk of weak links in supporting interoperability among institutions and bodies and leverage synergies thus enhancing the administration’s resilience facing evolving threats.
AMENDMENTS
The Committee on Constitutional Affairs calls on the Committee on Civil Liberties, Justice and Home Affairs as the committee responsible, to take into account the following amendments:
Amendment 1
Proposal for a regulation
Recital 2
| Text proposed by the Commission | Amendment |
|---|---|
| (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. | (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. An interinstitutional approach to the sharing of EUCI and sensitive non-classified information should be set up, with common categories of information and common key handling principles. Procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States should be simplified. |
Amendment 2
Proposal for a regulation
Recital 3
Read the rest (203 paragraphs)
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. | (3) Therefore, it is high time that effective rules ensuring a common level of information security in all Union institutions and bodies be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and common minimum standards. |
Amendment 3
Proposal for a regulation
Recital 4
| Text proposed by the Commission | Amendment |
|---|---|
| (4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. | (4) Many procedures that were still at least partly paper-based were in recent years adjusted to enable electronic processing and exchanges of information. These developments require changes in the production, handling and protection of information. This Regulation takes account of the new working practices. |
Amendment 4
Proposal for a regulation
Recital 5
| Text proposed by the Commission | Amendment |
|---|---|
| (5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy. | (5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient, independent and resilient administration in carrying out their missions. This Regulation shall under no circumstances prevent Union institutions and bodies from fulfilling their mission, as entrusted by the EU legislation, or disproportionately limit their institutional autonomy. |
Amendment 5
Proposal for a regulation
Recital 7
| Text proposed by the Commission | Amendment |
|---|---|
| (7) In order to preserve the specific nature of the European Atomic Energy Community activities regulated by Regulation 3/1958 of the Council of the European Atomic Energy Community25 , this Regulation should not apply to Euratom Classified Information. However, all information related to other Euratom activities not covered by Regulation 3/1958 should fall within the scope of this Regulation. | deleted |
| 25 EAEC Council: Regulation No 3 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406). |
Amendment 6
Proposal for a regulation
Recital 8
| Text proposed by the Commission | Amendment |
|---|---|
| (8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. | (8) With a view to establishing a formal common structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. The Coordination Group should adopt recommendations and provisions to enhance the coherence of policies in the field of information security and contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. |
Amendment 7
Proposal for a regulation
Recital 9
| Text proposed by the Commission | Amendment |
|---|---|
| (9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks. | (9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, the Coordination Group should be able to set up subgroups with specific tasks. While carrying out its tasks, the Coordination Group should also take into account the training component for the Union institutions' and bodies' personnel, with the aim of enhancing information security awareness and best practices, complementary to the established procedures. |
Amendment 8
Proposal for a regulation
Recital 10
| Text proposed by the Commission | Amendment |
|---|---|
| (10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. | (10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. Given the constantly evolving threat landscape at Union level, close cooperation with that committee is required in order to adapt prevention and mitigation methods for information security. |
Amendment 9
Proposal for a regulation
Recital 12
| Text proposed by the Commission | Amendment |
|---|---|
| (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each institution and body. | (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the common minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the needs and specificities of each institution and body. |
Amendment 10
Proposal for a regulation
Recital 13
| Text proposed by the Commission | Amendment |
|---|---|
| (13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes or in the exchange of information with their particular counterparts from other institutions and bodies or from the Member States. | (13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes. |
Amendment 11
Proposal for a regulation
Recital 14
| Text proposed by the Commission | Amendment |
|---|---|
| (14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures. | (14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by effective security measures. |
Amendment 12
Proposal for a regulation
Recital 15
| Text proposed by the Commission | Amendment |
|---|---|
| (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. | (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Such provisions should include, inter alia, a requirement in the tender procedures to undergo thorough vetting, taking into account the full range of the supply chain and economic and political environment in which the third parties operate. Where the relationships with third parties pose a risk to the integrity of democratic processes in the EU, they should be terminated without undue delay. |
Amendment 13
Proposal for a regulation
Recital 16
| Text proposed by the Commission | Amendment |
|---|---|
| (16) The substantive rules regarding access to EUCI in the internal rules of various Union institutions and bodies are currently aligned, but there are significant differences as regards denominations and required procedures. This creates a burden for the National Security Authorities of the Member States who need to adjust to different requirements. Thus it is necessary to provide for a common glossary and common procedures in the area of personnel security, thereby simplifying cooperation with the National Security Authorities of the Member States and limiting the risk of compromising EUCI. | (16) The substantive rules regarding access to EUCI in the internal rules of various Union institutions and bodies are currently aligned, but there are significant differences as regards denominations and required procedures. This creates a burden for the National Security Authorities of the Member States who need to adjust to different requirements. Thus it is necessary to provide for a common glossary and common procedures in the area of personnel security, thereby simplifying cooperation with the National Security Authorities of the Member States and limiting the risk of compromising EUCI, while respecting the Rules of Procedure of each institution and body. |
Amendment 14
Proposal for a regulation
Recital 18
| Text proposed by the Commission | Amendment |
|---|---|
| (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. | (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. Those security measures should, among others, build on a thorough evaluation of the relevant security infrastructure and services, taking into account the full range of the supply chain and economic and political environment in which their suppliers operate. |
Amendment 15
Proposal for a regulation
Recital 22
| Text proposed by the Commission | Amendment |
|---|---|
| (22) With the objective of achieving a single standard of accreditation of CISs handling and storing EUCI, the Union institutions and bodies should work together in a group set up for that purpose. It is recommended that all of them use that standard in order to contribute to a general level of EUCI protection. However, as regards organisational autonomy, the decision remains with the competent authority of each institution or body. | (22) With the objective of achieving a single standard of accreditation of CISs handling and storing EUCI, the Union institutions and bodies should work together in a group set up for that purpose. It is imperative that all of them use that standard in order to contribute to a common minimum level of EUCI protection. |
Amendment 16
Proposal for a regulation
Article 1 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation lays down information security rules for all Union institutions and bodies. | This Regulation lays down common minimum information security rules for all Union institutions and bodies. |
Amendment 17
Proposal for a regulation
Article 2 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community, other than Euratom Classified Information. | 1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community. |
Amendment 18
Proposal for a regulation
Article 2 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. These levels are based on the damage that unauthorised disclosure may cause to the legitimate private and public interests, including those of the Union, Union institutions and bodies and Member States or other stakeholders, so that the appropriate protective measures can be applied. | 3. These levels are based on the damage that unauthorised disclosure may cause to the private and public interests of the Union, Union institutions and bodies or one or more of the Member States, so that the appropriate protective measures can be applied. |
Amendment 19
Proposal for a regulation
Article 4 – title
| Text proposed by the Commission | Amendment |
|---|---|
| General principles | General principles and provisions |
Amendment 20
Proposal for a regulation
Article 4 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process. | 1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation, taking account of the coherence and interoperability of its document security framework with that of other relevant Union institutions and bodies. |
Amendment 21
Proposal for a regulation
Article 4 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Non-compliance with this Regulation, in particular the unauthorised disclosure of information with the confidentiality levels referred to in Article 2(2), except information for public use shall be subject to investigation and may trigger personnel liability in accordance with the Treaties or with their relevant staff rules. | 2. Non-compliance with this Regulation, in particular the unauthorised disclosure of information with the confidentiality levels referred to in Article 2(2), except information for public use shall be subject to investigation and may trigger personnel liability in accordance with the Treaties, with relevant criminal law and with their relevant staff rules. |
Amendment 22
Proposal for a regulation
Article 4 – paragraph 4 – point d
| Text proposed by the Commission | Amendment |
|---|---|
| (d) integrity: the fact that the information is complete and completeness of information is unaltered; | (d) integrity: the fact that the information is complete and completeness of information is unaltered and the fact that the technical infrastructure used to share information is protected from any foreign interference; |
Amendment 23
Proposal for a regulation
Article 4 – paragraph 6 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 6a. When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of EU democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions shall at least address the acquisition and maintenance of security infrastructure, the vetting of third party organisations and the clearance of staff. |
Amendment 24
Proposal for a regulation
Article 6 – paragraph 1 – subparagraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| It shall be composed of all Security Authorities of the Union institutions and bodies, and shall have a mandate to define their common policy in the field of information security. | It shall be composed of all Security Authorities of the Union institutions and bodies, and shall have a mandate to define common measures in the field of information security. |
Amendment 25
Proposal for a regulation
Article 6 – paragraph 2 – point c
| Text proposed by the Commission | Amendment |
|---|---|
| (c) establish guidance documents on the implementation of this Regulation, in cooperation with the Interinstitutional Cybersecurity Board referred to in Article 9 of the Regulation EU [...] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, where appropriate; | (c) establish recommendations and guidance documents on the implementation of this Regulation, in cooperation with the Interinstitutional Cybersecurity Board referred to in Article 9 of the Regulation EU [...] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, where appropriate; |
Amendment 26
Proposal for a regulation
Article 6 – paragraph 2 – point d
| Text proposed by the Commission | Amendment |
|---|---|
| (d) set up dedicated platforms for sharing best practices and knowledge on common topics relevant to information security as well as for providing assistance in case of information security incidents; | (d) set up dedicated platforms for sharing best practices, training and knowledge on common topics relevant to information security as well as for providing assistance in case of information security incidents; |
Amendment 27
Proposal for a regulation
Article 6 – paragraph 2 – point e a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) monitor compliance by Union institutions and bodies with this Regulation as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report, which shall compile input from the relevant sub-groups. |
Amendment 28
Proposal for a regulation
Article 6 – paragraph 2 – point e b (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (eb) carry out risk assessments, in particular with regard to foreign interference in EUCI. |
Amendment 29
Proposal for a regulation
Article 6 – paragraph 6 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 6a. The appointed members of the Coordination Group shall be adequately gender and geographically balanced. |
Amendment 30
Proposal for a regulation
Article 6 – paragraph 7
| Text proposed by the Commission | Amendment |
|---|---|
| 7. Union institutions and bodies shall bring to the attention of the Coordination Group any significant information security policy development within their organisation. | 7. Union institutions and bodies shall bring to the attention of the Coordination Group any significant information security policy development within their organisation within a reasonable timeframe. |
Amendment 31
Proposal for a regulation
Article 8 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and, where applicable, by its internal security rules. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks. | 1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and monitor and ensure compliance by that institution or body with the guidance documents adopted by the Coordination Group. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks. |
Amendment 32
Proposal for a regulation
Article 12 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Union institutions and bodies may mark with ‘PUBLIC USE’ the information referred to in paragraph 1. | 2. Union institutions and bodies shall mark with ‘PUBLIC USE’ the information referred to in paragraph 1. |
Amendment 33
Proposal for a regulation
Article 15 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Union institutions and bodies shall establish procedures for the reporting and management of any incident or suspected incident that could lead to a compromise of the security of non-classified information. | 1. Union institutions and bodies shall establish streamlined procedures for the reporting and management of any incident or suspected incident that could lead to a compromise of the security of non-classified information. |
Amendment 34
Proposal for a regulation
Article 15 – paragraph 2
| Text proposed by the Commission | Oral Amendment |
|---|---|
| 2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. Exceptionally, other equivalent markings may be used internally and in relation with their particular counterparts from other Union institutions and bodies or from the Member States, when all parties agree. Such exception shall be notified to the sub-group on non-classified information, as referred to in Article 7(1), point (b). | 2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. Exceptionally, other equivalent markings may be used internally. Such exception shall be notified to the sub-group on non-classified information, as referred to in Article 7(1), point (b). |
Amendment 35
Proposal for a regulation
Article 16 – paragraph 1 – point e a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
Amendment 36
Proposal for a regulation
Article 17 – paragraph 1 – point c
| Text proposed by the Commission | Amendment |
|---|---|
| (c) SNC information shall be stored and processed in the Union; | (c) SNC information shall be stored and processed exclusively in the Union; |
Amendment 37
Proposal for a regulation
Article 18 – paragraph 2 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 2a. In the event of any doubt as to the confidential nature of an item of information or its appropriate level of classification, the European Parliament and the Commission shall consult each other without delay and before transmission of the document. In those consultations, the European Parliament shall be represented by the chair of the parliamentary body concerned, accompanied, where necessary, by the rapporteur, or the office-holder who submitted the request. The Commission shall be represented by the member of the Commission with responsibility for that area, after consultation of the member of the Commission responsible for security matters. In the event of a disagreement, the matter shall be referred to the Presidents of the two institutions so that they may resolve the dispute. |
Justification
This is in order to align these provisions with the interinstitutional procedure to contest classification laid down in Annex II point 2.3 of the Framework Agreement on relations between the European Parliament and the European Commission.
Amendment 38
Proposal for a regulation
Article 19 – paragraph 1 – point a
| Text proposed by the Commission | Amendment |
|---|---|
| (a) it establishes rules and procedures in accordance with this Regulation, ensuring the protection of information for a given classification level; and | (a) it establishes rules and procedures in accordance with this Regulation and the guidance documents adopted by the Coordination Group, ensuring the protection of information for a given classification level; and |
Amendment 39
Proposal for a regulation
Article 19 – paragraph 1 – point b
| Text proposed by the Commission | Amendment |
|---|---|
| (b) it has undergone an assessment visit in accordance with Article 53, and it has been subsequently certified that it can protect EUCI in accordance with this Regulation and where applicable, any other relevant rules and procedures. | (b) it has undergone an assessment visit in accordance with Article 53, and it has been subsequently certified that it can protect EUCI in accordance with this Regulation, the guidance documents adopted by the Coordination Group, and where applicable, any other relevant rules and procedures. |
Amendment 40
Proposal for a regulation
Article 20 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The holder of any item of EUCI shall be responsible for its protection. | 1. The holder of any item of EUCI shall be legally responsible for its protection. This shall include responsibility under the Treaties, relevant criminal law and the Staff Regulations. |
Amendment 41
Proposal for a regulation
Article 20 – paragraph 3 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| 3a. This Article is without prejudice to Regulation No 1049/2001 regarding public access to European Parliament, Council and Commission documents. |
Amendment 42
Proposal for a regulation
Article 21 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The security Authority of each Union institution and body shall approve the security measures for protecting EUCI throughout its life-cycle in accordance with the outcome of a risk assessment performed by the respective Union institution or body. | 1. The security Authority of each Union institution and body shall approve the security measures for protecting EUCI throughout its life-cycle in accordance with the outcome of a risk assessment performed by the respective Union institution or body. The risk assessment shall have a common criteria to ensure that all Union institutions and bodies have aligned security measures, while also considering the particularities relevant to each institution or body. |
Amendment 43
Proposal for a regulation
Article 22 – paragraph 3 – point a
| Text proposed by the Commission | Amendment |
|---|---|
| (a) inform the originator; | (a) inform the originator without undue delay, and in any case no later than one week after the Security Authority is informed of the breach; |
Amendment 44
Proposal for a regulation
Article 22 – paragraph 3 – point e
| Text proposed by the Commission | Amendment |
|---|---|
| (e) notify the competent authorities about the actual or potential compromise and the action taken. | (e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any case no later than one week after the Security Authority is informed of the breach. |
Amendment 45
Proposal for a regulation
Article 23 – paragraph 3
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. | 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall in any event ensure that the principles under paragraphs 1 and 2 be observed. |
Amendment 46
Proposal for a regulation
Article 28 – paragraph 1 – point d a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (da) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
Amendment 47
Proposal for a regulation
Article 30 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Union institutions and bodies shall record, file, preserve and eventually eliminate, sample or transfer their EUCI documents to the relevant archives in accordance with retention policy and rules specific to the files of each Union institution and body. | 1. Union institutions and bodies shall record, file, preserve and eventually eliminate, sample or transfer their EUCI documents to the relevant archives in accordance with retention policy and rules specific to the files of each Union institution and body, while taking into account the retention policy and rules of other relevant Union institutions and bodies. |
Amendment 48
Proposal for a regulation
Article 39 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. EUCI documents shall not be transferred to the Historical Archives of the European Union. | 2. EUCI documents shall be transferred to the Historical Archives of the European Union after 30 years. The Historical Archives of the European Union shall take effective measures to protect EUCI from unauthorised access prior to declassification. |
Amendment 49
Proposal for a regulation
Article 40 – paragraph 1 – point c a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| (ca) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
Amendment 50
Proposal for a regulation
Article 51 – paragraph 3 – subparagraph 2 a (new)
| Text proposed by the Commission | Amendment |
|---|---|
| Such agreements and arrangements shall be subject to an ongoing review and assessment procedure, factoring in developments in the security measures, as well as the Union's relationship with these third countries, subject to the provisions laid down in Article 53. |
Amendment 51
Proposal for a regulation
Article 52 – paragraph 2
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service, ensuring gender and geographical balance, and shall work by consensus. |
Amendment 52
Proposal for a regulation
Article 53 – paragraph 1
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The sub-group on EUCI sharing and exchange of classified information shall carry out assessment visits in full cooperation with the officials of the Union institution or body being visited. It may seek assistance from the NSA on whose territory the Union institution or body is located. | 1. The sub-group on EUCI sharing and exchange of classified information shall carry out regular assessment visits in full cooperation with the officials of the Union institution or body being visited. It may seek assistance from the NSA on whose territory the Union institution or body is located. |
Procedure pages
How the committees handled the text, and how their members voted on it.
Procedure – committee asked for opinion 1 paragraph
| Title | Information security in the institutions, bodies, offices and agencies of the Union | |
| References | COM(2022)0119 – C9-0121/2022 – 2022/0084(COD) | |
| Committee responsible Date announced in plenary | LIBE 4.4.2022 | |
| Opinion by Date announced in plenary | AFCO 4.4.2022 | |
| Rapporteur for the opinion Date appointed | Maite Pagazaurtundúa 5.12.2022 | |
| Previous rapporteur for the opinion | Pascal Durand | |
| Discussed in committee | 17.10.2022 | 5.12.2022 |
| Date adopted | 25.1.2023 | |
| Result of final vote | +: –: 0: | 24 0 0 |
| Members present for the final vote | Gerolf Annemans, Gabriele Bischoff, Damian Boeselager, Gwendoline Delbos-Corfield, Salvatore De Meo, Daniel Freund, Charles Goerens, Esteban González Pons, Laura Huhtasaari, Victor Negrescu, Max Orville, Domènec Ruiz Devesa, Helmut Scholz, Pedro Silva Pereira, Sven Simon, Guy Verhofstadt, Loránt Vincze, Rainer Wieland | |
| Substitutes present for the final vote | Nathalie Colin-Oesterlé, Pascal Durand, Seán Kelly, Jaak Madison, Maite Pagazaurtundúa | |
| Substitutes under Rule 209(7) present for the final vote | Leszek Miller |
Final vote by roll call in committee asked for opinion 3 paragraphs
24 · For
- ID
- Gerolf Annemans, Laura Huhtasaari, Jaak Madison
- EPP
- Nathalie Colin-Oesterlé, Salvatore De Meo, Esteban González Pons, Seán Kelly, Sven Simon, Loránt Vincze, Rainer Wieland
- Renew
- Charles Goerens, Max Orville, Maite Pagazaurtundúa, Guy Verhofstadt
- S&D
- Gabriele Bischoff, Pascal Durand, Leszek Miller, Victor Negrescu, Domènec Ruiz Devesa, Pedro Silva Pereira
- The Left
- Helmut Scholz
- Greens
- Damian Boeselager, Gwendoline Delbos-Corfield, Daniel Freund
0 · Against
0 · Abstained