Skip to content
EU Parl Watch

opinion parliamentary committee, 30 January 2023

On the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

Document AFCO-AD-730186 · (COM(2022)0119 – C90121/2022 – 2022/0084(COD))

Committee on Constitutional Affairs · Rapporteur: Maite Pagazaurtundúa

On Parliament’s site PDF Word

AI:In short

The Committee on Constitutional Affairs gives its opinion on the proposed regulation on information security in the Union's institutions, bodies, offices and agencies. It proposes 52 amendments to the Commission proposal. The amendments add common minimum standards, an interinstitutional approach to sharing EUCI and sensitive non-classified information, and a Coordination Group that can adopt recommendations and monitor compliance. They require institutions to safeguard the integrity of EU democratic processes, vet contractors and terminate relationships that pose a risk to democratic processes. They set deadlines of one week for reporting breaches, require EUCI documents to go to the Historical Archives after 30 years, and require SNC information to be stored and processed exclusively in the Union.

Position. The Committee on Constitutional Affairs welcomes the proposal and proposes 52 amendments to strengthen common minimum standards, interinstitutional cooperation, monitoring by the Coordination Group, and protection against foreign interference.

Key points

  1. The committee calls on the Committee on Civil Liberties, Justice and Home Affairs, as committee responsible, to take into account its amendments.
  2. The amendments require an interinstitutional approach to sharing EUCI and sensitive non-classified information, with common categories and key handling principles, and simplified procedures.
  3. They state it is high time that effective rules ensuring a common level of information security in all Union institutions and bodies be laid down, with common minimum standards.
  4. They delete the recital excluding Euratom Classified Information from the regulation's scope.
  5. They require the Coordination Group to adopt recommendations and provisions to enhance policy coherence, set up subgroups, and take account of training for personnel.
  6. They require institutions to safeguard the integrity of EU democratic processes and adopt provisions in tender procedures to curb foreign interference, covering security infrastructure, vetting and staff clearance.
  7. They require the Coordination Group to monitor compliance through a yearly evaluation report and carry out risk assessments on foreign interference in EUCI.
  8. They require institutions to mark information 'PUBLIC USE', establish streamlined incident reporting procedures, and store and process SNC information exclusively in the Union.
  9. They set a consultation procedure between Parliament and the Commission when there is doubt about the confidential nature of information or its classification level.
  10. They require holders of EUCI to be legally responsible for its protection, including under the Treaties, relevant criminal law and the Staff Regulations.
  11. They require notification of breaches to the originator and competent authorities no later than one week after the Security Authority is informed.
  12. They require EUCI documents to be transferred to the Historical Archives after 30 years, with effective measures to protect them from unauthorised access prior to declassification.

Who is affected

  • Union institutions and bodies: must apply common minimum information security rules and safeguard EU democratic processes.
  • Contractors and third parties: subject to vetting in tender procedures and possible termination of relationships posing risks.
  • National Security Authorities of member states: benefit from a common glossary and procedures in personnel security.
  • European Parliament and Commission: must consult each other on classification doubts before transmitting documents.

Figures and deadlines

  • 30 years: period after which EUCI documents shall be transferred to the Historical Archives of the European Union.
  • one week: deadline for informing the originator and notifying competent authorities after the Security Authority is informed of a breach.

Written by AI from the full text · every figure comes from the text · ¶ opens the paragraph · 25 Sept 2026 · Report a problem

Full text

Jump to an amendment (52)
Short justification 215 paragraphs

Union institutions and bodies need to share between themselves ever-increasing amounts of sensitive non-classified and European Union classified information (‘EUCI’) in a landscape of dramatically increasing threat levels. As a result, the European administration is exposed to attack in all its areas of activity. The information handled by the Union institutions and bodies is very attractive for the threat actors and needs to be swiftly and appropriately protected. Currently, the Union institutions and bodies either have their own information security rules, based on their Rules of procedure or founding act, or they do not have information security rules at all.

The rapporteur thus welcomes this proposal, which is part of the EU Security Union Strategy adopted by the Commission on 24 July 2020 and which is aimed at streamlining the internal legal frameworks for information security in all Union institutions and bodies so as to protect our societies from the ever evolving threats targeting the information handled by institutions and bodies.

An efficient and independent administration relies on the security of its information. With a view to achieving their mission, the Union institutions and bodies shall benefit from a secure environment for the information they handle and store on a daily basis. In addition, providing a common baseline of standards mandatory for all would guarantee a high level of security, reduce the risk of weak links in supporting interoperability among institutions and bodies and leverage synergies thus enhancing the administration’s resilience facing evolving threats.

AMENDMENTS

The Committee on Constitutional Affairs calls on the Committee on Civil Liberties, Justice and Home Affairs as the committee responsible, to take into account the following amendments:

Amendment 1

Proposal for a regulation

Recital 2

Text proposed by the CommissionAmendment
(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States.(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. An interinstitutional approach to the sharing of EUCI and sensitive non-classified information should be set up, with common categories of information and common key handling principles. Procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States should be simplified.

Amendment 2

Proposal for a regulation

Recital 3

Read the rest (203 paragraphs)
Text proposed by the CommissionAmendment
(3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards.(3) Therefore, it is high time that effective rules ensuring a common level of information security in all Union institutions and bodies be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and common minimum standards.

Amendment 3

Proposal for a regulation

Recital 4

Text proposed by the CommissionAmendment
(4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices.(4) Many procedures that were still at least partly paper-based were in recent years adjusted to enable electronic processing and exchanges of information. These developments require changes in the production, handling and protection of information. This Regulation takes account of the new working practices.

Amendment 4

Proposal for a regulation

Recital 5

Text proposed by the CommissionAmendment
(5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy.(5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient, independent and resilient administration in carrying out their missions. This Regulation shall under no circumstances prevent Union institutions and bodies from fulfilling their mission, as entrusted by the EU legislation, or disproportionately limit their institutional autonomy.

Amendment 5

Proposal for a regulation

Recital 7

Text proposed by the CommissionAmendment
(7) In order to preserve the specific nature of the European Atomic Energy Community activities regulated by Regulation 3/1958 of the Council of the European Atomic Energy Community25 , this Regulation should not apply to Euratom Classified Information. However, all information related to other Euratom activities not covered by Regulation 3/1958 should fall within the scope of this Regulation.deleted
25 EAEC Council: Regulation No 3 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406).

Amendment 6

Proposal for a regulation

Recital 8

Text proposed by the CommissionAmendment
(8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies.(8) With a view to establishing a formal common structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. The Coordination Group should adopt recommendations and provisions to enhance the coherence of policies in the field of information security and contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies.

Amendment 7

Proposal for a regulation

Recital 9

Text proposed by the CommissionAmendment
(9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks.(9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, the Coordination Group should be able to set up subgroups with specific tasks. While carrying out its tasks, the Coordination Group should also take into account the training component for the Union institutions' and bodies' personnel, with the aim of enhancing information security awareness and best practices, complementary to the established procedures.

Amendment 8

Proposal for a regulation

Recital 10

Text proposed by the CommissionAmendment
(10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group.(10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. Given the constantly evolving threat landscape at Union level, close cooperation with that committee is required in order to adapt prevention and mitigation methods for information security.

Amendment 9

Proposal for a regulation

Recital 12

Text proposed by the CommissionAmendment
(12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each institution and body.(12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the common minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the needs and specificities of each institution and body.

Amendment 10

Proposal for a regulation

Recital 13

Text proposed by the CommissionAmendment
(13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes or in the exchange of information with their particular counterparts from other institutions and bodies or from the Member States.(13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes.

Amendment 11

Proposal for a regulation

Recital 14

Text proposed by the CommissionAmendment
(14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures.(14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by effective security measures.

Amendment 12

Proposal for a regulation

Recital 15

Text proposed by the CommissionAmendment
(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security.(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Such provisions should include, inter alia, a requirement in the tender procedures to undergo thorough vetting, taking into account the full range of the supply chain and economic and political environment in which the third parties operate. Where the relationships with third parties pose a risk to the integrity of democratic processes in the EU, they should be terminated without undue delay.

Amendment 13

Proposal for a regulation

Recital 16

Text proposed by the CommissionAmendment
(16) The substantive rules regarding access to EUCI in the internal rules of various Union institutions and bodies are currently aligned, but there are significant differences as regards denominations and required procedures. This creates a burden for the National Security Authorities of the Member States who need to adjust to different requirements. Thus it is necessary to provide for a common glossary and common procedures in the area of personnel security, thereby simplifying cooperation with the National Security Authorities of the Member States and limiting the risk of compromising EUCI.(16) The substantive rules regarding access to EUCI in the internal rules of various Union institutions and bodies are currently aligned, but there are significant differences as regards denominations and required procedures. This creates a burden for the National Security Authorities of the Member States who need to adjust to different requirements. Thus it is necessary to provide for a common glossary and common procedures in the area of personnel security, thereby simplifying cooperation with the National Security Authorities of the Member States and limiting the risk of compromising EUCI, while respecting the Rules of Procedure of each institution and body.

Amendment 14

Proposal for a regulation

Recital 18

Text proposed by the CommissionAmendment
(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites.(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. Those security measures should, among others, build on a thorough evaluation of the relevant security infrastructure and services, taking into account the full range of the supply chain and economic and political environment in which their suppliers operate.

Amendment 15

Proposal for a regulation

Recital 22

Text proposed by the CommissionAmendment
(22) With the objective of achieving a single standard of accreditation of CISs handling and storing EUCI, the Union institutions and bodies should work together in a group set up for that purpose. It is recommended that all of them use that standard in order to contribute to a general level of EUCI protection. However, as regards organisational autonomy, the decision remains with the competent authority of each institution or body.(22) With the objective of achieving a single standard of accreditation of CISs handling and storing EUCI, the Union institutions and bodies should work together in a group set up for that purpose. It is imperative that all of them use that standard in order to contribute to a common minimum level of EUCI protection.

Amendment 16

Proposal for a regulation

Article 1 – paragraph 1

Text proposed by the CommissionAmendment
1. This Regulation lays down information security rules for all Union institutions and bodies.This Regulation lays down common minimum information security rules for all Union institutions and bodies.

Amendment 17

Proposal for a regulation

Article 2 – paragraph 1

Text proposed by the CommissionAmendment
1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community, other than Euratom Classified Information.1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community.

Amendment 18

Proposal for a regulation

Article 2 – paragraph 3

Text proposed by the CommissionAmendment
3. These levels are based on the damage that unauthorised disclosure may cause to the legitimate private and public interests, including those of the Union, Union institutions and bodies and Member States or other stakeholders, so that the appropriate protective measures can be applied.3. These levels are based on the damage that unauthorised disclosure may cause to the private and public interests of the Union, Union institutions and bodies or one or more of the Member States, so that the appropriate protective measures can be applied.

Amendment 19

Proposal for a regulation

Article 4 – title

Text proposed by the CommissionAmendment
General principlesGeneral principles and provisions

Amendment 20

Proposal for a regulation

Article 4 – paragraph 1

Text proposed by the CommissionAmendment
1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process.1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation, taking account of the coherence and interoperability of its document security framework with that of other relevant Union institutions and bodies.

Amendment 21

Proposal for a regulation

Article 4 – paragraph 2

Text proposed by the CommissionAmendment
2. Non-compliance with this Regulation, in particular the unauthorised disclosure of information with the confidentiality levels referred to in Article 2(2), except information for public use shall be subject to investigation and may trigger personnel liability in accordance with the Treaties or with their relevant staff rules.2. Non-compliance with this Regulation, in particular the unauthorised disclosure of information with the confidentiality levels referred to in Article 2(2), except information for public use shall be subject to investigation and may trigger personnel liability in accordance with the Treaties, with relevant criminal law and with their relevant staff rules.

Amendment 22

Proposal for a regulation

Article 4 – paragraph 4 – point d

Text proposed by the CommissionAmendment
(d) integrity: the fact that the information is complete and completeness of information is unaltered;(d) integrity: the fact that the information is complete and completeness of information is unaltered and the fact that the technical infrastructure used to share information is protected from any foreign interference;

Amendment 23

Proposal for a regulation

Article 4 – paragraph 6 a (new)

Text proposed by the CommissionAmendment
6a. When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of EU democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions shall at least address the acquisition and maintenance of security infrastructure, the vetting of third party organisations and the clearance of staff.

Amendment 24

Proposal for a regulation

Article 6 – paragraph 1 – subparagraph 2

Text proposed by the CommissionAmendment
It shall be composed of all Security Authorities of the Union institutions and bodies, and shall have a mandate to define their common policy in the field of information security.It shall be composed of all Security Authorities of the Union institutions and bodies, and shall have a mandate to define common measures in the field of information security.

Amendment 25

Proposal for a regulation

Article 6 – paragraph 2 – point c

Text proposed by the CommissionAmendment
(c) establish guidance documents on the implementation of this Regulation, in cooperation with the Interinstitutional Cybersecurity Board referred to in Article 9 of the Regulation EU [...] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, where appropriate;(c) establish recommendations and guidance documents on the implementation of this Regulation, in cooperation with the Interinstitutional Cybersecurity Board referred to in Article 9 of the Regulation EU [...] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, where appropriate;

Amendment 26

Proposal for a regulation

Article 6 – paragraph 2 – point d

Text proposed by the CommissionAmendment
(d) set up dedicated platforms for sharing best practices and knowledge on common topics relevant to information security as well as for providing assistance in case of information security incidents;(d) set up dedicated platforms for sharing best practices, training and knowledge on common topics relevant to information security as well as for providing assistance in case of information security incidents;

Amendment 27

Proposal for a regulation

Article 6 – paragraph 2 – point e a (new)

Text proposed by the CommissionAmendment
(ea) monitor compliance by Union institutions and bodies with this Regulation as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report, which shall compile input from the relevant sub-groups.

Amendment 28

Proposal for a regulation

Article 6 – paragraph 2 – point e b (new)

Text proposed by the CommissionAmendment
(eb) carry out risk assessments, in particular with regard to foreign interference in EUCI.

Amendment 29

Proposal for a regulation

Article 6 – paragraph 6 a (new)

Text proposed by the CommissionAmendment
6a. The appointed members of the Coordination Group shall be adequately gender and geographically balanced.

Amendment 30

Proposal for a regulation

Article 6 – paragraph 7

Text proposed by the CommissionAmendment
7. Union institutions and bodies shall bring to the attention of the Coordination Group any significant information security policy development within their organisation.7. Union institutions and bodies shall bring to the attention of the Coordination Group any significant information security policy development within their organisation within a reasonable timeframe.

Amendment 31

Proposal for a regulation

Article 8 – paragraph 1

Text proposed by the CommissionAmendment
1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and, where applicable, by its internal security rules. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks.1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and monitor and ensure compliance by that institution or body with the guidance documents adopted by the Coordination Group. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks.

Amendment 32

Proposal for a regulation

Article 12 – paragraph 2

Text proposed by the CommissionAmendment
2. Union institutions and bodies may mark with ‘PUBLIC USE’ the information referred to in paragraph 1.2. Union institutions and bodies shall mark with ‘PUBLIC USE’ the information referred to in paragraph 1.

Amendment 33

Proposal for a regulation

Article 15 – paragraph 1

Text proposed by the CommissionAmendment
1. Union institutions and bodies shall establish procedures for the reporting and management of any incident or suspected incident that could lead to a compromise of the security of non-classified information.1. Union institutions and bodies shall establish streamlined procedures for the reporting and management of any incident or suspected incident that could lead to a compromise of the security of non-classified information.

Amendment 34

Proposal for a regulation

Article 15 – paragraph 2

Text proposed by the CommissionOral Amendment
2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. Exceptionally, other equivalent markings may be used internally and in relation with their particular counterparts from other Union institutions and bodies or from the Member States, when all parties agree. Such exception shall be notified to the sub-group on non-classified information, as referred to in Article 7(1), point (b).2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. Exceptionally, other equivalent markings may be used internally. Such exception shall be notified to the sub-group on non-classified information, as referred to in Article 7(1), point (b).

Amendment 35

Proposal for a regulation

Article 16 – paragraph 1 – point e a (new)

Text proposed by the CommissionAmendment
(ea) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group.

Amendment 36

Proposal for a regulation

Article 17 – paragraph 1 – point c

Text proposed by the CommissionAmendment
(c) SNC information shall be stored and processed in the Union;(c) SNC information shall be stored and processed exclusively in the Union;

Amendment 37

Proposal for a regulation

Article 18 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. In the event of any doubt as to the confidential nature of an item of information or its appropriate level of classification, the European Parliament and the Commission shall consult each other without delay and before transmission of the document. In those consultations, the European Parliament shall be represented by the chair of the parliamentary body concerned, accompanied, where necessary, by the rapporteur, or the office-holder who submitted the request. The Commission shall be represented by the member of the Commission with responsibility for that area, after consultation of the member of the Commission responsible for security matters. In the event of a disagreement, the matter shall be referred to the Presidents of the two institutions so that they may resolve the dispute.

Justification

This is in order to align these provisions with the interinstitutional procedure to contest classification laid down in Annex II point 2.3 of the Framework Agreement on relations between the European Parliament and the European Commission.

Amendment 38

Proposal for a regulation

Article 19 – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) it establishes rules and procedures in accordance with this Regulation, ensuring the protection of information for a given classification level; and(a) it establishes rules and procedures in accordance with this Regulation and the guidance documents adopted by the Coordination Group, ensuring the protection of information for a given classification level; and

Amendment 39

Proposal for a regulation

Article 19 – paragraph 1 – point b

Text proposed by the CommissionAmendment
(b) it has undergone an assessment visit in accordance with Article 53, and it has been subsequently certified that it can protect EUCI in accordance with this Regulation and where applicable, any other relevant rules and procedures.(b) it has undergone an assessment visit in accordance with Article 53, and it has been subsequently certified that it can protect EUCI in accordance with this Regulation, the guidance documents adopted by the Coordination Group, and where applicable, any other relevant rules and procedures.

Amendment 40

Proposal for a regulation

Article 20 – paragraph 1

Text proposed by the CommissionAmendment
1. The holder of any item of EUCI shall be responsible for its protection.1. The holder of any item of EUCI shall be legally responsible for its protection. This shall include responsibility under the Treaties, relevant criminal law and the Staff Regulations.

Amendment 41

Proposal for a regulation

Article 20 – paragraph 3 a (new)

Text proposed by the CommissionAmendment
3a. This Article is without prejudice to Regulation No 1049/2001 regarding public access to European Parliament, Council and Commission documents.

Amendment 42

Proposal for a regulation

Article 21 – paragraph 1

Text proposed by the CommissionAmendment
1. The security Authority of each Union institution and body shall approve the security measures for protecting EUCI throughout its life-cycle in accordance with the outcome of a risk assessment performed by the respective Union institution or body.1. The security Authority of each Union institution and body shall approve the security measures for protecting EUCI throughout its life-cycle in accordance with the outcome of a risk assessment performed by the respective Union institution or body. The risk assessment shall have a common criteria to ensure that all Union institutions and bodies have aligned security measures, while also considering the particularities relevant to each institution or body.

Amendment 43

Proposal for a regulation

Article 22 – paragraph 3 – point a

Text proposed by the CommissionAmendment
(a) inform the originator;(a) inform the originator without undue delay, and in any case no later than one week after the Security Authority is informed of the breach;

Amendment 44

Proposal for a regulation

Article 22 – paragraph 3 – point e

Text proposed by the CommissionAmendment
(e) notify the competent authorities about the actual or potential compromise and the action taken.(e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any case no later than one week after the Security Authority is informed of the breach.

Amendment 45

Proposal for a regulation

Article 23 – paragraph 3

Text proposed by the CommissionAmendment
3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement.3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall in any event ensure that the principles under paragraphs 1 and 2 be observed.

Amendment 46

Proposal for a regulation

Article 28 – paragraph 1 – point d a (new)

Text proposed by the CommissionAmendment
(da) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group.

Amendment 47

Proposal for a regulation

Article 30 – paragraph 1

Text proposed by the CommissionAmendment
1. Union institutions and bodies shall record, file, preserve and eventually eliminate, sample or transfer their EUCI documents to the relevant archives in accordance with retention policy and rules specific to the files of each Union institution and body.1. Union institutions and bodies shall record, file, preserve and eventually eliminate, sample or transfer their EUCI documents to the relevant archives in accordance with retention policy and rules specific to the files of each Union institution and body, while taking into account the retention policy and rules of other relevant Union institutions and bodies.

Amendment 48

Proposal for a regulation

Article 39 – paragraph 2

Text proposed by the CommissionAmendment
2. EUCI documents shall not be transferred to the Historical Archives of the European Union.2. EUCI documents shall be transferred to the Historical Archives of the European Union after 30 years. The Historical Archives of the European Union shall take effective measures to protect EUCI from unauthorised access prior to declassification.

Amendment 49

Proposal for a regulation

Article 40 – paragraph 1 – point c a (new)

Text proposed by the CommissionAmendment
(ca) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group.

Amendment 50

Proposal for a regulation

Article 51 – paragraph 3 – subparagraph 2 a (new)

Text proposed by the CommissionAmendment
Such agreements and arrangements shall be subject to an ongoing review and assessment procedure, factoring in developments in the security measures, as well as the Union's relationship with these third countries, subject to the provisions laid down in Article 53.

Amendment 51

Proposal for a regulation

Article 52 – paragraph 2

Text proposed by the CommissionAmendment
2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus.2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service, ensuring gender and geographical balance, and shall work by consensus.

Amendment 52

Proposal for a regulation

Article 53 – paragraph 1

Text proposed by the CommissionAmendment
1. The sub-group on EUCI sharing and exchange of classified information shall carry out assessment visits in full cooperation with the officials of the Union institution or body being visited. It may seek assistance from the NSA on whose territory the Union institution or body is located.1. The sub-group on EUCI sharing and exchange of classified information shall carry out regular assessment visits in full cooperation with the officials of the Union institution or body being visited. It may seek assistance from the NSA on whose territory the Union institution or body is located.

Procedure pages

How the committees handled the text, and how their members voted on it.

Procedure – committee asked for opinion 1 paragraph
TitleInformation security in the institutions, bodies, offices and agencies of the Union
ReferencesCOM(2022)0119 – C9-0121/2022 – 2022/0084(COD)
Committee responsible Date announced in plenaryLIBE 4.4.2022
Opinion by Date announced in plenaryAFCO 4.4.2022
Rapporteur for the opinion Date appointedMaite Pagazaurtundúa 5.12.2022
Previous rapporteur for the opinionPascal Durand
Discussed in committee17.10.20225.12.2022
Date adopted25.1.2023
Result of final vote+: –: 0:24 0 0
Members present for the final voteGerolf Annemans, Gabriele Bischoff, Damian Boeselager, Gwendoline Delbos-Corfield, Salvatore De Meo, Daniel Freund, Charles Goerens, Esteban González Pons, Laura Huhtasaari, Victor Negrescu, Max Orville, Domènec Ruiz Devesa, Helmut Scholz, Pedro Silva Pereira, Sven Simon, Guy Verhofstadt, Loránt Vincze, Rainer Wieland
Substitutes present for the final voteNathalie Colin-Oesterlé, Pascal Durand, Seán Kelly, Jaak Madison, Maite Pagazaurtundúa
Substitutes under Rule 209(7) present for the final voteLeszek Miller
Final vote by roll call in committee asked for opinion 3 paragraphs

24 · For

ID
Gerolf Annemans, Laura Huhtasaari, Jaak Madison
EPP
Nathalie Colin-Oesterlé, Salvatore De Meo, Esteban González Pons, Seán Kelly, Sven Simon, Loránt Vincze, Rainer Wieland
Renew
Charles Goerens, Max Orville, Maite Pagazaurtundúa, Guy Verhofstadt
S&D
Gabriele Bischoff, Pascal Durand, Leszek Miller, Victor Negrescu, Domènec Ruiz Devesa, Pedro Silva Pereira
The Left
Helmut Scholz
Greens
Damian Boeselager, Gwendoline Delbos-Corfield, Daniel Freund

0 · Against

0 · Abstained