Skip to content
EU Parl Watch

opinion parliamentary committee draft, 30 September 2022

On the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

Document AFCO-PA-730186 · (COM(2022)0119 – C90121/2022 – 2022/0084(COD))

Committee on Constitutional Affairs · Rapporteur: Pascal Durand

On Parliament’s site PDF Word

AI:In short

The Committee on Constitutional Affairs gives its draft opinion on the Commission proposal for a regulation on information security in the Union institutions and bodies. It welcomes the proposal and proposes amendments to strengthen common minimum rules, an interinstitutional approach and protection against foreign interference. The amendments would set common minimum information security rules for all Union institutions and bodies, require an interinstitutional approach to sharing EUCI and sensitive non-classified information, and simplify procedures for sharing with member states. They would require institutions and bodies to safeguard the integrity of EU democratic processes and adopt provisions in tender procedures to curb foreign interference, including vetting of third parties and clearance of staff. They would give the Interinstitutional Coordination Group a role in monitoring compliance through a yearly evaluation report and require Security Authorities to monitor compliance with the regulation and the group's guidance documents.

Position. The Committee on Constitutional Affairs calls on the Committee on Civil Liberties, Justice and Home Affairs, as the committee responsible, to take into account its amendments. The amendments strengthen common minimum rules, an interinstitutional approach, monitoring by the Coordination Group and protection against foreign interference.

Key points

  1. The rapporteur welcomes the proposal, part of the EU Security Union Strategy adopted by the Commission on 24 July 2020, to streamline information security rules across Union institutions and bodies.
  2. The amendments would require an interinstitutional approach to sharing EUCI and sensitive non-classified information, with common categories and key handling principles, and simplified procedures for sharing with member states.
  3. They would require effective rules ensuring a common level of information security in all Union institutions and bodies, with equivalence of basic principles and common minimum standards.
  4. They would require the regulation to take account of new working practices, including electronic processing and exchanges of information.
  5. They would require the regulation to contribute to an efficient, independent and resilient administration and not to prevent institutions and bodies from fulfilling their missions or disproportionately limit their institutional autonomy.
  6. They would set up an Interinstitutional Coordination Group, with all Security Authorities represented, to enhance coherence and harmonise information security procedures and tools; the group could set up subgroups with specific tasks.
  7. They would require each institution and body to adopt specific security measures based on an internal risk assessment, while meeting common minimum requirements, and to adapt technical means to their needs and specificities.
  8. They would allow institutions and bodies to maintain their own marking system for internal purposes, and require common provisions for contractors' personnel, including vetting in tender procedures and termination of relationships posing a risk to democratic processes.
  9. They would require security measures for premises to build on an evaluation of security infrastructure and services, taking into account the supply chain and the economic and political environment of suppliers.
  10. They would make it imperative that all institutions and bodies use a single standard of accreditation of communication and information systems handling EUCI, to contribute to a common minimum level of protection.
  11. They would require institutions and bodies to safeguard the integrity of EU democratic processes and adopt provisions in tender procedures to curb foreign interference, covering security infrastructure, vetting of third parties and clearance of staff.
  12. They would require the Coordination Group to monitor compliance through a yearly evaluation report, and Security Authorities to monitor compliance with the regulation and the group's guidance documents; breaches would be notified no later than 1 week after the Security Authority is informed.

Who is affected

  • All Union institutions and bodies, which would have to apply common minimum information security rules and monitor compliance.
  • Contractors and third parties, which would face vetting in tender procedures and possible termination of relationships posing risks.
  • Member states, which would benefit from simplified procedures for sharing EUCI and sensitive non-classified information.
  • Security Authorities of institutions and bodies, which would monitor compliance and report breaches.

Figures and deadlines

  • 24 July 2020: date the Commission adopted the EU Security Union Strategy.
  • 1 week: deadline for informing the originator and notifying competent authorities of a breach after the Security Authority is informed.

Written by AI from the full text · every figure comes from the text · ¶ opens the paragraph · 25 Sept 2026 · Report a problem

Full text

Jump to an amendment (30)
Short justification 155 paragraphs

Union institutions and bodies need to share between themselves ever-increasing amounts of sensitive non-classified and European Union classified information (‘EUCI’) in a landscape of dramatically increasing threat levels. As a result, the European administration is exposed to attack in all its areas of activity. The information handled by the Union institutions and bodies is very attractive for the threat actors and needs to be swiftly and appropriately protected. Currently, the Union institutions and bodies either have their own information security rules, based on their Rules of procedure or founding act, or they do not have information security rules at all.

The rapporteur thus welcomes this proposal, which is part of the EU Security Union Strategy adopted by the Commission on 24 July 2020 and which is aimed at streamlining the internal legal frameworks for information security in all Union institutions and bodies so as to protect our societies from the ever evolving threats targeting the information handled by institutions and bodies.

An efficient and independent administration relies on the security of its information. With a view to achieving their mission, the Union institutions and bodies shall benefit from a secure environment for the information they handle and store on a daily basis. In addition, providing a common baseline of standards mandatory for all would guarantee a high level of security, reduce the risk of weak links in supporting interoperability among institutions and bodies and leverage synergies thus enhancing the administration’s resilience facing evolving threats.

AMENDMENTS

The Committee on Constitutional Affairs calls on the Committee on Civil Liberties, Justice and Home Affairs as the committee responsible, to take into account the following amendments:

Amendment 1

Proposal for a regulation

Recital 2

Text proposed by the CommissionAmendment
(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States.(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. An interinstitutional approach to the sharing of EUCI and sensitive non-classified information should be set up, with common categories of information and common key handling principles. Procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States should be simplified.

Or. en

Amendment 2

Proposal for a regulation

Read the rest (143 paragraphs)

Recital 3

Text proposed by the CommissionAmendment
(3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards.(3) Therefore, it is high time that effective rules ensuring a common level of information security in all Union institutions and bodies be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and common minimum standards.

Or. en

Amendment 3

Proposal for a regulation

Recital 4

Text proposed by the CommissionAmendment
(4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices.(4) Many procedures that were still at least partly paper-based were in recent years adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices.

Or. en

Amendment 4

Proposal for a regulation

Recital 5

Text proposed by the CommissionAmendment
(5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy.(5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient, independent and resilient administration in carrying out their missions. This Regulation shall under no circumstances prevent Union institutions and bodies from fulfilling their mission, as entrusted by the EU legislation, or disproportionately limit their institutional autonomy.

Or. en

Amendment 5

Proposal for a regulation

Recital 7

Text proposed by the CommissionAmendment
(7) In order to preserve the specific nature of the European Atomic Energy Community activities regulated by Regulation 3/1958 of the Council of the European Atomic Energy Community25 , this Regulation should not apply to Euratom Classified Information. However, all information related to other Euratom activities not covered by Regulation 3/1958 should fall within the scope of this Regulation.deleted
25 EAEC Council: Regulation No 3 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406).

Or. en

Amendment 6

Proposal for a regulation

Recital 8

Text proposed by the CommissionAmendment
(8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies.(8) With a view to establishing a formal common structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. The Coordination Group should enhance the coherence of policies in the field of information security and contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies.

Or. en

Amendment 7

Proposal for a regulation

Recital 9

Text proposed by the CommissionAmendment
(9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks.(9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, the Coordination Group should be able to set up subgroups with specific tasks.

Or. en

Amendment 8

Proposal for a regulation

Recital 12

Text proposed by the CommissionAmendment
(12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each institution and body.(12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the common minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the needs and specificities of each institution and body.

Or. en

Amendment 9

Proposal for a regulation

Recital 13

Text proposed by the CommissionAmendment
(13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes or in the exchange of information with their particular counterparts from other institutions and bodies or from the Member States.(13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes.

Or. en

Amendment 10

Proposal for a regulation

Recital 15

Text proposed by the CommissionAmendment
(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security.(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Such provisions should include, inter alia, a requirement in the tender procedures to undergo thorough vetting, taking into account the full range of the supply chain and economic and political environment in which the third parties operate. Where the relationships with third parties pose a risk to the integrity of democratic processes in the EU, they should be terminated without undue delay.

Or. en

Amendment 11

Proposal for a regulation

Recital 18

Text proposed by the CommissionAmendment
(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites.(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. Those security measures should among others build on a thorough evaluation of the relevant security infrastructure and services, taking into account the full range of the supply chain and economic and political environment in which their suppliers operate.

Or. en

Amendment 12

Proposal for a regulation

Recital 22

Text proposed by the CommissionAmendment
(22) With the objective of achieving a single standard of accreditation of CISs handling and storing EUCI, the Union institutions and bodies should work together in a group set up for that purpose. It is recommended that all of them use that standard in order to contribute to a general level of EUCI protection. However, as regards organisational autonomy, the decision remains with the competent authority of each institution or body.(22) With the objective of achieving a single standard of accreditation of CISs handling and storing EUCI, the Union institutions and bodies should work together in a group set up for that purpose. It is imperative that all of them use that standard in order to contribute to a common minimum level of EUCI protection.

Or. en

Amendment 13

Proposal for a regulation

Article 1 – paragraph 1

Text proposed by the CommissionAmendment
1. This Regulation lays down information security rules for all Union institutions and bodies.This Regulation lays down common minimum information security rules for all Union institutions and bodies.

Or. en

Amendment 14

Proposal for a regulation

Article 2 – paragraph 1

Text proposed by the CommissionAmendment
1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community, other than Euratom Classified Information.1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community.

Or. en

Amendment 15

Proposal for a regulation

Article 2 – paragraph 3

Text proposed by the CommissionAmendment
3. These levels are based on the damage that unauthorised disclosure may cause to the legitimate private and public interests, including those of the Union, Union institutions and bodies and Member States or other stakeholders, so that the appropriate protective measures can be applied.3. These levels are based on the damage that unauthorised disclosure may cause to the private and public interests of the Union, Union institutions and bodies or one or more of the Member States, so that the appropriate protective measures can be applied.

Or. en

Amendment 16

Proposal for a regulation

Article 4 – title

Text proposed by the CommissionAmendment
General principlesGeneral principles and provisions

Or. en

Amendment 17

Proposal for a regulation

Article 4 – paragraph 1

Text proposed by the CommissionAmendment
1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process.1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation. Each Union institution and body shall also take into account the coherence and interoperability of their document security framework with that of other relevant Union institutions and bodies.

Or. en

Amendment 18

Proposal for a regulation

Article 4 – paragraph 4 – point d

Text proposed by the CommissionAmendment
(d) integrity: the fact that the information is complete and completeness of information is unaltered;(d) integrity: the fact that the information is complete and completeness of information is unaltered and the fact that the technical infrastructure used to share information is protected from any foreign interference.

Or. en

Amendment 19

Proposal for a regulation

Article 4 – paragraph 6 a (new)

Text proposed by the CommissionAmendment
6a. When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of EU democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions should at least address the acquisition and maintenance of security infrastructure, the vetting of third party organisations and the clearance of staff.

Or. en

Amendment 20

Proposal for a regulation

Article 6 – paragraph 2 – point e a (new)

Text proposed by the CommissionAmendment
(ea) monitor compliance by Union institutions and bodies with this Regulation as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report, which shall compile input from the relevant sub-groups.

Or. en

Amendment 21

Proposal for a regulation

Article 8 – paragraph 1

Text proposed by the CommissionAmendment
1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and, where applicable, by its internal security rules. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks.1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and monitor and ensure compliance by each Union institution or body concerned with the guidance documents adopted by the Coordination Group. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks.

Or. en

Amendment 22

Proposal for a regulation

Article 16 – paragraph 1 – point e a (new)

Text proposed by the CommissionAmendment
(ea) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group.

Or. en

Amendment 23

Proposal for a regulation

Article 19 – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) it establishes rules and procedures in accordance with this Regulation, ensuring the protection of information for a given classification level; and(a) it establishes rules and procedures in accordance with this Regulation and the guidance documents adopted by the Coordination Group, ensuring the protection of information for a given classification level; and

Or. en

Amendment 24

Proposal for a regulation

Article 19 – paragraph 1 – point b

Text proposed by the CommissionAmendment
(b) it has undergone an assessment visit in accordance with Article 53, and it has been subsequently certified that it can protect EUCI in accordance with this Regulation and where applicable, any other relevant rules and procedures.(b) it has undergone an assessment visit in accordance with Article 53, and it has been subsequently certified that it can protect EUCI in accordance with this Regulation, the guidance documents adopted by the Coordination Group, and where applicable, any other relevant rules and procedures.

Or. en

Amendment 25

Proposal for a regulation

Article 22 – paragraph 3 – point a

Text proposed by the CommissionAmendment
(a) inform the originator;(a) inform the originator without undue delay, and in any case no later than 1 week after the Security Authority is informed of the breach;

Or. en

Amendment 26

Proposal for a regulation

Article 22 – paragraph 3 – point e

Text proposed by the CommissionAmendment
(e) notify the competent authorities about the actual or potential compromise and the action taken.(e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any case no later than 1 week after the Security Authority is informed of the breach.

Or. en

Amendment 27

Proposal for a regulation

Article 23 – paragraph 3

Text proposed by the CommissionAmendment
3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement.3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall in any event ensure that the principles under paragraphs 1 and 2 be observed.

Or. en

Amendment 28

Proposal for a regulation

Article 28 – paragraph 1 – point d a (new)

Text proposed by the CommissionAmendment
(da) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group.

Or. en

Amendment 29

Proposal for a regulation

Article 30 – paragraph 1

Text proposed by the CommissionAmendment
1. Union institutions and bodies shall record, file, preserve and eventually eliminate, sample or transfer their EUCI documents to the relevant archives in accordance with retention policy and rules specific to the files of each Union institution and body.1. Union institutions and bodies shall record, file, preserve and eventually eliminate, sample or transfer their EUCI documents to the relevant archives in accordance with retention policy and rules specific to the files of each Union institution and body, while taking into account the retention policy and rules of other relevant Union institutions and bodies.

Or. en

Amendment 30

Proposal for a regulation

Article 40 – paragraph 1 – point c a (new)

Text proposed by the CommissionAmendment
(ca) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group.

Or. en