Skip to content
EU Parl Watch

opinion letter parliamentary committee, 22 October 2025

Opinion on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

Document AFET-AL-778158 · (COM(2022)0119 – C100121/2022 – 2022/0094(COD))

Committee on Foreign Affairs

On Parliament’s site PDF Word

Full text

Text 22 paragraphs

22.10.2025

Mr Javier Zarzalejos

Chair

Committee on Civil Liberties, Justice and Home Affairs

Subject: Opinion on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union (COM(2022)0119 – C100121/2022 – 2022/0094(COD))

Dear Chairman,

Dear Mr Zarzalejos,

Under the procedure referred to above, the Committee on Foreign Affairs has been asked to submit an opinion to your Committee. During the meeting of 13 January 2025, the Coordinators of the Committee on Foreign Affairs decided to send the opinion in the form of a letter. The Committee on Foreign Affairs adopted the opinion during the 16 October 2025 Committee meeting and called on the Committee responsible to incorporate the following suggestions into its report.

In a moment of rapid geopolitical changes combined with an evolving threats environment, the Union’s information security is increasingly put at risk. International crises demonstrate the need for the EU to obtain credible and first-hand information on current and possible external threats to the Union, in order to be able to react rapidly and effectively, as well as to better protect its citizens and its interests abroad. Foreign interference and disinformation are also posing a real danger to EU democratic processes and Union institutions, bodies, offices and agencies should receive the adequate means and resources to face these new challenges.

From a foreign affairs and security perspective, and as underlined in several Parliament’s resolutions on the implementation of the Common Foreign and Security Policy (CFSP), Parliament should be provided with the necessary information and documents in a transparent and timely manner in order to properly fulfil its important role of democratic oversight. This is why strengthening and harmonising of the categorisation, handling and storage of EU classified information and for non-classified information is key.

AFET welcomes this timely Commission proposal, which is part of the EU Security Union Strategy adopted by the Commission in July 2020 as Union institutions, bodies, offices and agencies need to be equipped with an appropriate common high level of security for EU classified information and for non-classified information. Also, AFET welcomes the fact that the proposed regulation intends to create a minimum set of rules and aims to establish an inter-institutional information security coordination group, a necessary step towards the harmonisation for ensuring a smooth implementation of an EU information security culture.

Notwithstanding this effort to facilitate and harmonise the protection of information in EU institutions, bodies and agencies, Parliament recalls the urgent need to upgrade the inter-institutional framework for Parliament's access to confidential information in the field of the CFSP.

Read the rest (10 paragraphs)

On this basis, AFET proposes that the following elements are included in the draft report:

1. The above-mentioned elements regarding the institutional prerogatives need to be properly clarified in Article 32: while the originator control is an undisputable principle, the text should be better formulated as it should not prevail over the Treaty prerogatives. Article 54 of the proposal is incomplete in the same manner, as it does not refer to the rights and obligations under the Treaties that an EU institution has as the basis for sharing EU classified information.

2. The proposal should clarify that Members of the European Parliament should have access by virtue of their mandate to all necessary information on the basis of the ‘need-to-know principle’ in order to exercise the powers vested to them by the Treaties. Therefore, the proposal should include the following new paragraph:

“(new paragraph). Members of the Union institutions should have access by virtue of their mandate to all necessary EU confidential and sensitive non-confidential information, on the basis of the ‘need-to-know principle’ and in respect of the rules for personal security clearance, in order to exercise the powers vested to them by the Treaties.”

3. A mechanism should be established how to deal with cases of over-classification of the information, notably in the form of consultations and a final decision between the originator and the recipient of the information.

4. Foreign interference and disinformation are posing a real danger to EU democratic processes and Union institutions, bodies, offices and agencies should receive the adequate means and resources to face these new challenges. The proposal should include the following new paragraph:

“(new paragraph). When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of EU democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions shall at least address the acquisition and maintenance of security infrastructure, the vetting of third party organisations and the clearance of staff.”

5. LIBE Committee as the Committee responsible should reconsider whether the establishment of the category of “NORMAL” information (Article 13 of the proposal) provides sufficient benefits that would outweigh the additional administrative requirements that would arise from the creation and application of this category of information and its distinction from “PUBLIC USE” information.

Yours sincerely,

David McAllister

Annex: declaration of input 1 paragraph

The Chair declares under his exclusive responsibility that he did not include in his opinion input from interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from representatives of public authorities of third countries, including their diplomatic missions and embassies, to be listed in this Annex pursuant to Article 8 of Annex I to the Rules of Procedure.