Skip to content
EU Parl Watch

amendment list, 27 July 2026

Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)

Document CJ72-AM-791883 · (COM(2025)0837 – 2025/0360(COD))

Committee on Industry, Research and Energy Committee on Civil Liberties, Justice and Home Affairs

On Parliament’s site PDF Word

Full text

Jump to an amendment (100)
Text 811 paragraphs

Amendment 1741

Katri Kulmuni

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1

Text proposed by the CommissionAmendment
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.(1) Member States shall ensure the establishment of a national single-entry point for the notification of incidents under Union legal acts providing for such obligations.

Or. en

Justification

Deliver a European harmonized secureinteroperable technical infrastructure toconnect national established Single-Entry Points (SEPs) for reporting thatfacilitates entities in scope of multiplelegal incident reporting obligations tosubmit one report to be compliant withall applicable rules. See example ofLuxembourg and Denmark. We supportthe settingup of one integrated reportingportal per Member State, covering allstatutory reporting obligations, coupledwith full EU interoperability throughuniform technical and functionalstandards; and automated and securetransmission where crossborder notifications are required. Companies inall sectors should be allowed to leveragetheir country of main establishment asthe primary interface (single entry point)for cybersecurity incident reportingunder relevant EU legislation, providedthat this is combined with commontemplates, definitions and deadlines,and with automated, securetransmission to competent authorities inMember States via national single entrypoints where cross border notificationsare required. ENISA’s role should besupportive and focus on standardisation,interoperability and quality assurance.

Amendment 1742

Henrik Dahl

Read the rest (799 paragraphs)

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1

Text proposed by the CommissionAmendment
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.(1) Member States shall ensure the establishment of a national single-entry point for the notification of incidents under Union legal acts providing for such obligations.

Or. en

Amendment 1743

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1

Text proposed by the CommissionAmendment
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.(1) Member States shall ensure the establishment of a national single-entry point for the notification of incidents under Union legal acts providing for such obligations.

Or. en

Amendment 1744

Markus Buchheit

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1

Text proposed by the CommissionAmendment
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.(1) ENISA may, at the request of one or more Member States, develop and maintain technical support tools for the notification of cross-border or Union-wide systemic incidents and related events, where this is expressly provided for in the relevant Union legal acts and without prejudice to national reporting channels.

Or. en

Amendment 1745

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1

Text proposed by the CommissionAmendment
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA shall ensure that the single-entry point builds on the single reporting platform established under that Regulation.

Or. en

Amendment 1746

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive 2022/2555

Article 23a – paragraph 1

Text proposed by the CommissionAmendment
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA shall ensure that the single-entry point builds on the single reporting platform established under that Regulation.

Or. en

Amendment 1747

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – Paragraph 1a (new)

Text proposed by the CommissionAmendment
(1a) In Article 23a, the following paragraph is inserted:
'1a. The EU entry point shall build on existing national reporting systems and shall ensure the secure routing and interoperability of notifications between reporting entities and the competent national authorities, without centralising the storage of those notifications within a single body. The role of ENISA is limited to the technical operation, routing and format and completeness check of the notifications; ENISA is not a recipient of the notifications for substantive purposes.'

Or. en

Amendment 1748

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1a (new)

Text proposed by the CommissionAmendment
(1a) In Article 23a, the following paragraph is inserted:
'1a. ENISA shall forward the information submitted or disseminated via the single-entry point according to the relevant Union legal acts to the competent authorities in the relevant Member State or Member States.'

Or. en

Amendment 1749

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1b (new)

Text proposed by the CommissionAmendment
(1b) In Article 23a, the following paragraph is inserted:
'1b. ENISA should take into account existing such national technical solutions when developing the specifications on the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point to ensure continuity and interoperability.'

Or. en

Amendment 1750

Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 2

Text proposed by the CommissionAmendment
(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.(2) ENISA shall make a definition of what constitutes a significant incident that should be reported to the national single-entry point.

Or. en

Amendment 1751

Katri Kulmuni

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 2

Text proposed by the CommissionAmendment
(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.(2) ENISA shall make a definition of what constitutes a significant incident that should be reported to the national single-entry point.

Or. en

Amendment 1752

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 2

Text proposed by the CommissionAmendment
(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.(2) ENISA shall make a definition of what constitutes a significant incident that should be reported to the national single-entry point.

Or. en

Amendment 1753

Diego Solier, Sebastian Tynkkynen, Elena Donazzan

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 2

Text proposed by the CommissionAmendment
(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. The Commission, ENISA and the Cooperation Group shall develop harmonised reporting templates, reporting guidance and coordinated supervisory criteria for incidents that may trigger obligations under more than one Union cybersecurity instrument. Member States shall ensure that entities can submit the required information through a single-entry point.”

Or. en

Amendment 1754

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – Paragraph 2

Text proposed by the CommissionAmendment
(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.(2) ENISA and the national points of entry shall each, within their respective responsibilities, take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via it. ENISA and the national points of entry shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.

Or. en

Amendment 1755

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 2a (new)

Text proposed by the CommissionAmendment
(2a) In Article 23a, the following paragraph is inserted:
'2a. The Commission shall, by means of delegated act, develop one European notification template for the single-entry point. The European notification template shall:
(a) enable entities to submit a single notification to fulfil multiple reporting obligations;
(b) harmonize reporting timelines, deadlines, thresholds and, where possible, other data relevant to the reporting obligations covered in, at leat, Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR, Directive (EU) 2022/2557 (CER), Regulation (EU) No 910/2014 (eIDAS), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act);
(c) consist of a core section of data points applicable across all reporting obligations from relevant Union legal acts under point (b), that may be complemented by modular extensions that incorporate sectoral or other data fields specific to a particular Union legal act.
In preparing the template, the Commission shall carry out a mapping of the Union’s reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations under point (b), in coopreration with ENISA, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned. The mapping shall provide an analysis of the extent to which reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations can be harmonized.'

Or. en

Amendment 1756

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, Katri Kulmuni, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 2a (new)

Text proposed by the CommissionAmendment
(2a) In Article 23a, the following paragraph is inserted:
'2a. The Commission shall, by means of delegated act, develop one European notification template for the single-entry point. The European notification template shall:
(a) enable entities to submit a single notification to fulfil multiple reporting obligations;
(b) harmonize reporting timelines, deadlines, thresholds and, where possible, other data relevant to the reporting obligations covered in, at leat, Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR, Directive (EU) 2022/2557 (CER), Regulation (EU) No 910/2014 (eIDAS), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act), Regulation (EU) 2024/1689 (AI Act);
(c) consist of a core section of data points applicable across all reporting obligations from relevant Union legal acts under point (b), that may be complemented by modular extensions that incorporate sectoral or other data fields specific to a particular Union legal act.
In preparing the template, the Commission shall carry out a mapping of the Union’s reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations under point (b), in coopreration with ENISA, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned. The mapping shall provide an analysis of the extent to which reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations can be harmonized.'

Or. en

Amendment 1757

Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3

Text proposed by the CommissionAmendment
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:(3) ENISA shall develop and maintain an incident reporting information point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so.

Or. en

Amendment 1758

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3

Text proposed by the CommissionAmendment
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:(3) ENISA shall develop and maintain an incident reporting information point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so.

Or. en

Amendment 1759

Katri Kulmuni

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3

Text proposed by the CommissionAmendment
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:(3) ENISA shall develop and maintain an incident reporting information point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so.

Or. en

Amendment 1760

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Eva Maydell, Christian Ehler

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a (new) – paragraph 3

Text proposed by the CommissionAmendment
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:(3) ENISA shall provide and implement, in a timely manner, the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications, following a prior public consultation with the relevant stakeholders in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:

Or. en

Amendment 1761

Damian Boeselager, Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3

Text proposed by the CommissionAmendment
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:(3) ENISA shall implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point as established according to paragraph 8. ENISA shall support the Commission in developing the specifications, in consultation with the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:

Or. en

Amendment 1762

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – Paragraph 3

Text proposed by the CommissionAmendment
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network, the national single-entry points, and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:

Or. en

Amendment 1763

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3

Text proposed by the CommissionAmendment
(a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;deleted

Or. en

Amendment 1764

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3

Text proposed by the CommissionAmendment
(a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;(a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) and between the national points of entry is ensured;

Or. en

Amendment 1765

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point b

Text proposed by the CommissionAmendment
(b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;deleted

Or. en

Amendment 1766

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point b

Text proposed by the CommissionAmendment
(b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;(b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information through their national point of entry from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;

Or. en

Amendment 1767

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point c

Text proposed by the CommissionAmendment
(c) the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;deleted

Or. en

Amendment 1768

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point d

Text proposed by the CommissionAmendment
(d) where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;deleted

Or. en

Amendment 1769

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point d

Text proposed by the CommissionAmendment
(d) where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;(d) where relevant, the national points of entry and the EU entry point are interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;

Or. en

Amendment 1770

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point e

Text proposed by the CommissionAmendment
(e) entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;deleted

Or. en

Amendment 1771

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point e

Text proposed by the CommissionAmendment
(e) entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;(e) entities using a national point of entry can retrieve and supplement information that they have previously submitted via the single-entry point;

Or. en

Amendment 1772

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point f

Text proposed by the CommissionAmendment
(f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.deleted

Or. en

Amendment 1773

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Paulo Cunha, Christian Ehler

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point f

Text proposed by the CommissionAmendment
(f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.(f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point, and shall, to the greatest extent possible, enable entities to comply with existing reporting obligations under Union law, including Regulation (EU) 2022/2554 (DORA) and without requiring the resubmission of information already provided under other reporting frameworks.. In line with the principle of administrative simplification and the 'report-once' policy, it is necessary to avoid duplicative reporting obligations for financial entities that are already subject to stringent operational resilience requirements. Where a financial entity submits an incident report under Regulation (EU) 2022/2554 [DORA], that submission should be considered sufficient to satisfy the reporting requirements under the Regulation (EU) 2024/2847 [CRA]. This approach ensures regulatory coherence, legal clarity and reduces the compliance burden on the financial sector.

Or. en

Amendment 1774

Damian Boeselager, Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point f

Text proposed by the CommissionAmendment
(f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.(f) a single notification of information submitted by an entity via the single-entry point shall constitute timely submission to all competent authorities provided that the report is submitted within the applicable legal deadline as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.

Or. en

Amendment 1775

Damian Boeselager, Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – point fa (new)

Text proposed by the CommissionAmendment
(fa) In Article 23, paragraph 3, the following point is added:
'(fa) technical measures include at least:
i. end-to-end encryption;
ii. zero-trust architecture;
iii. compartmentalisation;
iv. mandatory audits and penetration testing;'

Or. en

Amendment 1776

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1 – point fa (new)

Text proposed by the CommissionAmendment
(fa) In Article 23a, paragraph 1, the following point is inserted:
'(fa) notifications submitted in English are allowed, at least for the first notification.'

Or. en

Amendment 1777

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 1 – point fb (new)

Text proposed by the CommissionAmendment
(fb) In Article 23a, paragraph 1, the following point is added:
'(fa) the single entry-point has the ability to save a partially completed notification as a draft, allows for multi-user colloberative access, and offers an automated notification systems to alert reporting entities of upcoming compliance deadlines.'

Or. en

Amendment 1778

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3a (new)

Text proposed by the CommissionAmendment
(3a) In Article 23a, the following paragraph is inserted:
'3a. The Commission should, by means of implementing acts, develop a common notification template for the single-entry point covering the Union Acts referred to in paragraph (1) that provide for notification through this single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations, including, where technically feasible, through interoperable reporting channels designed to reduce duplication of reporting obligations. In preparing the draft implementing acts, the Commission shall cooperate with ENISA, the Cooperation Group, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned.'

Or. en

Amendment 1779

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3 – points fa and fb

Text proposed by the CommissionAmendment
(3a) In Article 23a, paragraph 3, the following points are added:
'(fa) notifications submitted in English are allowed, at least for the first notification
(fb) the single entry-point has the ability to save a partially completed notification as a draft, allows for multi-user colloberative access, and offers an automated notification systems to alert reporting entities of upcoming compliance deadlines.'

Or. en

Amendment 1780

Katri Kulmuni

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3a (new)

Text proposed by the CommissionAmendment
(3a) In Article 23a, the following paragraph is inserted:
'3a. Entities shall submit incident notifications within 96 hours to the national single-entry point of their Member State of main establishment.'

Or. en

Amendment 1781

Katri Kulmuni

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3b (new)

Text proposed by the CommissionAmendment
(3b) In Article 23a, the following paragraph is inserted:
'3b. Member States shall ensure interoperability between national single-entry points, including secure and automated transmission of information where cross-border notifications are required.'

Or. en

Amendment 1782

Katri Kulmuni

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 3c (new)

Text proposed by the CommissionAmendment
(3c) In Article 23a, the following paragraph is inserted:
'3c. ENISA shall support interoperability and convergence by developing common technical standards and promoting a harmonised reporting template aligned with international standards.'

Or. en

Amendment 1783

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – Paragraph 4

Text proposed by the CommissionAmendment
(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through national single-entry points. The substantive receipt and processing of notifications shall take place at the level of the competent national authorities.

Or. en

Amendment 1784

Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 4

Text proposed by the CommissionAmendment
(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.(4) Entities shall submit incident notifications within 96 hours to the national singleentry point of their Member State of main establishment.

Or. en

Amendment 1785

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 4

Text proposed by the CommissionAmendment
(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.(4) Entities shall submit incident notifications within 96 hours to the national single entry point of their Member State of main establishment.

Or. en

Amendment 1786

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Christian Ehler

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – point 4a (new)

Text proposed by the CommissionAmendment
(4a) In Article 23a, the following paragraph is inserted:
'4a. The establishment and operation of a single-entry point represent a critical technical milestone for the Union’s cybersecurity related incidents notification framework. To ensure that the specifications developed by ENISA are technically robust, future-proof, and operationally viable, it is essential that the drafting process remains open and transparent. Therefore, ENISA should consult not only with national authorities but also with relevant industry representatives.'

Or. en

Amendment 1787

Damian Boeselager, Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 4a (new)

Text proposed by the CommissionAmendment
(4a) In Article 23a, the following paragraph is inserted:
'4a. Where the same incident triggers notification obligations under more than one Union legal act, the Member states shall designate a coordinating competent authority responsible for coordinating requests for additional information and ensuring coherent communication with the reporting entity. The coordinating competent authority will be notified to ENISA and be included in the single-entry point system.'

Or. en

Amendment 1788

Damian Boeselager, Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 4b (new)

Text proposed by the CommissionAmendment
(4b) In Article 23a, the following paragraph is inserted:
'4b. ENISA in cooperation with the coordinating competent authorities shall create a database of cases and where relevant publish at least anonymised threat intelligence, lessons learned, mitigation advice.'

Or. en

Amendment 1789

Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 5

Text proposed by the CommissionAmendment
(5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.(5) The competent authorities, including CSIRTs, shall process the notifications and, where required under Union law, transmit relevant information to ENISA. Entities shall not be required to report directly to ENISA.

Or. en

Amendment 1790

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 5

Text proposed by the CommissionAmendment
(5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.(5) The competent authorities, including CSIRTs, shall process the notifications and, where required under Union law, transmit relevant information to ENISA. Entities shall not be required to report directly to ENISA.

Or. en

Amendment 1791

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 5

Text proposed by the CommissionAmendment
(5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.(5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the EU and national single-entry points for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.

Or. en

Amendment 1792

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 6

Text proposed by the CommissionAmendment
(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.(6) Member States shall ensure interoperability between national single-entry points, including secure and automated transmission of information where crossborder notifications are required.

Or. en

Amendment 1793

Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 6

Text proposed by the CommissionAmendment
(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.(6) Member States shall ensure interoperability between national single-entry points, including secure and automated transmission of information where crossborder notifications are required.

Or. en

Amendment 1794

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 6

Text proposed by the CommissionAmendment
(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the EU and national single-entry points. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.

Or. en

Amendment 1795

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 6

Text proposed by the CommissionAmendment
(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity, availability and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.

Or. en

Amendment 1796

Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 7

Text proposed by the CommissionAmendment
(7) Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.(7) ENISA shall support interoperability and convergence by developing common technical standards and promoting a harmonised reporting template aligned with international standards.

Or. en

Amendment 1797

Alice Teodorescu Måwe, Henrik Dahl

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 7

Text proposed by the CommissionAmendment
(7) Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.(7) ENISA shall support interoperability and convergence by developing common technical standards and promoting a harmonised reporting template aligned with international standards.point and shall publish a notice in accordance with paragraph 6.

Or. en

Amendment 1798

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 7

Text proposed by the CommissionAmendment
(7) Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.(7) Where the Commission finds in its assessment that the EU and national single-entry points do not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.

Or. en

Amendment 1799

Damian Boeselager, Markéta Gregorová

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 6 – paragraph 1 – point 1

Directive (EU) 2022/2555

Article 23a – paragraph 7a (new)

Text proposed by the CommissionAmendment
(7a) In Article 23a, the following paragraph is added:
'7a. The Commission shall adopt implementing acts establishing a common Union incident reporting data model and interoperable technical specifications for all reporting obligations covered by this Regulation. The implementing act shall include a EU-wide incident taxonomy including common incident categories, common severity levels, common terminology.'

Or. en

Amendment 1800

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 6 – paragraph 1 – point 1 – point i (new)

Directive (EU) 2022/2555

Article 6 – point 42

Text proposed by the CommissionAmendment
i) In Article 6, the following point is added:
'(42) ‘Main establishment’ means the main establishment in Europe where the decisions related to the cybersecurity risk-management measures are predominantly taken. This could be the legal place of establishment, or another office address, which should be determined according to objective criteria and should imply the effective and real exercise of management activities determining the main cybersecurity decisions, including the purposes and means for those decisions. ENISA and the competent authorities shall make that list.'

Or. en

Amendment 1801

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Henrik Dahl, Christian Ehler

Proposal for a regulation

Article 6 – paragraph 1 – point 1 a (new)

Directive (EU) 2022/2555

Article 14a (new)

Text proposed by the CommissionAmendment
1a. The following Article 14a is added:
'Article 14a
Harmonised application of the NIS2 Directive
To ensure a consistent and proportionate application of Directive (EU) 2022/2555 across the Union, The Commission shall, in cooperation with the Cooperation Group referred to in Article 14 of this Directive and ENISA, issue guidance on the harmonised interpretation and application of key obligations under that Directive. Such guidance shall, in particular, address:
(a) the classification of entities as essential or important entities, including the avoidance of additional or diverging national categorisations beyond those provided for in Directive (EU) 2022/2555;
(b) the conditions under which cybersecurity audits, assessments or equivalent supervisory measures may be required, including their frequency and scope;
(c) registration, notification, and reporting obligations applicable to entities operating in more than one Member State and;
(d) the application of proportionality in supervisory and enforcement practices
Member States shall take utmost account of such guidance when implementing and applying Directive (EU) 2022/2555 and shall refrain from introducing additional obligations that would undermine the uniform application of Union law.'

Or. en

Amendment 1802

François-Xavier Bellamy

Proposal for a regulation

Article 6 – paragraph 1 – point 1 a (new)

Directive (EU) 2022/2555

Article 23a – paragraph 1a (new)

Text proposed by the CommissionAmendment
1a. ENISA shall develop and maintain a single point of contact to provide an overview of regulatory obligations regarding incident reporting, and to direct users to the various national reporting platforms.
This incident reporting information point shall identify the applicable reporting obligations, the direction to the appropriate national entry point, and make available simplified and documented information on incident notification processes in the different Member States.
The incident reporting information point shall not collect any information allowing the identification of the notifying entity or of any incident. Member States shall endeavour to design their national entry point with a view to making the national entry points interoperable with the national entry points of other Member States, to facilitate the alignment of incident notifications with cross-border reporting obligations.

Or. en

Amendment 1803

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück

Proposal for a regulation

Article 6 – paragraph 1 – point 1 a (new)

Directive (EU) 2022/2555

Article 6 – point 42

Text proposed by the CommissionAmendment
1a. In Article 6, the following point is added:
'(42) ‘Main establishment’ means the main establishment in Europe where the decisions related to the cybersecurity risk-management measures are predominantly taken. This could be the legal place of establishment, or another office address, which should be determined according to objective criteria and should imply the effective and real exercise of management activities determining the main cybersecurity decisions, including the the purposes and means for those decisions. ENISA and the competent authorities shall make that list.

Or. en

Amendment 1804

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 6 – paragraph 1 – point 1 a (new)

Directive (EU) 2022/2555

Article 14a (new)

Text proposed by the CommissionAmendment
1a. The following Article 14a is added:
'Article 14a
Harmonised application of the NIS2
Directive To ensure a consistent and proportionate application of Directive (EU) 2022/2555 across the Union,The Commission shall, in cooperation with the Cooperation Group referred to in Article 14 of this Directive and ENISA, issue guidance to contribute to a harmonised interpretation and application of key obligations under that Directive.'

Or. en

Amendment 1805

François-Xavier Bellamy

Proposal for a regulation

Article 6 – paragraph 1 – point 1 b (new)

Directive (EU) 2022/2555

Article 23a – paragraph 1b (new)

Text proposed by the CommissionAmendment
1b. By 6 months after the entry into force of this Regulation, the Commission shall submit a report to the European Parliament and to the Council outlining common elements and differences in definitions, thresholds, deadlines, formats and procedures applying to Article 23 of Directive (EU) 2022/2555, Article 19a (1a), Article 24 (2a) and Article 45a (3a) of Regulation (EU) 910/2014, Article 33 (1) of Regulation (EU) 2016/679, Article 19 (1) and (2) of Regulation (EU) 2022/2554, and Article 15(1) of Directive (EU) 2022/2557.
The report shall in particular consider concrete steps and a timeline for introducing the unified approach to incident reporting under the Union legal acts.

Or. en

Amendment 1806

Markus Buchheit

Proposal for a regulation

Article 6 – paragraph 1 – point 2 – point a

Directive (EU) 2022/2555

Article 23 – paragraph 1

Text proposed by the CommissionAmendment
Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entry point established pursuant to Article 23a.Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority of any incident having a significant impact on the provision of their services. Member States may provide for national digital reporting channels for that purpose. Notification through tools referred to in Article 23a may be required only in cases of cross-border or Union-wide systemic relevance.

Or. en

Amendment 1807

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 2 – point a

Directive (EU) 2022/2555

Article 23 – paragraph 1

Text proposed by the CommissionAmendment
Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entry point established pursuant to Article 23a.Each Member State shall ensure that their national single-entry points notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) to the EU single-entry point established pursuant to Article 23a.

Or. en

Amendment 1808

Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Henrik Dahl, Christian Ehler

Proposal for a regulation

Article 6 – paragraph 1 – point 2 a (new)

Directive (EU) 2022/2555

Article 26 – paragraph 1 – point ca (new)

Text proposed by the CommissionAmendment
2a. In Article 26, paragraph 1 the following point is added:
‘(ca) Manufacturers referred to in Annex II of this Directive shall be considered to fall under the jurisdiction of the Member State in which they have their main establishment in the Union under paragraph 2.'

Or. en

Amendment 1809

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 6 – paragraph 1 – point 3

Directive (EU) 2022/2555

Article 30 – paragraph 1

Text proposed by the CommissionAmendment
1. Member States shall ensure that, in addition to the notification obligation provided for in Article 23, notifications can be submitted to the CSIRTs or, where applicable, the competent authorities, on a voluntary basis via the single-entry point established pursuant to Article 23a, by:1. Member States shall ensure that, in addition to the notification obligation provided for in Article 23, notifications can be submitted to the CSIRTs or, where applicable, the competent authorities, on a voluntary basis to the EU single-entry point established pursuant to Article 23a, by:

Or. en

Amendment 1810

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 6 – paragraph 1 – point 3 a (new)

Directive 2022/2555

Article 32 – paragraph 7 – point a – point ii

Text proposed by the CommissionAmendment
3a. In Article 32, paragraph 7, point a(ii) is amended as follows:
(ii) A failure to notify or remedy significant cyber incidents via the SEP-portal.

Or. en

Amendment 1811

Markus Buchheit

Proposal for a regulation

Article 7

Regulation (EU) 910/2014

Article 7

Text proposed by the CommissionAmendment
Article 7deleted
Amendment of Regulation (EU) 910/2014
Regulation (EU) 910/2014 is amended as follows:
1. in Article 19a, the following paragraph 1a is inserted:
‘1a. Notifications pursuant to paragraph 1, point (b) of this Article to the supervisory body and, where applicable, to other relevant competent authorities, shall be made through the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.;
‘2a. Notifications pursuant to in paragraph 2, point (fb), of this Article to the supervisory body and, where applicable, to other relevant competent bodies, shall be made through the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.;
‘3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.

Or. en

Amendment 1812

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 7 – paragraph 1 – point 1

Regulation (EU) 910/2014

Article 19a – paragraph 1a

Text proposed by the CommissionAmendment
1a. Notifications pursuant to paragraph 1, point (b) of this Article to the supervisory body and, where applicable, to other relevant competent authorities, shall be made through the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.;1a. Notifications pursuant to paragraph 1, point (b) of this Article to the supervisory body and, where applicable, to other relevant competent authorities, shall be made by the national single-entry points to the EU single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.;

Or. en

Amendment 1813

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 7 – paragraph 1 – point 2

Regulation (EU) 910/2014

Article 24 – paragraph 2a

Text proposed by the CommissionAmendment
2a. Notifications pursuant to in paragraph 2, point (fb), of this Article to the supervisory body and, where applicable, to other relevant competent bodies, shall be made through the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.;2a. Notifications pursuant to in paragraph 2, point (fb), of this Article to the supervisory body and, where applicable, to other relevant competent bodies, shall be made by the national single-entry points to the EU single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.;

Or. en

Amendment 1814

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 7 – paragraph 1 – point 3

Regulation (EU) 910/2014

Article 45a – paragraph 3a

Text proposed by the CommissionAmendment
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made by the national single-entry points to the EU the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.

Or. en

Amendment 1815

Markus Buchheit

Proposal for a regulation

Article 8

Regulation (EU) 2022/2554

Article 19

Text proposed by the CommissionAmendment
Article 8deleted
Amendments to Regulation (EU) 2022/2554
Article 19 of Regulation (EU) 2022/2554 is amended as follows:
1. in paragraph 1, the first subparagraph is replaced by the following:
‘Financial entities shall report major ICT-related incidents to the relevant competent authority as referred to in Article 46 via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 in accordance with paragraph 4 of this Article.
‘Financial entities may, on a voluntary basis, notify via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 significant cyber threats to the relevant competent authority when they deem the threat to be of relevance to the financial system, service users or clients. The relevant competent authority may provide such information to other relevant authorities referred to in paragraph 6.

Or. en

Amendment 1816

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 8 – paragraph 1 – point 1

Regulation (EU) 2022/2554

Article 19 – paragraph 1 – first subparagraph

Text proposed by the CommissionAmendment
Financial entities shall report major ICT-related incidents to the relevant competent authority as referred to in Article 46 via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 in accordance with paragraph 4 of this Article.Financial entities shall report major ICT-related incidents to the relevant competent authority as referred to in Article 46 by the national single-entry points to the EU single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 in accordance with paragraph 4 of this Article.

Or. en

Amendment 1817

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 8 – paragraph 1 – point 2

Regulation (EU) 2022/2554

Article 19 – paragraph 2 – first subparagraph

Text proposed by the CommissionAmendment
Financial entities may, on a voluntary basis, notify via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 significant cyber threats to the relevant competent authority when they deem the threat to be of relevance to the financial system, service users or clients. The relevant competent authority may provide such information to other relevant authorities referred to in paragraph 6.Financial entities may, on a voluntary basis, notify by the national single-entry points to the EU single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 significant cyber threats to the relevant competent authority when they deem the threat to be of relevance to the financial system, service users or clients. The relevant competent authority may provide such information to other relevant authorities referred to in paragraph 6.

Or. en

Amendment 1818

Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 8 – paragraph 1 – point 2 a (new)

Regulation (EU) 2022/2554

Article 19 – paragraph 8a (new)

Text proposed by the CommissionAmendment
2a. In Article 19, paragraph 8a is added:
'8a. The Commission shall adopt delegated acts that lay down the specifications of a European template for reporting obligations under the single-entry point. Those delegated acts may harmonize reporting timelines, deadlines, thesholds and other data points in under this Act with those of other Union Acts. Those delegated acts shall be adopted in accordance with the examination procedure referred to in Article 57.'

Or. en

Amendment 1819

Markus Buchheit

Proposal for a regulation

Article 9

Regulation (EU) 2022/2557

Article 15

Text proposed by the CommissionAmendment
Article 9deleted
Amendments to Directive (EU) 2022/2557
Article 15 of Directive (EU) 2022/2557 is amended as follows:
1. in paragraph 1, the first sentence is replaced as follows:
‘Member States shall ensure that critical entities notify via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 the competent authority, without undue delay, of incidents that significantly disrupt or have the potential to significantly disrupt the provision of essential services.;
‘The Commission may adopt implementing acts further specifying the type and format of information notified pursuant to Article 15(1). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 24(2).

Or. en

Amendment 1820

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 9 – paragraph 1 – point 1

Directive (EU) 2022/2557

Article 15 – paragraph 1 – first sentence

Text proposed by the CommissionAmendment
Member States shall ensure that critical entities notify via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555 the competent authority, without undue delay, of incidents that significantly disrupt or have the potential to significantly disrupt the provision of essential services.;Member States shall ensure that critical entities notify by the national single-entry points to the EU single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555, through the competent authority, without undue delay, of incidents that significantly disrupt or have the potential to significantly disrupt the provision of essential services.;

Or. en

Amendment 1821

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 9 – paragraph 1 – point 2

Directive (EU) 2022/2557

Article 15 – paragraph 2 – subparagraph

Text proposed by the CommissionAmendment
The Commission may adopt implementing acts further specifying the type and format of information notified pursuant to Article 15(1). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 24(2).deleted

Or. en

Amendment 1822

Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück

Proposal for a regulation

Article 9 a (new)

Regulation (EU) 2024/1689

Article 3 and Article 73

Text proposed by the CommissionAmendment
Article9a
Amendments to Regulation (EU) 2024/1689 (AI Act)
Regulation (EU) 2024/1689 is amended as follows:
1. In Article 3, point (49) is replaced by the following:
'(49) ‘Significant incident’ means an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following:
(a) the death of a person, or serious harm to a person’s health;
(b) a serious and irreversible disruption of the management or operation of critical infrastructure;
(c) the infringement of obligations under Union law intended to protect fundamental rights;
(d) serious harm to property or the environment.'
2. Article 73 is amended as follows:
In paragraph 1, the first sentence is replaced by the following:
‘1.Providers of high-risk AI systems placed on the Union market shall report any significant incident via the single-entry point established pursuant to Article 23a of Directive (EU) 2022/2555, which it forwards to the market surveillance authorities of the Member States where that incident occurred without undue delay.’
In paragraph 2, the following sub-paragraph is added:
‘The Commission shall adopt delegated acts that lay down the specifications of a European template for reporting obligations under the single-entry point. Those delegated acts may harmonize reporting timelines, deadlines, thesholds and other data points in under this Act with those of other Union Acts. Those delegated acts shall be adopted in accordance with the examination procedure referred to in Article XX.’

Or. en

Amendment 1823

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová

Proposal for a regulation

Article 9 a (new)

Regulation (EU) 2024/2847

Article 14 – paragraph 8 – point a (new)

Text proposed by the CommissionAmendment
Article9a
Amendments to Regulation (EU) 2024/2847
In Article 14, the following paragraph 8a is inserted:
'8a. A notification made by a manufacturer pursuant to Article 23(4) of Directive (EU) 2022/2555 which contains the information required under paragraph 3 of this Article shall be deemed to satifisfy compliance with the reporting obligation under that paragraph. The Commission shall adopt delegated acts that lay down the specifications of a European template for reporting obligations under the single-entry point. Those delegated acts may harmonize reporting timelines, deadlines, thesholds and other data points in under this Act with those of other Union Acts. Those delegated acts shall be adopted in accordance with the examination procedure referred to in Article 61.'

Or. en

Amendment 1824

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 10 – title

Regulations 2019/1150/EU, (EU) 2022/868, (EU) 2018/1807 and Directive 2019/1024

Text proposed by the CommissionAmendment
Repeals and transitory clausesAmendments, repeals and transitory clauses

Or. en

Amendment 1825

João Oliveira

Proposal for a regulation

Article 10.º – paragraph 1

Regulation (EU) 2019/1150

Text proposed by the CommissionAmendment
1. Regulation 2019/1150/EU is repealed with effect from [date = entry into application of this Regulation].deleted

Or. pt

Amendment 1826

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 10 – paragraph 1

Regulation (EU) 2019/1150

Text proposed by the CommissionAmendment
1. Regulation 2019/1150/EU is repealed with effect from [date = entry into application of this Regulation].deleted

Or. en

Amendment 1827

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 10 – paragraph 1

Regulation (EU) 2019/1150

Text proposed by the CommissionAmendment
1. Regulation 2019/1150/EU is repealed with effect from [date = entry into application of this Regulation].deleted

Or. en

Amendment 1828

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 10 – paragraph 1

Regulation (EU) 2019/1150

Text proposed by the CommissionAmendment
1. Regulation 2019/1150/EU is repealed with effect from [date = entry into application of this Regulation].deleted

Or. en

Justification

The P2B regulation constitues the sole legal framework protecting business users in their commercial relations with online platforms. Indeed, neither the Digital Services Act, nor the Digital Markets Act, is capable of providing equivalent safeguards. The repeal of the P2B Regulation would therefore deprive the vast majority of SMEs of an any effective protection against unfair platform practices, without any substitute mechanism being provided for.

Amendment 1829

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 10 – paragraph 1

Regulation (EU) 2019/1150

Text proposed by the CommissionAmendment
1. Regulation 2019/1150/EU is repealed with effect from [date = entry into application of this Regulation].deleted

Or. en

Amendment 1830

Alex Agius Saliba

Proposal for a regulation

Article 10 – paragraph 1

Regulation (EU) 2019/1150

Text proposed by the CommissionAmendment
1. Regulation 2019/1150/EU is repealed with effect from [date = entry into application of this Regulation].deleted

Or. en

Justification

The full repeal of the P2B, even with a sunset clause, leaves gaps for protecting business users (SMEs). Instead the Commission should do an impact assessment analysing the exact overlaps with other laws such as the e-commerce Directive, DSA and DMA rather than repealing it in full in this omnibus.

Amendment 1831

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 10 – paragraph 1

Regulation (EU) 2019/1150

Text proposed by the CommissionAmendment
1. Regulation 2019/1150/EU is repealed with effect from [date = entry into application of this Regulation].1. Regulation 2019/1150/EU is amended as follows:
Articles 2(11), 2(12), 6, 8 to 10, 12 to 14, 16, 17, and 18 paragraphs (2) to (4), are deleted as of [date = entry into application of this Regulation].

Or. en

Justification

Regulation (EU) 2019/1150 fills a gap that is not fully covered by Regulation (EU) 2022/2065 or Regulation (EU) 2022/1925. To avoid overlaps while keeping safeguards for SMEs that rely on online intermediaries, some provisions in Regulation (EU) 2019/1150 should be maintained.

Amendment 1832

Tomas Tobé, Arba Kokalari, Jörgen Warborn

Proposal for a regulation

Article 10 – paragraph 2

Regulation (EU) 2019/1150

Articles 2 – paragraphs 1, 2 and 5, Articles 4, 11, 15

Text proposed by the CommissionAmendment
2. By way of derogation from paragraph 1, the following provisions shall continue to apply until 31 December 2032:deleted
(a) Article 2, point (1);
(b) Article 2, point (2);
(c) Article 2, point (5);
(d) Article 4;
(e) Article 11;
(f) Article 15.

Or. en

Amendment 1833

Alex Agius Saliba

Proposal for a regulation

Article 10 – paragraph 2

Regulation (EU) 2019/1150

Articles 2 – paragraphs 1, 2 and 5, Articles 4, 11, 15

Text proposed by the CommissionAmendment
2. By way of derogation from paragraph 1, the following provisions shall continue to apply until 31 December 2032:deleted
(a) Article 2, point (1);
(b) Article 2, point (2);
(c) Article 2, point (5);
(d) Article 4;
(e) Article 11;
(f) Article 15.

Or. en

Amendment 1834

Damian Boeselager

on behalf of the Verts/ALE Group

Proposal for a regulation

Article 10 – paragraph 2

Regulation (EU) 2019/1150

Articles 2 – paragraphs 1, 2 and 5, Articles 4, 11, 15

Text proposed by the CommissionAmendment
2. By way of derogation from paragraph 1, the following provisions shall continue to apply until 31 December 2032:deleted
(a) Article 2, point (1);
(b) Article 2, point (2);
(c) Article 2, point (5);
(d) Article 4;
(e) Article 11;
(f) Article 15.

Or. en

Amendment 1835

Michael McNamara, Irena Joveva, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Christophe Grudler

Proposal for a regulation

Article 10 – paragraph 2

Regulation (EU) 2019/1150

Articles 2 – paragraphs 1, 2 and 5, Articles 4, 11, 15

Text proposed by the CommissionAmendment
2. By way of derogation from paragraph 1, the following provisions shall continue to apply until 31 December 2032:deleted
(a) Article 2, point (1);
(b) Article 2, point (2);
(c) Article 2, point (5);
(d) Article 4;
(e) Article 11;
(f) Article 15.

Or. en

Amendment 1836

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 10 – paragraph 2

Regulation (EU) 2019/1150

Articles 2 – paragraphs 1, 2 and 5, Articles 4, 11, 15

Text proposed by the CommissionAmendment
2. By way of derogation from paragraph 1, the following provisions shall continue to apply until 31 December 2032:deleted
(a) Article 2, point (1);
(b) Article 2, point (2);
(c) Article 2, point (5);
(d) Article 4;
(e) Article 11;
(f) Article 15.

Or. en

Amendment 1837

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 10 – paragraph 2

Regulation (EU) 2019/1150

Articles 2 – paragraphs 1, 2 and 5, Articles 4, 11, 15

Text proposed by the CommissionAmendment
2. By way of derogation from paragraph 1, the following provisions shall continue to apply until 31 December 2032:deleted
(a) Article 2, point (1);
(b) Article 2, point (2);
(c) Article 2, point (5);
(d) Article 4;
(e) Article 11;
(f) Article 15.

Or. en

Justification

The proposed repeal, even with a sunset clause, risks leaving SMEs unprotected. Instead, the Commission should first carry out an impact assessment identifying overlaps with the E-Commerce Directive, the Digital Services Act and the Digital Markets Act. Failing that, provisions whose repeal would reduce protection for SMEs, particularly vis-à-vis intermediaries that are not DMA gatekeepers, should be retained.

Amendment 1838

João Oliveira

Proposal for a regulation

Article 10.º – paragraph 2

Regulation (EU) 2019/1150

Articles 2 – paragraphs 1, 2 and 5, Articles 4, 11, 15

Text proposed by the CommissionAmendment
2. By way of derogation from paragraph 1, the following provisions shall continue to apply until 31 December 2032:deleted
(a) Article 2, point (1);
(b) Article 2, point (2);
(c) Article 2, point (5);
(d) Article 4;
(e) Article 11;
(f) Article 15.

Or. pt

Amendment 1839

Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay

Proposal for a regulation

Article 10 – paragraph 3 – introductory part

Regulation (EU) 2022/868, Regulation (EU) 2018/1807 and Directive (EU) 2019/1024

Text proposed by the CommissionAmendment
3. The following acts are repealed, with effect from [Date, aligned with the entry into application of the amendments]:3. The following acts are repealed, with effect from [Date, aligned with the entry into application of the amendments], provided that the Commission has first carried out a comprehensive impact assessment and identified any substantive provisions in those acts whose repeal would go beyond the objective of legislative simplification, in particular where their removal would materially affect the fundamental rights of data subjects, the public or economic security of the Member States, or the strategic interests of the Union.

Or. en

Justification

Appropriate recovery vehicles should be provided for the recitals and provisions of the repealed acts — such as the reinstatement of the useful recitals in the preamble, the carrying-over of the definitions into Article 2, the repatriation of the operative provisions into the corresponding chapters, and bridging clauses ensuring legal continuity — it being understood that the target architecture rests on two central acts, Regulation (EU) 2016/679 (GDPR) and Regulation (EU) 2023/2854 (Data Act), into which the useful substance is to be repatriated. Particular care is required for Regulation (EU) 2022/868 (Data Governance Act), whose recitals carry a substantial part of the normative meaning — trust, neutral intermediation, collective governance, altruism, secure processing environments — which would be lost without explicit carry-over; for Directive (EU) 2019/1024 (Open Data Directive), whose recitals and annexes on high-value data sets and the open-by-design principle must be preserved; and, to a lesser but non-negligible extent, for the acts only partially affected — Regulation (EU) 2018/1807 (free flow of non-personal data), whose non-localisation principle is retained in the Data Act, and Directive 2002/58/EC (ePrivacy), whose security and confidentiality safeguards must not be lost when the rules are moved into the GDPR.

Amendment 1840

Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba

Proposal for a regulation

Article 10 – paragraph 3 – point c

Directive (EU) 2019/1024

Text proposed by the CommissionAmendment
c) Directive 2019/1024.deleted

Or. en