Text · Amendment list
Information security in the institutions, bodies, offices and agencies of the Union
Document LIBE-AM-752883 · COM(2022)0119 – C9-0121/2022 – 2022/0084(COD)
- Kind
- Amendment list LIBE-AM-752883
- Date
- 7 September 2023
- Committee
- Committee on Civil Liberties, Justice and Home Affairs
- Dossier
- 2022-0084
More facts (2)
- Formats
- Official page PDF Word
- Reference
- COM(2022)0119 – C9-0121/2022 – 2022/0084(COD)
Text
The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.
Jump to an amendment (148)
- Amendment 34
- Amendment 35
- Amendment 36
- Amendment 37
- Amendment 38
- Amendment 39
- Amendment 40
- Amendment 41
- Amendment 42
- Amendment 43
- Amendment 44
- Amendment 45
- Amendment 46
- Amendment 47
- Amendment 48
- Amendment 49
- Amendment 50
- Amendment 51
- Amendment 52
- Amendment 53
- Amendment 54
- Amendment 55
- Amendment 56
- Amendment 57
- Amendment 58
- Amendment 59
- Amendment 60
- Amendment 61
- Amendment 62
- Amendment 63
- Amendment 64
- Amendment 65
- Amendment 66
- Amendment 67
- Amendment 68
- Amendment 69
- Amendment 70
- Amendment 71
- Amendment 72
- Amendment 73
- Amendment 74
- Amendment 75
- Amendment 76
- Amendment 77
- Amendment 78
- Amendment 79
- Amendment 80
- Amendment 81
- Amendment 82
- Amendment 83
- Amendment 84
- Amendment 85
- Amendment 86
- Amendment 87
- Amendment 88
- Amendment 89
- Amendment 90
- Amendment 91
- Amendment 92
- Amendment 93
- Amendment 94
- Amendment 95
- Amendment 96
- Amendment 97
- Amendment 98
- Amendment 99
- Amendment 100
- Amendment 101
- Amendment 102
- Amendment 103
- Amendment 104
- Amendment 105
- Amendment 106
- Amendment 107
- Amendment 108
- Amendment 109
- Amendment 110
- Amendment 111
- Amendment 112
- Amendment 113
- Amendment 114
- Amendment 115
- Amendment 116
- Amendment 117
- Amendment 118
- Amendment 119
- Amendment 120
- Amendment 121
- Amendment 122
- Amendment 123
- Amendment 124
- Amendment 125
- Amendment 126
- Amendment 127
- Amendment 128
- Amendment 129
- Amendment 130
- Amendment 131
- Amendment 132
- Amendment 133
- Amendment 134
- Amendment 135
- Amendment 136
- Amendment 137
- Amendment 138
- Amendment 139
- Amendment 140
- Amendment 141
- Amendment 142
- Amendment 143
- Amendment 144
- Amendment 145
- Amendment 146
- Amendment 147
- Amendment 148
- Amendment 149
- Amendment 150
- Amendment 151
- Amendment 152
- Amendment 153
- Amendment 154
- Amendment 155
- Amendment 156
- Amendment 157
- Amendment 158
- Amendment 159
- Amendment 160
- Amendment 161
- Amendment 162
- Amendment 163
- Amendment 164
- Amendment 165
- Amendment 166
- Amendment 167
- Amendment 168
- Amendment 169
- Amendment 170
- Amendment 171
- Amendment 172
- Amendment 173
- Amendment 174
- Amendment 175
- Amendment 176
- Amendment 177
- Amendment 178
- Amendment 179
- Amendment 180
- Amendment 181
| Text proposed by the Commission | Amendment |
|---|---|
| Having regard that for the effective exercise of their mandate in accordance with the Treaties, Members of Parliament shall have access to all types of information based on a need-to-know; |
| Text proposed by the Commission | Amendment |
|---|---|
| Having regard to the specificity of the mandate of Members of Parliament elected in EU Member States and to the separation of powers between the executive and legislative branches, and as a result, that Members shall be exempted from a security vetting procedure by national security authorities; |
| Text proposed by the Commission | Amendment |
|---|---|
| (1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected. | (1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable or impregnable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected, as well as on the interoperability of such tools. |
| Text proposed by the Commission | Amendment |
|---|---|
| (1a) Given that Union institutions are obliged to apply Article 15(3) TFEU in line with democratic principles, in particular those laid down in Article 10(3) TEU and Article 42 of the Charter of Fundamental Rights of the European Union (‘the Charter’), the European Union classified information (‘EUCI’) system should adhere to the principles of data classification minimisation and time limitation for any such classification. |
| Text proposed by the Commission | Amendment |
|---|---|
| (1a) There are concerns surrounding the fact that the Commission and the European External Action Service (EEAS) are putting in place two concurrent initiatives to collaborate with private companies on cybersecurity threats. |
| Text proposed by the Commission | Amendment |
|---|---|
| (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. | (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Interinstitutional cooperation and trust is key to protecting, in an efficient and effective manner, the Information security environment of the Union. Further efforts should therefore be made to enable an interinstitutional approach based on increased synergies to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. |
| Text proposed by the Commission | Amendment |
|---|---|
| (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. | (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. An interinstitutional approach to the sharing of EUCI and sensitive non-classified information should be set up, with common categories of information and common key handling principles. Procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States should be simplified. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. | (3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down, especially as the cybersecurity threats are growing and many national bodies have been attacked. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. | (3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and common minimum standards. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) This Regulation lays down rules applicable to the administration of the all Union institutions and bodies, but it does not include the Commissioners, the Representatives of Member States acting within the Council, the Members of the European Parliament, the Judges of the Union Courts or the Members of the European Court of Auditors who are subject to their internal rules. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) Article 15 TFEU states that the Unions’ institutions, bodies, offices and agencies shall conduct their work as openly as possible, and that every citizen of the Union shall have a right of access to documents. Accordingly, every classification of documents shall take place in the light of these overarching principles. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) Whereas the Treaties attribute powers to the different Union institutions. For these powers to be exercised effectively, Members thereof should have access by virtue of their mandate to all necessary information on the basis of a need-to-know. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) Members of the Union institutions should have access by virtue of their mandate to all necessary information on the basis of the ‘need-to-know principle’ in order to exercise the powers vested to them by the Treaties. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) EU governments should keep ownership of their sensitive information. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3b) In order to ensure the effectiveness of this Regulation it would be appropriate to assess whether the internal rules applicable to Commissioners, the Representatives of Member States acting within the Council, the Members of the European Parliament, the Judges of the Union Courts or the Members of the European Court of Auditors are in line with the common minimum level of protection established by this Regulation and make the modifications needed, if this is not the case. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3b) In the context of information security, Union institutions and bodies should increase organisational interoperability and take joint action to ensure that networks, information systems, data, and all material assets employed to capture, store, process and transmit the information are duly protected. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3c) Access to information in a secure manner and in a context of mutual trust is essential for the European co-legislators to exercise their functions and not to be restricted in the exercise of their democratic functions; Members of the European Parliament exercise this legislative function and their access to information should therefore be governed by rules comparable in requirements to the common minimum standards established by this Regulation. |
| Text proposed by the Commission | Amendment |
|---|---|
| (4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. | (4) The recent pandemic expedited the significant underlying transformation in working practices, with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy. | (5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy. This minimum common level of protection for EUCI should ensure a careful balance between transparency and the use of classification in a way that prevents the EU bodies from carrying out their role. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy. | (5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy. Due account should also be taken that the measures do not negatively affect the Union entities’ efficient information exchange and operations with other Union entities and national competent authorities. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5a) Sharing of EUCI in a transparent and timely manner is paramount for the proper functioning of Union institutions and bodies. When implementing this Regulation, Union institutions and bodies should strive to enhance transparency, minimise and limit in time the use of confidential documents, provide safeguards against the use of classification in a manner that would prevent Union entities from fulfilling their mission, and ensure that whistle-blowers are adequately protected and that there is a high level of protection of information in line with Union law and best practices. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5a) This Regulation should ensure that any limitation of the right to the protection of personal data and privacy is necessary and proportionate and respect the essence of the right in accordance with Article 52(1) of the Charter of Fundamental Rights of the European Union. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5b) All information security measures involving processing of personal data should be compliant with the relevant Union data protection and privacy law. Union institutions and bodies should provide relevant technical and organisational safeguards to ensure compliance in an accountable, transparent and justified manner. |
| Text proposed by the Commission | Amendment |
|---|---|
| (6a) Most of the information on cyberthreats relates to the vulnerabilities exploited, in other words the weaknesses hackers exploit to obtain unauthorised access. The European Union Agency for Cybersecurity (ENISA) may not have sufficient capacity to deal with the volume of reports received from product manufacturers about such vulnerabilities. Member States would prefer these notifications to be sent to the national computer security incident response teams (CSIRT). |
| Text proposed by the Commission | Amendment |
|---|---|
| (7a) In order to preserve the specific nature of the European Central Bank’s (ECB) tasks and activities as part of the European System of Central Banks (ESCB) and the Single Supervisory Mechanism (SSM), which are performed in cooperation with the national central banks and national competent authorities, this Regulation should not apply to ESCB and SSM Information. |
| Text proposed by the Commission | Amendment |
|---|---|
| (8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. | (8) With a view to establishing a formal common and uniform structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| (9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks. | (9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to reduce administrative burden and prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks. |
| Text proposed by the Commission | Amendment |
|---|---|
| (10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. | (10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group, while respecting the prerogatives of the Member States as regards confidential security data. |
| Text proposed by the Commission | Amendment |
|---|---|
| (10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. | (10) The Coordination Group should closely cooperate with the Classification Authority of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. |
| Text proposed by the Commission | Amendment |
|---|---|
| (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each institution and body. | (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the common minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the needs and specificities of each institution and body. |
| Text proposed by the Commission | Amendment |
|---|---|
| (13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes or in the exchange of information with their particular counterparts from other institutions and bodies or from the Member States. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures. | (14) With the purpose of adjusting to the new teleworking practices, the network information systems, digital infrastructure, and terminal devices used for connecting to the Union institution’s or body’s remote access services should be protected by state of the art security measures. |
| Text proposed by the Commission | Amendment |
|---|---|
| (14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures. | (14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures, through investment in end-to-end network security. |
| Text proposed by the Commission | Amendment |
|---|---|
| (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. | (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Such provisions should include, inter alia, a requirement in the tender procedures to undergo thorough vetting, taking into account the full range of the supply chain and economic and political environment in which the third parties operate. Where the relationships with third parties pose a risk to the integrity of democratic processes in the EU, they should be terminated without undue delay. |
| Text proposed by the Commission | Amendment |
|---|---|
| (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. | (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security and to verify the quality and confidentiality of external contractors. |
| Text proposed by the Commission | Amendment |
|---|---|
| (16) The substantive rules regarding access to EUCI in the internal rules of various Union institutions and bodies are currently aligned, but there are significant differences as regards denominations and required procedures. This creates a burden for the National Security Authorities of the Member States who need to adjust to different requirements. Thus it is necessary to provide for a common glossary and common procedures in the area of personnel security, thereby simplifying cooperation with the National Security Authorities of the Member States and limiting the risk of compromising EUCI. | (16) The substantive rules regarding access to EUCI in the internal rules of various Union institutions and bodies are currently aligned, but there are significant differences as regards denominations and required procedures. Thus it is necessary to provide for a common glossary and common procedures in the area of personnel security, thereby limiting the risk of compromising EUCI. |
| Text proposed by the Commission | Amendment |
|---|---|
| (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. | (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. A thorough evaluation of security infrastructure, including services, should be carried out, encompassing all aspects of the operational chain and environment. |
| Text proposed by the Commission | Amendment |
|---|---|
| (20) Originator control is an important principle in the EUCI management, therefore it needs to be clearly stipulated and developed. In that regard, the creation of EUCI confers to the originator a responsibility which should cover the entire life cycle of the relevant EUCI document. | (20) Originator control is a principle in the EUCI management, therefore it needs to be taken into account. In that regard, the creation of EUCI confers to the originator a responsibility at the beginning of the life cycle of the relevant EUCI document. |
| Text proposed by the Commission | Amendment |
|---|---|
| (21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling and storing both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. | (21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling, storing, and transmitting both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. |
| Text proposed by the Commission | Amendment |
|---|---|
| (21a) Information held by the Union entities is also exchanged through the ICT environment, on-premises or through virtual assets, ICT products, ICT services and ICT processes, as well as networks and information systems whether owned and operated by a Union entity or hosted or operated by a third party, including mobile devices, corporate networks, and business networks not connected to the internet and any devices connected to the ICT environment. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation lays down information security rules for all Union institutions and bodies. | 1. This Regulation lays down a minimum set of common and uniform information security rules for all Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation lays down information security rules for all Union institutions and bodies. | 1. This Regulation lays down common minimum information security rules for all Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. This Regulation is without prejudice to Regulation (EC) 1049/2001 of the European Parliament and of the Council. Nothing in this Regulation, in particular the provisions on EUCI, may be used to restrict the right of access to documents of the Union institutions, bodies, offices and agencies beyond the applicable legislation on such access. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community, other than Euratom Classified Information. | 1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community, other than Euratom Classified Information, and excluding information related to the ECB’s tasks and activities within the ESCB and the SSM. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. This Regulation is without prejudice to Regulation (Euratom) No 3/1958[1], Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community[2], Regulation (EC) 1049/2001 of the European Parliament and of the Council[3], Regulation (EU) 2018/1725 of the European Parliament and of the Council[4], Council Regulation (EEC, EURATOM) No 354/83[5], Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council[6], Regulation (EU) 2021/697 of the European Parliament and of the Council[7], Regulation (EU) [...] of the European Parliament and of the Council[8] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union.[KL1] [1] Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406). [2] OJ 45, 14.6.1962, p. 1385. [3] Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43). [4] Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39). [5] Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1). [6] Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1). [7] Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149). [8] Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. This Regulation does not apply to the Commissioners, the Representatives of Member States acting within the Council, the Members of the European Parliament, the Judges of the Union Courts or the Members of the European Court of Auditors. In order to ensure the effectiveness of the Regulation and not to create any gap within the information security system or any discrepancies among people within the same institution, this institutions and bodies shall adopt internal rules aligned with this Regulation. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) three levels of non-classified information: public use, normal and sensitive non-classified; | (a) three levels of non-classified information: public use, normal and protected non-classified; |
| (This amendment applies throughout the text. Adopting it will necessitate corresponding changes throughout.) |
Only CONFIDENTIEL UE/EU CONFIDENTIAL, SECRET UE/EU SECRET, TRES SECRET UE/EU TOP SECRET are called ‘sensitive’ in Article 9 of Regulation 1049/2001. In order to avoid confusion, a different terminology should be used.
| Text proposed by the Commission | Amendment |
|---|---|
| (b) four levels of EU classified information: RESTREINT UE/EU RESTRICTED, CONFIDENTIEL UE/EU CONFIDENTIAL, SECRET UE/EU SECRET, TRES SECRET UE/EU TOP SECRET. | (b) three levels of EU classified information: CONFIDENTIEL UE/EU CONFIDENTIAL, SECRET UE/EU SECRET, TRES SECRET UE/EU TOP SECRET. |
| (This amendment applies throughout the text. Adopting it will necessitate corresponding changes throughout.) |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. These levels are based on the damage that unauthorised disclosure may cause to the legitimate private and public interests, including those of the Union, Union institutions and bodies and Member States or other stakeholders, so that the appropriate protective measures can be applied. | 3. These levels are based on the damage that unauthorised disclosure may cause to the legitimate public interests, including those of the Union, Union institutions and bodies and Member States or other stakeholders, so that the appropriate protective measures can be applied. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. Members of the Union Institutions shall have access to all types of information on the basis of a need-to-know for the effective exercise of their mandate in accordance with the Treaties. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Non-compliance with this Regulation, in particular the unauthorised disclosure of information with the confidentiality levels referred to in Article 2(2), except information for public use shall be subject to investigation and may trigger personnel liability in accordance with the Treaties or with their relevant staff rules. | 2. Non-compliance with this Regulation, in particular the unauthorised disclosure of information with the confidentiality levels referred to in Article 2(2), except information for public use shall be subject to investigation and may trigger personnel liability in accordance with the Treaties or with their relevant staff rules with due regard to the provisions on the disclosure of facts which give rise to a presumption of the existence of possible illegal activity, including fraud or corruption, detrimental to the interests of the Union, or of conduct relating to the discharge of professional duties which may constitute a serious failure to comply with the professional obligations, as well as the protection of persons who report breaches of Union law. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Union institutions and bodies shall assess all information they handle and store in order to categorise it in accordance with the confidentiality levels referred to in Article 2(2). | 3. Whithout prejudice to Article 15 TFEU, Union institutions and bodies shall assess all information they handle and store in order to categorise it in accordance with the confidentiality levels referred to in Article 2(2). |
| Text proposed by the Commission | Amendment |
|---|---|
| (d) integrity: the fact that the information is complete and completeness of information is unaltered; | (d) integrity: the fact that the information is complete and completeness of information is unaltered and the fact that the technical infrastructure used to share information is protected from any foreign interference; |
| Text proposed by the Commission | Amendment |
|---|---|
| Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. | Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. Union entities shall, not later than six months after the date of entry into force of this Regulation, design and implement effective and appropriate training courses for all individuals authorised to access EUCI, commensurate to the risks identified in accordance with Article 5. |
| Text proposed by the Commission | Amendment |
|---|---|
| (aa) the risks to the rights and freedoms of natural persons; |
| Text proposed by the Commission | Amendment |
|---|---|
| (f) business continuity and disaster recovery; | (f) business continuity, crisis management and disaster recovery; |
| Text proposed by the Commission | Amendment |
|---|---|
| The appointed members of the Coordination Group shall be adequately gender and geographically balanced. |
| Text proposed by the Commission | Amendment |
|---|---|
| (aa) adopt decisions on the establishment of thematic sub-groups, their terms of reference and the regularity of their meetings; |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) monitor compliance by Union institutions and bodies with this Regulation as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report, which shall compile input from the relevant sub-groups. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) monitor compliance by Union institutions and bodies with this Regulation, as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report; |
| Text proposed by the Commission | Amendment |
|---|---|
| 6. Each Union institution or body shall be appropriately represented in the Coordination Group and where applicable, in the thematic sub-groups. | 6. Each Union institution or body shall be appropriately represented in the Coordination Group. The Parliament, the Commission and the Council shall be represented in all thematic sub-groups. Other institutions and bodies where applicable. |
| Text proposed by the Commission | Amendment |
|---|---|
| 7. Union institutions and bodies shall bring to the attention of the Coordination Group any significant information security policy development within their organisation. | 7. Union institutions and bodies shall bring to the attention of the Coordination Group any significant information security policy development within their organisation without undue delay. |
| Text proposed by the Commission | Amendment |
|---|---|
| 8. In the performance of the tasks referred to in paragraph 2, point (e), the Coordination Group shall be assisted by an Information Security Committee. That Committee shall be composed of one representative from each National Security Authority and shall be chaired by the Secretariat of the Coordination Group, referred to in paragraph 5. The Information Security Committee shall have an advisory role. | 8. In the performance of the tasks referred to in paragraph 2, point (e), the Coordination Group shall be assisted by an Information Security Committee. That Committee shall be composed of one representative from each National Security Authority and shall be chaired by the Secretariat of the Coordination Group, referred to in paragraph 5. A representative of the Parliament shall attend as observer. The Information Security Committee shall have an advisory role. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) a sub-group on administrative arrangements with third countries and international organisations. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and, where applicable, by its internal security rules. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks. | 1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and monitor and ensure compliance by each Union institution or body concerned with the guidance documents adopted by the Coordination Group. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks. |
| Text proposed by the Commission | Amendment |
|---|---|
| (d) encryption of information at rest and in transit; | (d) end-to-end encryption of information at all stages of the relevant processes; |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Union institutions and bodies may mark with ‘PUBLIC USE’ the information referred to in paragraph 1. | 2. Union institutions and bodies may mark with ‘PUBLIC USE’ the information referred to in paragraph 1. The absence of such marking shall not give rise to a presumption that the information could be classified. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Union institutions and bodies may mark with ‘PUBLIC USE’ the information referred to in paragraph 1. | 2. Union institutions and bodies shall mark with ‘PUBLIC USE’ the information referred to in paragraph 1. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. All Union institutions and bodies shall ensure the integrity and availability of information for public use by appropriate measures based on its security needs. | 3. All Union institutions and bodies shall ensure the integrity and availability of information for public use by appropriate measures based on their security needs and accounting for the right to information. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Normal information may be marked visually or in metadata where necessary to ensure its protection, particularly where shared outside Union institutions and bodies. The marking ‘EU NORMAL’ or the ‘name or acronym of the Union institution or body NORMAL’ (adjusted on a case-by-case basis) shall be used in that case. | 2. Normal information may be marked visually or in metadata where necessary to ensure its protection, particularly where shared outside Union institutions and bodies. The marking ‘EU NORMAL’ or the ‘name or acronym of the Union institution or body NORMAL’ (adjusted on a case-by-case basis) shall be used in that case. The absence of such marking shall not give rise to a presumption that the information could be classified. |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. Normal information shall be exchanged outside Union institutions and bodies only with natural or legal persons having a need-to-know. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. Normal information shall be exchanged outside Union institutions and bodies only with natural or legal persons having a need-to-know. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Union institutions and bodies shall categorise, handle and stored as sensitive non-classified all information that is not classified but which they must protect due to legal obligations or because of the harm that may be caused to the legitimate private and public interests, including those of the Union institutions and bodies, Member States or individuals by its unauthorised disclosure. | 1. Union institutions and bodies shall categorise, handle and stored as sensitive non-classified all information that is not classified but which they must protect due to legal obligations or because of the harm that may be caused to the legitimate public interests, including those of the Union institutions and bodies or Member States by its unauthorised disclosure. |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. Sensitive non-classified information shall be exchanged outside Union institutions and bodies only with natural and legal persons that have a need-to-know while respecting the handling instructions accompanying the information. All parties involved shall be made aware of the appropriate handling instructions. | 4. Sensitive non-classified information shall be exchanged outside Union institutions and bodies only with natural and legal persons that have a need-to-know while respecting the handling instructions accompanying the information and the requirements stemming from legal protections that might apply as per paragraph 1 . All parties involved shall be made aware of the appropriate handling instructions. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Union institutions and bodies shall establish procedures for the reporting and management of any incident or suspected incident that could lead to a compromise of the security of non-classified information. | 1. Union institutions and bodies shall establish uniform procedures for the reporting and management of any incident or suspected incident that could lead to a compromise of the security of non-classified information. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. Exceptionally, other equivalent markings may be used internally and in relation with their particular counterparts from other Union institutions and bodies or from the Member States, when all parties agree. Such exception shall be notified to the sub-group on non-classified information, as referred to in Article 7(1), point (b). | 2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
| Text proposed by the Commission | Amendment |
|---|---|
| (d) RESTREINT UE/EU RESTRICTED: information and material the unauthorised disclosure of which could be disadvantageous to the interests of the Union or of one or more of the Member States. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. | 2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. Such documents shall take into account both the principle of minimisation of the use of classified information and the risk of overclassification of certain documents, and shall include rules on assessing and justifying information and material classification, aimed at increasing transparency and avoiding unjustified lock-in effects. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2a. In the event of any doubt as to the confidential nature of an item of information or its level of classification or in the event of a disagreement in between the European institutions, they shall consult each other without any delay and before transmission of this item of information. In these consultations, institutions shall be represented by the chair of the body concerned or the responsible for security matters. In the event of a disagreement, the matter shall be referred to the Presidents of the institutions so that they may resolve the dispute. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3a. This Article is without prejudice to Regulation (EC) No 1049/2001. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. An act or omission of a Union institution or body or an individual, which is in breach of this Regulation, shall be considered as a breach of security. | 1. Any act or omission of a Union institution or body or an individual, which is in breach of this Regulation, shall be considered as a breach of security. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) inform the originator; | (a) inform the originator without undue delay, and in any event no later than three days after the Security Authority has been informed of the breach; |
| Text proposed by the Commission | Amendment |
|---|---|
| (b) ensure that the case is investigated by personnel not immediately concerned with the breach in order to establish the facts; | (b) ensure that the case is throughly investigated by personnel not immediately concerned with the breach in order to establish the facts; |
| Text proposed by the Commission | Amendment |
|---|---|
| (e) notify the competent authorities about the actual or potential compromise and the action taken. | (e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any event no later than three days after the Security Authority has been informed of the breach. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Union institutions and bodies shall take into account the loyalty, trustworthiness and reliability of an individual as determined by means of a security investigation conducted by the competent authorities of the Member State of which the applicant is a citizen or a national. | 2. Union institutions and bodies shall take into account the loyalty, trustworthiness and reliability of an individual as determined by means of a security investigation conducted by the Commission in cooperation with the competent authorities of the relevant Member States. The Commission may also cooperate with third countries and international organisations with which the Union has a security of information agreement. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. | 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall, in any event, ensure that the principles under paragraphs 1 and 2 are observed. |
| Text proposed by the Commission | Amendment |
|---|---|
| Where a SLA is concluded, the Commission Security Authority shall be the contact point between the security offices of the Union institution and body concerned and the national competent authorities of the Member States in the context of security clearance issues. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. In exceptional circumstances, where duly justified in the interests of the service and pending completion of a full security investigation, the Security Authority of a Union institution or body may grant a temporary authorisation for individuals to access EUCI for a specific position, without prejudice to the provisions regarding renewal of authorisation to access EUCI and upon verification of the relevant National Security Authority. | 4. In exceptional circumstances, where duly justified in the interests of the service and pending completion of a full security investigation, the Security Authority of a Union institution or body may grant a temporary authorisation for individuals to access EUCI for a specific position, without prejudice to the provisions regarding renewal of authorisation to access EUCI. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Where the holder of an authorisation to access EUCI takes up employment in another Union institution or body, that Union institution or body shall notify the relevant NSA of a change of employer, through the competent Security Authority. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Where the holder of an authorisation to access EUCI takes up employment in another Union institution or body, that Union institution or body shall notify the relevant NSA of a change of employer, through the competent Security Authority. | 3. Where the holder of an authorisation to access EUCI takes up employment in another Union institution or body, that Union institution or body shall, without undue delay, notify the relevant NSA of a change of employer, through the competent Security Authority. |
| Text proposed by the Commission | Amendment |
|---|---|
| (da) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Any Union institution and body which is the originator of EUCI shall determine the security classification of that information upon its creation and in accordance with Article 18(1). | 2. Any Union institution and body which is the originator of EUCI shall determine the initial security classification of that information upon its creation and in accordance with Article 18(1). |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) each page shall be marked clearly with the classification level; | (a) each page shall be marked clearly with the classification level and the duration of classification ; |
| Text proposed by the Commission | Amendment |
|---|---|
| Originator control | Originator consent |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: | 1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. The originator may consult intended recipients regarding the classification level of an EUCI document, in particular in the event of any doubt as to the confidential nature of an item of information and its appropriate level of classification, and to prevent over-classification of such documents. For the purposes of the initial dissemination of an EUCI document, the originator shall take into account the rights and obligations of information recipients arising from the Treaties. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: | 1. The Union institution or body under whose authority an EUCI document classified CONFIDENTIEL UE/EU-CONFIDENTIAL or higher is created shall have originator consent right over that document. The originator shall determine the initial classification level of the document and shall be responsible for its initial dissemination. The originator’s prior written consent shall be obtained if necessary in order to protect essential interests of the European Union or of one or more of its Member States in the area of public security, defence and military matters, international relations or the financial, monetary or economic policy, before the information is: |
| Text proposed by the Commission | Amendment |
|---|---|
| (d) copied and translated in case of TRES SECRET-UE/EU-TOP SECRET level. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Where the originator of an EUCI document cannot be identified, the Union institution or body holding that classified information shall exercise originator control. | 2. Where the originator of an EUCI document cannot be identified, the Union institution or body holding that classified information shall exercise originator consent. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Information shall be classified only for as long as it requires protection. EUCI that no longer needs the original classification shall be downgraded to a lower level. EUCI that no longer needs to be considered as classified at all shall be declassified. | 1. Information shall be classified only for as long as it requires protection. EUCI that no longer needs the original classification shall be downgraded to a lower level. EUCI that no longer needs to be considered as classified at all shall be declassified. Any classification shall be reviewed at the latest one year after the document’s creation and every year afterwards. In case of documents that concern an ongoing legislative process, this review shall be done no later than two months after the document’s creation and every two months afterwards. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. At the time of creation of EUCI, the originator shall indicate, where possible, and in particular for information classified RESTREINT UE/EU RESTRICTED, whether the EUCI can be downgraded or declassified on a given date or following a specific event. | 2. At the time of creation of EUCI, the originator shall indicate whether the EUCI can be downgraded or declassified on a given date or following a specific event. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. At the time of creation of EUCI, the originator shall indicate, where possible, and in particular for information classified RESTREINT UE/EU RESTRICTED, whether the EUCI can be downgraded or declassified on a given date or following a specific event. | 2. At the time of creation of EUCI, the originator shall indicate, where possible, whether the EUCI can be downgraded or declassified on a given date or following a specific event. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. The originating Union institution or body shall be responsible for deciding whether a EUCI document can be downgraded or declassified. It shall review the information and assess the risks regularly and at least every 5 years in order to determine whether the original classification level is still appropriate. | 3. Each Union institution or body shall be responsible for deciding whether a EUCI document can be downgraded or declassified. |
| Text proposed by the Commission | Amendment |
|---|---|
| The operational details of emergency evacuation and destruction plans shall themselves be classified as RESTREINT UE/EU RESTRICTED. | The operational details of emergency evacuation and destruction plans shall themselves be classified. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Union institutions and bodies shall decide whether and when to archive EUCI, and the corresponding practical measures, in accordance with their policy on document management. | 1. Union institutions and bodies shall decide whether and when to archive EUCI, and the corresponding uniform practical measures. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. EUCI documents shall not be transferred to the Historical Archives of the European Union. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| Article39a | |
| Disputes | |
| 1. In the event of any doubt as to the protected nature of information or its appropriate level of classification, the Union institutions and bodies shall consult each other without delay and before transmission of the information. In the event of a disagreement, the matter shall be referred to the Presidents of the Institutions or bodies so that they may resolve the dispute. | |
| 2. If, at the end of the procedure referred to in paragraph 1, no agreement has been reached, the refusal to revise the protected nature of information or its appropriate level of classification shall be subject to review of its legality in accordance with Article 263 TFEU. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ca) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
| Text proposed by the Commission | Amendment |
|---|---|
| (b) key security principles for the design of CIS handling and storing EUCI shall apply at the inception of the project, as part of the information security risk management process and taking into account need-to-know, minimal functionality, defence in depth, least privilege, segregation of duties and four eyes; | (b) crucial security principles for the design of CIS handling and storing EUCI shall apply at the inception of the project, as part of the information security risk management process and taking into account need-to-know, minimal functionality, defence in depth, least privilege, segregation of duties and four eyes; |
| Text proposed by the Commission | Amendment |
|---|---|
| (fa) the system owner or the Information Assurance Operational Authority shall ensure that a process of identifying and reporting vulnerabilities is in place; that process shall be complemented by regular audits and penetration tests where appropriate. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. For all information and material classified as EUCI a list of approved cryptographic products shall be maintained by the Council, on the basis of input from the National Security Authorities. |
| Text proposed by the Commission | Amendment |
|---|---|
| 4a. For information and material classified as RESTREINT UE/EU RESTRICTED a list of additional approved cryptographic products shall be established by ENISA/EU-CERT within 18 months following the publication of the regulation in the Official Journal of the European Union. The list should be reviewed in view of putting it up to date with technological and market developments every subsequent year. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5. The Coordination Group shall inform the Council on a yearly basis of any cryptographic products that it recommends for evaluation by a Crypto Authority Approval of a Member State on the basis of a survey carried out in the Union institutions and bodies. | 5. The Coordination Group shall inform the Council on a yearly basis of any cryptographic products that it recommends for evaluation by a Crypto Authority Approval of a Member State, or ENISA/EU-CERT on the basis of a survey carried out in the Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. All Union institutions and bodies may share EUCI with other Union institutions or bodies under the conditions set out in Article 54. | 1. All Union institutions and bodies shall share EUCI with other Union institutions or bodies under the conditions set out in Article 54. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That subgroup shall seek a fair balance between the need to protect EUCI and Regulation (EC) No 1049/2001, and shall ensure that the classification does not in itself prevent disclosure. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) there is a proven need for the exchange; | (a) there is a legal obligation under Union law or under an agreement concluded between Union institutions;or |
| (a) there is a proven need for the exchange; |
| Text proposed by the Commission | Amendment |
|---|---|
| (aa) there is a legal obligation pursuant to the Treaties, secondary law or an Interinstitutional agreement concluded between Union institutions; |
| Text proposed by the Commission | Amendment |
|---|---|
| (c) the Security Authority of the Union institution or body concerned decides that it may share information classified up to a specified level with other such certified Union institutions and bodies. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) the Union institution or body concerned needs to exchange, on a long-term basis information classified, as a general rule, no higher than RESTREINT UE/EU RESTRICTED with its counterpart in a third country or international organisation; | (a) the Union institution or body concerned needs to exchange, on a long-term basis information classified, as a general rule, no higher than CONFIDENTIEL UE/EU CONFIDENTIAL with its counterpart in a third country or international organisation; |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. All Union institutions and bodies that have been assessed either by Commission or Council or EEAS before the [dd/mm/yyyy date of applicability], as suitable to handle and store EUCI, shall be considered as meeting the conditions referred to in Article 19(1). | 2. All Union institutions and bodies that have been assessed either by Commission, European Parliament, Council or EEAS before the [dd/mm/yyyy date of applicability], as suitable to handle and store EUCI, shall be considered as meeting the conditions referred to in Article 19(1). |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. All Union institutions and bodies that have been assessed either by Commission or Council or EEAS before the [dd/mm/yyyy date of applicability], as suitable to handle and store EUCI, shall be considered as meeting the conditions referred to in Article 19(1). | 2. All Union institutions and bodies that have been assessed either by Parliament, Commission, Council or EEAS before the [dd/mm/yyyy date of applicability], as suitable to handle and store EUCI, shall be considered as meeting the conditions referred to in Article 19(1). |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. By [dd/mm/yyyy 3 years after the date of application] at the latest, the Commission shall present a report on the implementation of this Regulation to the European Parliament and the Council. | 1. By [dd/mm/yyyy 2 years after the date of application] at the latest, the Commission shall present a report on the implementation of this Regulation to the European Parliament and the Council. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. No sooner than [5 years after the date of application] and every 5 years thereafter, the Commission shall carry out an evaluation of this Regulation and present a report on the main findings to the European Parliament and the Council. | 2. No sooner than [3 years after the date of application] and every 5 years thereafter, the Commission shall carry out an evaluation of this Regulation and present a report on the main findings to the European Parliament and the Council. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Documents containing sensitive non-classified information must be marked using a security marking and, where relevant, one or more distribution marking or markings specifying the target audience as appropriate. The standard security marking shall be the word ‘SENSITIVE’ in upper case, except in cases referred to in Article 15(2). | 1. Documents containing sensitive non-classified information must be marked using a security marking and, where relevant, one or more distribution marking or markings specifying the target audience as appropriate. The standard security marking shall be the word ‘PROTECTED’ in upper case, except in cases referred to in Article 15(2). |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. Documents marked SENSITIVE are downgraded to EU NORMAL or PUBLIC USE, through the removal or striking of the markings. | 4. Documents marked PROTECTED are downgraded to EU NORMAL or PUBLIC USE, through the removal or striking of the markings. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1) ‘personnel Security Clearance’ or ‘PSC’ means a statement by a relevant authority of a Member State which is made following completion of a security investigation conducted by the competent authority and which certifies that an individual may be granted access to EUCI up to a specified level (CONFIDENTIEL UE/EU CONFIDENTIAL or higher) and for a set period of time; | 1) 1) ‘personnel Security Clearance’ or ‘PSC’ means a statement by the Commission which is made following completion of a security investigation conducted by the Commission in cooperation with the competent authorities of the relevant Member States and which certifies that an individual may be granted access to EUCI up to a specified level (CONFIDENTIEL UE/EU CONFIDENTIAL or higher) and for a set period of time; |
| Text proposed by the Commission | Amendment |
|---|---|
| 2) ‘personnel Security Clearance Certificate’ means a certificate issued by a competent authority establishing that an individual holds a valid security clearance, or equivalent, or a security authorisation and that shows the level of EUCI to which that individual may be granted access (CONFIDENTIEL UE/EU CONFIDENTIAL or higher), the period of validity of the relevant security clearance or authorisation and the date of expiry of the certificate itself. | 2) ‘personnel Security Clearance Certificate’ means a certificate issued by the Commission establishing that an individual holds a valid security clearance, or equivalent, or a security authorisation and that shows the level of EUCI to which that individual may be granted access (CONFIDENTIEL UE/EU CONFIDENTIAL or higher), the period of validity of the relevant security clearance or authorisation and the date of expiry of the certificate itself. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Security Authority of the Union institution and body concerned must seek the written consent of the individual for the security clearance procedure before sending a completed security clearance questionnaire to the National Security Authority of the Member State of nationality of the applicant. | 1. The Security Authority of the Union institution and body concerned must seek the written consent of the individual for the security clearance procedure before sending a completed security clearance questionnaire to the Commission. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Where information relevant to a security investigation becomes known to a Union institution or body, concerning an individual who has applied for a security clearance for access to EUCI, the competent Security Authority, acting in accordance with this Regulation, must notify the relevant National Security Authority thereof. | 2. Where information relevant to a security investigation becomes known to a Union institution or body, concerning an individual who has applied for a security clearance for access to EUCI, the competent Security Authority, acting in accordance with this Regulation, must notify the Commission thereof. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Following notification of the relevant National Security Authority’s overall assessment of the findings of the security investigation, the competent Security Authority: | 3. Following notification of the Commission’s overall assessment of the findings of the security investigation, the competent Security Authority: |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. Where the individual starts service 12 months or more after the date of the notification of the result of the security investigation, or when there is a break of 12 months in the individual’s service, the competent Security Authority must seek confirmation from the relevant National Security Authority about the validity of the security clearance. | 4. Where the individual starts service 12 months or more after the date of the notification of the result of the security investigation, or when there is a break of 12 months in the individual’s service, the competent Security Authority must seek confirmation from the Commission about the validity of the security clearance. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Where information concerning a security risk posed by an individual who has authorisation to access EUCI becomes known to the Union institution or body concerned, the Security Authority of that Union institution or body must notify the relevant National Security Authority thereof and may suspend the individual’s access to EUCI or withdraw authorisation to access EUCI. | 5. Where information concerning a security risk posed by an individual who has authorisation to access EUCI becomes known to the Union institution or body concerned, the Security Authority of that Union institution or body must notify the Commission thereof and may suspend the individual’s access to EUCI or withdraw authorisation to access EUCI. |
| Text proposed by the Commission | Amendment |
|---|---|
| 6. Where an National Security Authority notifies the relevant Union institution or body that there is no longer assurance for an individual who has access to EUCI, the Security Authority of the Union institution or body concerned must withdraw its security authorisation and exclude the individual from access to EUCI in accordance with its relevant internal rules. | 6. Where the Commission notifies the relevant Union institution or body that there is no longer assurance for an individual who has access to EUCI, the Security Authority of the Union institution or body concerned must withdraw its security authorisation and exclude the individual from access to EUCI in accordance with its relevant internal rules. |
| Text proposed by the Commission | Amendment |
|---|---|
| The Security Authority of the Union institution and body concerned may extend the validity of an authorisation to access EUCI for a period of up to 12 months, where no adverse information has been received from the relevant National Security Authority or other competent national authority within a period of 2 months from the date of transmission of the request for renewal and the corresponding clearance questionnaire. | The Security Authority of the Union institution and body concerned may extend the validity of an authorisation to access EUCI for a period of up to 12 months, where no adverse information has been received from the Commission within a period of 2 months from the date of transmission of the request for renewal and the corresponding clearance questionnaire. |
| Text proposed by the Commission | Amendment |
|---|---|
| 10. The Security Authority of the Union institution or body concerned may exceptionally grant temporary authorisation to access EUCI provided that the competent National Security Authority has conducted a preliminary check, based on the completed and transmitted security questionnaire, to verify that no relevant adverse information is known. | 10. The Security Authority of the Union institution or body concerned may exceptionally grant temporary authorisation to access EUCI provided that the Commission has conducted a preliminary check, based on the completed and transmitted security questionnaire, to verify that no relevant adverse information is known. |
| Text proposed by the Commission | Amendment |
|---|---|
| 13. All Union institutions and bodies must ensure that national experts seconded to them for a position requiring security clearance present, prior to taking up their assignment, a valid Personnel Security Clearance or Personnel Security Clearance Certificate, according to national law and regulations, to the competent Security Authority. Provided that the requirements referred to in Article 23(1) are met, the Security Authority may then grant an authorisation to access EUCI up to the level equivalent to the one referred to in the national security clearance, with a maximum validity not longer than the duration of their assignment. | 13. All Union institutions and bodies must ensure that national experts seconded to them for a position requiring security clearance present, prior to taking up their assignment, a valid national security clearance, according to national law and regulations, to the competent Security Authority. Provided that the requirements referred to in Article 23(1) are met, the Security Authority may then grant an authorisation to access EUCI up to the level equivalent to the one referred to in the national security clearance, with a maximum validity not longer than the duration of their assignment. |
| Text proposed by the Commission | Amendment |
|---|---|
| 8. EUCI which is classified RESTREINT UE/EU RESTRICTED must be handled and stored in any of the following areas: | deleted |
| (a) in a Secured Area; | |
| (b) in an Administrative Area provided the EUCI is protected from access by unauthorised individuals; | |
| (c) outside a Secured Area or Administrative Area provided the holder has undertaken to comply with compensatory measures decided by the Security Authority of each Union institution and body. |
| Text proposed by the Commission | Amendment |
|---|---|
| 9. EUCI which is classified RESTREINT UE/EU RESTRICTED must be stored in locked office furniture in an Administrative Area or a Secured Area. It may temporarily be stored outside an Administrative Area or a Secured Area provided the holder has undertaken to store the documents concerned in appropriate locked office furniture when they are not being read or discussed. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 10. Union institutions and bodies may handle and store RESTREINT UE/EU RESTRICTED information outside their sites provided the relevant information be protected appropriately. For such purpose, Union institutions and bodies must comply with the measures provided in point 8(c). | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 8. RESTREINT UE/EU RESTRICTED information must be carried in at least one layer of opaque packaging, such as envelopes, opaque folders or a briefcase. Information classified CONFIDENTIEL UE/EU CONFIDENTIAL or higher must be carried in two layers of opaque packaging. | 8. Information classified CONFIDENTIEL UE/EU CONFIDENTIAL or higher must be carried in two layers of opaque packaging. |
| Text proposed by the Commission | Amendment |
|---|---|
| 10. Commercial couriers may convey information classified RESTREINT UE/EU RESTRICTED and CONFIDENTIEL UE/EU CONFIDENTIAL within a Member State and from one Member State to another. Commercial couriers may deliver SECRET UE/EU SECRET information only within a Member State and provided that they are approved by the relevant National Security Authority. No EUCI at TRES SECRET UE/EU TOP SECRET level can be entrusted to a commercial courier. | 10. Commercial couriers may convey information classified CONFIDENTIEL UE/EU CONFIDENTIAL within a Member State and from one Member State to another. Commercial couriers may deliver SECRET UE/EU SECRET information only within a Member State and provided that they are approved by the relevant National Security Authority. No EUCI at TRES SECRET UE/EU TOP SECRET level can be entrusted to a commercial courier. |
| Text proposed by the Commission | Amendment |
|---|---|
| 18. Where Member States require an FSC or a Personnel Security Clearance for contracts, grant agreements or subcontracts at RESTREINT UE/EU RESTRICTED level under their national laws and regulations, the Union institutions and bodies, as contracting or granting authorities, must not use those national requirements to place additional obligations on other Member States or exclude tenderers, applicants, contractors, beneficiaries or subcontractors from Member States that have no such FSC or Personnel Security Clearance requirements for access to RESTREINT UE/EU RESTRICTED information from related contracts, grant agreements or subcontracts, or a competition for such. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 22. Visits involving access to information classified RESTREINT UE/EU RESTRICTED must be arranged directly between the sending and receiving entity. | deleted |
| Text proposed by the Commission | Amendment |
|---|---|
| 24. The security accreditation of contractors’ or beneficiaries’ CIS handling EUCI at RESTREINT UE/EU RESTRICTED level and any interconnection thereof may be delegated to the security officer of a contractor or beneficiary where allowed by national laws and regulations. | deleted |
| Where the security accreditation task is delegated, the contractor or beneficiary must be responsible for implementing the security requirements described in the Security Aspects Letter when handling RESTREINT UE/EU RESTRICTED information in its CIS. The relevant National Security Authorities or National Security Authorities and SAAs retain responsibility for the protection of information classified RESTREINT UE/EU RESTRICTED handled or stored by the contractor or beneficiary and the right to inspect the security measures taken by the contractor or beneficiary. | |
| In addition, the contractor or beneficiary must provide the Union institution and body, as contracting or granting authority, and where required by national laws and regulations, the competent national SAA, with a statement of compliance certifying that the contractor or beneficiary CIS and related interconnections have been accredited for handling and storing EUCI at RESTREINT UE/EU RESTRICTED level. |
| Text proposed by the Commission | Amendment |
|---|---|
| 26. RESTREINT UE/EU RESTRICTED information may be hand carried by contractor or beneficiary personnel within the European Union, provided the following requirements are met: | deleted |
| (a) the envelope or packaging used is opaque and bears no indication of the classification of its contents; | |
| (b) the bearer retains possession of the classified information at all times; | |
| (c) the envelope or packaging is not opened until it reaches its final destination. |
Connections
The dossier, the decisions on this text and its other versions.
No connections found for this item.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2023). “AMENDMENTS 34 - 181 - Draft report Information security in the institutions, bodies, offices and agencies of the Union”. Text, 7 September 2023. docId LIBE-AM-752883. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-AM-752883 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/LIBE-AM-752883 (CC BY 4.0).
BibTeX
@misc{epw-text-libe-am-752883,
author = {{European Parliament}},
title = {{AMENDMENTS 34 - 181 - Draft report Information security in the institutions, bodies, offices and agencies of the Union}},
year = {2023},
date = {2023-09-07},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-AM-752883}},
url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-AM-752883},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. docId LIBE-AM-752883. Data: EP Open Data API: document record (CC BY 4.0)}
}