Text
The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.
▸Jump to an amendment (223)
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendmenthaving regard to judgment of the CJEU of 27 November 2019 in Case T-31/18, Luisa Izuzquiza and Arne Semsrott v European Border and Coast Guard Agency, |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected. | Amendment(1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable or impregnable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected as well as on the interoperability of such tools . |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected. | Amendment(1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where there are potential security gaps and inconsistencies and exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(1 a) Given that Union institutions are obliged to apply Article 15(3) of the Treaty on the Functioning of the European Union ("TFEU") in line with democratic principles, in particular those laid down in Article 10(3) of the Treaty on European Union ("TEU") and Article 42 of the Charter of Fundamental Rights of the European Union (‘the Charter’), the European Union classified information (‘EUCI’) system should adhere to the principles of data classification minimisation and time limitation for any such classification. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. | Amendment(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Interinstitutional cooperation and trust is key to protecting, in an efficient and effective manner, the information security environment of the Union. Further efforts should therefore be made to enable an interinstitutional approach based on increased synergies to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. | Amendment(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the exchange between the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. | Amendment(3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. These rules should ensure both adequate protection of EU classified and non-classified information and appropriate transparency where and when necessary to enable democratic scrutiny and public trust. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(3 a) Article 15 of the Treaty on the Functioning of the European Union stipulates that the Unions’ institutions, bodies, offices and agencies are to conduct their work as openly as possible, and that every citizen of the Union is to have a right of access to documents. Accordingly, every classification of documents should take place in the light of these overarching principles. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(3 a) The judgment of the CJEU of November 27, 2019 in Case T-31/18, Luisa Izuzquiza and Arne Semsrott v European Border and Coast Guard Agency, concludes that there is a risk that the dissemination of information could affect public security, thus highlighting the importance of proportionate transmission of information. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(3 b) In the context of information security, Union institutions and bodies should increase organisational interoperability and take joint action to ensure that networks, information systems, data, and all material assets employed to capture, store, process and transmit the information are duly protected. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. | Amendment(4) The recent pandemic expedited the significant underlying transformation in working practices, with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. | Amendment(4) The recent pandemic caused a significant change in working practices with remote communication tools becoming commonplace. Therefore, many procedures that were previously at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. | Amendment(4) The COVID-19 pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(4a) Information security in the digital age must also cover the emerging risks of artificial intelligence. In particular, the key parameters of AI systems – including model architectures, training algorithms and research ideas – constitute sensitive information, comparable in terms of risk to the proliferation of knowledge in nuclear or biotechnological matters. Unauthorised disclosure of or access to features of that kind could make it possible to reuse them for malicious purposes, including cyber attacks, the development of biological weapons and the manipulation of critical infrastructure. Protecting that information is not only a technical matter but also a social and organisational one, requiring measures to be taken against external and internal threats and espionage. The Union must, therefore, adopt enhanced security mechanisms based on the need-to-know principle, the prevention of internal threats, interinstitutional cooperation and the exchange of information on risks and incidents. At the same time, it must promote international initiatives to prevent the uncontrolled proliferation of artificial intelligence capabilities that could undermine collective security. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(4c) Traditional perimeter security models are proving inadequate in a context of increasingly sophisticated and persistent cyber threats. Progressive adoption of the zero-trust model, based on continuous identity validation, the principle of least privilege, permanent monitoring and network segmentation, is essential to reducing the area of exposure to attacks, preventing risks of espionage and data leakage, and bolstering the protection of critical information, particularly information on artificial intelligence and other high-risk areas. Union institutions and bodies should, therefore, progressively integrate this model into their information security systems. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy. | Amendment(5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. Each Union institution and body, however, shall take cost-effectiveness into account in its implementation. This Regulation shall in no case prevent Union institutions and bodies from fulfilling their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(5 a) Sharing of EUCI in a transparent and timely manner is paramount for the proper functioning of Union institutions and bodies. When implementing this Regulation, Union institutions and bodies should strive to enhance transparency, minimise and limit in time the use of confidential documents, provide safeguards against the use of classification in a manner that would prevent Union entities from fulfilling their mission, and ensure that whistle-blowers are adequately protected and that there is a high level of protection of information in line with Union law and best practices. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(5 a) This Regulation should ensure that any limitation of the right to the protection of personal data and privacy is necessary and proportionate and respects the essence of the right in accordance with Article 52(1) of the Charter of Fundamental Rights of the European Union. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(5 b) All information security measures involving processing of personal data should be compliant with the relevant Union data protection and privacy law. Union institutions and bodies should provide relevant technical and organisational safeguards to ensure compliance in an accountable, transparent and justified manner. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(5 c) Members of the Union institutions should have access by virtue of their mandate to all necessary information, on the basis of the ‘need-to-know principle’ , in order to exercise the powers vested to them by the Treaties. |
This should apply to MEPs, Commissioners and Members of the court of auditors and the ECJ, etc.
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. | Amendment(8) With a view to establishing a formal common and uniform structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks. | Amendment(9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to reduce administrative burden and prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks. | Amendment(9) The Coordination Group’s work needs the support of experts in different areas of information security, including: categorisation and marking, declassification, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. | Amendment(10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union and to facilitating the exchange of EUCI where appropriate. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(10) The Coordination Group should closely cooperate with the National Security Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. | Amendment(10) The Coordination Group should closely cooperate with the Classification Authorities of the Member States with a view to enhancing information security in the Union. An Information Security Committee of the Member States should therefore be set up to provide advice to the Coordination Group. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(10 a) In line with Article 4(2) of the Treaty on European Union, this Regulation should take full account of the legitimate national security interests of the Member States when establishing and applying classification and protection standards for European Union Classified Information (EUCI). Cooperation mechanisms shall ensure that national expertise and security requirements are fully taken into account. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(10 b) To ensure that the European Parliament is capable of handling classified information and to strengthen mutual trust between the Union institutions and the Member States, the European Parliament should establish appropriate facilities and technical arrangements for the secure handling of EU classified information. These arrangements should include secure rooms for consultation and discussion, protected communication channels, and the regular inspection of devices used for handling EUCI by Members and authorised staff to protect against interception. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes or in the exchange of information with their particular counterparts from other institutions and bodies or from the Member States. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures. | Amendment(14) With the purpose of adjusting to the new teleworking practices, the network information systems, digital infrastructure, and terminal devices used for connecting to the Union institution’s or body’s remote access services should be protected by state of the art security measures. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. | Amendment(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Where contractors and outsourcing are used, preference should be given to European operators. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. | Amendment(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel, IT systems and practices for carrying out tasks related to information security. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(16) The substantive rules regarding access to EUCI in the internal rules of various Union institutions and bodies are currently aligned, but there are significant differences as regards denominations and required procedures. This creates a burden for the National Security Authorities of the Member States who need to adjust to different requirements. Thus it is necessary to provide for a common glossary and common procedures in the area of personnel security, thereby simplifying cooperation with the National Security Authorities of the Member States and limiting the risk of compromising EUCI. | Amendment(16) The substantive rules regarding access to EUCI in the internal rules of various Union institutions and bodies are currently aligned, but there are significant differences as regards denominations and required procedures. Thus it is necessary to provide for a common glossary and common procedures in the area of personnel security, thereby limiting the risk of compromising EUCI. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(17) Given the disparity of resources amongst Union institutions and bodies and in order to streamline their relevant procedures and practices, the security clearance tasks can be entrusted to the Commission in order to provide a continuation of a long-standing practice in the field of security clearance and contribute to the centralisation of the tasks assigned to each Security Authority. | Amendmentdeleted |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(17) Given the disparity of resources amongst Union institutions and bodies and in order to streamline their relevant procedures and practices, the security clearance tasks can be entrusted to the Commission in order to provide a continuation of a long-standing practice in the field of security clearance and contribute to the centralisation of the tasks assigned to each Security Authority. | Amendment(17) In accordance with the spirit of the text, each institution or body of the Union should retain full responsibility for the security clearance tasks of its staff, in accordance with the common rules established and its own operational needs. To this end, clearance vetting should be processed in cooperation between Union entity and national authorities responsible for clearance, supplemented where necessary by referral to the Member State of residence of the person to be cleared; Member States involve their intelligence services in line with their national rules. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. | Amendment(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. A thorough evaluation of security infrastructure, including services, should be carried out, encompassing all aspects of the operational chain and environment. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(19) All Union institutions and bodies handling and storing EUCI should establish physically protected areas in their sites, in order to ensure the same level of protection for the relevant levels of EUCI classification handled and stored within. Those areas should be designated as Administrative Areas and Secured Areas and respect common minimum standards for the protection of EUCI. | Amendment(19) All Union institutions and bodies handling and storing EUCI should establish physically and digitally protected areas in their sites, in order to ensure the same level of protection for the relevant levels of EUCI classification handled and stored within. Those areas should be designated as Administrative Areas and Secured Areas and respect common minimum standards for the protection of EUCI. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(20) Originator control is an important principle in the EUCI management, therefore it needs to be clearly stipulated and developed. In that regard, the creation of EUCI confers to the originator a responsibility which should cover the entire life cycle of the relevant EUCI document. | Amendment(20) Originator control is an important principle in the EUCI management, therefore it needs to be clearly stipulated and developed. In that regard, the creation of EUCI confers to the originator a responsibility which should cover the entire life cycle of the relevant EUCI document; the originating authority remains the owner of its information and has the final say to oppose its transfer. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(20) Originator control is an important principle in the EUCI management, therefore it needs to be clearly stipulated and developed. In that regard, the creation of EUCI confers to the originator a responsibility which should cover the entire life cycle of the relevant EUCI document. | Amendment(20) Originator’s opinion is an important principle in the EUCI management, therefore it needs to be clearly stipulated and developed. In that regard, the creation of EUCI confers to the originator a responsibility which should cover the entire life cycle of the relevant EUCI document. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling and storing both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. | Amendment(21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling, storing, and transmitting both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling and storing both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. | Amendment(21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their exchange across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling and storing both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(21 a) Information held by the Union entities is also exchanged through the ICT environment, on-premises or through virtual assets, ICT products, ICT services and ICT processes, as well as networks and information systems whether owned and operated by a Union entity or hosted or operated by a third party, including mobile devices, corporate networks, and business networks not connected to the internet and any devices connected to the ICT environment. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(25) Furthermore, the sharing of EUCI between the Union institutions and bodies and the exchange of classified information with international organisations and third countries should also be regulated by appropriate security measures for the protection of that information. Where agreements on security of information are envisaged, the provisions of Article 218 of the Treaty should apply. | Amendment(25) Furthermore, the sharing of EUCI between the Union institutions and bodies and the exchange of classified information with international organisations and third countries should also be regulated by appropriate security measures for exchange and storage in order to ensure the same level of protection for such information. Where agreements on security of information are envisaged, the provisions of Article 218 of the Treaty should apply. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(26) The agreements on security of information are meant to ensure the overall legal framework for the exchange of classified information of the Union with the third countries and international organisations, it is also necessary to provide for the possibility of Union institutions and bodies to enter into administrative arrangements with a specific counterpart of a third country or of an international organisation for the purpose of exchanging EUCI. | Amendment(26) The agreements on security of information are meant to ensure the overall legal framework for the exchange of classified information of the Union with the third countries and international organisations, it is also necessary to provide for the possibility of Union institutions and bodies to enter into administrative arrangements with a specific counterpart of a third country or of an international organisation for the purpose of exchanging EUCI both through secure data exchange and storage. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. This Regulation lays down information security rules for all Union institutions and bodies. | Amendment1. This Regulation lays down a minimum set of common and uniform information security rules for all Union institutions and bodies. |
Proposal for a regulation
Article 1 – paragraph 1 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment1 a. This Regulation is without prejudice to the right of access to documents of the Union institutions, bodies, offices and agencies as enshrined in Article 15(3) of the Treaty on the Functioning of the European Union and determined in Regulation (EC) 1049/2001 of the European Parliament and of the Council. Nothing in this Regulation, in particular the provisions on EUCI, may be used to restrict the right of access to documents of the Union institutions, bodies, offices and agencies beyond the restrictions set out in applicable legislation on such access. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Article 1 – paragraph 1 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment1 a. This Regulation is without prejudice to and shall not affect the application of Regulation (EC) No 1049/2001 of the European Parliament and of the Council regarding public access to European Parliament, Council and Commission documents. |
Proposal for a regulation
Article 1 – paragraph 1 b (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment1 b. This Regulation is without prejudice to the modalities of access to information applicable to the Members of Union institutions, such as the Members of the European Parliament, Members of the Commission, the Representatives of Member States acting within the Council, the Judges of the Court of Justice of the European Union or the Members of the Court of Auditors. In particular, in light of Parliament’s prerogatives and competences, the Members of the European Parliament who have not been given a personal security clearance shall be granted access to EU classified information under practical arrangements defined by common accord, including signature of a solemn declaration that they will not disclose the contents of those documents to any third person. |
Proposal for a regulation
Article 2 – paragraph 1 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment1 a. This Regulation is without prejudice to Regulation (Euratom) No 3/1958[1], Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community[2], Regulation (EC) 1049/2001 of the European Parliament and of the Council[3], Regulation (EU) 2018/1725 of the European Parliament and of the Council[4], Council Regulation (EEC, EURATOM) No 354/83[5], Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council[6], Regulation (EU) 2021/697 of the European Parliament and of the Council[7], Regulation (EU) (EU, EURATOM) No 2023/2841 of the European Parliament and of the Council[8] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. |
Proposal for a regulation
Article 2 – paragraph 2 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) three levels of non-classified information: public use, normal and sensitive non-classified; | Amendment(a) three levels of non-classified information: public use, working and protected non-classified; |
| Text proposed by the Commission | Amendment(This amendment applies throughout the text. Adopting it will necessitate corresponding changes throughout.) |
Only CONFIDENTIEL UE/EU CONFIDENTIAL, SECRET UE/EU SECRET, TRES SECRET UE/EU TOP SECRET are called ‘sensitive’ in Article 9 of Regulation 1049/2001. In accordance with Article 12(1) of Regulation 1049/2001, public use should be considered as 'normal'. In order to avoid confusion, a different terminology should be used.
Proposal for a regulation
Article 2 – paragraph 2 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) three levels of non-classified information: public use, normal and sensitive non-classified; | Amendment(a) two levels of non-classified information: public use and normal |
Proposal for a regulation
Article 2 – paragraph 2 – point b
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(b) four levels of EU classified information: RESTREINT UE/EU RESTRICTED, CONFIDENTIEL UE/EU CONFIDENTIAL, SECRET UE/EU SECRET, TRES SECRET UE/EU TOP SECRET. | Amendment(b) three levels of EU classified information: CONFIDENTIEL UE/EU CONFIDENTIAL, SECRET UE/EU SECRET, TRES SECRET UE/EU TOP SECRET. |
| Text proposed by the Commission | Amendment(This amendment applies throughout the text. Adopting it will necessitate corresponding changes throughout.) |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. These levels are based on the damage that unauthorised disclosure may cause to the legitimate private and public interests, including those of the Union, Union institutions and bodies and Member States or other stakeholders, so that the appropriate protective measures can be applied. | Amendment3. These levels are based on the damage that unauthorised disclosure may cause to the legitimate public interests, including those of the Union, Union institutions and bodies and Member States or other stakeholders, so that the appropriate protective measures can be applied. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 3 – paragraph 1 – point b
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(b) ‘information security’ means ensuring the authenticity, availability, confidentiality, integrity and non-repudiation of information; | Amendment(b) ‘information security’ means ensuring the authenticity, availability, confidentiality, integrity, within a secure European storage solution and non-repudiation of information; |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 3 – paragraph 1 – point d
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(d) 'storing' means the act of keeping information on any medium to ensure its availability for future use; | Amendment(d) 'storing' means the act of keeping information on any secure European medium to ensure its availability for future use, and non-interference from outside; |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 3 – paragraph 1 – point k
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(k) ‘communication and information system’ or ‘CIS’ means any system enabling the handling and the storage of information in electronic form, including all assets required for its operation; | Amendment(k) ‘communication and information system’ or ‘CIS’ means any system, preferably European, enabling the handling and the storage of information in electronic form, including all assets required for its operation; |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 3 – paragraph 1 – point r
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(r) ‘need-to-know’ means the necessity for an individual to access specified information handled or stored by an Union institution or body in order to fulfil the tasks of that particular Union institution or body; | Amendment(r) ‘need-to-know’ means the necessity for an individual to access specified information handled or stored by an Union institution or body in order to fulfil the official professional tasks of that particular Union institution or body; |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 3 – paragraph 1 – point r – point i (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendmenti) The decision to authorize a person to access information on a need-to-know basis is made on a case-by-case basis by each EU entity, in cooperation with national authorities responsible for clearance, supplemented where necessary by referral to the Member State of residence of the person to be cleared; Member States involve their intelligence services in line with their national rules depending on the level of information concerned; |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 3 – paragraph 1 – point af
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(af) ‘holder’ means a duly authorised individual with an established need-to-know who is in possession of an item of information requiring protection and accordingly responsible for protecting it; | Amendment(af) ‘holder’ means a duly authorised individual by its European entity in cooperation with Member States with an established need-to-know who is in possession of an item of information requiring protection and accordingly responsible for protecting it; |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 3 – paragraph 1 – point ai
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(ai) ‘authorisation to access EUCI’ means a decision by a Security Authority that an official, other servant or seconded national expert of a Union institution or body may be granted access to EUCI up to a specified level for a set period of time; | Amendment(ai) ‘authorisation to access EUCI’ means a decision by a Security Authority, after verification with the national authorities of establishment or even the Member State of residence, that an official, other servant or seconded national expert of a Union institution or body may be granted access to EUCI up to a specified level for a set period of time; |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Non-compliance with this Regulation, in particular the unauthorised disclosure of information with the confidentiality levels referred to in Article 2(2), except information for public use shall be subject to investigation and may trigger personnel liability in accordance with the Treaties or with their relevant staff rules. | Amendment2. Non-compliance with this Regulation, in particular the unauthorised disclosure of information with the confidentiality levels referred to in Article 2(2), except information for public use shall be subject to investigation and may trigger personnel liability in accordance with the Treaties or with their relevant staff rules. Any investigation or triggering of liability must consider the provisions on the disclosure of facts which give rise to a presumption of the existence of possible illegal activity, including fraud or corruption, detrimental to the interests of the Union, or of conduct relating to the discharge of professional duties which may constitute a serious failure to comply with the professional obligations, as well as the protection of persons who report breaches of Union law. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Union institutions and bodies shall assess all information they handle and store in order to categorise it in accordance with the confidentiality levels referred to in Article 2(2). | Amendment3. Without prejudice to Article 15 TFEU, Union institutions and bodies shall assess all information they handle and store in order to categorise it in accordance with the confidentiality levels referred to in Article 2(2). |
Proposal for a regulation
Article 4 – paragraph 4 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment4 a. Union institutions and bodies shall ensure that information is classified only where strictly necessary to protect legitimate interests of the Union or of the Member States. Classification levels shall be proportionate to the sensitivity of the information. An adequate level of transparency shall be maintained to support democratic accountability, avoiding practices of over-classification that may hinder information-sharing. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Article 4 – paragraph 5 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment5 a. The classification of information by Union institutions and bodies shall not be misused to unduly restrict public access to information. Classification measures shall be applied strictly in accordance with the legitimate security needs identified through the information security risk assessment, and not as a means to avoid transparency, accountability, or public scrutiny. In safeguarding confidentiality, institutions shall maintain a balanced approach that upholds the principles of openness and the public’s right to access information as enshrined in the Treaties. |
Proposal for a regulation
Article 4.º – paragraph 5 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment5a. Union institutions and bodies should progressively and proportionately adopt a security architecture based on the zero-trust principle. |
Proposal for a regulation
Article 4 – paragraph 6 – subparagraph 2
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionUnion institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. | AmendmentUnion institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. Union entities shall, not later than six months from the date of entry into force of this Regulation, design and implement effective and appropriate training courses for all individuals authorised to access EUCI, commensurate to the risks identified in accordance with Article 5. |
Proposal for a regulation
Article 4 – paragraph 6 – subparagraph 2
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionUnion institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. | AmendmentUnion institutions and bodies handling and storing EUCI shall organise mandatory training at least once every two years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. Special training shall also be organised in the event of any data leaks or breaches of information security, and in situations where swift and significant technological changes in the field of information security require the immediate updating of staff skills. |
Proposal for a regulation
Article 4 – paragraph 6 – subparagraph 2
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionUnion institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. | AmendmentUnion institutions and bodies handling and storing EUCI shall organise mandatory training within 6 months of them taking up their position and at least once every 5 years thereafter for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. |
Proposal for a regulation
Article 4 – paragraph 6 – subparagraph 2
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionUnion institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. | AmendmentUnion institutions and bodies handling and storing EUCI shall organise mandatory training at least once every year for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. |
Proposal for a regulation
Article 4 – paragraph 6 – subparagraph 3
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionA Union institution or body may coordinate such training and awareness activities with other Union institutions and bodies. | AmendmentA Union institution or body may coordinate such training and awareness activities with other Union institutions and bodies and with Member State authorities. |
Proposal for a regulation
Article 5 – paragraph 3 – point a a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(a a) the risks to the rights and freedoms of natural persons; |
Proposal for a regulation
Article 5 – paragraph 3 – point b a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(b a) design features of the facilities or CISs, including, in particular, the role of subcontractors in the development and maintenance of those facilities or CISs; |
Proposal for a regulation
Article 5 – paragraph 3 – point c
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(c) the persons accessing the information on sites or remotely; | Amendment(c) the persons accessing the information on sites or remotely, both from within and outside of the institution or body; |
Proposal for a regulation
Article 5 – paragraph 3 – point e
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(e) the threats targeting the Union, the Union institutions and bodies or the Member States from cyberattacks, supply chain attacks, espionage, sabotage, terrorist, subversive or other criminal activities; | Amendment(e) the threats targeting the Union, the Union institutions and bodies or the Member States from cyberattacks, supply chain attacks, espionage, sabotage, terrorist, subversive, social engineering or other criminal activities; |
Proposal for a regulation
Article 5 – paragraph 3 – point f
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(f) business continuity and disaster recovery; | Amendment(f) business continuity, crisis management and disaster recovery; |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | AmendmentArticle5a |
| Text proposed by the Commission | AmendmentRight to appeal information classification and access |
| Text proposed by the Commission | Amendment1. Any natural or legal person who submits a request for access to information held by a Union institution or body and whose request is denied on the grounds of confidentiality or classification may submit an appeal against that decision to the President of the institution or body concerned. |
| Text proposed by the Commission | Amendment2. The President shall ensure that the appeal is duly examined, with the assistance of the competent services, to determine whether the classification of the requested information complies with the principles and criteria established in this Regulation. |
| Text proposed by the Commission | Amendment3. The President shall adopt a reasoned decision within 3 months, either upholding the classification or deciding to grant full or partial access to the requested information. |
| Text proposed by the Commission | Amendment4. If the requester’s appeal is rejected, they shall have the right to seek judicial remedy before the Court of Justice of the European Union in accordance with the Treaties. |
| Text proposed by the Commission | Amendment5. Union institutions and bodies shall ensure that this appeal procedure is transparent, accessible, and clearly communicated to the public, thereby safeguarding both the legitimate need for information security and the fundamental right of access to information. |
Proposal for a regulation
Article 6 – paragraph 2 – point e a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(e a) monitor compliance by Union institutions and bodies with this Regulation, as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report; |
Proposal for a regulation
Article 6 – paragraph 2 – point e a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(ea) draw up a coordination plan for situations where one or more Union body or institution has suffered a data leak or breach of information security; |
Proposal for a regulation
Article 6.º – paragraph 2 – point e b (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(eb) Sets out common guidelines for the implementation of a zero-trust architecture at the Union's institutions and bodies, in cooperation with the European Union Agency for Cybersecurity (ENISA) and the national security authorities, ensuring consistency with international best practices and with the obligations arising from this Regulation. |
Proposal for a regulation
Article 6 – paragraph 4 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment4a. The Coordination Group shall meet immediately in the event of a serious data leak or data hack at one or more Union body or institution. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission5. The Coordination Group shall have the administrative support of a permanent secretariat provided by the Commission. | Amendment5. The Coordination Group shall have the administrative support of a permanent secretariat jointly provided by the Commission and by the Parliament. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission5. The Coordination Group shall have the administrative support of a permanent secretariat provided by the Commission. | Amendment5. The Coordination Group shall have the administrative support of a permanent joint secretariat provided by Parliament and the Commission. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission6. Each Union institution or body shall be appropriately represented in the Coordination Group and where applicable, in the thematic sub-groups. | Amendment6. Each Union institution or body shall be appropriately represented in the Coordination Group and, where applicable, in the thematic sub-groups. Appointments shall strive to ensure gender balance and a fair geographical representation. |
Proposal for a regulation
Article 7 – paragraph 1 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) a sub-group on information assurance; | Amendment(a) a sub-group on information assurance and declassification; |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Any CIS that handles and stores EUCI shall be accredited in accordance with Chapter 5, Section 5. Any CIS that handles and stores sensitive non-classified information shall comply with the minimum requirements for sensitive non-classified information in CISs set out in Chapter 4. | Amendment2. Any CIS that handles and stores EUCI shall be accredited in accordance with Chapter 5, Section 5. Any CIS that handles and stores normal information that merits particular caution, such as personal data, shall comply with the minimum requirements for CISs set out in Chapter 4. |
Proposal for a regulation
Article 10 – paragraph 1 – introductory part
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. The sub-group on information assurance, as referred to in Article 7(1) point (a), shall have the following roles and responsibilities: | Amendment1. The sub-group on information assurance and declassification, as referred to in Article 7(1) point (a), shall have the following roles and responsibilities: |
Proposal for a regulation
Article 10 – paragraph 1 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) providing guidance and best practices on the marking, handling and storing of information in CISs in close cooperation with the Interinstitutional cybersecurity board referred to in Article 9 of Regulation EU [XXX] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union; | Amendment(a) providing guidance and best practices on the marking, handling, storing and, where possible, declassification, of information in CISs in close cooperation with the Interinstitutional cybersecurity board referred to in Article 9 of Regulation EU [XXX] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union; |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 10 – paragraph 1 – point b
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(b) establishing a metadata scheme for markings and all necessary technical information to contribute to an interoperable and seamless exchange of information across Union institutions and bodies, when interconnecting their respective CISs; | Amendment(b) establishing a metadata scheme for markings and all necessary technical information to contribute to a seamless exchange of information across Union institutions and bodies; |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Union institutions and bodies shall inform users about the confidentiality levels of information that can be handled and stored in a CIS. Where a CIS handles and stores multiple confidentiality levels, metadata and visual markings shall be used to ensure that the different levels can be distinguished. | Amendment1. Union institutions and bodies shall inform users about the confidentiality levels of information that can be handled and stored in a CIS. Where a CIS processes information subject to confidentiality, metadata and visual markings shall be applied to clearly indicate the level of confidentiality. |
Proposal for a regulation
Article 11 – paragraph 4 – point d
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(d) encryption of information at rest and in transit; | Amendment(d) end-to-end encryption of information at all stages of the relevant processes; |
Proposal for a regulation
Article 11 – paragraph 4 – subparagraph 1 (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | AmendmentUnion institutions and bodies shall ensure interoperability of their communication and information systems with a view to facilitating seamless information exchange, including through common metadata schemes and shared digital platforms that reduce technical or procedural barriers. |
Proposal for a regulation
Article 12 – paragraph 1 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment1 a. Union institutions and bodies shall as far as possible make documents directly accessible to the public in electronic form or through a register in accordance with the rules of the institution concerned and Article 12 of Regulation 1049/2001. In particular, this provision applies to legislative documents, that is to say, documents drawn up or received in the course of procedures for the adoption of acts which are legally binding in or for the Member States. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Article 12 – paragraph 1 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment1 a. Union institutions and bodies shall, to the extent possible, make documents directly accessible to the public in electronic form or through a register in accordance with the rules of the institution concerned. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Union institutions and bodies may mark with ‘PUBLIC USE’ the information referred to in paragraph 1. | Amendment2. Union institutions and bodies may mark with ‘PUBLIC USE’ the information referred to in paragraph 1. The absence of such marking shall not give rise to a presumption that the information could be classified. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. All Union institutions and bodies shall ensure the integrity and availability of information for public use by appropriate measures based on its security needs. | Amendment3. All Union institutions and bodies shall ensure the integrity and availability of information for public use by appropriate measures. They shall conduct their work as openly as possible, thereby promoting good governance and enabling the effective participation of civil society. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. All Union institutions and bodies shall ensure the integrity and availability of information for public use by appropriate measures based on its security needs. | Amendment3. All Union institutions and bodies shall ensure the integrity and availability of information for public use by appropriate measures based on their security needs and accounting for the right to information. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionNormal information | AmendmentWorking information |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Information intended for use by a Union institution or body in the execution of its functions which is neither sensitive non-classified nor for public use shall be categorised, handled and stored as normal information. This category covers all normal working level information processed in the Union institution or body concerned. | Amendment1. Information intended for use by a Union institution or body in the execution of its functions which is neither protected non-classified nor for public use shall be categorised, handled and stored as working information. This category covers all working level information processed in the Union institution or body concerned for which no public interest is conceivable and which has not been drawn up or received in the course of procedures for the adoption of acts which are legally binding in or for the Member States. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Information intended for use by a Union institution or body in the execution of its functions which is neither sensitive non-classified nor for public use shall be categorised, handled and stored as normal information. This category covers all normal working level information processed in the Union institution or body concerned. | Amendment1. Information intended for use by a Union institution or body in the execution of its functions which is neither classified nor for public use shall be categorised, handled and stored as normal information. Where necessary for the proper performance of tasks, the category normal information may include personal data and other non-classified information that requires particular care. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Normal information may be marked visually or in metadata where necessary to ensure its protection, particularly where shared outside Union institutions and bodies. The marking ‘EU NORMAL’ or the ‘name or acronym of the Union institution or body NORMAL’ (adjusted on a case-by-case basis) shall be used in that case. | Amendment2. Normal information may be marked visually or in metadata where necessary to ensure its protection, particularly where shared outside Union institutions and bodies. The marking ‘EU NORMAL’ or the ‘name or acronym of the Union institution or body NORMAL’ (adjusted on a case-by-case basis) shall be used in that case. Where the information contains personal data or other sensitive elements, the marking shall indicate their presence and any specific handling requirements. Union institutions and bodies shall apply appropriate and proportionate technical and organisational measures to protect normal information, taking into account its sensitivity and the risks involved, including but not limited to: access control on a need-to-know basis; authentication and authorisation; encryption or pseudonymisation when stored or transmitted; retention limits and secure deletion; and logging and audit trails. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Normal information may be marked visually or in metadata where necessary to ensure its protection, particularly where shared outside Union institutions and bodies. The marking ‘EU NORMAL’ or the ‘name or acronym of the Union institution or body NORMAL’ (adjusted on a case-by-case basis) shall be used in that case. | Amendment2. Normal information may be marked visually or in metadata where necessary to ensure its protection, particularly where shared outside Union institutions and bodies. The marking ‘EU NORMAL’ or the ‘name or acronym of the Union institution or body NORMAL’ (adjusted on a case-by-case basis) shall be used in that case. The absence of such marking shall not give rise to a presumption that the information could be classified. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Normal information may be marked visually or in metadata where necessary to ensure its protection, particularly where shared outside Union institutions and bodies. The marking ‘EU NORMAL’ or the ‘name or acronym of the Union institution or body NORMAL’ (adjusted on a case-by-case basis) shall be used in that case. | Amendment2. Working information may be marked visually or in metadata where necessary to ensure its protection, particularly where shared outside Union institutions and bodies. The marking ‘EU WORKING’ or the ‘name or acronym of the Union institution or body WORKING’ (adjusted on a case-by-case basis) shall be used in that case. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. Normal information shall be exchanged outside Union institutions and bodies only with natural or legal persons having a need-to-know. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. Normal information shall be exchanged outside Union institutions and bodies only with natural or legal persons having a need-to-know. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. Normal information shall be exchanged outside Union institutions and bodies only with natural or legal persons having a need-to-know. | Amendment4. Normal information shall be exchanged outside Union institutions and bodies only with natural or legal persons having a need-to-know. However, where the information does not concern matters that merit particular care, it may be exchanged with the public if an overriding public interest justifies its disclosure. |
Proposal for a regulation
Article 13 – paragraph 4 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(4a) Refusal to provide classified information as normal must be justified by means of an impact assessment or by recourse to approved experts. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionArticle 14 | Amendmentdeleted |
| Text proposed by the CommissionSensitive non-classified information |
| Text proposed by the Commission1. Union institutions and bodies shall categorise, handle and stored as sensitive non-classified all information that is not classified but which they must protect due to legal obligations or because of the harm that may be caused to the legitimate private and public interests, including those of the Union institutions and bodies, Member States or individuals by its unauthorised disclosure. |
| Text proposed by the Commission2. Each Union institution and body shall identify sensitive non-classified information by a visible security marking and shall define corresponding handling instructions in accordance with Annex I. |
| Text proposed by the Commission3. Union institutions and bodies shall protect sensitive non-classified information by applying appropriate measures in respect of its handling and storage. Such information may only be made available inside Union institutions and bodies to individuals with a need-to-know for the fulfilment of their assigned tasks. |
| Text proposed by the Commission4. Sensitive non-classified information shall be exchanged outside Union institutions and bodies only with natural and legal persons that have a need-to-know while respecting the handling instructions accompanying the information. All parties involved shall be made aware of the appropriate handling instructions. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionSensitive non-classified information | AmendmentProtected non-classified information |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Union institutions and bodies shall categorise, handle and stored as sensitive non-classified all information that is not classified but which they must protect due to legal obligations or because of the harm that may be caused to the legitimate private and public interests, including those of the Union institutions and bodies, Member States or individuals by its unauthorised disclosure. | Amendment1. Union institutions and bodies shall categorise, handle and stored as sensitive non-classified all information that is not classified but which they must protect due to legal obligations or because of the harm that may be caused to the legitimate public interests, including those of the Union institutions and bodies or Member States by its unauthorised disclosure. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. Sensitive non-classified information shall be exchanged outside Union institutions and bodies only with natural and legal persons that have a need-to-know while respecting the handling instructions accompanying the information. All parties involved shall be made aware of the appropriate handling instructions. | Amendment4. Sensitive non-classified information shall be exchanged outside Union institutions and bodies only with natural and legal persons that have a need-to-know while respecting the handling instructions accompanying the information and the requirements stemming from legal protections that might apply under paragraph 1. All parties involved shall be made aware of the appropriate handling instructions. |
Proposal for a regulation
Article 14 – paragraph 4 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(4a) Refusal to provide sensitive non-classified information to the media, when it requests this on the basis of its public mission and in the performance of its work, must be justified by means of an impact assessment or by recourse to approved experts. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionProtection of non-classified information and interoperability | AmendmentProtection of non-classified information and data exchange |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Union institutions and bodies shall establish procedures for the reporting and management of any incident or suspected incident that could lead to a compromise of the security of non-classified information. | Amendment1. Union institutions and bodies shall establish uniform procedures for the reporting and management of any incident or suspected incident that could lead to a compromise of the security of non-classified information. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. Exceptionally, other equivalent markings may be used internally and in relation with their particular counterparts from other Union institutions and bodies or from the Member States, when all parties agree. Such exception shall be notified to the sub-group on non-classified information, as referred to in Article 7(1), point (b). | Amendment2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12, 13 and 14. Exceptionally, other equivalent markings may be used internally and in relation with their particular counterparts from other Union institutions and bodies or from the Member States, when all parties agree. Such exception shall be notified to the sub-group on non-classified information, as referred to in Article 7(1), point (b). | Amendment2. Where required, Union institutions and bodies shall use the markings provided for in Articles 12 and 13. Exceptionally, other equivalent markings may be used internally and in relation with their particular counterparts from other Union institutions and bodies or from the Member States, when all parties agree. Such exception shall be notified to the sub-group on non-classified information, as referred to in Article 7(1), point (b). |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Contractual safeguards shall be established to ensure the protection of normal and sensitive non-classified information processed by outsourced services. The safeguards shall be designed to guarantee at least an equivalent level of protection to that provided by this Regulation, and shall include confidentiality and non-disclosure undertakings to be signed by all relevant service providers involved in the provision of the outsourced systems. | Amendment3. Contractual safeguards shall be established to ensure the protection of working and protected non-classified information processed by outsourced services. The safeguards shall be designed to guarantee at least an equivalent level of protection to that provided by this Regulation, and shall include confidentiality and non-disclosure undertakings to be signed by all relevant service providers involved in the provision of the outsourced systems. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Contractual safeguards shall be established to ensure the protection of normal and sensitive non-classified information processed by outsourced services. The safeguards shall be designed to guarantee at least an equivalent level of protection to that provided by this Regulation, and shall include confidentiality and non-disclosure undertakings to be signed by all relevant service providers involved in the provision of the outsourced systems. | Amendment3. Contractual safeguards shall be established to ensure the protection of normal information processed by outsourced services. The safeguards shall be designed to guarantee at least an equivalent level of protection to that provided by this Regulation, and shall include confidentiality and non-disclosure undertakings to be signed by all relevant service providers involved in the provision of the outsourced systems. |
Proposal for a regulation
Article 16 – paragraph 1 – point c
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(c) preparing handling instructions for the different confidentiality levels of non-classified information; | Amendment(c) preparing handling instructions for non-classified information; |
Proposal for a regulation
Article 16 – paragraph 1 – point d
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(d) assisting Union institutions and bodies in establishing the equivalence between their particular categories of non-classified information and those provided for in Articles 12, 13 and 14; | Amendment(d) assisting Union institutions and bodies in establishing the equivalence between their particular categories of non-classified information and those provided for in Articles 12 and 13; |
Proposal for a regulation
Article 16 – paragraph 1 – point e
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(e) facilitating the sharing of non-classified information between Union institutions and bodies, by providing assistance and guidance. | Amendment(e) Facilitating the sharing of non-classified information between Union institutions and bodies, and with third parties where appropriate, by providing assistance and guidance. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionHandling and storing of sensitive non-classified information in CISs | AmendmentHandling and storing of normal information in CISs |
Proposal for a regulation
Article 17 – paragraph 1 – introductory part
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Union institutions and bodies shall ensure that CISs meet the following minimum requirements when handling and storing sensitive non-classified information: | Amendment1. Union institutions and bodies shall ensure that CISs meet the following minimum requirements when handling and storing normal information: |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 17 – paragraph 1 – point e
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(e) interoperable metadata shall be used to record the confidentiality level of electronic documents and to facilitate the automation of security measures; | Amendment(e) exchanged metadata shall be used to record the confidentiality level of electronic documents and to facilitate the automation of security measures; |
Proposal for a regulation
Article 17 – paragraph 1 – point f
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(f) measures to prevent and detect data leaks shall be implemented by the Union institutions and bodies to protect sensitive non-classified information; | Amendment(f) measures to prevent and detect data leaks shall be implemented by the Union institutions and bodies to protect normal information; |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 17 – paragraph 1 – point h
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(h) implementation of security measures based on the principles of need-to-know and zero trust to minimise access to sensitive non-classified information by service providers and contractors. | Amendment(h) implementation of security measures based on the principles of strict need-to-know and zero trust to minimise access to sensitive non-classified information by service providers and contractors. |
Proposal for a regulation
Article 17 – paragraph 1 – point h
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(h) implementation of security measures based on the principles of need-to-know and zero trust to minimise access to sensitive non-classified information by service providers and contractors. | Amendment(h) implementation of security measures based on the principles of need-to-know and zero trust to minimise access to normal information by service providers and contractors. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Any derogation from the minimum requirements set out in paragraph 1 shall be subject to approval by the appropriate level of management of the Union institution or body concerned, on the basis of a risk assessment covering the legal and technical risks to the security of the sensitive non-classified information. | Amendment2. Any derogation from the minimum requirements set out in paragraph 1 shall be subject to approval by the appropriate level of management of the Union institution or body concerned, on the basis of a risk assessment covering the legal and technical risks to the security of the normal information. |
Proposal for a regulation
Article 18 – paragraph 1 – point d
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(d) RESTREINT UE/EU RESTRICTED: information and material the unauthorised disclosure of which could be disadvantageous to the interests of the Union or of one or more of the Member States. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. | Amendment2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. Such documents shall take into account both the principle of minimisation of the use of classified information and the risk of overclassification of certain documents, and shall include rules on assessing and justifying information and material classification, aimed at increasing transparency and avoiding unjustified lock-in effects. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 20 – paragraph 2 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment2 a. Every entity of the Union remains the owner of its information and has the final say to oppose its transfer; |
Proposal for a regulation
Article 20 – paragraph 3 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment3 a. This Article is without prejudice to Regulation (EC) No 1049/2001. |
Proposal for a regulation
Article 21 – paragraph 3 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) contingency plans to ensure EUCI security during emergencies; | Amendment(a) contingency plans to ensure EUCI security in the event of data leaks and breaches of information security and in other emergencies; |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. An act or omission of a Union institution or body or an individual, which is in breach of this Regulation, shall be considered as a breach of security. | Amendment1. Any act or omission of a Union institution or body or an individual, which is in breach of this Regulation, shall be considered as a breach of security. |
Proposal for a regulation
Article 22 – paragraph 3 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) inform the originator; | Amendment(a) inform the originator without undue delay, and in any event no later than three days after the Security Authority has been informed of the breach; |
Proposal for a regulation
Article 22 – paragraph 3 – point b
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(b) ensure that the case is investigated by personnel not immediately concerned with the breach in order to establish the facts; | Amendment(b) ensure that the case is thoroughly investigated by personnel not immediately concerned with the breach in order to establish the facts; |
Proposal for a regulation
Article 22 – paragraph 3 – point e
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(e) notify the competent authorities about the actual or potential compromise and the action taken. | Amendment(e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any event no later than three days after the Security Authority has been informed of the breach. |
Proposal for a regulation
Article 22 – paragraph 3 – point e a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(ea) if personal data security has been compromised in connection with an information security breach, the matter must be reported immediately, in accordance with data protection legislation, to the Member State data protection authority and to the individuals whose personal data have been leaked. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 23 – paragraph 1 – point c
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(c) for information classified CONFIDENTIEL UE/EU CONFIDENTIAL or higher, the individuals have been granted security clearance and have been authorised to the relevant level. | Amendment(c) for information classified CONFIDENTIEL UE/EU CONFIDENTIAL or higher, the individuals have been granted security clearance and have been authorised to the relevant level, after consultation of their intelligence services in line with respective national rules; |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Union institutions and bodies shall take into account the loyalty, trustworthiness and reliability of an individual as determined by means of a security investigation conducted by the competent authorities of the Member State of which the applicant is a citizen or a national. | Amendment2. Union institutions and bodies shall take into account the loyalty, trustworthiness and reliability of an individual as determined by means of a security investigation conducted by the Commission in cooperation with the competent authorities of the relevant Member States. The Commission may also cooperate with third countries and international organisations with which the Union has a security of information agreement. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. | Amendmentdeleted |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. | Amendment3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement, provided that vetting is carried out with the same level of security guarantee as in EU Member States; |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. | Amendment3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall, in any event, ensure that the principles under paragraphs 1 and 2 are observed. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 23 – paragraph 4 – subparagraph 1
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionUnion institutions and bodies may manage the clearance processes autonomously or seek a Service Level Agreement ('SLA') with the Commission for security clearance purposes. | AmendmentUnion institutions and bodies manage the clearance processes autonomously. |
Proposal for a regulation
Article 23 – paragraph 4 – subparagraph 2
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionWhere a SLA is concluded, the Commission Security Authority shall be the contact point between the security offices of the Union institution and body concerned and the national competent authorities of the Member States in the context of security clearance issues. | Amendmentdeleted |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 23 – paragraph 4 – subparagraph 2
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionWhere a SLA is concluded, the Commission Security Authority shall be the contact point between the security offices of the Union institution and body concerned and the national competent authorities of the Member States in the context of security clearance issues. | Amendmentdeleted |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission6. Union institutions and bodies that conclude an SLA with the Commission shall make the relevant records available to the Commission’s Security Authority regarding as a minimum the level of EUCI to which the individual may be granted access, the date of issue of the authorisation to access EUCI and its period of validity. Those records shall be accessible to other Union institutions and bodies with an SLA, where justified. | Amendment6. Union institutions and bodies shall make the relevant records available to the Commission’s Security Authority regarding as a minimum the level of EUCI to which the individual may be granted access, the date of issue of the authorisation to access EUCI and its period of validity. Those records shall be accessible to other Union institutions and bodies, where justified. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. The Security Authority of each Union institution and body shall be responsible for granting, suspending, withdrawing and renewing authorisations to access EUCI for their staff. | Amendment3. The Security Authority of each Union institution and body shall be responsible for granting, suspending, withdrawing and renewing authorisations to access EUCI for their staff, in conjunction with national authorities, including during the period of validity of the authorization to access information. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. In exceptional circumstances, where duly justified in the interests of the service and pending completion of a full security investigation, the Security Authority of a Union institution or body may grant a temporary authorisation for individuals to access EUCI for a specific position, without prejudice to the provisions regarding renewal of authorisation to access EUCI and upon verification of the relevant National Security Authority. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. In exceptional circumstances, where duly justified in the interests of the service and pending completion of a full security investigation, the Security Authority of a Union institution or body may grant a temporary authorisation for individuals to access EUCI for a specific position, without prejudice to the provisions regarding renewal of authorisation to access EUCI and upon verification of the relevant National Security Authority. | Amendment4. In exceptional circumstances, where duly justified in the interests of the service and pending completion of a full security investigation, the Security Authority of a Union institution or body may grant a temporary authorisation for individuals to access EUCI for a specific position, without prejudice to the provisions regarding renewal of authorisation to access EUCI. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. An authorisation to access EUCI up to the specified level shall be valid in any Union institution or body to which the individual is assigned. | Amendment1. An authorisation to access EUCI up to the specified level shall be valid in the sole institution to which an individual is assigned at the time of issuance and for a defined scope and duration. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Union institutions and bodies shall accept authorisations to access EUCI granted by other Union institution or body. | Amendment2. Union institutions and bodies shall accept authorisations to access EUCI granted by other Union institution or body on a case-by-case basis while strictly enforcing the need-to-know principle and provided that the EU entity owning the information has the final say to object to its transmission. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Where the holder of an authorisation to access EUCI takes up employment in another Union institution or body, that Union institution or body shall notify the relevant NSA of a change of employer, through the competent Security Authority. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Where the holder of an authorisation to access EUCI takes up employment in another Union institution or body, that Union institution or body shall notify the relevant NSA of a change of employer, through the competent Security Authority. | Amendment3. Where the holder of an authorisation to access EUCI takes up employment in another Union institution or body, that Union institution or body shall, without undue delay, notify the relevant NSA of a change of employer, through the competent Security Authority. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. The Security Authority of a Union institution or body shall brief all individuals who need to access EUCI on any threats to security and about their obligation to report any suspicious activity. The briefing shall take place before access to EUCI is granted and at least every 5 years thereafter. | Amendment1. The Security Authority of a Union institution or body shall brief all individuals who need to access EUCI on any threats to security and about their obligation to report any suspicious activity. The briefing shall take place before access to EUCI is granted and at least every two years thereafter, as well as in the event of any data leaks and breaches of information security and in situations where swift and significant technological changes in the field of information security require the immediate updating of staff skills. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. The Security Authority of a Union institution or body shall brief all individuals who need to access EUCI on any threats to security and about their obligation to report any suspicious activity. The briefing shall take place before access to EUCI is granted and at least every 5 years thereafter. | Amendment1. The Security Authority of a Union institution or body shall brief all individuals who need to access EUCI on any threats to security and about their obligation to report any suspicious activity. The briefing shall take place before access to EUCI is granted and at least every year thereafter. |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Union institutions and bodies shall put in place physical security measures for all sites where EUCI is discussed, stored or handled, including areas housing communication and information systems as referred to in Section 5 of this Chapter. | Amendment2. Union institutions and bodies shall put in place physical security measures, including with the assistance of national authorities, for all sites where EUCI is discussed, stored or handled, including areas housing communication and information systems as referred to in Section 5 of this Chapter. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Any Union institution and body which is the originator of EUCI shall determine the security classification of that information upon its creation and in accordance with Article 18(1). | Amendment2. Any Union institution and body which is the originator of EUCI shall determine the initial security classification of that information upon its creation and in accordance with Article 18(1). |
Proposal for a regulation
Article 31 – paragraph 1 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) each page shall be marked clearly with the classification level; | Amendment(a) each page shall be marked clearly with the classification level and the duration of classification; |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionOriginator control | AmendmentOriginator’s opinion |
Proposal for a regulation
Article 32 – paragraph 1 – introductory part
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: | Amendment1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. The originator may consult intended recipients regarding the classification level of an EUCI document, in particular in the event of any doubt as to the confidential nature of an item of information and its appropriate level of classification, and to prevent over-classification of such documents. For the purposes of the initial dissemination of an EUCI document, the originator shall take into account the rights and obligations of information recipients arising from the Treaties. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: |
Proposal for a regulation
Article 32 – paragraph 1 – introductory part
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: | Amendment1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator may provide an opinion on the following actions, which shall be duly taken into account by the Union institution or body holding the information: |
Proposal for a regulation
Article 32 – paragraph 1 – introductory part
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: | Amendment1. The Union institution or body under whose authority an EUCI document classified CONFIDENTIEL UE/EU-CONFIDENTIAL or higher is created shall have originator control over that document. The originator shall determine the initial classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: |
Fabrice Leggeri, António Tânger Corrêa, Petra Steger, Susanna Ceccardi, Nikola Bartůšek
Proposal for a regulation
Article 32 – paragraph 1 – introductory part
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: | Amendment1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be decision-maker and responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: |
Proposal for a regulation
Article 32 – paragraph 1 – point d
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(d) copied and translated in case of TRES SECRET-UE/EU-TOP SECRET level. | Amendmentdeleted |
Proposal for a regulation
Article 32 – paragraph 1 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment1 a. Where a Union institution or a body disagrees with the refusal to give the originator's written consent, it may have recourse to the dispute resolution mechanism referred to in Article 39a. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Where the originator of an EUCI document cannot be identified, the Union institution or body holding that classified information shall exercise originator control. | Amendment2. Where the originator of an EUCI document cannot be identified, the Union institution or body holding that classified information shall exercise Originator’s opinion. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Information shall be classified only for as long as it requires protection. EUCI that no longer needs the original classification shall be downgraded to a lower level. EUCI that no longer needs to be considered as classified at all shall be declassified. | Amendment1. Information shall be classified only for as long as it requires protection. EUCI that no longer needs the original classification shall be downgraded to a lower level. EUCI that no longer needs to be considered as classified at all shall be declassified. Any classification shall be reviewed at the latest one year after the document’s creation and every year afterwards. In case of documents that concern an ongoing legislative process, this review shall be done no later than two months after the document’s creation and every two months afterwards. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Information shall be classified only for as long as it requires protection. EUCI that no longer needs the original classification shall be downgraded to a lower level. EUCI that no longer needs to be considered as classified at all shall be declassified. | Amendment1. Information shall be classified only for as long as it requires protection. EUCI that no longer needs the original classification shall be downgraded to a lower level. EUCI that no longer needs to be considered as classified at all shall be declassified. In case of documents that concern an ongoing legislative process, a review shall be done no later than two months after the document’s creation and every two months afterwards until the adoption of the legislation. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. At the time of creation of EUCI, the originator shall indicate, where possible, and in particular for information classified RESTREINT UE/EU RESTRICTED, whether the EUCI can be downgraded or declassified on a given date or following a specific event. | Amendment2. At the time of creation of EUCI, the originator shall indicate whether the EUCI can be downgraded or declassified on a given date or following a specific event. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. At the time of creation of EUCI, the originator shall indicate, where possible, and in particular for information classified RESTREINT UE/EU RESTRICTED, whether the EUCI can be downgraded or declassified on a given date or following a specific event. | Amendment2. At the time of creation of EUCI, the originator shall indicate, where possible, whether the EUCI can be downgraded or declassified on a given date or following a specific event. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. The originating Union institution or body shall be responsible for deciding whether a EUCI document can be downgraded or declassified. It shall review the information and assess the risks regularly and at least every 5 years in order to determine whether the original classification level is still appropriate. | Amendment3. The originating Union institution or body shall be responsible for deciding whether a EUCI document can be downgraded or declassified. It shall review the information and assess the risks regularly and at least every 3 years in order to determine whether the original classification level is still appropriate. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. Union institutions and bodies holding EUCI of which they are not the originator shall not downgrade or declassify that document, nor shall they modify or remove any of the markings referred to in Article 18(1) without the prior written consent of the originator. | Amendment4. Union institutions and bodies holding EUCI of which they are not the originator shall not downgrade or declassify that document, nor shall they modify or remove any of the markings referred to in Article 18(1) without the prior written consent of the originator. Where a Union institution or a body disagrees with the refusal to give the originator's written consent, it may have recourse to the dispute resolution mechanism referred to in Article 39a. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Where Union institutions and bodies decide to declassify an EUCI document, consideration shall be given as to whether it is to bear a sensitive non-classified information distribution marking. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Union institutions and bodies shall review EUCI, both on paper and in CISs, at least every 5 years to determine whether they are to be destroyed or deleted. Where EUCI is destroyed or deleted, they shall instruct anyone having previously received that EUCI. | Amendment1. Union institutions and bodies shall review EUCI, both on paper and in CISs, at least every 5 years to determine whether they are to be retained, destroyed or deleted. Any decision to destroy or delete EUCI shall be duly justified and documented. Where EUCI is destroyed or deleted, the institutions and bodies shall instruct anyone having previously received that EUCI accordingly. |
Proposal for a regulation
Article 38 – paragraph 1 – subparagraph 2
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionThe operational details of emergency evacuation and destruction plans shall themselves be classified as RESTREINT UE/EU RESTRICTED. | AmendmentThe operational details of emergency evacuation and destruction plans shall themselves be classified. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Union institutions and bodies shall decide whether and when to archive EUCI, and the corresponding practical measures, in accordance with their policy on document management. | Amendment1. Union institutions and bodies shall decide whether and when to archive EUCI, and the corresponding uniform practical measures. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. EUCI documents shall not be transferred to the Historical Archives of the European Union. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | AmendmentArticle 39a |
| Text proposed by the Commission | AmendmentDisputes |
| Text proposed by the Commission | Amendment1. In the event of any doubt as to the protected nature of information or its appropriate level of classification, the Union institutions and bodies shall consult each other without delay and before transmission of the information. In the event of a disagreement, the matter shall be referred to the Presidents of the Institutions or bodies so that they may resolve the dispute. |
| Text proposed by the Commission | Amendment2. If, at the end of the procedure referred to in paragraph 1, no agreement has been reached, the refusal to revise the protected nature of information or its appropriate level of classification shall be subject to review of its legality in accordance with Article 263 TFEU. |
Proposal for a regulation
Article 41 – paragraph 1 – point b
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(b) key security principles for the design of CIS handling and storing EUCI shall apply at the inception of the project, as part of the information security risk management process and taking into account need-to-know, minimal functionality, defence in depth, least privilege, segregation of duties and four eyes; | Amendment(b) crucial security principles for the design of CIS handling and storing EUCI shall apply at the inception of the project, as part of the information security risk management process and taking into account need-to-know, minimal functionality, defence in depth, least privilege, segregation of duties and four eyes; |
Proposal for a regulation
Article 41 – paragraph 1 – point e
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(e) all staff involved in the operation of a CIS handling and storing EUCI shall notify to the Security Authority and the relevant system owner or Information Assurance Operational Authority any potential security weaknesses, incidents, breaches of security or system compromises that may have an impact on the protection of the CIS or the EUCI therein; | Amendment(e) all staff involved in the operation of a CIS handling and storing EUCI shall notify the Security Authority and the relevant system owner or Information Assurance Operational Authority of any potential security weaknesses, incidents, breaches of security or system compromises that may have an impact on the protection of the CIS or the EUCI therein; |
Proposal for a regulation
Article 41 – paragraph 1 – point f a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(f a) the system owner or the Information Assurance Operational Authority shall ensure that a process of identifying and reporting vulnerabilities is in place; that process shall be complemented by regular audits and penetration tests where appropriate. |
Proposal for a regulation
Article 42 – paragraph 1 – subparagraph 1 (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | AmendmentPreference should be given to European products and technology for the electronic transmission and storage of EUCI. |
Proposal for a regulation
Article 44 – paragraph 2 – point c a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(ca) staff handling classified information shall be deemed to be trained and to have sufficient expertise in information security; |
Proposal for a regulation
Article 48 – paragraph 1 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(1a) The Security Classification Guide most take account of justified public interest. The inclusion of any information in the category of information not for public use must be justified by a social impact assessment. |
Proposal for a regulation
Article 48 – paragraph 2 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(2a) Any changes to the Security Classification Guide, regardless of when these are made, must be justified by social impact assessments. Contracts/awards in the field of public health cannot be subject to classifications that restrict their access by the media. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | Amendment2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That subgroup shall seek a fair balance between the need to protect EUCI and Regulation (EC) No 1049/2001, and shall ensure that the classification does not in itself prevent disclosure. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | Amendment2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That subgroup shall ensure synergy between the need to protect EUCI and Regulation (EC) No 1049/2001 and shall ensure that the classification does not in itself prevent disclosure. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | Amendment2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | Amendment2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council, the European Parliament and the European External Action Service and shall work by consensus. |
Proposal for a regulation
Article 53 – paragraph 2 – point d
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(d) to reinforce security authorities’ ongoing security education and awareness programmes. | Amendment(d) to reinforce ongoing security education and awareness programmes for security authorities and staff. |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Article 54 – paragraph 1 – introductory part
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. A Union institution or body may share EUCI with another Union institution or body where the following conditions are fulfilled: | Amendment1. A Union institution or body shall share EUCI with another Union institution or body where the following conditions are fulfilled: |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Article 54 – paragraph 1 – point -a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment(-a) there is a legal obligation pursuant to the Treaties, secondary law or an Interinstitutional agreement concluded between Union institutions; or |
Proposal for a regulation
Article 54 – paragraph 1 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) there is a proven need for the exchange; | Amendment(a) there is a proven need for the exchange, or a legal obligation under Union law or under an agreement concluded between Union institutions; |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Article 54 – paragraph 1 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) there is a proven need for the exchange; | Amendment(a) there is a proven need for the exchange; and |
Kristian Vigenin, Krzysztof Śmiszek, Elio Di Rupo, Matjaž Nemec
Proposal for a regulation
Article 54 – paragraph 1 – point b
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(b) an assessment visit has been carried out at the Union institution or body concerned, in accordance with Article 53, the outcome of which certifies the capacity of that Union institution or body to handle and store a specified level of EUCI; | Amendment(b) an assessment visit has been carried out at the Union institution or body concerned, in accordance with Article 53, the outcome of which certifies the capacity of that Union institution or body to handle and store a specified level of EUCI; and |
Proposal for a regulation
Article 54 – paragraph 2 a (new)
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission | Amendment2 a. The procedures established under this Article shall be implemented in a manner that prioritises efficiency and prevents delays. Union institutions and bodies shall regularly review and simplify the modalities of sharing EUCI in order to avoid unnecessary complications or administrative burdens. |
Proposal for a regulation
Article 56 – paragraph 1 – point a
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission(a) the Union institution or body concerned needs to exchange, on a long-term basis information classified, as a general rule, no higher than RESTREINT UE/EU RESTRICTED with its counterpart in a third country or international organisation; | Amendment(a) the Union institution or body concerned needs to exchange, on a long-term basis information classified, as a general rule, no higher than CONFIDENTIEL UE/EU CONFIDENTIAL with its counterpart in a third country or international organisation; |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. All Union institutions and bodies that have been assessed either by Commission or Council or EEAS before the [dd/mm/yyyy date of applicability], as suitable to handle and store EUCI, shall be considered as meeting the conditions referred to in Article 19(1). | Amendment2. All Union institutions and bodies that have been assessed either by Commission, Council, the European Parliament or EEAS before the [dd/mm/yyyy date of applicability], as suitable to handle and store EUCI, shall be considered as meeting the conditions referred to in Article 19(1). |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. All Union institutions and bodies that have been assessed either by Commission or Council or EEAS before the [dd/mm/yyyy date of applicability], as suitable to handle and store EUCI, shall be considered as meeting the conditions referred to in Article 19(1). | Amendment2. All Union institutions and bodies that have been assessed either by Parliament or Commission or Council or EEAS before the [dd/mm/yyyy date of applicability], as suitable to handle and store EUCI, shall be considered as meeting the conditions referred to in Article 19(1). |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. By [dd/mm/yyyy 3 years after the date of application] at the latest, the Commission shall present a report on the implementation of this Regulation to the European Parliament and the Council. | Amendment1. By [dd/mm/yyyy 2 years after the date of application] at the latest, the Commission shall present a report on the implementation of this Regulation to the European Parliament and the Council. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. No sooner than [5 years after the date of application] and every 5 years thereafter, the Commission shall carry out an evaluation of this Regulation and present a report on the main findings to the European Parliament and the Council. | Amendment2. No sooner than [3 years after the date of application] and every 5 years thereafter, the Commission shall carry out an evaluation of this Regulation and present a report on the main findings to the European Parliament and the Council. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. Documents containing sensitive non-classified information must be marked using a security marking and, where relevant, one or more distribution marking or markings specifying the target audience as appropriate. The standard security marking shall be the word ‘SENSITIVE’ in upper case, except in cases referred to in Article 15(2). | Amendment1. Documents containing sensitive non-classified information must be marked using a security marking and, where relevant, one or more distribution marking or markings specifying the target audience as appropriate. The standard security marking shall be the word ‘PROTECTED’ in upper case, except in cases referred to in Article 15(2). |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. Documents marked SENSITIVE are downgraded to EU NORMAL or PUBLIC USE, through the removal or striking of the markings. | Amendment4. Documents marked PROTECTED are downgraded to EU WORKING or PUBLIC USE, through the removal or striking of the markings. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission12. Union institutions and bodies shall provide training to all personnel working remotely on the handling of sensitive non-classified information when working outside the office. | Amendment12. Union institutions and bodies shall provide regular training to all personnel working remotely on the handling of sensitive non-classified information when working outside the office. |
Proposal for a regulation
Annex II – paragraph 1 – point 1
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1) ‘personnel Security Clearance’ or ‘PSC’ means a statement by a relevant authority of a Member State which is made following completion of a security investigation conducted by the competent authority and which certifies that an individual may be granted access to EUCI up to a specified level (CONFIDENTIEL UE/EU CONFIDENTIAL or higher) and for a set period of time; | Amendment1) ‘personnel Security Clearance’ or ‘PSC’ means a statement by the Commission which is made following completion of a security investigation conducted by the Commission in cooperation with the competent authorities of the relevant Member States and which certifies that an individual may be granted access to EUCI up to a specified level (CONFIDENTIEL UE/EU CONFIDENTIAL or higher) and for a set period of time; |
Proposal for a regulation
Annex II – paragraph 1 – point 2
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2) ‘personnel Security Clearance Certificate’ means a certificate issued by a competent authority establishing that an individual holds a valid security clearance, or equivalent, or a security authorisation and that shows the level of EUCI to which that individual may be granted access (CONFIDENTIEL UE/EU CONFIDENTIAL or higher), the period of validity of the relevant security clearance or authorisation and the date of expiry of the certificate itself. | Amendment2) ‘personnel Security Clearance Certificate’ means a certificate issued by the Commission establishing that an individual holds a valid security clearance, or equivalent, or a security authorisation and that shows the level of EUCI to which that individual may be granted access (CONFIDENTIEL UE/EU CONFIDENTIAL or higher), the period of validity of the relevant security clearance or authorisation and the date of expiry of the certificate itself. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission1. The Security Authority of the Union institution and body concerned must seek the written consent of the individual for the security clearance procedure before sending a completed security clearance questionnaire to the National Security Authority of the Member State of nationality of the applicant. | Amendment1. The Security Authority of the Union institution and body concerned must seek the written consent of the individual for the security clearance procedure before sending a completed security clearance questionnaire to the Commission. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission2. Where information relevant to a security investigation becomes known to a Union institution or body, concerning an individual who has applied for a security clearance for access to EUCI, the competent Security Authority, acting in accordance with this Regulation, must notify the relevant National Security Authority thereof. | Amendment2. Where information relevant to a security investigation becomes known to a Union institution or body, concerning an individual who has applied for a security clearance for access to EUCI, the competent Security Authority, acting in accordance with this Regulation, must notify the Commission thereof. |
Proposal for a regulation
Annex II – point 3 – introductory part
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission3. Following notification of the relevant National Security Authority’s overall assessment of the findings of the security investigation, the competent Security Authority: | Amendment3. Following notification of the Commission’s overall assessment of the findings of the security investigation, the competent Security Authority: |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission4. Where the individual starts service 12 months or more after the date of the notification of the result of the security investigation, or when there is a break of 12 months in the individual’s service, the competent Security Authority must seek confirmation from the relevant National Security Authority about the validity of the security clearance. | Amendment4. Where the individual starts service 12 months or more after the date of the notification of the result of the security investigation, or when there is a break of 12 months in the individual’s service, the competent Security Authority must seek confirmation from the Commission about the validity of the security clearance. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission5. Where information concerning a security risk posed by an individual who has authorisation to access EUCI becomes known to the Union institution or body concerned, the Security Authority of that Union institution or body must notify the relevant National Security Authority thereof and may suspend the individual’s access to EUCI or withdraw authorisation to access EUCI. | Amendment5. Where information concerning a security risk posed by an individual who has authorisation to access EUCI becomes known to the Union institution or body concerned, the Security Authority of that Union institution or body must notify the Commission thereof and may suspend the individual’s access to EUCI or withdraw authorisation to access EUCI. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission6. Where an National Security Authority notifies the relevant Union institution or body that there is no longer assurance for an individual who has access to EUCI, the Security Authority of the Union institution or body concerned must withdraw its security authorisation and exclude the individual from access to EUCI in accordance with its relevant internal rules. | Amendment6. Where the Commission notifies the relevant Union institution or body that there is no longer assurance for an individual who has access to EUCI, the Security Authority of the Union institution or body concerned must withdraw its security authorisation and exclude the individual from access to EUCI in accordance with its relevant internal rules. |
Proposal for a regulation
Annex II – point 8 – paragraph 1
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the CommissionThe Security Authority of the Union institution and body concerned may extend the validity of an authorisation to access EUCI for a period of up to 12 months, where no adverse information has been received from the relevant National Security Authority or other competent national authority within a period of 2 months from the date of transmission of the request for renewal and the corresponding clearance questionnaire. | AmendmentThe Security Authority of the Union institution and body concerned may extend the validity of an authorisation to access EUCI for a period of up to 12 months, where no adverse information has been received from the Commission within a period of 2 months from the date of transmission of the request for renewal and the corresponding clearance questionnaire. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission10. The Security Authority of the Union institution or body concerned may exceptionally grant temporary authorisation to access EUCI provided that the competent National Security Authority has conducted a preliminary check, based on the completed and transmitted security questionnaire, to verify that no relevant adverse information is known. | Amendment10. The Security Authority of the Union institution or body concerned may exceptionally grant temporary authorisation to access EUCI provided that the Commission has conducted a preliminary check, based on the completed and transmitted security questionnaire, to verify that no relevant adverse information is known. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission13. All Union institutions and bodies must ensure that national experts seconded to them for a position requiring security clearance present, prior to taking up their assignment, a valid Personnel Security Clearance or Personnel Security Clearance Certificate, according to national law and regulations, to the competent Security Authority. Provided that the requirements referred to in Article 23(1) are met, the Security Authority may then grant an authorisation to access EUCI up to the level equivalent to the one referred to in the national security clearance, with a maximum validity not longer than the duration of their assignment. | Amendment13. All Union institutions and bodies must ensure that national experts seconded to them for a position requiring security clearance present, prior to taking up their assignment, a valid national security clearance, according to national law and regulations, to the competent Security Authority. Provided that the requirements referred to in Article 23(1) are met, the Security Authority may then grant an authorisation to access EUCI up to the level equivalent to the one referred to in the national security clearance, with a maximum validity not longer than the duration of their assignment. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission8. EUCI which is classified RESTREINT UE/EU RESTRICTED must be handled and stored in any of the following areas: | Amendmentdeleted |
| Text proposed by the Commission(a) in a Secured Area; |
| Text proposed by the Commission(b) in an Administrative Area provided the EUCI is protected from access by unauthorised individuals; |
| Text proposed by the Commission(c) outside a Secured Area or Administrative Area provided the holder has undertaken to comply with compensatory measures decided by the Security Authority of each Union institution and body. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission9. EUCI which is classified RESTREINT UE/EU RESTRICTED must be stored in locked office furniture in an Administrative Area or a Secured Area. It may temporarily be stored outside an Administrative Area or a Secured Area provided the holder has undertaken to store the documents concerned in appropriate locked office furniture when they are not being read or discussed. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission10. Union institutions and bodies may handle and store RESTREINT UE/EU RESTRICTED information outside their sites provided the relevant information be protected appropriately. For such purpose, Union institutions and bodies must comply with the measures provided in point 8(c). | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission8. RESTREINT UE/EU RESTRICTED information must be carried in at least one layer of opaque packaging, such as envelopes, opaque folders or a briefcase. Information classified CONFIDENTIEL UE/EU CONFIDENTIAL or higher must be carried in two layers of opaque packaging. | Amendment8. Information classified CONFIDENTIEL UE/EU CONFIDENTIAL or higher must be carried in two layers of opaque packaging, such as envelopes, opaque folders or a briefcase. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission10. Commercial couriers may convey information classified RESTREINT UE/EU RESTRICTED and CONFIDENTIEL UE/EU CONFIDENTIAL within a Member State and from one Member State to another. Commercial couriers may deliver SECRET UE/EU SECRET information only within a Member State and provided that they are approved by the relevant National Security Authority. No EUCI at TRES SECRET UE/EU TOP SECRET level can be entrusted to a commercial courier. | Amendment10. Commercial couriers may convey information classified CONFIDENTIEL UE/EU CONFIDENTIAL within a Member State and from one Member State to another. Commercial couriers may deliver SECRET UE/EU SECRET information only within a Member State and provided that they are approved by the relevant National Security Authority. No EUCI at TRES SECRET UE/EU TOP SECRET level can be entrusted to a commercial courier. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission18. Where Member States require an FSC or a Personnel Security Clearance for contracts, grant agreements or subcontracts at RESTREINT UE/EU RESTRICTED level under their national laws and regulations, the Union institutions and bodies, as contracting or granting authorities, must not use those national requirements to place additional obligations on other Member States or exclude tenderers, applicants, contractors, beneficiaries or subcontractors from Member States that have no such FSC or Personnel Security Clearance requirements for access to RESTREINT UE/EU RESTRICTED information from related contracts, grant agreements or subcontracts, or a competition for such. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission22. Visits involving access to information classified RESTREINT UE/EU RESTRICTED must be arranged directly between the sending and receiving entity. | Amendmentdeleted |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission24. The security accreditation of contractors’ or beneficiaries’ CIS handling EUCI at RESTREINT UE/EU RESTRICTED level and any interconnection thereof may be delegated to the security officer of a contractor or beneficiary where allowed by national laws and regulations. | Amendmentdeleted |
| Text proposed by the CommissionWhere the security accreditation task is delegated, the contractor or beneficiary must be responsible for implementing the security requirements described in the Security Aspects Letter when handling RESTREINT UE/EU RESTRICTED information in its CIS. The relevant National Security Authorities or National Security Authorities and SAAs retain responsibility for the protection of information classified RESTREINT UE/EU RESTRICTED handled or stored by the contractor or beneficiary and the right to inspect the security measures taken by the contractor or beneficiary. |
| Text proposed by the CommissionIn addition, the contractor or beneficiary must provide the Union institution and body, as contracting or granting authority, and where required by national laws and regulations, the competent national SAA, with a statement of compliance certifying that the contractor or beneficiary CIS and related interconnections have been accredited for handling and storing EUCI at RESTREINT UE/EU RESTRICTED level. |
Proposal for a regulation
Amendment: Text proposed by the Commission and Amendment| Text proposed by the Commission | Amendment |
|---|
| Text proposed by the Commission26. RESTREINT UE/EU RESTRICTED information may be hand carried by contractor or beneficiary personnel within the European Union, provided the following requirements are met: | Amendmentdeleted |
| Text proposed by the Commission(a) the envelope or packaging used is opaque and bears no indication of the classification of its contents; |
| Text proposed by the Commission(b) the bearer retains possession of the classified information at all times; |
| Text proposed by the Commission(c) the envelope or packaging is not opened until it reaches its final destination. |