CADA tracker · source extraction
Article 29
Risk assessments
1. By [date of entry into force plus 1 year], and thereafter every two years, or whenever
necessary, Member States and Union entities shall carry out risk assessments that
shall:
(a) identify the public sector activities that use or will make use of cloud
computing services, that contribute to the preservation of public order in
sectors falling under Annex I or II of Directive (EU) 2022/2555 and in the
areas of national security, internal security, external border management,
defence, justice or law enforcement, including the prevention, investigation,
detection and prosecution of criminal offence;
(b) determine which Union assurance level 2, 3, or 4 set out in Annex II of this
Regulation is appropriate for the identified public sector activities.
Where Union entities and Member States share responsibilities in relation to the
public sector activities, they shall, where appropriate, consider carrying out the
relevant risk assessment or assessments jointly.
2. In carrying out their risk assessments, Member States and Union entities shall
consider at least the following aspects:
(a) the sensitivity, criticality, and magnitude of the non-personal data processed,
including the potential impact on public order and the nature, scope, context
and purpose of processing of personal data, as well as the risk of varying
likelihood and severity for the rights and freedoms of data subjects;
(b) the risk and consequent impact on public order of unlawful access under Union
law to such data by a third country or a legal entity established in a third
country;
(c) the risk and consequent impact on public order of possible service disruption;
3. The Commission shall, by means of implementing acts in accordance with Article
46(2), specify the methodology to be applied, the templates to be used and the
elements to be taken into account by the Member States and Union entities for the
purpose of carrying out the risk assessments referred to in paragraph 1. The
methodology shall specify how Member States use the highest level of assurance for
the most critical public sectors activities including, but not limited to, defence.
4. Within three months of carrying out the risk assessments referred to in paragraph 1,
Member States shall provide the Commission with the results of those risk
assessments, indicating where they depart from the implementing acts referred to in
paragraph 3.
5. If the Commission concludes, after reviewing the results of the risk assessment or
assessments of a Member State, that the Union assurance level identified for the
public sector activity in a risk assessment is not appropriate or does not adequately
address the public order concerns, the Commission may adopt implementing acts in
accordance with Article 46(2) specifying the Union assurance levels needed for the
public sector activity.
6. Where the risk assessment requires the migration to another cloud computing
service, the Member State or Union entity shall migrate within a reasonable
transition period that shall not exceed 12 months, taking into account technical
feasibility, continuity of service and data portability requirements applicable to such
migration.
7. Member States shall cooperate with each other and with the Commission through
established consistency mechanisms and promote cooperation and effective
exchange of information and best practices.
8. For the purpose of paragraph 3, the Commission shall be empowered to request
cloud computing service providers to provide all the necessary information.
9. In their risk assessments, Member States and Union entities shall consider whether a
multi-vendor or multi-cloud strategy is appropriate as part of their procurement of
cloud computing services.