CADA tracker · source extraction

Article 29

Source context: Chapter II

printed pages 60–61 · source locator: Article 29 occurrence 1; printed pages 60–61

Official source: COM(2026) 502 final — Proposal for a Cloud and AI Development Act

Article 29

Risk assessments
     1.   By [date of entry into force plus 1 year], and thereafter every two years, or whenever
          necessary, Member States and Union entities shall carry out risk assessments that
          shall:
          (a)   identify the public sector activities that use or will make use of cloud
                computing services, that contribute to the preservation of public order in
                sectors falling under Annex I or II of Directive (EU) 2022/2555 and in the
                areas of national security, internal security, external border management,
                defence, justice or law enforcement, including the prevention, investigation,
                detection and prosecution of criminal offence;
          (b)   determine which Union assurance level 2, 3, or 4 set out in Annex II of this
                Regulation is appropriate for the identified public sector activities.

          Where Union entities and Member States share responsibilities in relation to the
          public sector activities, they shall, where appropriate, consider carrying out the
          relevant risk assessment or assessments jointly.
     2.   In carrying out their risk assessments, Member States and Union entities shall
          consider at least the following aspects:
          (a)   the sensitivity, criticality, and magnitude of the non-personal data processed,
                including the potential impact on public order and the nature, scope, context
                and purpose of processing of personal data, as well as the risk of varying
                likelihood and severity for the rights and freedoms of data subjects;
          (b)   the risk and consequent impact on public order of unlawful access under Union
                law to such data by a third country or a legal entity established in a third
                country;
          (c)   the risk and consequent impact on public order of possible service disruption;
     3.   The Commission shall, by means of implementing acts in accordance with Article
          46(2), specify the methodology to be applied, the templates to be used and the
          elements to be taken into account by the Member States and Union entities for the
          purpose of carrying out the risk assessments referred to in paragraph 1. The
          methodology shall specify how Member States use the highest level of assurance for
          the most critical public sectors activities including, but not limited to, defence.
     4.   Within three months of carrying out the risk assessments referred to in paragraph 1,
          Member States shall provide the Commission with the results of those risk
          assessments, indicating where they depart from the implementing acts referred to in
          paragraph 3.
     5.   If the Commission concludes, after reviewing the results of the risk assessment or
          assessments of a Member State, that the Union assurance level identified for the
          public sector activity in a risk assessment is not appropriate or does not adequately
          address the public order concerns, the Commission may adopt implementing acts in
          accordance with Article 46(2) specifying the Union assurance levels needed for the
          public sector activity.
     6.   Where the risk assessment requires the migration to another cloud computing
          service, the Member State or Union entity shall migrate within a reasonable
          transition period that shall not exceed 12 months, taking into account technical
          feasibility, continuity of service and data portability requirements applicable to such
          migration.
     7.   Member States shall cooperate with each other and with the Commission through
          established consistency mechanisms and promote cooperation and effective
          exchange of information and best practices.
     8.   For the purpose of paragraph 3, the Commission shall be empowered to request
          cloud computing service providers to provide all the necessary information.
     9.   In their risk assessments, Member States and Union entities shall consider whether a
          multi-vendor or multi-cloud strategy is appropriate as part of their procurement of
          cloud computing services.

Qualifications