CADA tracker · source extraction

Recital (61)

printed pages 29–30 · source locator: Recital (61); printed pages 29–30

Official source: COM(2026) 502 final — Proposal for a Cloud and AI Development Act

(61)

The Union’s objective of strengthening its autonomy should be pursued in a manner
            that remains open, cooperative and consistent with the Union’s international
            commitments and partnerships. The policy objectives pursued through Union
            assurance levels 1, 2, and 3 should therefore be understood as the Union’s capacity to
            act autonomously where necessary, while remaining engaged with its international
            partners and fostering mutually beneficial cooperation. Against this background, the

            Commission may decide, for Union assurance level 3, that a cloud computing service
            subject to the control of a third country or a legal entity established in a third-country
            can still be audited against the audit criteria where the third country has implemented
            specific safeguards that ensure that there is no risk of unauthorised access to Union
            data or possible disruption of service quality or continuity. The Commission should
            assess whether the third country is covered by an adequacy decision adopted pursuant
            to Article 45 of Regulation (EU) 2016/679. In particular, it should be determined
            whether the adequacy decision applies generally to the third country as a whole or is
            limited to specific sectors or certified organisations. It should be further assessed
            whether the scope of the adequacy decision extends to the specific processing
            activities that are carried out in the context of the service provision, or whether
            transfers remain subject to the requirements to implement appropriate safeguards.

Qualifications