CADA tracker · source extraction
(61)
The Union’s objective of strengthening its autonomy should be pursued in a manner
that remains open, cooperative and consistent with the Union’s international
commitments and partnerships. The policy objectives pursued through Union
assurance levels 1, 2, and 3 should therefore be understood as the Union’s capacity to
act autonomously where necessary, while remaining engaged with its international
partners and fostering mutually beneficial cooperation. Against this background, the
Commission may decide, for Union assurance level 3, that a cloud computing service
subject to the control of a third country or a legal entity established in a third-country
can still be audited against the audit criteria where the third country has implemented
specific safeguards that ensure that there is no risk of unauthorised access to Union
data or possible disruption of service quality or continuity. The Commission should
assess whether the third country is covered by an adequacy decision adopted pursuant
to Article 45 of Regulation (EU) 2016/679. In particular, it should be determined
whether the adequacy decision applies generally to the third country as a whole or is
limited to specific sectors or certified organisations. It should be further assessed
whether the scope of the adequacy decision extends to the specific processing
activities that are carried out in the context of the service provision, or whether
transfers remain subject to the requirements to implement appropriate safeguards.