CADA tracker · source extraction
(63)
In their risk assessments, Union entities and Member State shall assess the sensitivity,
criticality and magnitude of personal and non-personal data processed in cloud
environment. Such processing may include ordinary business information,
commercially sensitive information, operationally critical data, personal data within
the meaning of Regulation (EU) 2016/679, and data that is subject to sector-specific
obligations under Union law, including Directive (EU) 2022/2555 and Regulation
(EU) 2022/2554. The guidance by the Commission allows for a degree of flexibility to
Union entities and Member States in determining the appropriate Union assurance
levels and the categories of information and users for which such levels are
appropriate. At the same time, divergent national approaches to the classification and
mapping of data sensitivity and assurance requirements may undermine the consistent
application of the sovereignty framework across the Union. To ensure harmonised
implementation across the Union, the Commission should, in cooperation with
relevant authorities, provide centrally coordinated guidance on the mapping between
Union assurance levels and categories of information, taking into account the
sensitivity, criticality and magnitude of the data processed by the cloud environment,
the systematic importance of the activities of the contracting authorities, and the
applicable obligations arising from Union law. Furthermore, the criteria under the
Union assurance levels should not affect obligations of cross-border cooperation
provided by Union law. Where cloud computing services are used to process personal
data, Regulation (EU) 2016/679 provides for an obligation to agree on organisational
and technical measures to comply with that Regulation. Where the cloud computing
service provider relies on subcontractors in the provision of the services, the same
agreements apply to the subcontractors. Where specific technical and organisational
measures should be implemented pursuant to this Regulation to ensure that personal
data are processed in line with this Regulation, such specific measures could be
foreseen in the mandatory agreements pursuant to Regulation (EU) 2016/679 and
could be relied on to demonstrate that the necessary Union assurance levels are met.