CADA tracker · source extraction

Recital (63)

printed pages 30–31 · source locator: Recital (63); printed pages 30–31

Official source: COM(2026) 502 final — Proposal for a Cloud and AI Development Act

(63)

In their risk assessments, Union entities and Member State shall assess the sensitivity,
            criticality and magnitude of personal and non-personal data processed in cloud
            environment. Such processing may include ordinary business information,
            commercially sensitive information, operationally critical data, personal data within
            the meaning of Regulation (EU) 2016/679, and data that is subject to sector-specific
            obligations under Union law, including Directive (EU) 2022/2555 and Regulation
            (EU) 2022/2554. The guidance by the Commission allows for a degree of flexibility to
            Union entities and Member States in determining the appropriate Union assurance
            levels and the categories of information and users for which such levels are
            appropriate. At the same time, divergent national approaches to the classification and
            mapping of data sensitivity and assurance requirements may undermine the consistent
            application of the sovereignty framework across the Union. To ensure harmonised
            implementation across the Union, the Commission should, in cooperation with
            relevant authorities, provide centrally coordinated guidance on the mapping between
            Union assurance levels and categories of information, taking into account the
            sensitivity, criticality and magnitude of the data processed by the cloud environment,
            the systematic importance of the activities of the contracting authorities, and the
            applicable obligations arising from Union law. Furthermore, the criteria under the
            Union assurance levels should not affect obligations of cross-border cooperation
            provided by Union law. Where cloud computing services are used to process personal
            data, Regulation (EU) 2016/679 provides for an obligation to agree on organisational
            and technical measures to comply with that Regulation. Where the cloud computing
            service provider relies on subcontractors in the provision of the services, the same

            agreements apply to the subcontractors. Where specific technical and organisational
            measures should be implemented pursuant to this Regulation to ensure that personal
            data are processed in line with this Regulation, such specific measures could be
            foreseen in the mandatory agreements pursuant to Regulation (EU) 2016/679 and
            could be relied on to demonstrate that the necessary Union assurance levels are met.

Qualifications