CADA tracker · source extraction

Recital (64)

printed pages 31 · source locator: Recital (64); printed pages 31

Official source: COM(2026) 502 final — Proposal for a Cloud and AI Development Act

(64)

The free flow of data within the Union is an essential condition for the proper
            functioning of the internal market. To promote the free flow of data within the Union
            and to support the functioning of the internal market, it is appropriate that Member
            States ensure that data is not confined to the territory of a single Member State and
            may be stored and processed across the Union without unjustified restrictions.The
            Union maintains an open and non-discriminatory framework for market access, in
            accordance with the TFEU and subject to international commitments. Those include
            commitments under the World Trade Organization (WTO) Agreement on Government
            Procurement (GPA), as well as bilateral trade agreements. Nevertheless, where
            necessary and in duly justified circumstances, the Union retains the right, in
            accordance with Article III:2(a) of the WTO GPA, to adopt or maintain measures
            necessary to protect public morals, order or safety, allowing for necessary and
            proportionate restrictions on access to public procurement procedures. Indeed,
            identifying and addressing risks such as critical dependencies, unauthorised access to
            Union data, technology leakage, sabotage and espionage by third-country actors is
            fundamental for preserving Union public order. Preserving the protection of public
            order of the Union and its Member States requires a prudent but firm political, legal
            and operational response for both national and Union-level award procedures, in full
            respect of international commitments. To protect and preserve the public order of the
            Union and its Member States, contracting authorities whose activities have been
            identified on the basis of the Member State risk assessment should therefore procure
            only the cloud computing service providing the appropriate level of assurance between
            levels 2 and 4. A minimum assurance level, by mandating Union assurance level 1
            across the Union, is necessary to establish a consistent baseline of safeguards for the
            public sector, thereby reducing vulnerabilities in the public sector to third country
            access to Union data and disruption of services.

Qualifications