My bookmarksSign up free

Regulation (EU, Euratom) 2023/2841 of the European… CHAPTER I — GENERAL PROVISIONS

Article 1–Article 4 · 4 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Subject matter

Article 1

This Regulation lays down measures that aim to achieve a high common level of cybersecurity within Union entities with regard to: (a) the establishment by each Union entity of an internal cybersecurity risk-management, governance and control framework pursuant to Article 6; (b) cybersecurity risk management, reporting and information sharing; (c) the organisation, functioning and operation of the Interinstitutional Cybersecurity Board established pursuant to Article 10, as well as the organisation, functioning and operation of the Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU); (d) the monitoring of the implementation of this Regulation.

Scope

Article 2

1.   This Regulation applies to Union entities, to the Interinstitutional Cybersecurity Board established pursuant to Article 10 and to CERT-EU. 2.   This Regulation applies without prejudice to the institutional autonomy pursuant to the Treaties. 3.   With the exception of Article 13(8), this Regulation does not apply to network and information systems handling EU classified information (EUCI).

Definitions

Article 3

For the purposes of this Regulation, the following definitions apply: (1) ‘Union entities’ means the Union institutions, bodies, offices and agencies set up by or pursuant to the Treaty on European Union, the Treaty on the Functioning of European Union (TFEU) or the Treaty establishing the European Atomic Energy Community; (2) ‘network and information system’ means a network and information system as defined in Article 6, point (1), of Directive (EU) 2022/2555; (3) ‘security of network and information systems’ means security of network and information systems as defined in Article 6, point (2), of Directive (EU) 2022/2555; (4) ‘cybersecurity’ means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; (5) ‘highest level of management’ means a manager, management body or coordination and oversight body that is responsible for the functioning of a Union entity, at the most senior administrative level, with a mandate to adopt or authorise decisions in line with the high-level governance arrangements of that Union entity, without prejudice to the formal responsibilities of other levels of management for compliance and cybersecurity risk management in their respective areas of responsibility; (6) ‘near miss’ means a near miss as defined in Article 6, point (5), of Directive (EU) 2022/2555; (7) ‘incident’ means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; (8) ‘major incident’ means an incident which causes a level of disruption that exceeds a Union entity’s and CERT-EU’s capacity to respond to it or which has a significant impact on at least two Union entities; (9) ‘large-scale cybersecurity incident’ means a large-scale cybersecurity incident as defined in Article 6, point (7), of Directive (EU) 2022/2555; (10) ‘incident handling’ means incident handling as defined in Article 6, point (8), of Directive (EU) 2022/2555; (11) ‘cyber threat’ means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; (12) ‘significant cyber threat’ means a significant cyber threat as defined in Article 6, point (11), of Directive (EU) 2022/2555; (13) ‘vulnerability’ means a vulnerability as defined in Article 6, point (15), of Directive (EU) 2022/2555; (14) ‘cybersecurity risk’ means a risk as defined in Article 6, point (9), of Directive (EU) 2022/2555; (15) ‘cloud computing service’ means a cloud computing service as defined in Article 6, point (30), of Directive (EU) 2022/2555.

Processing of personal data

Article 4

1.   The processing of personal data under this Regulation by CERT-EU, the Interinstitutional Cybersecurity Board established pursuant to Article 10 and Union entities shall be carried out in accordance with Regulation (EU) 2018/1725. 2.   Where they perform tasks or fulfil obligations pursuant to this Regulation, CERT-EU, the Interinstitutional Cybersecurity Board established pursuant to Article 10 and Union entities shall process and exchange personal data only to the extent necessary and for the sole purpose of performing those tasks or fulfilling those obligations. 3.   The processing of special categories of personal data as referred to in Article 10(1) of Regulation (EU) 2018/1725 shall be considered to be necessary for reasons of substantial public interest pursuant to Article 10(2), point (g), of that Regulation. Such data may be processed only to the extent necessary for the implementation of cybersecurity risk-management measures referred to in Articles 6 and 8, for the provision of services by CERT-EU pursuant to Article 13, for the sharing of incident-specific information pursuant to Article 17(3) and Article 18(3), for the sharing of information pursuant Article 20, for the reporting obligations pursuant to Article 21, for incident response coordination and cooperation pursuant to Article 22 and for the management of major incidents pursuant to Article 23 of this Regulation. The Union entities and CERT-EU, when acting as data controllers, shall apply technical measures to prevent the processing of special categories of personal data for other purposes and shall provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subjects.

Back to Regulation (EU, Euratom) 2023/2841 of the European… — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next