Subject matter and scope
1. This Regulation lays down measures that promote the cross-border interoperability of trans-European digital public services, thus contributing to the interoperability of the underlying network and information systems by establishing common rules and a governance framework.
2. This Regulation applies to Union entities and public sector bodies that regulate, provide, manage or implement trans-European digital public services.
3. This Regulation applies without prejudice to the competence of Member States to define what constitutes public services or to their ability to establish procedural rules for or to provide, manage or implement those services.
4. This Regulation is without prejudice to the competence of Member States with regard to their activities concerning public security, defence and national security.
5. This Regulation does not entail the supply of information the disclosure of which would be contrary to the essential interests of Member States’ public security, defence or national security.
Definitions
For the purposes of this Regulation, the following definitions apply:
(1)
‘cross-border interoperability’ means the ability of Union entities and public sector bodies of Member States to interact with each other across borders by sharing data, information and knowledge through digital processes in line with the legal, organisational, semantic and technical requirements related to such cross-border interaction;
(2)
‘trans-European digital public services’ means digital services provided by Union entities or public sector bodies to one another or to natural or legal persons in the Union, and requiring interaction across Member State borders, among Union entities or between Union entities and public sector bodies, by means of their network and information systems;
(3)
‘network and information system’ means a network and information system as defined in Article 6, point (1), of Directive (EU) 2022/2555 of the European Parliament and of the Council ( 14 ) ;
(4)
‘interoperability solution’ means a reusable asset concerning legal, organisational, semantic or technical requirements to enable cross-border interoperability, such as conceptual frameworks, guidelines, reference architectures, technical specifications, standards, services and applications, as well as documented technical components, such as source code;
(5)
‘Union entities’ means the Union institutions, bodies, offices and agencies set up by, or on the basis of, the TEU, the Treaty on the functioning of European Union or the Treaty establishing the European Atomic Energy Community;
(6)
‘public sector body’ means a public sector body as defined in Article 2, point (1), of Directive (EU) 2019/1024 of the European Parliament and of the Council ( 15 ) ;
(7)
‘data’ means data as defined in Article 2, point (1), of Regulation (EU) 2022/868 of the European Parliament and of the Council ( 16 ) ;
(8)
‘machine-readable format’ means a machine-readable format as defined in Article 2, point (13), of Directive (EU) 2019/1024;
(9)
‘GovTech’ means technology-based cooperation between public and private sector actors supporting public sector digital transformation;
(10)
‘standard’ means a standard as defined in Article 2, point (1), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council ( 17 ) ;
(11)
‘ICT technical specification’ means ICT technical specification as defined in Article 2, point (5), of Regulation (EU) No 1025/2012;
(12)
‘open source licence’ means a licence whereby the reuse, redistribution and modification of software is permitted for all uses on the basis of a unilateral declaration by the right holder that may be subject to certain conditions, and where the source code of the software is made available to users indiscriminately;
(13)
‘highest level of management’ means a manager, management or coordination and oversight body at the most senior administrative level, taking account of the high-level governance arrangements in each Union entity;
(14)
‘interoperability regulatory sandbox’ means a controlled environment set up by a Union entity or a public sector body for the development, training, testing and validation of innovative interoperability solutions, where appropriate in real world conditions, supporting the cross-border interoperability of trans-European digital public services for a limited period of time under regulatory supervision;
(15)
‘binding requirement’ means an obligation, prohibition, condition, criterion or limit of a legal, organisational, semantic or technical nature, which is set by a Union entity or a public sector body concerning one or more trans-European digital public services and which has an effect on cross-border interoperability.
Interoperability assessment
1. Before taking a decision on new or substantially modified binding requirements, a Union entity or a public sector body shall carry out an interoperability assessment.
Where, in relation to binding requirements, an interoperability assessment has already been carried out or where binding requirements are implemented by solutions provided by Union entities, the public sector body concerned shall not be required to carry out a further interoperability assessment in relation to those requirements. A single interoperability assessment may be carried out to address a set of binding requirements.
The Union entity or public sector body concerned may also carry out the interoperability assessment in other cases.
2. An interoperability assessment shall, in an appropriate manner, identify and assess the following:
(a)
the effects of the binding requirements on cross-border interoperability, using the European Interoperability Framework referred to in Article 6as a support tool;
(b)
the stakeholders to which the binding requirements are relevant;
(c)
the Interoperable Europe solutions referred to in Article 7 that support the implementation of the binding requirements.
The Union entity or public sector body concerned shall publish, in a machine-readable format facilitating automated translation, a report presenting the outcome of the interoperability assessment, including the items listed in the Annex, on an official website. It shall share that report electronically with the Interoperable Europe Board established pursuant to Article 15 (the ‘Board’). The requirements laid down in this paragraph shall not restrict existing Member States’ rules on access to documents. The publication of that report shall not compromise intellectual property rights or trade secrets, public order or security.
3. Union entities and public sector bodies may decide which body is to provide the necessary support to carry out the interoperability assessment. The Commission shall provide technical tools to support the interoperability assessment, including an online tool to facilitate the completion of the report and its publication on the Interoperable Europe portal referred to in Article 8.
4. The Union entity or public sector body concerned shall consult recipients of the services directly affected, including citizens, or their representatives. That consultation shall be without prejudice to the protection of commercial or public interests or the security of such services.
5. By 12 January 2025, the Board shall adopt the guidelines referred to in Article 15(5), point (a).
Share and reuse of interoperability solutions between Union entities and public sector bodies
1. A Union entity or public sector body shall make available to any other Union entity or public sector body that requests it an interoperability solution supporting a trans-European digital public service, including the technical documentation, and, where applicable, the version history, documented source code and the references to open standards or technical specifications used.
The obligation to share shall not apply to any of the following interoperability solutions, namely those:
(a)
that support processes which fall outside the scope of the public task of the Union entity or public sector body concerned as defined by law or by other binding rules, or, in the absence of such rules, as defined in accordance with common administrative practice in the Union entities or Member State in question, provided that the scope of the public tasks is transparent and subject to review;
(b)
for which third parties hold intellectual property rights that restrict the possibility of sharing the solution for reuse;
(c)
access to which is excluded or restricted on grounds of:
(i)
sensitive critical infrastructure protection related information as defined in Article 2, point (d), of Council Directive 2008/114/EC ( 18 ) ;
(ii)
the protection of defence interests or public security, including national critical infrastructure.
2. To enable the reusing entity to manage the interoperability solution autonomously, the sharing entity shall specify any conditions that apply to the reuse of the solution, including any guarantees provided to the reusing entity with regard to cooperation, support and maintenance. Such conditions may include the exclusion of liability of the sharing entity in the case of misuse of the interoperability solution by the reusing entity. Before adopting the interoperability solution, the reusing entity shall, upon request, provide to the sharing entity an assessment of the solution covering its ability to manage autonomously the cybersecurity and the evolution of the reused interoperability solution.
3. The obligation in paragraph 1 may be fulfilled by publishing the relevant content on the Interoperable Europe portal or a portal, catalogue or repository connected to the Interoperable Europe portal. In that case, paragraph 2 shall not apply to the sharing entity. At the request of the sharing entity, the Commission shall publish the relevant content on the Interoperable Europe portal.
4. A Union entity or public sector body, or a third party reusing an interoperability solution, may adapt it to its own needs, unless intellectual property rights held by a third party restrict the adaptation of the interoperability solution. If the interoperability solution is made public pursuant to paragraph 3, the adapted interoperability solution shall be made public in the same way.
5. The sharing and reusing entities may conclude an agreement on sharing the costs for future developments of the interoperability solution.
6. When deciding on the implementation of interoperability solutions, Union entities and public sector bodies shall prioritise the implementation of interoperability solutions that do not carry restrictive licensing terms, such as open source solutions, where such interoperability solutions are equivalent in terms of functionalities, total cost, user-centricity, cybersecurity or other relevant objective criteria. The Commission shall provide support in identifying such interoperability solutions, as provided for in Article 9.
7. The Board shall adopt guidelines on the sharing of interoperability solutions.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.