Policy implementation support projects
1. The Board may propose that the Commission set up projects to support public sector bodies in the digital implementation of Union policies ensuring the cross-border interoperability of trans-European digital public services (policy implementation support project).
2. The policy implementation support project shall set out:
(a)
the existing Interoperable Europe solutions that are deemed to be necessary for the digital implementation of the policy requirements;
(b)
any missing interoperability solutions to be developed that are deemed to be necessary for the digital implementation of the policy requirements;
(c)
other recommended support measures, such as training, the sharing of expertise or peer review, as well as financial support opportunities to assist the implementation of interoperability solutions.
3. The Commission shall, after consulting the Board, lay down the scope, timeline, necessary involvement of particular sectors and administrative levels and working methods of the support project. Where the Commission has already carried out and published an interoperability assessment pursuant to Article 3, the outcome of that assessment shall be taken into account when setting up the support project.
4. In order to reinforce the policy implementation support project, the Board may propose the establishment of an interoperability regulatory sandbox pursuant to Article 11.
5. The outcome of a policy implementation support project as well as interoperability solutions developed during the project shall be openly available and made public on the Interoperable Europe portal.
Innovation measures
1. The Board may propose that the Commission set up innovation measures to support the development and uptake of innovative interoperability solutions in the Union (innovation measures).
2. Innovation measures shall contribute to the development of existing or new Interoperable Europe solutions and may involve GovTech actors.
3. In order to support the development of innovation measures, the Board may propose the establishment of an interoperability regulatory sandbox.
4. The Commission shall make the results from the innovation measures openly available on the Interoperable Europe portal.
Establishment of interoperability regulatory sandboxes
1. Interoperability regulatory sandboxes shall be operated under the responsibility of the participating Union entities or public sector bodies. Interoperability regulatory sandboxes that entail the processing of personal data by public sector bodies, shall be operated under the supervision of the national data protection authorities as well as other relevant national, regional or local supervisory authorities. Interoperability regulatory sandboxes that entail the processing of personal data by Union entities shall be operated under the supervision of the European Data Protection Supervisor.
2. The establishment of an interoperability regulatory sandbox as referred to paragraph 1 shall aim to contribute to the following objectives:
(a)
fostering innovation and facilitating the development and roll-out of innovative digital interoperability solutions for public services;
(b)
facilitating cross-border cooperation between national regional and local competent authorities and synergies in public service delivery;
(c)
facilitating the development of an open European GovTech ecosystem, including cooperation with SMEs, research and educational institutions and start-ups;
(d)
enhancing authorities’ understanding of the opportunities or barriers to cross-border interoperability of innovative interoperability solutions, including legal barriers;
(e)
contributing to the development or update of Interoperable Europe solutions;
(f)
contributing to evidence-based regulatory learning;
(g)
improving legal certainty and contributing to the sharing of best practices through cooperation with the authorities involved in the interoperability regulatory sandbox with a view to ensuring compliance with this Regulation and, where appropriate, with other Union and national law.
3. In order to ensure a harmonised approach and to support the implementation of interoperability regulatory sandboxes, the Commission may issue guidelines and clarifications, without prejudice to other Union law.
4. The Commission, after consulting the Board shall, upon a joint request from at least three participants, authorise the establishment of an interoperability regulatory sandbox. Where appropriate the request shall specify information such as the purpose of the processing of personal data, the actors involved and their roles, the categories of personal data concerned and their sources, and the envisaged retention period. The consultation shall not replace the prior consultation referred to in Article 36 of Regulation (EU) 2016/679 and Article 40 of Regulation (EU) 2018/1725. Where the interoperability regulatory sandbox is established for interoperability solutions supporting the cross-border interoperability of trans-European digital public services by one or more Union entities, including with the participation of public sector bodies, no authorisation shall be required.
Participation in interoperability regulatory sandboxes
1. The participating Union entities or public sector bodies shall ensure, where the operation of the interoperability regulatory sandbox requires the processing of personal data or otherwise falls under the supervisory remit of other national, regional or local authorities providing or supporting access to data, that national data protection authorities as well as other national, regional or local authorities are associated with the operation of the interoperability regulatory sandbox. As appropriate, participants may allow for the involvement in the interoperability regulatory sandbox of other GovTech actors such as national or European standardisation organisations, notified bodies, research and experimentation labs, innovation hubs, and companies wishing to test innovative interoperability solutions, in particular SMEs and start-ups.
2. Participation in the interoperability regulatory sandbox shall be limited to a period appropriate to the complexity and scale of the project, which shall, in any event, not exceed two years from the establishment of the interoperability regulatory sandbox. Participation may be extended by up to one year if necessary to achieve the purpose of the processing.
3. Participation in the interoperability regulatory sandbox shall be based on a specific plan elaborated by the participants and taking into account, as applicable, the advice of other national competent authorities or the European Data Protection Supervisor. The plan shall contain at least the following:
(a)
a description of the participants involved and their roles, the envisaged innovative interoperability solution and its intended purpose, and relevant development, testing and validation process;
(b)
the specific regulatory issues at stake and the guidance that is expected from the authorities supervising the interoperability regulatory sandbox;
(c)
the specific arrangements for collaboration between the participants and the authorities, as well as any other actor involved in the interoperability regulatory sandbox;
(d)
a risk management and monitoring mechanism to identify, prevent and mitigate risks;
(e)
the key milestones to be completed by the participants for the interoperability solution to be considered ready to put into service;
(f)
evaluation and reporting requirements and possible follow-up;
(g)
where it is strictly necessary and proportionate to process personal data, the reasons for such processing, an indication of the categories of personal data concerned, the purposes of the processing for which the personal data are intended, the controllers and processors involved in the processing and their role.
4. Participation in the interoperability regulatory sandboxes shall not affect the supervisory and corrective powers of any authorities supervising those sandboxes.
5. Participants in the interoperability regulatory sandbox shall remain liable under applicable Union and national law on liability for any damage caused in the course of their participation in the interoperability regulatory sandbox.
6. Personal data may be processed in the interoperability regulatory sandbox for purposes other than that for which it has initially been lawfully collected, subject to all of the following conditions:
(a)
the innovative interoperability solution is developed for safeguarding public interests in the context of a high level of efficiency and quality of public administration and public services;
(b)
the data processed is limited to what is necessary for the functioning of the interoperability solution to be developed or tested in the interoperability regulatory sandbox, and that functioning cannot be effectively achieved by processing anonymised, synthetic or other non-personal data;
(c)
there are effective monitoring mechanisms to identify whether any high risk to the rights and freedoms of the data subjects, as referred to in Article 35(1) of Regulation (EU) 2016/679 and in Article 39 of Regulation (EU) 2018/1725, may arise during the operation of the interoperability regulatory sandbox, as well as a response mechanism to promptly mitigate that risk and, where necessary, stop the processing;
(d)
any personal data to be processed are in a functionally separate, isolated and protected data processing environment under the control of the participants and only duly authorised persons have access to that data;
(e)
any personal data processed are not to be transmitted, transferred or otherwise accessed by other parties that are not participants in the interoperability regulatory sandbox unless such disclosure occurs in accordance with Regulation (EU) 2016/679 or, where applicable, Regulation (EU) 2018/1725, and all participants have agreed to it;
(f)
any processing of personal data do not affect the application of the rights of the data subjects as provided for under Union law on the protection of personal data, in particular in Article 22 of Regulation (EU) 2016/679 and Article 24 of Regulation (EU) 2018/1725;
(g)
any personal data processed are protected by means of appropriate technical and organisational measures and erased once the participation in the interoperability regulatory sandbox has terminated or the personal data has reached the end of its retention period;
(h)
the logs of the processing of personal data are kept for the duration of the participation in the interoperability regulatory sandbox, unless provided otherwise by Union or national law;
(i)
a complete and detailed description of the process and rationale behind the training, testing and validation of the interoperability solution is kept together with the testing results as part of the technical documentation and transmitted to the Board;
(j)
a short summary of the interoperability solution to be developed in the interoperability regulatory sandbox, including its objectives and expected results, is made available on the Interoperable Europe portal.
7. Paragraph 1 is without prejudice to Union or national law laying down the basis for the processing of personal data which is necessary for the purpose of developing, testing and training of innovative interoperability solutions or any other legal basis, in accordance with Union law on the protection of personal data.
8. The participants shall submit periodic reports and a final report to the Board and the Commission on the results from the interoperability regulatory sandboxes, including good practices, lessons learnt, security measures and recommendations on their operation and, where relevant, on the development of this Regulation and other Union law supervised within the interoperability regulatory sandbox. The Board shall issue an opinion to the Commission on the outcome of the interoperability regulatory sandbox, specifying, where applicable, the actions needed to implement new interoperability solutions to promote the cross-border interoperability of trans-European digital public services.
9. The Commission shall ensure that information on the interoperability regulatory sandboxes is available on the Interoperable Europe portal.
10. By 12 April 2025, the Commission shall adopt implementing acts setting out the detailed rules and the conditions for the establishment and the operation of the interoperability regulatory sandboxes, including the eligibility criteria and the procedure for the application for, selection of, participation in and exiting from the interoperability regulatory sandbox and the rights and obligations of the participants. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 22(2).
Training
1. The Commission, assisted by the Board, shall provide training material on the use of the EIF and on Interoperable Europe solutions, including solutions that are free and open source. Union entities and public sector bodies shall provide their staff entrusted with strategical or operational tasks having an impact on trans-European digital public services with appropriate training programmes concerning interoperability issues.
2. The Commission shall organise training courses on interoperability issues at Union level to enhance cooperation and the exchange of best practices between the staff of Union entities and public sector bodies, targeting public sector employees in particular at regional and local level. The Commission shall make the training courses publicly accessible online, free of charge.
3. The Commission shall promote the development of a certification programme on interoperability matters to promote best practices, human resources qualification and a culture of excellence.
Peer review
1. A voluntary mechanism for peer review shall be established for the purpose of facilitating cooperation between public sector bodies, designed to support them in implementing Interoperable Europe solutions, to support trans-European digital public services and to help them carry out an interoperability assessments pursuant to Article 3.
2. A peer review shall be conducted by interoperability experts drawn from Member States other than the Member State where the public sector body undergoing the peer review is located.
3. Any information obtained through a peer review shall be used solely for the purpose of that peer review. The interoperability experts participating in the peer review shall not disclose any sensitive or confidential information obtained in the course of that peer review to third parties. The Member State concerned shall ensure that any risk of a conflict of interest concerning the designated interoperability experts is communicated to the other Member States and the Commission without undue delay.
4. The interoperability experts conducting the peer review shall prepare and present a report within one month of the finalisation of the peer review and submit it to the public sector body concerned and to the Board. The Commission shall publish a report on the Interoperable Europe portal when authorised by the Member State where the public sector body undergoing the peer review is located.
5. The Commission may, after consulting the Board, adopt guidelines on the methodology and content of peer review.