My bookmarksSign up free

Commission Implementing Regulation (EU) 2025/1420 of 17 July 2025 laying down rules for the application of Regulation (EU) 2024/903 of the European Parliament and of the Council, as regards the establishment and the operation of the interoperability regulatory sandboxes

Commission Implementing Regulation (EU) 2025/1420 of 17 July 2025 laying down rules for the application of Regulation (EU) 2024/903 of the European Parliament and of the Council, as regards the establishment and the operation of the interoperability regulatory sandboxes

Implementing Regulation (EU) 2025/1420 · Regulation · 17 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

CHAPTER I — GENERAL PROVISIONS

Definitions

Article 1

For the purpose of this Regulation, the following definitions shall apply: (1) ‘project’ means a specific set of actions aiming to develop, train, test and validate innovative interoperability solutions, running in the controlled environment of an interoperability regulatory sandbox according to a specific plan and involving participants as referred to in Article 12(3) of Regulation (EU) 2024/903; (2) ‘regulatory sandbox coordinators’ means Union entities or public sector bodies that jointly establish and manage an interoperability regulatory sandbox, including overseeing their setup, coordinating participation, monitoring progress, reporting on the activities and termination; (3) ‘specific agreement’ means a formal instrument concluded between at least three Union entities or public sector bodies that outlines the terms, roles, responsibilities, and working methods for the creation, governance, and operation of an interoperability regulatory sandbox; (4) ‘regulator’ means regulatory bodies or authorities that oversee and enforce compliance within specific sectors at Union, Member States, regional or local level relevant for the projects in an interoperability regulatory sandbox; (5) ‘specific plan’ means a specific plan on the development, training, testing and validation of innovative interoperability solutions in an interoperability regulatory sandbox, as referred to in Article 12(3) of Regulation (EU) 2024/903.

CHAPTER II — ESTABLISHMENT OF AN INTEROPERABILITY REGULATORY SANDBOX

General provisions

Article 2

1.   An interoperability regulatory sandbox shall be established through a specific agreement between at least three Union entities or public sector bodies. Legal entities forming a consortium may establish an interoperability regulatory sandbox, provided that the consortium involves at least three Union entities or public sector bodies and complies with the conditions set out in this Regulation. 2.   Before formalising the specific agreement, the Union entities or public sector bodies establishing the interoperability regulatory sandbox shall ensure that: (a) the interoperability regulatory sandbox meets the criteria set out in Article 3 and specified in the checklist set out in the Annex to this Regulation; (b) the interoperability regulatory sandbox was notified to the Commission and, where applicable, authorised by the Commission pursuant to Article 11(4) of Regulation (EU) 2024/903 and Article 5 of this Regulation. 3.   An interoperability regulatory sandbox shall be established for an initial period that should not exceed three years. An interoperability regulatory sandbox may be renewed, following the procedure set out in Article 7. Participation in the interoperability regulatory sandbox has to be started and terminated within the lifespan of the interoperability regulatory sandbox, not exceeding the maximum duration of participation in an interoperability regulatory sandbox set out in Article 12(2) of Regulation (EU) 2024/903.

Criteria for the establishment of interoperability regulatory sandboxes

Article 3

1.   Any public sector body or Union entity may take part in establishing an interoperability regulatory sandbox, subject to the conditions laid down in this Regulation. 2.   The goal of an interoperability regulatory sandbox should contribute to the objectives set out in Article 11(2) of Regulation (EU) 2024/903. 3.   Public sector bodies or Union entities shall assess the possibility to join an existing interoperability regulatory sandbox with the same scope or to link to existing regulatory sandboxes with an overlapping scope before establishing a new interoperability regulatory sandbox. 4.   The regulatory sandbox coordinators shall conclude a specific agreement on the establishment of an Interoperability regulatory sandbox that shall, at least, contain the following elements: (a) a description of the interoperability regulatory sandbox objective, scope and deliverables, in particular how the interoperability regulatory sandbox, effectively contributes to the objectives set out in Article 11(2) of Regulation (EU) 2024/903, the innovative interoperability solutions that may be developed, trained, tested or validated in the interoperability regulatory sandbox and the open regulatory issues covered in the interoperability regulatory sandbox, as well as its planned duration; (b) a governance plan outlining how the interoperability regulatory sandbox will operate, including the management of projects in the interoperability regulatory sandbox, setting out clear and transparent arrangements for collaboration between the participants, regulatory authorities, and any other actor involved in the interoperability regulatory sandbox, and outlining roles and responsibilities of the participants entering or exiting the interoperability regulatory sandbox; the regulatory sandbox coordinators may agree on the division of the tasks set out in Article 9 of this Regulation among them; (c) description of a risk management mechanism to supervise, monitor, and mitigate risks, ensuring the protection of fundamental rights, health, safety and personal data protection supported by clear policies and procedures to address potential violations of these fundamental rights, health and safety standards and personal data protection; (d) description of a framework for evaluation and reporting across the interoperability regulatory sandbox and on the projects running within the interoperability regulatory sandbox, including mechanisms for monitoring progress, addressing challenges, documenting lessons learned and potential follow-up, and ensuring alignment with regulatory objectives; (e) where the processing of personal data in the projects running in the interoperability regulatory sandbox is envisioned, specifying the information referred to in in Article 11(4) of Regulation (EU) 2024/903. 5.   The regulatory sandbox coordinators shall agree on initiating at least one project subject to the conditions set out in the specific agreement, and Chapter III of this Regulation by establishing a draft specific plan.

Single point of contact

Article 4

The regulatory sandbox coordinators shall designate among themselves, a single point of contact for the purposes of communication with the Commission throughout the entire lifespan of the interoperability regulatory sandbox.

Notification and authorisation of an interoperability regulatory sandbox

Article 5

1.   In the case that public sector bodies or Union entities want to establish an interoperability regulatory sandbox, they shall send a joint request through the Interoperable Europe Portal. 2.   The joint request shall include all information necessary for the Commission to assess the compliance of requests by only public sector bodies with the criteria set out in Article 3 of this Regulation. 3.   The Commission shall notify the single point of contact of its decision on the request referred to in paragraph 1. In case of a negative decision, the regulatory sandbox coordinators may submit a reasoned review request within 30 days of receiving the Commission’s decision. The Commission shall examine the review request within 30 days and shall notify the single contact point of its decision on that review request. 4.   The start date of an interoperability regulatory sandbox set out in the specific agreement shall not be before receiving the notification referred to in paragraph 3.

Transparency

Article 6

1.   The Commission shall create a single, dedicated interface for information and exchange on interoperability regulatory sandboxes within the Interoperable Europe Portal, including: (a) general information and guidelines for Union entities and public sector bodies interested in establishing an interoperability regulatory sandbox, including features that help interested stakeholders to exchange information, requests and best practices; (b) dedicated information on each of the established interoperability regulatory sandboxes, including eligibility and selection criteria for participation in the interoperability regulatory sandboxes and information on running and closed projects in the interoperability regulatory sandbox. 2.   The single contact point shall collect any missing information, specified in paragraph (1)(b), at least 10 days before the starting of the operations of the interoperability regulatory sandbox and share it with the Commission. The single point of contact shall regularly update the information on projects within the interoperability regulatory sandbox.

Renewal of the interoperability regulatory sandbox

Article 7

1.   Regulatory sandbox coordinators may decide to renew the interoperability regulatory sandbox under the following conditions: (a) the objectives of the interoperability regulatory sandbox have not yet been achieved; (b) the interoperability regulatory sandbox is not closed pursuant to Article 8. 2.   In the case that the regulatory sandbox coordinators decide to renew the interoperability regulatory sandbox, they shall follow the procedure set out in Article 5. 3.   In the case that the regulatory sandbox coordinators want to make substantial changes to the specific agreement, referred to in Article 2(1), including, among others, modifications regarding the number and the identity of the regulatory sandbox coordinators, or the extension of the initially agreed timeframe necessary to achieve the sandbox objectives, then the regulatory sandbox coordinators shall start the renewal procedure as set out in paragraph 2.

Closing of an interoperability regulatory sandbox

Article 8

1.   Regulatory sandbox coordinators shall close the interoperability regulatory sandbox in one of the following cases: (a) the interoperability regulatory sandbox has fulfilled its objectives; (b) the interoperability regulatory sandbox has reached its determined end date pursuant to Article 2(3) and the regulatory sandbox coordinators have not reached an agreement on its renewal; (c) the Commission has not authorised the renewal pursuant to Article 7; (d) the necessary funding to continue the activities of the interoperability regulatory sandbox is not available. 2.   Upon closing of the interoperability regulatory sandbox, the regulatory sandbox coordinators shall ensure that all projects in the interoperability regulatory sandbox are properly terminated, as set out in Article 15. 3.   Regulatory sandbox coordinators shall submit the final report referred to in Article 12(8) of Regulation (EU) 2024/903 within three months following the closing of the interoperability regulatory sandbox.

CHAPTER III — OPERATION OF INTEROPERABILITY REGULATORY SANDBOXES

General rights and obligations of the regulatory sandbox coordinators

Article 9

1.   Regulatory sandbox coordinators shall manage the operations in the interoperability regulatory sandbox and its related projects throughout the lifespan of the interoperability regulatory sandbox. 2.   Regulatory sandbox coordinators are specifically responsible for the following tasks: (a) to invite regulators to the interoperability regulatory sandbox; (b) to steer the regulatory dialogue with the regulators involved around the set-up of and the learnings from the projects; (c) to decide on the number of projects running sequential or in parallel during the lifespan of the interoperability regulatory sandbox; (d) to publish calls for participation in the interoperability regulatory sandbox on the Interoperable Europe Portal and admit participants to the interoperability regulatory sandbox, as referred to in Article 10; (e) to select projects to run in the interoperability regulatory sandbox, while verifying that each projects remains in the scope of the interoperability regulatory sandbox with particular attention to the following aspects: — to support the cross-border interoperability of trans-European digital public services involving participants from at least two different Member States, or from at least one public sector body and one Union entity, — to contribute to the development, testing and validation of an innovative interoperability solution, and — to identify the specific regulatory issues at stake and the guidance that is expected from the authorities supervising the interoperability regulatory sandbox; (f) to ensure that participation is based on a specific plan; (g) to determine a time-limit for participation in a project; (h) to decide on extension of a project, as referred to in Article 12(2) of Regulation (EU) 2024/903; (i) to end a project, as referred to in Article 15; (j) to ensure periodic and final reporting to the Commission and the Interoperable Europe Board; (k) to set up a risk management framework, as referred to in Article 12. 3.   In case it is necessary to process personal data in the context of projects running in the interoperability regulatory sandbox, regulatory sandbox coordinators shall take the necessary measures to allow for the competent data protection authorities to effectively carry out their supervision tasks, as provided for in Article 11(1) of Regulation (EU) 2024/903.

Admission of participants and other actors

Article 10

1.   Regulatory sandbox coordinators shall publish on the Interoperable Europe Portal information on the eligibility and selection criteria for participation in the interoperability regulatory sandbox. Those criteria shall include the provision of information on the possibility for GovTech actors, including national or European standardisation organisations, notified bodies, research and experimentation labs, innovation hubs and companies wishing to test innovative interoperability solutions, in particular SMEs and start-ups, to be involved in the interoperability regulatory sandbox, as provided for in Article 12(1) of Regulation (EU) 2024/903. 2.   Regulatory sandbox coordinators shall decide on requests from other Union entities, public sector bodies or GovTech actors seeking to join the interoperability regulatory sandbox as participants or other actors, based on the rules for the respective interoperability regulatory sandbox, published on the Interoperable Europe Portal according to paragraph 1. 3.   The participants or other actors shall submit a declaration of commitment to the regulatory sandbox coordinators that provides for the assumption of obligations and the commitment for the candidate to meet financial, organizational, human resources and any other conditions that are relevant for this purpose.

General rights and obligation of participants

Article 11

1.   Participants that have been admitted to an interoperability regulatory sandbox according to Article 10 shall have the following obligations: (a) to contribute to the specific plan; (b) to assume full responsibility, as set out in Article 12(5) Regulation (EU) 2024/903, for the legality of the development, training, testing and validation of the interoperability solution; (c) to ensure that the interoperability solutions tested within the interoperability regulatory sandboxes comply with all applicable legal requirements and have obtained any necessary authorisations or approvals from competent authorities before they start the projects or that the competent authorities are involved in the interoperability regulatory sandbox; (d) to ensure, if personal data is processed within an interoperability regulatory sandbox, that such processing is in full compliance with applicable data protection law and to agree with the relevant data protection authorities, referred to in in Article 12(1) of Regulation (EU) 2024/903, on their expected involvement in the interoperability regulatory sandbox and its projects; (e) to adhere to the risk management framework, as set out in Article 12; (f) to regularly report on learnings in the interoperability regulatory sandbox, as specified in Article 13; (g) to ensure lawful handling of personal data processed in the projects as specified in Article 15(3). 2.   Participants may exit the interoperability regulatory sandbox under the conditions set out in Article 14.

Risk management

Article 12

1.   Regulatory sandbox coordinators shall establish the risk management process for the interoperability regulatory sandbox covering the risk management process referred to in Article 12(3), point (d), of Regulation (EU) 2024/903. Regulatory sandbox coordinators shall define, implement, and monitor overarching risk management objectives for the interoperability regulatory sandbox, including specific risk management standards applicable to all projects therein, with due consideration of any mandatory risk management requirements pursuant to other applicable law. Regulatory sandbox coordinators shall ensure effective communication on risk management between participants, competent authorities, and other stakeholders. 2.   Regulatory sandbox coordinators shall develop a specific risk management plan for each project that follows the risk management process referred to in paragraph 1. 3.   Regulatory sandbox coordinators shall appoint one among them as risk manager for each project. The risk manager shall ensure that the project complies with the specific risk management plan referred to in paragraph 2 of this Article. Where risks are identified, the risk manager shall ensure that appropriate mitigation measures are taken. 4.   In the case where appropriate risk mitigation is not feasible, the risk manager may temporarily suspend any project or participant’s involvement within the interoperability regulatory sandbox as an immediate safeguard. The risk manager shall promptly inform the regulatory sandbox coordinators and the relevant authorities. The single point of contact shall report this temporary suspension to the Commission. 5.   The risk manager shall maintain records of risk management activities for the respective projects and make those records available for review by all regulatory sandbox coordinators and the Commission.

Reporting obligations

Article 13

1.   Regulatory sandbox coordinators shall establish a mechanism for periodic reporting that covers at least the topics referred to in Article 12(8) of Regulation (EU) 2024/903. In the case of processing of personal data in the projects, the reporting shall include metrics assessing the effectiveness of the innovative interoperability solution in qualifying personal data, along with the accuracy and fairness of the output and usability of the results produced by the solution for the relevant authorities. 2.   The mechanism shall include collecting data from all projects on an ongoing basis that ensures that progress is tracked, risks are managed, and compliance with the interoperability regulatory sandboxes’ objectives and legal requirements is maintained. The mechanism shall cover reporting on the learnings from the dialogue with the regulators. 3.   Regulatory sandbox coordinators shall submit the periodic reports to the Commission and the Interoperable Europe Board referred to in Article 12(8) of Regulation (EU) 2024/903 at least once every six months from the date of establishment of the interoperability regulatory sandbox. 4.   All reports shall be published on the Interoperable Europe Portal. The reports shall not contain confidential information.

Exiting of participants

Article 14

1.   If a participant wants to exit the interoperability regulatory sandbox before the termination of the project that the participant is involved in, as referred to in Article 15, or the termination of the assigned task in the specific plan, the participant shall provide a detailed explanation to the regulatory sandbox coordinators and to the Commission of the reasons for exiting. 2.   Participants exiting an interoperability regulatory sandbox shall have the following obligations: (a) to complete any outstanding requirements linked to the monitoring and reporting of their activity; (b) to ensure that the data collected and any interoperability solutions developed during the lifespan of the interoperability regulatory sandbox are managed in accordance with the applicable legislation, and with the conditions for admission to the interoperability regulatory sandbox, as defined by the sandbox coordinators; and (c) to take all necessary steps to mitigate potential risks for the success of the interoperability regulatory sandbox project and for public services and their delivery linked to the exiting the interoperability regulatory sandbox and its specific projects. 3.   Upon the exiting of a participant from an interoperability regulatory sandbox, the regulatory sandbox coordinators shall assess the necessary measures with regard to the obligations set out in Article 9.

Termination of a project

Article 15

1.   Regulatory sandbox coordinators shall terminate a project in the interoperability regulatory sandbox in any of the following cases: (a) the project has fulfilled the objectives before the maximum initial duration is reached; (b) the regulators involved in the interoperability regulatory sandbox or other competent authorities have requested the termination of the project and no mitigation is possible; (c) the necessary funding to continue the activities is not available; (d) the project no longer fulfils the minimum criteria in terms of scope and participation set out in its specific plan and no mitigation is possible. 2.   In case the regulatory sandbox coordinators plan to terminate a project before the initially scheduled ending date, the regulatory sandbox coordinators shall inform all participants in due time. 3.   Personal data that was exceptionally processed in order to reach the objectives of a projects shall not be used as operative data outside the projects, unless there is a proper legal basis authorising a change of purpose. 4.   Within three months following the termination of the projects, regulatory sandbox coordinators shall: (a) publish on the Interoperable Europe portal or a portal, catalogue or repository connected to the Interoperable Europe portal the interoperability solutions and related materials developed during the project, including documentation, version history, documented source code and references to open standards or technical specifications used, if such solutions and material are in line with the applicable quality criteria for the Interoperable Europe Portal; (b) where solutions are issued as open source, use the EUPL or another appropriate open source licence; (c) clearly indicate, if sharing restrictions apply due to: — intellectual property rights held by third parties, — sensitive critical infrastructure protection, — protection of defence interests or public security.

CHAPTER IV — FINAL PROVISIONS

Entry into force

Article 16

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union .

Supplementary provisions

Checklist for an interoperability regulatory sandbox (referred to in Article 2(2), point (a))

ANNEXSupplementary provisions

ANNEX Checklist for an interoperability regulatory sandbox (referred to in Article 2(2), point (a)) No Criteria Description Description 1 Participants have been adequately specified — Please list the name and contact information for each participating public entity that will be involved in the interoperability regulatory sandbox. — Specify the designated role for each public entity within the interoperability regulatory sandbox (regulatory sandbox coordinator, observer, or regulator). — Please specify the single contact point. Please provide the required information. Keep in mind that the interoperability regulatory sandbox must be established by at least three regulatory sandbox coordinators, either public sector bodies and/or Union entities. 2 Scope, objectives and deliverables have been adequately specified Scope: — legislation and sector(s) covered by the interoperability regulatory sandbox, — if not EU wide scope, cross-border region covered by the interoperability regulatory sandbox, — duration of the interoperability regulatory sandbox, — please show links with existing regulatory sandboxes, if any. Objectives: — list the interoperability regulatory sandbox objectives, — specify how the interoperability regulatory sandbox effectively contributes to the objectives set out in Article 11(2) of Regulation (EU) 2024/903. Deliverables: — clearly identify the specific regulatory issues that the interoperability regulatory sandbox should help to clarify, — specify the innovative interoperability solutions that the interoperability regulatory sandbox should help to develop, train, test or validate, — specify the number and timeframe of the projects that are envisioned under the interoperability regulatory sandbox, — provide a draft specific plan for at least one project. Please provide the required information. 3 Governance has been adequately specified — Please set out how the interoperability regulatory sandbox will operate: — detailing clear and transparent arrangements for collaboration between the participants, regulatory authorities, and any other actor involved in the interoperability regulatory sandbox and its projects, and — outlining roles and responsibilities of all participants entering or exiting the interoperability regulatory sandbox. — Please specify which type of other actors are eligible to join the interoperability regulatory sandbox, at which point in the lifespan of the interoperability regulatory sandbox and under which conditions. — Please be specific on the involvement of actors with supervisory or advisory capacity, such as national data protection authorities, regional or local supervisory bodies, and other relevant regulatory authorities. — Please specify if the involvement of other GovTech actors is foreseen. Please provide the required information. The description should demonstrate that relevant regulators and other stakeholders have been clearly identified and considered, and, where applicable, include evidence of their readiness to participate in the interoperability regulatory sandbox. 4 Risk management has been adequately specified — Please list the initial potential risks identified for the interoperability regulatory sandbox. — Please list the risk management objectives for the interoperability regulatory sandbox, including specific risk management standards applicable to all projects therein. Please provide the required information. 5 Evaluation and reporting requirements have been adequately specified — Please specify when the periodic reports and final report will be available. — Please specify the topics to be covered by the report. Please provide the required information. Keep in mind: the mechanism should include collecting data from individual projects on an ongoing basis to ensure that progress is tracked, risks are managed, and compliance with the framework’s objectives and legal requirements is maintained. 6 Further processing of personal data has been adequately specified — If the interoperability regulatory sandbox allows for the set-up of projects that entail further processing of personal data, please, confirm that the competent data protection supervisory authorities are adequately involved. — Please specify the information set out in Article 11(4), second sentence, of Regulation (EU) 2024/903: — in case the further processing falls within Directive (EU) 2016/680, the legal basis of further processing pursuant to national or Union law, — why the further processing of personal data in the interoperability regulatory sandbox is necessary, — the concrete purpose of the further processing of personal data, — the actors involved and their roles, — the categories of personal data intended to be further processed in the interoperability regulatory sandbox, — the envisaged retention period for the personal data, ensuring that data is not kept longer than necessary for the specified purposes. — Please set out, how the alignment of the regulatory sandboxes with the conditions set out in Article 12(6) of that Regulation will be ensured. Please provide the required information.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next