SkarpSkarp

Chapter 13 of 17

Data Governance, Operational Flows, and Interoperable Platforms

The framework depends on information moving reliably among providers, auditors, national authorities, the Commission, public bodies, and the public. This module traces those flows and evaluates the planned repository, federation, procurement, and open-source systems against EU data, cybersecurity, identity, and interoperability principles.

20 min readen

1. Reading the Framework: Scope, Status, and Actors

What Sections 4.2-4.5 Do

The text maps data types, senders, recipients, triggers, and frequencies. It treats governance as an operational information system, not simply as a list of legal duties.

Status on July 20, 2026

This material reflects the Commission proposal for the Cloud and AI Development Act, COM(2026) 502, adopted on June 3, 2026. It is a proposal, not yet a final binding Regulation.

The Network of Actors

Information moves among providers, auditors, national competent authorities, Member States, the Commission, and the public. Some flows are national-to-Commission; others are authority-to-authority.

2. Data in Scope: From Strategies to Recognition

Several Datasets, Not One

Section 4.2 separates information by purpose: national strategies, strategic-project applications, capacity-gap monitoring, recognition, audits, transparency, cooperation, risk assessment, and procurement.

Recognition Evidence

Article 17 covers recognition requests; Article 19 covers EU statements of conformity; Articles 20 and 21 concern audits. The text requires: Data quality: sufficiently complete and reliable; minimum content for audits.

What the Text Does Not Specify

For several categories the table says `N/A`. In particular, it does not provide a universal schema, numeric data-quality threshold, or technical standard for every data type.

3. Worked Example: The Recognition and Audit Trail

Start: Provider Request

A provider seeking to serve Union entities or public sector bodies sends its Article 17 request to the national competent authority of its establishment.

Decision and Review

The authority may reject, request additional evidence, or recognise the service. Its conclusion is then distributed to all national competent authorities, which may object.

Escalation and Evidence

Unresolved disagreement goes to the Commission. Separately, provider audit information goes to an auditor, and finished audit reports reach the auditor and national competent authorities.

4. Reuse, FAIR-Style Data, and Public Transparency

Data Act as an Enabler

The text presents Data Act switching and interoperability rules as enabling provider choice and multi-cloud use. It says they do not alone create a sovereign, trusted EU cloud sector.

Once-Only Commitment

The once-only principle has been duly considered and will systematically be enforced wherever relevant. Named cases include capacity-gap statistics, recognised-service data, and market-analysis information.

FAIR-Style Implementation

Digital solutions will be provided to ensure the findability, accessibility, interoperability, and reusability of newly created data. Minimum-content requirements are intended to support high-quality data.

5. Quiz: Reuse and Recognition

Choose the statement that most accurately reflects the source text.

Which item is explicitly identified as a case where the once-only principle is particularly relevant?

  1. Statistics and data required for monitoring the capacity gap
  2. Every item of audit evidence without exception
  3. All data exchanged between private cloud providers
  4. The complete technical design of the EuroCloud Platform
Show Answer

Answer: A) Statistics and data required for monitoring the capacity gap

The text specifically names capacity-gap statistics, data on recognised services, and information supplied to the Commission for market analysis. It does not declare that every audit item or every private-provider exchange is covered without qualification.

6. Operational Data Flows: Triggers, Deadlines, and Frequencies

Do Not Invent a Deadline

Each flow has sender, recipient, and trigger; only some have a timing rule. When the table shows `//`, the source does not state a frequency or deadline for that entry.

Three Core Timing Rules

Strategies: Within three months of the adoption of a national strategy. Cross-border outcomes: Within two months of a request being made. Risk assessments: Bi-annually.

Procurement and Material Change

Procurement-monitoring data go from Member States to the Commission Annually. A provider's material change triggers notifications to auditors, authorities, and the Commission.

7. Cooperation, the Central Repository, and Public Visibility

From Recognition to Repository

Once recognition is granted, the verifying national competent authority sends service information to the central repository. The Commission and authorities support its public availability.

Mutual Assistance vs Cross-Border Cooperation

Article 27 covers authority-to-authority information exchange and assistance. Article 28 concerns suspected non-compliance across borders and includes informing the Commission.

Who Governs the Repository?

The European Commission is tasked with establishing and maintaining the repository. The verifying national authority uploads relevant data; later Commission work must detail organisational, semantic, and technical measures.

8. Flow-Mapping Exercise: Identify the Correct Route

Map the message before revealing the answer

For each situation, identify four elements: sender, recipient, trigger, and timing or frequency if the text gives one.

Scenario A: A national strategy is revised

A Member State has adopted a revised national cloud and AI strategy. Ask yourself:

  1. Who sends the information?
  2. Who receives it?
  3. What starts the obligation?
  4. Is this a recurring annual report?

Reveal: The Member State sends the strategy to the European Commission. The trigger is adoption of the national strategy, and the deadline is "Within three months of the adoption of a national strategy". The flow happens per adoption or revision, not annually.

Scenario B: Another authority suspects non-compliance

A national competent authority in the destination country suspects a service may not comply. Ask:

  1. Which authority receives the request for assessment?
  2. Who must also be informed?
  3. Who later supplies the outcome?
  4. What is the stated response period?

Reveal: The destination authority requests assessment from the national competent authority of the service's origin and informs the European Commission when it decides to ask the authority of establishment for information. The competent authority of origin sends the outcome to requestors and the Commission "Within two months of a request being made".

Scenario C: An audit outcome changes

The auditing organisation, not the provider, is the sender for the second-stage notification. It sends the changing audit outcome to national competent authorities of the establishment and other Member States, as well as the Commission. The table gives the trigger, "outcome of audit changing," but no separate numeric deadline.

9. Digital Solutions and Interoperability Assessment

Repository: Security and eIDAS

The repository will follow cybersecurity best practices of the Commission and reuse eIDAS insofar as relevant. A further Interoperable Europe Act assessment is deferred until operational details are known.

EuroCloud Platform

The platform should include mechanisms for secure access and incident management, such as shared identity management, mutual authentication tools, and incident-reporting tools.

What Remains Open

For the repository and federation, semantic and technical measures will be specified later. The detailed governance of the Eurocloud platform will be dealt with through secondary legislation.

10. Quiz: Platforms, Security, and Governance

Select the answer that correctly distinguishes what the source specifies now from what it leaves for later.

Which statement is supported by the source?

  1. The EuroCloud Platform must already use a fully specified eIDAS implementation defined in the text.
  2. The repository is exempt from cybersecurity requirements because it is a public website.
  3. The EuroCloud Platform should include secure-access and incident-management mechanisms, while its detailed governance is to be dealt with through secondary legislation.
  4. The Interoperable Europe Act assessment has already been completed for every platform described.
Show Answer

Answer: C) The EuroCloud Platform should include secure-access and incident-management mechanisms, while its detailed governance is to be dealt with through secondary legislation.

The source says the EuroCloud Platform should include secure access and incident management mechanisms, and that detailed EuroCloud platform governance will be dealt with through secondary legislation. eIDAS details and possible further interoperability assessments are deferred in the relevant cases.

11. Flashcards: Core Terms, Exact Phrases, and Timelines

Flip each card, then use the back to reconstruct the relevant provision or flow in your own words.

Audit-data quality
Data quality: sufficiently complete and reliable; minimum content for audits.
National-strategy notification deadline
Member States notify the European Commission within three months of the adoption of a national strategy; the flow occurs per adoption or revision.
Once-only principle
The once-only principle has been duly considered and will systematically be enforced wherever relevant.
FAIR-style implementation
Digital solutions will be provided to ensure the findability, accessibility, interoperability, and reusability of newly created data.
Cross-border response
The competent authority of origin sends the assessment outcome to requestors and the Commission within two months of a request being made.
Risk-assessment frequency
Bi-annually.
Procurement reporting
Annually.
Repository governance
The European Commission is tasked with establishing and maintaining the repository. The verifying national authority uploads relevant data.
EuroCloud security
The platform should include mechanisms for secure access and incident management, such as shared identity management, mutual authentication tools, and incident reporting tools.
EuroCloud governance
The detailed governance of the Eurocloud platform will be dealt with through secondary legislation.

Key Terms

eIDAS
The EU framework that the text says certain repositories or catalogues will reuse insofar as relevant; for some platforms, detailed application is to be specified later by the Commission.
recognition
The Article 17 process through which a cloud computing service provider seeks to provide services to Union entities and public sector bodies at a Union assurance level.
mutual assistance
Article 27 cooperation in which national competent authorities exchange information and make requests for assistance and replies.
EuroCloud Platform
The platform accessible to Federation Members for sharing capabilities within the EuroCloud Federation. The text anticipates secure access and incident-management mechanisms.
once-only principle
A principle requiring reuse of information where relevant so that the same data are not needlessly requested again; the text highlights capacity-gap data, recognised-service data, and market-analysis information.
EuroCloud Federation
The European public sector cloud federation established by Article 34 to bring together national cloud initiatives with highly trusted and secure public-sector cloud capabilities.
secondary legislation
Later legal measures that the text identifies as the vehicle for detailed governance of the EuroCloud Platform.
Interoperable Europe Act
Regulation (EU) 2024/903. The text refers to possible additional interoperability assessments once operational details for the repository or EuroCloud Platform are available.
cross-border cooperation
Article 28 cooperation triggered by suspicions of non-compliance, including requests between destination and origin authorities and information to the Commission.
cloud computing service provider
The provider that may request recognition in order to provide services to Union entities and public sector bodies, provide audit information, issue an EU statement of conformity, and notify material changes.
competent authority of establishment
The national competent authority connected to the provider's establishment. In the recognition process, it receives the provider's request and may communicate conclusions for review.
central repository of cloud computing services
The dedicated repository for cloud computing services recognised under a specific Union assurance level. The Commission establishes and maintains it, while the competent authority of establishment registers relevant recognised services.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself