Chapter 13 of 17
Data Governance, Operational Flows, and Interoperable Platforms
The framework depends on information moving reliably among providers, auditors, national authorities, the Commission, public bodies, and the public. This module traces those flows and evaluates the planned repository, federation, procurement, and open-source systems against EU data, cybersecurity, identity, and interoperability principles.
1. Reading the Framework: Scope, Status, and Actors
What Sections 4.2-4.5 Do
The text maps data types, senders, recipients, triggers, and frequencies. It treats governance as an operational information system, not simply as a list of legal duties.
Status on July 20, 2026
This material reflects the Commission proposal for the Cloud and AI Development Act, COM(2026) 502, adopted on June 3, 2026. It is a proposal, not yet a final binding Regulation.
The Network of Actors
Information moves among providers, auditors, national competent authorities, Member States, the Commission, and the public. Some flows are national-to-Commission; others are authority-to-authority.
2. Data in Scope: From Strategies to Recognition
Several Datasets, Not One
Section 4.2 separates information by purpose: national strategies, strategic-project applications, capacity-gap monitoring, recognition, audits, transparency, cooperation, risk assessment, and procurement.
Recognition Evidence
Article 17 covers recognition requests; Article 19 covers EU statements of conformity; Articles 20 and 21 concern audits. The text requires: Data quality: sufficiently complete and reliable; minimum content for audits.
What the Text Does Not Specify
For several categories the table says `N/A`. In particular, it does not provide a universal schema, numeric data-quality threshold, or technical standard for every data type.
3. Worked Example: The Recognition and Audit Trail
Start: Provider Request
A provider seeking to serve Union entities or public sector bodies sends its Article 17 request to the national competent authority of its establishment.
Decision and Review
The authority may reject, request additional evidence, or recognise the service. Its conclusion is then distributed to all national competent authorities, which may object.
Escalation and Evidence
Unresolved disagreement goes to the Commission. Separately, provider audit information goes to an auditor, and finished audit reports reach the auditor and national competent authorities.
4. Reuse, FAIR-Style Data, and Public Transparency
Data Act as an Enabler
The text presents Data Act switching and interoperability rules as enabling provider choice and multi-cloud use. It says they do not alone create a sovereign, trusted EU cloud sector.
Once-Only Commitment
The once-only principle has been duly considered and will systematically be enforced wherever relevant. Named cases include capacity-gap statistics, recognised-service data, and market-analysis information.
FAIR-Style Implementation
Digital solutions will be provided to ensure the findability, accessibility, interoperability, and reusability of newly created data. Minimum-content requirements are intended to support high-quality data.
5. Quiz: Reuse and Recognition
Choose the statement that most accurately reflects the source text.
Which item is explicitly identified as a case where the once-only principle is particularly relevant?
- Statistics and data required for monitoring the capacity gap
- Every item of audit evidence without exception
- All data exchanged between private cloud providers
- The complete technical design of the EuroCloud Platform
Show Answer
Answer: A) Statistics and data required for monitoring the capacity gap
The text specifically names capacity-gap statistics, data on recognised services, and information supplied to the Commission for market analysis. It does not declare that every audit item or every private-provider exchange is covered without qualification.
6. Operational Data Flows: Triggers, Deadlines, and Frequencies
Do Not Invent a Deadline
Each flow has sender, recipient, and trigger; only some have a timing rule. When the table shows `//`, the source does not state a frequency or deadline for that entry.
Three Core Timing Rules
Strategies: Within three months of the adoption of a national strategy. Cross-border outcomes: Within two months of a request being made. Risk assessments: Bi-annually.
Procurement and Material Change
Procurement-monitoring data go from Member States to the Commission Annually. A provider's material change triggers notifications to auditors, authorities, and the Commission.
7. Cooperation, the Central Repository, and Public Visibility
From Recognition to Repository
Once recognition is granted, the verifying national competent authority sends service information to the central repository. The Commission and authorities support its public availability.
Mutual Assistance vs Cross-Border Cooperation
Article 27 covers authority-to-authority information exchange and assistance. Article 28 concerns suspected non-compliance across borders and includes informing the Commission.
Who Governs the Repository?
The European Commission is tasked with establishing and maintaining the repository. The verifying national authority uploads relevant data; later Commission work must detail organisational, semantic, and technical measures.
8. Flow-Mapping Exercise: Identify the Correct Route
Map the message before revealing the answer
For each situation, identify four elements: sender, recipient, trigger, and timing or frequency if the text gives one.
Scenario A: A national strategy is revised
A Member State has adopted a revised national cloud and AI strategy. Ask yourself:
- Who sends the information?
- Who receives it?
- What starts the obligation?
- Is this a recurring annual report?
Reveal: The Member State sends the strategy to the European Commission. The trigger is adoption of the national strategy, and the deadline is "Within three months of the adoption of a national strategy". The flow happens per adoption or revision, not annually.
Scenario B: Another authority suspects non-compliance
A national competent authority in the destination country suspects a service may not comply. Ask:
- Which authority receives the request for assessment?
- Who must also be informed?
- Who later supplies the outcome?
- What is the stated response period?
Reveal: The destination authority requests assessment from the national competent authority of the service's origin and informs the European Commission when it decides to ask the authority of establishment for information. The competent authority of origin sends the outcome to requestors and the Commission "Within two months of a request being made".
Scenario C: An audit outcome changes
The auditing organisation, not the provider, is the sender for the second-stage notification. It sends the changing audit outcome to national competent authorities of the establishment and other Member States, as well as the Commission. The table gives the trigger, "outcome of audit changing," but no separate numeric deadline.
9. Digital Solutions and Interoperability Assessment
Repository: Security and eIDAS
The repository will follow cybersecurity best practices of the Commission and reuse eIDAS insofar as relevant. A further Interoperable Europe Act assessment is deferred until operational details are known.
EuroCloud Platform
The platform should include mechanisms for secure access and incident management, such as shared identity management, mutual authentication tools, and incident-reporting tools.
What Remains Open
For the repository and federation, semantic and technical measures will be specified later. The detailed governance of the Eurocloud platform will be dealt with through secondary legislation.
10. Quiz: Platforms, Security, and Governance
Select the answer that correctly distinguishes what the source specifies now from what it leaves for later.
Which statement is supported by the source?
- The EuroCloud Platform must already use a fully specified eIDAS implementation defined in the text.
- The repository is exempt from cybersecurity requirements because it is a public website.
- The EuroCloud Platform should include secure-access and incident-management mechanisms, while its detailed governance is to be dealt with through secondary legislation.
- The Interoperable Europe Act assessment has already been completed for every platform described.
Show Answer
Answer: C) The EuroCloud Platform should include secure-access and incident-management mechanisms, while its detailed governance is to be dealt with through secondary legislation.
The source says the EuroCloud Platform should include secure access and incident management mechanisms, and that detailed EuroCloud platform governance will be dealt with through secondary legislation. eIDAS details and possible further interoperability assessments are deferred in the relevant cases.
11. Flashcards: Core Terms, Exact Phrases, and Timelines
Flip each card, then use the back to reconstruct the relevant provision or flow in your own words.
- Audit-data quality
- Data quality: sufficiently complete and reliable; minimum content for audits.
- National-strategy notification deadline
- Member States notify the European Commission within three months of the adoption of a national strategy; the flow occurs per adoption or revision.
- Once-only principle
- The once-only principle has been duly considered and will systematically be enforced wherever relevant.
- FAIR-style implementation
- Digital solutions will be provided to ensure the findability, accessibility, interoperability, and reusability of newly created data.
- Cross-border response
- The competent authority of origin sends the assessment outcome to requestors and the Commission within two months of a request being made.
- Risk-assessment frequency
- Bi-annually.
- Procurement reporting
- Annually.
- Repository governance
- The European Commission is tasked with establishing and maintaining the repository. The verifying national authority uploads relevant data.
- EuroCloud security
- The platform should include mechanisms for secure access and incident management, such as shared identity management, mutual authentication tools, and incident reporting tools.
- EuroCloud governance
- The detailed governance of the Eurocloud platform will be dealt with through secondary legislation.
Key Terms
- eIDAS
- The EU framework that the text says certain repositories or catalogues will reuse insofar as relevant; for some platforms, detailed application is to be specified later by the Commission.
- recognition
- The Article 17 process through which a cloud computing service provider seeks to provide services to Union entities and public sector bodies at a Union assurance level.
- mutual assistance
- Article 27 cooperation in which national competent authorities exchange information and make requests for assistance and replies.
- EuroCloud Platform
- The platform accessible to Federation Members for sharing capabilities within the EuroCloud Federation. The text anticipates secure access and incident-management mechanisms.
- once-only principle
- A principle requiring reuse of information where relevant so that the same data are not needlessly requested again; the text highlights capacity-gap data, recognised-service data, and market-analysis information.
- EuroCloud Federation
- The European public sector cloud federation established by Article 34 to bring together national cloud initiatives with highly trusted and secure public-sector cloud capabilities.
- secondary legislation
- Later legal measures that the text identifies as the vehicle for detailed governance of the EuroCloud Platform.
- Interoperable Europe Act
- Regulation (EU) 2024/903. The text refers to possible additional interoperability assessments once operational details for the repository or EuroCloud Platform are available.
- cross-border cooperation
- Article 28 cooperation triggered by suspicions of non-compliance, including requests between destination and origin authorities and information to the Commission.
- cloud computing service provider
- The provider that may request recognition in order to provide services to Union entities and public sector bodies, provide audit information, issue an EU statement of conformity, and notify material changes.
- competent authority of establishment
- The national competent authority connected to the provider's establishment. In the recognition process, it receives the provider's request and may communicate conclusions for review.
- central repository of cloud computing services
- The dedicated repository for cloud computing services recognised under a specific Union assurance level. The Commission establishes and maintains it, while the competent authority of establishment registers relevant recognised services.