EUROPEAN
COMMISSION
Brussels, 19.2.2020
COM(2020) 66 final
COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN
PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL
COMMITTEE AND THE COMMITTEE OF THE REGIONS
A European strategy for data
EN EN
A European strategy for data
1. Introduction
Over the last few years, digital technologies have transformed the economy and society,
affecting all sectors of activity and the daily lives of all Europeans. Data is at the centre of this
transformation and more is to come. Data-driven innovation will bring enormous benefits for
citizens, for example through improved personalised medicine, new mobility and through its
contribution to the European Green Deal. In a society where individuals will generate ever-
increasing amounts of data, the way in which the data are collected and used must place the
interests of the individual first, in accordance with European values, fundamental rights and
rules. Citizens will trust and embrace data-driven innovations only if they are confident that
any personal data sharing in the EU will be subject to full compliance with the EU’s strict
data protection rules. At the same time, the increasing volume of non-personal industrial data
and public data in Europe, combined with technological change in how the data is stored and
processed, will constitute a potential source of growth and innovation that should be tapped.
Citizens should be empowered to make better decisions based on insights gleaned from non-
personal data. And that data should be available to all – whether public or private, big or
small, start-up or giant. This will help society to get the most out of innovation and
competition and ensure that everyone benefits from a digital dividend. This digital Europe
should reflect the best of Europe - open, fair, diverse, democratic, and confident.
The EU can become a leading role model for a society empowered by data to make better
decisions – in business and the public sector. To fulfil this ambition, the EU can build on a
strong legal framework – in terms of data protection, fundamental rights, safety and cyber-
security – and its internal market with competitive companies of all sizes and varied industrial
base. If the EU is to acquire a leading role in the data economy, it has to act now and tackle,
in a concerted manner, issues ranging from connectivity to processing and storage of data,
computing power and cybersecurity. Moreover, it will have to improve its governance
structures for handling data and to increase its pools of quality data available for use and re-
use.
Ultimately, Europe aims to capture the benefits of better use of data, including greater
productivity and competitive markets, but also improvements in health and well-being,
environment, transparent governance and convenient public services. The measures laid out in
this paper contribute to a comprehensive approach to the data economy that aim to increase
the use of, and demand for, data and data-enabled products and services throughout the Single
Market.
This Communication outlines a strategy for policy measures and investments to enable the
data economy for the coming five years. This data strategy is presented at the same time as
the Commission’s Communication on “Shaping Europe’s digital future” and a White Paper on
1
artificial intelligence that indicates how the Commission will support and promote the
development and uptake of artificial intelligence across the EU.
On the basis of this strategy, the Commission launches a comprehensive consultation on the
specific measures that could be taken to keep the EU at the forefront of the data-agile
economy, while respecting and promoting the fundamental values that are the foundation of
European societies.
2. What is at stake?
Growing data volumes and technological change
The volume of data produced in the world is growing rapidly, from 33 zettabytes in 2018 to
an expected 175 zettabytes in 20251. Each new wave of data represents major opportunities
for the EU to become a world leader in this area. Furthermore, the way in which data is stored
and processed will change dramatically over the coming 5 years. Today 80% of the
processing and analysis of data takes place in data centres and centralised computing
facilities, and 20% in smart connected objects, such as cars, home appliances or
manufacturing robots, and in computing facilities close to the user (‘edge computing’). By
2025 these proportions are likely to be inverted2. Aside from the economic and sustainability
advantages that this development presents, it opens up additional opportunities for businesses
to develop tools for data producers to increase control over their own data.
The importance of data for the economy and society
Data will reshape the way we produce, consume and live. Benefits will be felt in every single
aspect of our lives, ranging from more conscious energy consumption and product, material
and food traceability, to healthier lives and better health-care.
Personalised medicine will better respond to the patients’ needs by enabling doctors
to take data-enabled decisions. This will make it possible to tailor the right
therapeutic strategy to the needs of the right person at the right time, and/or to
determine the predisposition to disease and/or to deliver timely and targeted
prevention.
Data is the lifeblood of economic development: it is the basis for many new products and
services, driving productivity and resource efficiency gains across all sectors of the economy,
allowing for more personalised products and services and enabling better policy making and
upgrading government services. It is an essential resource for start-ups and small and
medium-sized enterprises (SMEs) in developing products and services. The availability of
data is essential for training artificial intelligence systems, with products and services rapidly
1
IDC, 2018.
2
Gartner, 2017.
2
moving from pattern recognition and insight generation to more sophisticated forecasting
techniques and, thus, better decisions.
Data will also fuel the wide implementation of transformative practices such as the use of
digital twins in manufacturing.
Digital twins create a virtual replica of a physical product, process or system. The
replica can for example predict when a machine will fail, based on data analysis,
which allows to increase productivity through predictive maintenance.
Moreover, making more data available and improving the way in which data is used is
essential for tackling societal, climate and environment-related challenges, contributing to
healthier, more prosperous and more sustainable societies. It will for example lead to better
policies to achieve the objectives of the European Green Deal. At the same time, the current
environmental footprint of the ICT sector is estimated to be between 5 to 9% of the world’s
total electricity use and more than 2% of all emissions, a large part of which is due to data
centres, cloud services and connectivity. The EU’s digital strategy ‘Shaping Europe’s digital
future’ proposes green transformation measures for the ICT sector.
The EU has everything to play for in the data economy of the future
Currently, a small number of Big Tech firms hold a large part of the world’s data. This could
reduce the incentives for data-driven businesses to emerge, grow and innovate in the EU
today, but numerous opportunities lie ahead. A large part of the data of the future will come
from industrial and professional applications, areas of public interest or internet-of-things
applications in everyday life, areas where the EU is strong. Opportunities will also arise from
technological change, with new perspectives for European business in areas such as cloud at
the edge, from digital solutions for safety critical applications, and also from quantum
computing. These trends indicate that the winners of today will not necessarily be the winners
of tomorrow. But the sources of competitiveness for the next decades in the data economy are
determined now. This is why the EU should act now .
The EU has the potential to be successful in the data-agile economy. It has the technology, the
know-how and a highly skilled workforce. However, competitors such as China and the US
are already innovating quickly and projecting their concepts of data access and use across the
globe. In the US, the organisation of the data space is left to the private sector, with
considerable concentration effects. China has a combination of government surveillance with
a strong control of Big Tech companies over massive amounts of data without sufficient
safeguards for individuals.
In order to release Europe’s potential we have to find our European way, balancing the flow
and wide use of data, while preserving high privacy, security, safety and ethical standards.
3
What has been done so far?
The Commission has already taken a number of steps since 2014. With the General Data
Protection Regulation (GDPR)3, the EU created a solid framework for digital trust. The
upcoming review of the GDPR may provide further useful elements in this regard. Other
initiatives that have fostered the development ofthe data economy are the Regulation on the
free flow of non-personal data (FFD)4, the Cybersecurity Act (CSA)5, and the Open Data
Directive6. The Commission had also engaged in digital diplomacy recognising 13 countries
as providing adequate level of protection for personal data.
Sector-specific legislation on data access has also been adopted in some fields to address
identified market failures, such as automotive7, payment service providers8, smart metering
information9, electricity network data10, or intelligent transport systems11. The Digital Content
Directive12 contributed to empowering individuals by introducing contractual rights when
digital services are supplied to consumers who provide access to their data.
3. The vision
The Commission’s vision stems from European values and fundamental rights and the
conviction that the human being is and should remain at the centre. The Commission is
convinced that businesses and the public sector in the EU can be empowered through the use
of data to make better decisions. It is all the more compelling to seize the opportunity
presented by data for social and economic good, as data – unlike most economic resources –
can be replicated at close to zero cost and its use by one person or organisation does not
prevent the simultaneous use by another person or organisation. That potential should be put
to work to address the needs of individuals and thus create value for the economy and society.
To release this potential, there is a need to ensure better access to data and its responsible
usage.
The EU should create an attractive policy environment so that, by 2030, the EU’s share of the
data economy – data stored, processed and put to valuable use in Europe - at least corresponds
to its economic weight, not by fiat but by choice. The aim is to create a single European data
space – a genuine single market for data, open to data from across the world – where personal
as well as non-personal data, including sensitive business data, are secure and businesses also
3
Regulation (EU) 2016/679.
4
Regulation (EU) 2018/1807.
5
Regulation (EU) 2019/881.
6
Directive (EU) 2019/1024.
7
Regulation 715/2007 as amended by Regulation 595/2009.
8
Payment Service Directive Directive 2015/2366.
9
Directive 2019/944 for electricity, Directive 2009/73/EC for gas meters.
10
Commission Regulation (EU) 2017/1485, Commission Regulation (EU) 2015/703.
11
Directive 2010/40/EU.
12
Directive (EU) 2019/770.
4
have easy access to an almost infinite amount of high-quality industrial data, boosting growth
and creating value, while minimising the human carbon and environmental footprint. It should
be a space where EU law can be enforced effectively, and where all data-driven products and
services comply with the relevant norms of the EU’s single market. To this end, the EU
should combine fit-for-purpose legislation and governance to ensure availability of data, with
investments in standards, tools and infrastructures as well as competences for handling data.
This favourable context, promoting incentives and choice, will lead to more data being stored
and processed in the EU.
The European data space will give businesses in the EU the possibility to build on the scale of
the Single market. Common European rules and efficient enforcement mechanisms should
ensure that:
- data can flow within the EU and across sectors;
- European rules and values, in particular personal data protection, consumer protection
legislation and competition law, are fully respected;
- the rules for access to and use of data are fair, practical and clear, and there are clear and
trustworthy data governance mechanisms in place;there is an open, but assertive approach
to international data flows, based on European values.
The steps listed here to enable access to data need to be complemented with a broader
industrial strategy for the data-agile economy. Data spaces should foster an ecosystem (of
companies, civil society and individuals) creating new products and services based on more
accessible data. Public policy can increase demand for data-enabled offerings, both by
increasing the public sector’s own ability to employ data for decision-making and public
services and by updating regulation and sectoral policies to reflect the opportunities provided
by data and ensure that they do not maintain disincentives for productive data use.
The functioning of the European data space will depend on the capacity of the EU to invest in
next-generation technologies and infrastructures as well as in digital competences like data
literacy. This in turn will increase Europe’s technological sovereignty in key enabling
technologies and infrastructures for the data economy. The infrastructures should support the
creation of European data pools enabling Big Data analytics and machine learning, in a
manner compliant with data protection legislation and competition law, allowing the
emergence of data-driven ecosystems. These pools may be organised in a centralised or a
distributed way13. The organisations contributing data would get a return in the form of
increased access to data of other contributors, analytical results from the data pool, services
such as predictive maintenance services, or licence fees.
13
In the latter case the data are not moved to a central place in order to analyse them together with other data
assets. The analytical tools come to the data, not the other way around. This makes it easier to keep the data
secure and to ensure control over who accesses what data for what purposes.
5
While data is essential for all sectors of the economy and society, each domain has its own
specificities and not all sectors are moving at the same speed. Therefore, cross-sectoral
actions towards a European data space need to be accompanied by the development of
sectoral data spaces in strategic areas such as manufacturing, agriculture, health, and mobility.
4. The problems
Several issues are holding the EU back from realising its potential in the data economy.
Fragmentation between Member States is a major risk for the vision of a common European
data space and for the further development of a genuine single market for data. A number of
Member States have started with adaptations of their legal framework, such as on use of
privately-held data by government authorities14, data processing for scientific research
purposes15, or adaptations to competition law16. Others are only starting to explore how to
handle the issues at stake. The emerging differences underline the importance of common
action in order to leverage the scale of the internal market. Progress will need to be made
together on the following issues:
Availability of data: The value of data lies in its use and re-use. Currently there is not enough
data available for innovative re-use, including for the development of artificial intelligence.
The issues can be grouped according to who is the data holder and who is the data user, but
also depend on the nature of data involved (i.e. personal data, non-personal data, or mixed
data-sets combining the two17). Several of the issues concern the availability of data for the
public good.
Data for the public good: Data is created by society and can serve to combat
emergencies, such as floods and wildfires, to ensure that people can live longer and
healthier lives, to improve public services, and to tackle environmental degradation
and climate change, and, where necessary and proportionate, to ensure more efficient
fight against crime. Data generated by the public sector as well as the value created
should be available for the common good by ensuring, including through preferential
access, that these data are used by researchers, other public institutions, SMEs or
start-ups. Data from the private sector can also make a significant contribution as
14
For example the French ‘LOI n° 2016-1321 du 7 octobre 2016 pour une République numérique’, allowing the
public sector to access certain (private sector) data of general interest or the Finnish Forest Act obliging forest
owners to share information related to the management of the forest with the public sector.
15
For example the Finnish law on secondary use of health and social data, creating a data permit authority.
16
Discussions on adapting the competition rules to make them better equipped for the data economy are for
example ongoing in Germany. See also the report for the Commission on ‘Competition policy for the digital era’.
17
For adding legal certainty, the European Commission issued practical guidance for businesses on how to
process mixed datasets in May 2019; see COM(2019)250 https://ec.europa.eu/digital-single-
market/en/news/practical-guidance-businesses-how-process-mixed-datasets
6
public goods. The use of aggregated and anonymised social media data can for
example be an effective way of complementing the reports of general practitioners in
case of an epidemic.
- Use of public sector information by business (government-to-business – G2B – data
sharing). Opening up government-held information is a long-standing EU policy18. This
data has been produced with public money and should therefore benefit society. The
recently revised Open Data Directive19 as well as other sector-specific legislation ensures
that the public sector makes more of the data it produces easily available for use 20, in
particular by SMEs but also for civil society, and the scientific community, in the
framework of independent public policy evaluations. However, governments can do more.
High-value datasets are often not available under the same conditions across the EU to the
detriment of the use of the data by SMEs that cannot afford this fragmentation. At the
same time, sensitive data (e.g. health data) in public databases is often not made available
for research purposes, in the absence of capacity or mechanisms that allow specific
research actions to be taken in a manner compliant with personal data protection rules.
- Sharing and use of privately-held data by other companies (business-to-business – B2B –
data-sharing). In spite of the economic potential, data sharing between companies has not
taken off at sufficient scale. This is due to a lack of economic incentives (including the
fear of losing a competitive edge), lack of trust between economic operators that the data
will be used in line with contractual agreements, imbalances in negotiating power, the fear
of misappropriation of the data by third parties, and a lack of legal clarity on who can do
what with the data (for example for co-created data, in particular IoT data).
- Use of privately-held data by government authorities (business-to-government – B2G –
data sharing). There is currently not enough private sector data available for use by the
public sector to improve evidence-driven policy-making21 and public services such as
mobility management or enhancing the scope and timeliness of official statistics22, and
hence their relevance in the context of new societal developments. The recommendations
of an Expert Group23 created by the Commission, include the creation of national
structures for B2G data sharing, the development of appropriate incentives to create a
18
Since the adoption of Directive 2003/98/EC on the re-use of public sector information.
19
Directive (EU) 2019/1024, repealing Directive 2003/98/EC as revised by Directive 2013/37/EU.
20
The European open data portal contains examples of a range of companies from across the EU that have
benefited from open data, and some of them would not exist without the data availability.
https://www.europeandataportal.eu/en/using-data/use-cases.
21
For example in new areas such as platform work.
22
The scope of the work on B2G does not include the use of data for law enforcement purposes. Any action in
this area should comply with data protection and privacy legislation.
23
see here: https://ec.europa.eu/digital-single-market/news-redirect/666643.
7
data-sharing culture, and the suggestion to explore an EU regulatory framework to govern
the public sector’s re-use for the public interest of privately-held data..
- Sharing of data between public authorities is equally important. It can make a
considerable contribution to improving policy making and public services, but also to
reduce the administrative burden on companies operating in the Single Market (‘once
only’ principle).
Imbalances in market power: Beside the high concentration in the provision of cloud services
and data infrastructures, there are also market imbalances in relation to access to and use of
data, for example when it comes to access to data by SMEs. A case in point comes from large
online platforms, where a small number of players may accumulate large amounts of data,
gathering important insights and competitive advantages from the richness and variety of the
data they hold. This can affect, in turn, the contestability of markets in specific cases – not
only the market for such platform services, but also the various specific markets for goods and
services served by the platform, in particular if the platform is itself active on such related
markets. The high degree of market power resulting from the ‘data advantage’ can enable
large players to set the rules on the platform and unilaterally impose conditions for access and
use of data or, indeed, allow leveraging of such ‘power advantage’ when developing new
services and expanding towards new markets. Imbalances may also arise in other situations,
such as with regard to access to co-generated IoT data from industrial and consumer devices.
Data interoperability and quality: Data interoperability and quality, as well as their structure,
authenticity and integrity are key for the exploitation of the data value, especially in the
context of AI deployment. Data producers and users have identified significant
interoperability issues which impede the combination of data from different sources within
sectors, and even more so between sectors. The application of standard and shared compatible
formats and protocols for gathering and processing data from different sources in a coherent
and interoperable manner across sectors and vertical markets should be encouraged through
the rolling plan for ICT standardisation24 and (as regards public services) a strengthened
European Interoperability Framework.25
Data governance: There have been calls to further reinforce the governance of data use in
society and the economy.26 For these data spaces to become operational, organisational
approaches and structures (both public and private) are needed that enable data-driven
innovation on the basis of the existing legal framework.
24
https://ec.europa.eu/digital-single-market/en/news/rolling-plan-ict-standardisation.
25
https://ec.europa.eu/isa2/eif_en; see: COM(2017)134 final.
26
E.g. in a recent series of workshops undertaken by the Commission on the concept of ‘common European data
spaces’ https://ec.europa.eu/digital-single-market/en/news/report-european-commissions-workshops-common-
european-data-spaces.
8
Data infrastructures and technologies: The digital transformation of the EU economy
depends on the availability and uptake of secure, energy-efficient, affordable and high-quality
data processing capacities, such as those offered by cloud infrastructures and services, both in
data centres and at the edge. In this perspective, the EU needs to reduce its technological
dependencies in these strategic infrastructures, at the centre of the data economy.
However problems persist on both the supply and demand side of cloud.
On the supply side:
- EU-based cloud providers have only a small share of the cloud market, which makes the
EU highly dependent on external providers, vulnerable to external data threats and subject
to a loss of investment potential for the European digital industry in the data processing
market;
- Service providers operating in the EU may also be subject to legislation of third countries,
which presents the risk that data of EU citizens and businesses are accessed by third
country jurisdictions that are in contradiction with the EU’s data protection framework. In
particular, concerns have been voiced about several Chinese laws related to cybersecurity
and national intelligence.
- While third country legislations like the U.S. CLOUD Act are based on public policy
reasons such as law enforcement access to data for criminal investigations, the application
of foreign jurisdictions’ legislation raises legitimate concerns for European businesses,
citizens and public authorities over legal uncertainty and compliance with applicable EU
law, such as data protection rules. The EU is acting to mitigate such concerns through
mutually beneficial international cooperation, such as the proposed EU-U.S. Agreement to
facilitate cross border access to electronic evidence, alleviating the risk of conflict of laws
and establishing clear safeguards for the data of EU citizens and companies. The EU is
also working at the multilateral level, including in the context of the Council of Europe, to
develop common rules on access to electronic evidence, based on a high level of
protection of fundamental and procedural rights.
- There is uncertainty about compliance of cloud service providers with important EU rules
and standards, for example on data protection.
- Micro-enterprises and SMEs suffer economic detriment because of contract-related
problems, e.g. non-conformity with the contract or unfair contract terms.27
On the demand side:
- There is a low cloud uptake in Europe (1 company in 4, only 1 in 5 for SMEs 28).
Significant divergences in cloud uptake exist between Member States (from below 10% to
up to 65% of businesses using cloud);
27
Study on the economic detriment from unfair and unbalanced cloud computing contract terms.
28
https://ec.europa.eu/eurostat/statistics-explained/index.php/Cloud_computing_-
_statistics_on_the_use_by_enterprises.
9
- Specifically, cloud uptake in the European public sector is low. This may lead to less
efficient digital public services, not only because of the clear potential to cut IT costs by
cloud adoption, but also because governments need the scalability of cloud computing to
deploy technologies like Artificial Intelligence.
- There is frequently insufficient visibility on the market of smaller, often European,
providers of innovative cloud services.
- European businesses often experience problems with multi-cloud interoperability, in
particular data portability.
Empowering individuals to exercise their rights: Individuals value the high level of
protection granted by the GDPR and ePrivacy legislation. However, they suffer from the
absence of technical tools and standards that make the exercise of their rights simple and not
overly burdensome. The potential of Article 20 of the GDPR to enable novel data flows and
foster competition is recognised in reports for the Commission and Member State
governments29, not limited to the EU30. Yet, as a result of its design to enable switching of
service providers rather than enabling data reuse in digital ecosystems the right has practical
limitations.
Since increasingly large amounts of data are generated by consumers when they use IoT
devices and digital services, consumers may be faced with risks of discrimination, unfair
practices and ‘lock-in’ effects. Considerations of consumer and innovation empowerment
underlie the provisions on data access and reuse of the Payment Services Directive
In response to this, there are calls to give individuals the tools and means to decide at a
granular level what is done with their data (by the MyData movement and others) 31. This
promises significant benefits to individuals, including to their health and wellness, better
personal finances, reduced environmental footprint, hassle-free access to public and private
services and greater oversight and transparency over their personal data. Those tools and
means include consent management tools, personal information management apps, including
fully decentralised solutions building on blockchain, as well as personal data cooperatives or
trusts acting as novel neutral intermediaries in the personal data economy32. Currently such
tools are still in their infancy, although they have significant potential and need a supportive
environment.
Skills and data literacy: Currently, big data and analytics are top of the list of critical skills
shortages. In 2017, there were approximately 496 000 unfilled positions in the area of big data
29
Cf. e.g. Cremer/deMontjoye/Schweitzer, Competition policy for the digital era; Furman, Unlocking digital
competition, report for the UK government; German Datenethikkommission.
30
See introduction of a new Consumer Data Right in Australia, https://www.accc.gov.au/focus-areas/consumer-
data-right-cdr-0 and the consultation in on data portability in Singapore.
31
https://mydata.org/; https://www.decodeproject.eu/; https://solid.mit.edu/, https://radicalxchange.org/
32
See report of German Datenethikkommission, p. 133 and Staff Working Document, p. 8.
10
and analytics in the EU2733. Moreover, general data literacy in the workforce and across the
population is relatively low and participation gaps exist (for example by elderly people). If it
is not addressed, the shortage in data experts and the lack of data literacy will affect the EU’s
capacity to master the challenges of the data economy and society.
Cybersecurity: In the area of cybersecurity Europe has developed an already comprehensive
framework to support Member States, businesses and citizens to tackle cybersecurity threats
and attacks, and Europe will continue to develop and improve its mechanisms to protect its
data and the services building on it. The safe and widespread use of data-fuelled products and
services will also depend on the highest cybersecurity standards. The EU Cybersecurity
Certification Framework and the EU Agency for Cybersecurity (ENISA)34 are expected to
play an important role towards that endeavour.
However, the new data paradigm where less data will be stored in data centres, and more data
will be spread in a pervasive way closer to the user ‘at the edge’, brings new challenges for
cybersecurity. It will be essential to preserve data security when data are being exchanged.
Ensuring the continuity of access controls (i.e. how security attributes of data are managed
and respected) across data value chains will be a key, but demanding, pre-requisite to foster
data sharing and ensure trust among the different actors of European data ecosystems.
New decentralised digital technologies such as blockchain offer a further possibility for
both individuals and companies to manage data flows and usage, based on individual
free choice and self-determination. Such technologies will make dynamic data portability
in real time possible for individuals and companies, along with various compensation
models.
5. The strategy
This European data strategy serves to realise the vision for a genuine single market for data
and tackles the problems identified through policy measures and funding, building on what
has already been achieved in the last few years.
Each of the new legislative measures will be prepared and assessed in full compliance with
the Better Regulation principles.
The actions are based on four pillars:
33
IDC 2019.
34
Regulation (EU) 2019/881 – European Cybersecurity Act.
11
A. A cross-sectoral governance framework for data access and use
Cross-sectoral (or horizontal) measures for data access and use should create the necessary
over-arching framework for the data-agile economy, thereby avoiding harmful fragmentation
of the internal market through inconsistent actions between sectors and between the Member
States. Such measures should nonetheless take into account the specificities of individual
sectors and of the Member States.
The Commission’s approach to regulation is to create frameworks that shape the context,
allowing lively, dynamic and vivid ecosystems to develop. Because it is difficult to fully
comprehend all elements of this transformation towards a data-agile economy, the
Commission deliberately abstains from overly detailed, heavy-handed ex ante regulation, and
will prefer an agile approach to governance that favours experimentation (such as regulatory
sandboxes), iteration, and differentiation.
In line with this principle, a first priority for operationalising the vision is to put in place an
enabling legislative framework for the governance of common European data spaces
(Q4 2020). Such governance structures should support decisions on what data can be used in
which situations, facilitate cross-border data use, and prioritise interoperability requirements
and standards within and across sectors, while taking into account the need for sectoral
authorities to specify sectoral requirements. The framework will reinforce the necessary
structures in the Member States and at EU level to facilitate the use of data for innovative
business ideas, both at sector- or domain-specific level and from a cross-sector perspective. It
will build on recent initiatives in the Member States35 and in individual sectors to address one
or more of the following issues:
- strengthen the governance mechanisms at EU level and in the Member States relevant for
cross-sector data use and for data use in the common sectoral data spaces, involving both
private and public players. This could include a mechanism to prioritise standardisation
activities36 and to work towards a more harmonised description and overview of datasets,
data objects and identifiers to foster data interoperability (i.e. their usability at a technical
level37) between sectors and, where relevant, within sectors38. This can be done in line
with the principles on Findability, Accessibility, Interoperability and Reusability (FAIR)
of data taking into account the developments and decisions of sector-specific authorities;
35
Finnish Health and Social Data Permit Authority (https://www.findata.fi/en/), French Health Data Hub
(https://www.health-data-hub.fr/), German Forschungsdatenzentrum
(https://www.forschungsdatenzentrum.de/en).
36
The idea is not to create a body that develops new standards, but rather to be able to prioritise between existing
and future standards to be developed.
37
See also the FAIR data principles: https://www.force11.org/group/fairgroup/fairprinciples.
38
For instance, the 2017 Tallinn Ministerial Declaration on e-Government calls on governments to “increase the
findability, quality and technical accessibility of data in key base registers.”
12
- facilitate decisions on which data can be used, how and by whom for scientific research
purposes in a manner compliant with the GDPR. This is particularly relevant for publicly-
held databases with sensitive data not covered by the Open Data Directive;
- make it easier for individuals to allow the use of the data they generate for the public
good, if they wish to do so (‘data altruism’), in compliance with the GDPR.
Secondly, the Commission will work on making more high-quality public sector data
available for re-use, in particular in view of its potential for SMEs. In order to open up key
public sector reference data sets for innovation, it shall start the procedure for the adoption of
an Implementing act on high-value data sets (Q1 2021) under the Open Data Directive,
making these data sets available across the EU for free, in machine-readable format and
through standardised Application Programming Interfaces (APIs). The Commission will look
into mechanisms to take into account the particular needs of SMEs. It will also assist the
Member States to ensure a timely and accurate transposition of the new rules of the Open
Data Directive by 17 July 2021.
Third, the Commission will explore the need for legislative action on issues that affect
relations between actors in the data-agile economy to provide incentives for horizontal data
sharing across sectors (complementing data sharing within sectors as described in the
appendix)). One or more of the following issues could be taken forward in a Data Act (2021):
- Foster business-to-government data sharing for the public interest also in the light of the
recommendations included in the report of the Expert Group on Business-to-Government
Data Sharing).
- support business-to-business data sharing, in particular addressing issues related to usage
rights for co-generated data (such as IoT data in industrial settings), typically laid down in
private contracts. The Commission will also seek to identify and address any undue
existing hurdles hindering data sharing and to clarify rules for the responsible use of data
(such as legal liability). The general principle shall be to facilitate voluntary data sharing.
- only where specific circumstances so dictate39, access to data should be made compulsory,
where appropriate under fair, transparent, reasonable, proportionate and/or non-
discriminatory conditions40.
- evaluating the IPR framework with a view to further enhance data access and use
(including a possible revision of the Database Directive41 and a possible clarification of
the application of the Trade Secrets Protection Directive42 as an enabling framework).
39
A data access right should only be sector-specific and only given if a market failure in this sector is
identified/can be foreseen, which competition law cannot solve. The scope of a data access right should take into
account legitimate interests of the data holder and needs to respect the legal framework.
40
Variations of this principle apply in particular with respect to certain motor vehicle repair and maintenance
information to be made accessible under Regulation 715/2007 as well as for information resulting from testing of
chemicals on vertebrate animals under Regulation 1907/2006 (REACH).
41
Directive 96/9/EC.
13
Furthermore, the Commission will assess what measures are necessary to establish data pools
for data analysis and machine learning.
The Commission will provide more guidance to stakeholders on the compliance of data
sharing and pooling arrangements with EU competition law by means of an update of the
Horizontal Co-operation Guidelines43. The Commission is also prepared to provide additional
individual project-related guidance on the compatibility with EU competition rules, if needed.
In the exercise of its merger control powers, the Commission will look closely at the possible
effects on competition of large-scale data accumulation through acquisitions and at the utility
of data-access or data-sharing remedies to resolve any concerns.
In its ongoing review of a number of State Aid guidelines, the Commission will examine the
relationship between public support to undertakings (e.g. for digital transformation) and the
minimisation of competition distortions through data-sharing requirements for beneficiaries.
The review of the current self-regulatory approach for cloud provider switching44 could lead
to further action, depending on the progress made by market players.
The Commission will also consider jurisdictional issues related to data. These issues create
uncertainty for businesses which may face conflicting rules. The EU should not compromise
on its principles: all companies which sell goods or provide services related to the data-agile
economy in the EU must respect EU legislation and this should not be compromised by
jurisdictional claims from outside the EU.
The Commission will consider measures that facilitate the use of data in products and services
and increase demand for data-enabled services. Sectoral reviews should identify regulatory
and non-regulatory obstacles to the use of data and data-enabled offerings. Increased
availability and standardisation of data should also facilitate real-time and cross-border
compliance, leading to reductions in administrative burdens and barriers to the Single Market.
Furthermore, governments can also foster demand through increased use of data-analytics and
automated services in public services and decision making.
The accumulation of vast amounts of data by Big Tech companies, the role of data in creating
or reinforcing imbalances in bargaining power and the way these companies use and share the
data across sectors is being analysed by the Observatory of the Online Platforms Economy.
The issue will not be addressed as part of the Data Act, but under the broader fact-finding
around the high degree of market power of certain platforms and also in the context of the
Commission’s work on the Digital Services Act package. On the basis of this fact-finding, the
Commission will consider how best to address more systemic issues related to platforms and
data, including by ex ante regulation if appropriate, to ensure that markets stay open and fair.
42
Directive (EU) 2016/943.
43
2011/C 11/01.
44
https://swipo.eu/ The approach is based on the Free flow of data regulation, Regulation (EU) 2018/1807.
14
Leading by example
The Commission will strive for excellence in the way it organises its own data, uses the data
for better policy making, and makes the data it produces and funds available to others,
including through the EU Open Data Portal45.
The EU will continue to make data resulting from its research and deployment programmes
available in line with the principle ‘as open as possible, as closed as necessary’, and will
continue to facilitate discovery, sharing of, access to and reuse of data and services by
researchers through the European Open Science Cloud (EOSC)46.
The EU will also contribute data and infrastructure from the Copernicus earth observation
programme to underpinning the European data spaces where relevant. At the same time,
enhancing the Copernicus ecosystem through the application of European digital
technological solutions will offer new innovation opportunities to the data spaces
constituency, both public and private.
The EU will seek to make increased use of data and data analytics in its internal processes and
as an input to Commission decision-making and reviews of existing policy
Key actions
- Propose a legislative framework for the governance of common European data spaces, Q4
2020
- Adopt an implementing act on high-value data-sets, Q1 2021
- Propose, as appropriate, a Data Act, 2021
- Analysis of the importance of data in the digital economy (e.g. through the Observatory of
the Online Platform Economy), and review of the existing policy framework in the context
of the Digital Services Act package (Q4 2020).
B. Enablers: Investments in data and strengthening Europe’s capabilities and
infrastructures for hosting, processing and using data, interoperability
Europe’s data strategy relies on a thriving ecosystem of private actors to create economic and
societal value from data. Start-ups and scale-ups will play a key role in developing and
growing disruptive new business models that fully take advantage of the data revolution.
Europe should offer an environment that supports data-driven innovation and stimulates
demand for products and services that rely on data as an important factor of production.
45
https://data.europa.eu/euodp/en/data/.
46
https://ec.europa.eu/research/openscience/index.cfm?pg=open-science-cloud. See also COM (2016) 178 final
and SWD(2018)83.
15
Making rapid progress on data-driven innovation in strategic areas requires investments, both
from the private and public sectors. The Commission will use its convening power as well as
EU funding programmes to strengthen Europe’s technological sovereignty for the data-agile
economy. This will be done through standard setting, tool development, best practices
collection on how to deal with personal data (especially around pseudonymization) as well as
build-out of next-generation infrastructures for data processing. Where relevant, the
investments will be co-ordinated with relevant authorities in Member States and paired, in
line with state aid rules, with national and regional funding and with investments through the
structural and investment funds.
In the period 2021-2027, the Commission will invest in a High Impact Project on
European data spaces and federated cloud infrastructures..
The project will fund infrastructures, data-sharing tools, architectures and governance
mechanisms for thriving data-sharing and Artificial Intelligence ecosystems. It will be based
on the European federation (i.e. interconnection) of energy-efficient and trustworthy edge and
cloud infrastructures (Infrastructure-as-a-Service, Platform-as-a-Service and Software-as-a-
Service services). It will address the specific needs of industries in the EU, including hybrid
cloud deployment models that allow data processing at the edge with no latency (cloud-to-
edge). This project will involve and benefit the European ecosystem of data-intensive
companies, and will support European companies and the public sector in their digital
transformation.
For this project to be credible as a pan-European initiative, it needs an adequate level of
investment. The Member States and industry are expected to co-invest with the Commission
in the project, which could arrive at a total funding in the order of €4-6 billion, of which the
Commission could aim at financing €2 billion, drawing upon different spending programmes,
subject to an agreement on the next Multiannual Financial Framework.
This Project needs to be seen in the context of a wider set of strategic EU investments in
new technologies that the Commission will present in March 2020 as part of its industrial
strategy. They concern in particular funding for edge computing, high-performance
computing/quantum computing, cyber-security, low-power processors and 6G networks.
These investments are essential for the EU’s data infrastructure of the future, to equip Europe
with the right infrastructures, computing power, encryption capacity and cybersecurity tools
to process data.
High Impact Project: developing common European data spaces and interconnecting cloud
infrastructures
Concretely, the Commission intends to fund the establishment of EU-wide common,
interoperable data spaces in strategic sectors. Such spaces aim at overcoming legal and
technical barriers to data sharing across organisations, by combining the necessary tools and
infrastructures and addressing issues of trust, for example by way of common rules developed
16
for the space. The spaces will include: (i) the deployment of data-sharing tools and platforms;
(ii) the creation of data governance frameworks; (iii) improving the availability, quality and
interoperability of data – both in domain-specific settings and across sectors. Funding will
also support authorities in the Member States in making high value data sets available for re-
use in the different common data spaces.
The support for data spaces will also cover data processing and computing capacities that
comply with essential requirements in terms of environmental performance, security, data
protection, interoperability and scalability.
With focus on the areas where EU level support has clear added value, investments may also
cover the interconnection of existing computing capacities at national47 and European level,
including High Performace Computing capacities48, and will -where needed- bring together
the capacity of data processing resources. The aim is to help common data and world class
cloud infrastructures for the public good to emerge, enabling secure data storage and
processing for the public sector and research institutions. Similar positive effects are expected
from the interconnection with the European Open Science Cloud (EOSC) and the Data and
Information Access Services (DIAS) cloud-based platform that provides access to services
based on the Copernicus earth observation data.
The private sector, including notably SMEs, also needs data and cloud infrastructures and
services that provide the essential features of security, sustainability, interoperability and
scalability. This is essential for European businesses to benefit from a complete value chain of
data generation, processing, access and re-use49. The investment track will bring together
private actors with public support to develop common platforms offering access to a large
diversity of cloud services for secure data storage and sharing as well as applications ranging
from artificial intelligence to simulation, modelling, digital twins and high performance
computing (HPC) resources. The platform will cover all the layers of data and computing
infrastructure and services and will seize the opportunities offered by latest developments
such as edge computing, the deployment of 5G and the uptake of Internet of Things across
industrial sectors. It will also help develop a dynamic ecosystem for a data- and cloud-based
supply industry in Europe across the value chain.
The cloud federation component of the High Impact Project will foster the gradual
rebalancing between centralised data infrastructure in the cloud and highly distributed and
smart data processing at the edge. Such a project should therefore interconnect emerging edge
computing capacities from the start. Over time, the project should furthermore enable access
to top-end high-performance computers and its integration with mainstream data processing
47
Such as the French “Cloud de Confiance” initiative or the Polish Common State IT Infrastructure Programme
(WIIP)
48
Notably the capacities supported under the EuroHPC initiative.
49
For example as expressed by the industry support to the German Gaia-X project.
17
services. This will provide a seamless computing continuum to maximize the growth and
exploitation of common European data spaces for public, industrial and scientific
applications.
In this context, the Commission will foster synergies between the work on European cloud
federation and Member States’ initiatives such as Gaia-X50. This is necessary to avoid
multiplication of fragmented cloud federation and data-sharing initiatives, as the success of
such an initiative would depend on pan-European participation and capacity to scale. For this
reason, the Commission will facilitate Memoranda of Understanding with Member States
by Q3 2020, starting with those having existing cloud federation and data-sharing initiatives.
Enabling access to competitive, secure and fair European cloud services
In order to protect the rights and interests of EU companies and citizens, the Commission,
with the support of the relevant authorities of the Member States, will pay particular attention
to the adherence of cloud service providers operating on the EU market to EU rules (e.g.
General Data Protection Regulation, Free Flow of non-personal Data Regulation and the
Cybersecurity Act) and, where relevant, their envisaged implementation through self- and co-
regulatory mechanisms and technological means to increase trust, such as security by design
and automated compliance. Currently, no comprehensive overview of these EU rules and self-
/co-regulatory schemes is available for cloud providers and users. In this context, the
Commission will bring together by Q2 2022 a coherent framework around the different
applicable rules (including self-regulation) for cloud services, in the form of a ‘cloud
rulebook’. In a first instance, the cloud rulebook will offer a compendium of existing cloud
codes of conduct and certification on security, energy efficiency, quality of service, data
protection and data portability. In the area of energy efficiency earlier action will be
considered.
In coherence with the cloud rulebook, the Commission will facilitate the development of
common European standards and requirements for the public procurement of data
processing services. This will enable the EU’s public sector at European, national, regional
and local level to also become a driver of new EU data processing capacities, rather than just
a beneficiary of such European infrastructures51.
To fully leverage this potential, additional work should be done to connect demand-side
organisations in the private and public sector to the new and innovative offering of tailored
data processing services, specifically at Platform-as-a-Service and Software-as-a-Service
50
An initiative to stimulate cloud federation from the German perspective, presented by the German government
on 29 October 2019. The purpose of the project is to cater for European standards and reference architectures to
create EU-based ‘virtual hyperscale providers’.
51
Examples of similar public procurement programmes in this area can be drawn from third countries, e.g. the
American ‘FedRAMP’ government procurement program. It provides a standardised approach to security
assessment, authorisation, and continuous monitoring for cloud products and services across federal agencies.
18
levels. The set-up of a cloud services marketplace for EU users from the private and public
sector will be facilitated by the Commission by Q4 2022. The marketplace will put potential
users (in particular the public sector and SMEs) in the position to select cloud processing,
software and platform service offerings that comply with a number of requirements in areas
like data protection, security, data portability, energy efficiency and market practice.
Participation in the marketplace for service providers will be made conditional on the use of
transparent and fair contract conditions, which the current market does not always provide,
specifically to micro-enterprises and SME users52. The marketplace can facilitate public
sector procurement of alternative solutions, and take-up by the public sector can support the
marketplace due to its significant aggregate demand.
While a number of Member States are already developing similar marketplace initiatives at
national level, the advantage of an EU-level cloud services marketplace is two-fold: first, it
can resolve the current problem of market asymmetry between hyperscale global actors that
often offer integrated solutions containing applications also provided by smaller (EU) players.
Second, it can generate clarity about the compliance of cloud services with relevant rules.
This will ensure a better match between the EU offer and demand stemming notably from
public administrations, services of general public interest and SMEs.
Support progress on data technologies
The Horizon Europe programme will continue to support technologies that are crucial for the
next stages of the data economy, such as privacy preserving technologies and technologies
underpinning industrial and personal data spaces. Several Horizon Europe candidate
partnerships, such as the partnership for Artificial intelligence, data and robotics and the
European Open Science Cloud partnership, that are in preparation can help steer the
investments in this area.
Key actions
- Invest in a High Impact project on European data spaces, encompassing data sharing
architectures (including standards for data sharing, best practices, tools) and governance
mechanisms, as well as the European federation of energy-efficient and trustworthy cloud
infrastructures and related services, with a view to facilitating combined investments of €4-6
billion, of which the Commission could aim at investing €2 billion. First implementation
phase foreseen for 2022;
- Sign Memoranda of Understanding with Member States on cloud federation, Q3 2020;
52
See: ‘Study on the economic detriment to SMEs arising from unfair and unbalanced cloud computing
contracts’, https://ec.europa.eu/info/sites/info/files/dg_just_cloud_computing_final_report_web_final.pdf.
19
- Launch a European cloud services marketplace, integrating the full stack of cloud service
offering, Q4 2022;
- Create an EU (self-)regulatory cloud rulebook, Q2 2022.
C. Competences: Empowering individuals, investing in skills and in SMEs
Empowering individuals with respect to their data
Individuals should be further supported in enforcing their rights with regard to the use of the
data they generate. They can be empowered to be in control of their data through tools and
means to decide at a granular level about what is done with their data (‘personal data spaces’).
This could be supported by enhancing the portability right for individuals under Article 20 of
the GDPR, giving them more control over who can access and use machine-generated data,
for example through stricter requirements on interfaces for real-time data access and making
machine-readable formats compulsory for data from certain products and services, e.g. data
coming from smart home appliances or wearables. In addition, rules for providers of personal
data apps or novel data intermediaries such as providers of personal data spaces could be
considered, guaranteeing their role as a neutral broker53. These issues can be further explored
in the context of the Data Act mentioned above. The Digital Europe programme will also
support the development and roll-out of ‘personal data spaces’.
Investments in skills and general data literacy
The funding dedicated to skills under the Digital Europe programme will contribute to
narrowing the gap in terms of big data and analytics capacities. The programme will make
funding available to expand the digital talent pool with in the order of 250 000 people who
will be able to deploy the latest technologies in businesses throughout the EU. Given the
importance of data in the digital economy, many of these are likely to be related to data.
Overall, by 2025, the EU and the Member States should have halved the current gap of
1 million digital specialists, including by putting a focus on increasing the participation of
women.
The idea of a network of data stewards from across data-intensive organisations (both
businesses and the public sector), put forward by the expert group on Business-to-
Government data sharing, will be further explored.
In terms of general data literacy, the Reinforced Skills agenda will set out a pathway showing
how EU and Member State action can increase the proportion of the EU population with basic
digital skills, from the current 57% to 65% by 2025.
53
Secure and universally usable digital identities are also crucial to enabling individuals’ access to and control
over their data.
20
Big data and learning analytics offer new opportunities to capture, analyse and use data to
improve education and training. The updated Digital Education Action Plan will reinforce
better access to and use of data as one of its key priorities, in order to make education and
training institutions fit for the digital age and equip them with the capabilities needed for
making better decisions and improving skills and competences.
Dedicated capacity building for SMEs
The forthcoming European SME strategy will define measures to build capacity for SMEs and
start-ups. Data is an important asset in this context, since starting or scaling a company based
on data is not very capital intensive. SMEs and start-ups often require legal and regulatory
advice to fully capture the many opportunities ahead from data-based business models.
The Horizon Europe and Digital Europe programmes as well as the structural and investment
funds will create opportunities for SMEs in the data economy, to have better access to data
and to develop new services and applications based on data, inter alia through incubation
schemes.
Key action
- Explore enhancing the portability right for individuals under Article 20 of the GDPR
giving them more control over who can access and use machine-generated data (possibly
as part of the Data Act in 2021).
D. Common European data spaces in strategic sectors and domains of public interest
In complement to the horizontal framework, as well as to the funding and the actions on skills
and empowerment of individuals under A, B and C54, the Commission will promote the
development of common European data spaces in strategic economic sectors and domains of
public interest. These sectors or domains are those where the use of data will have systemic
impact on the entire ecosystem, but also on citizens.
This should lead to the availability of large pools of data in these sectors and domains,
combined with the technical tools and infrastructures necessary to use and exchange data, as
well as appropriate governance mechanisms. While not having a one-size-fits-all approach,
common governance concepts and models can be replicated in the different sectors.
The horizontal framework will – where appropriate – be complemented by sectoral legislation
for data access and use, and mechanisms for ensuring interoperability. Differences between
the sectors will depend on the maturity of the discussions on and problems identified with
data availability in the sector. A further relevant factor is the degree of public interest and
involvement in a given sector, which may be higher in areas such as health and lower in areas
such as manufacturing. The potential cross-sector use of data between sectors also needs to be
54
The list of sectoral data spaces is not exhaustive and can be extended.
21
taken into account. The data spaces will be developed in full compliance with data protection
rules and according to the highest available cyber-security standards.
Data spaces need to be complemented by policies that stimulate the use of data and demand
for services enriched with data. Work on sectoral data spaces will be complemented by
sectoral measures across the data value chain.
Building on the ongoing experience with the research community with the European Open
Science Cloud, the Commission will also support the establishment of the following nine
common European data spaces:
A Common European industrial (manufacturing) data space, to support the
competitiveness and performance of the EU’s industry, allowing to capture the
potential value of use of non-personal data in manufacturing (estimated at € 1,5 trillion
by 2027).
A Common European Green Deal data space, to use the major potential of data in
support of the Green Deal priority actions on climate change, circular economy, zero-
pollution, biodiversity, deforestation and compliance assurance. The “GreenData4All”
and ‘Destination Earth’ (digital twin of the Earth) initiatives will cover concrete
actions.
A Common European mobility data space, to position Europe at the forefront of the
development of an intelligent transport system, including connected cars as well as
other modes of transport. Such data space will facilitate access, pooling and sharing of
data from existing and future transport and mobility databases.
A Common European health data space, which is essential for advances in
preventing, detecting and curing diseases as well as for informed, evidence-based
decisions to improve the accessibility, effectiveness and sustainability of the
healthcare systems.
A Common European financial data space, to stimulate, through enhanced data
sharing, innovation, market transparency, sustainable finance, as well as access to
finance for European businesses and a more integrated market.
A Common European energy data space, to promote a stronger availability and
cross-sector sharing of data, in a customer-centric, secure and trustworthy manner, as
this would facilitate innovative solutions and support the decarbonisation of the energy
system.
A Common European agriculture data space, to enhance the sustainability
performance and competitiveness of the agricultural sector through the processing and
analysis of production and other data, allowing for precise and tailored application of
production approaches at farm level.
Common European data spaces for public administration, to improve transparency
and accountability of public spending and spending quality, fighting corruption, both
22
at EU and national level, and to address law enforcement needs and support the
effective application of EU law and enable innovative ‘gov tech’, ‘reg tech’ and ‘legal
tech’ applications supporting practitioners as well as other services of public interest
A Common European skills data space, to reduce the skills mismatches between the
education and training system on the one hand and the labour market needs on the
other.
The annex presents in more detail each of the sector- and domain-specific common European
data spaces, with background on the sector-specific policies and legislation underpinning the
creation of such spaces in the different sectors and domains, and proposing sector-specific
actions that are tangible, sizable, focused on data, and accompanied by a clear and realistic
timeline.
The Commission may consider launching, in a sequential way, additional common European
data spaces in other sectors.
6. An open, but proactive international approach
The vision of a common European data space implies an open, but assertive approach to
international data flows, based on European values. Today’s European companies operate in a
connected environment that goes beyond the EU’s borders, so that international data flows are
indispensable for their competitiveness. Building upon the strength of the Single Market’s
regulatory environment, the EU has a strong interest in leading and supporting international
cooperation with regard to data, shaping global standards and creating an environment in
which economic and technological development can thrive, in full compliance with EU law.
At the same time, European companies operating in some third countries are increasingly
faced with unjustified barriers and digital restrictions. The EU will continue to address these
unjustified obstacles to data flows in bilateral discussions and international fora – including
the World Trade Organisation – while promoting and protecting European data processing
rules and standards, in full compliance with EU legislation. The Commission will be
particularly vigilant to protect and assert the rights, obligations and interests of Europeans and
companies, in particular as regards data protection, security and fair and trustworthy market
practices. The Commission is convinced that international cooperation must be based on an
approach that promotes the EU’s fundamental values, including protection of privacy. The EU
must ensure, therefore, that any access to EU citizen’s personal data and European
commercially sensitive data is in compliance with its values and legislative framework. In that
context, transfers and sharing of data between trusted countries should be promoted. As
regards personal data, international transfers are done via adequacy decisions and other
existing transfer tools which guarantee that the protection travels with the data no matter
where the data is. Additionally, and without prejudice to the EU’s framework for the
protection of personal data, free and safe flow of data should be ensured with third countries,
23
subject to exceptions and restrictions for public security, public order and other legitimate
public policy objectives of the European Union, in line with international obligations. This
would allow the EU to have an open but assertive international data approach based on its
values and strategic interests.
The Commission will continue to improve its capacity to analyse the EU’s strategic interest
with regard to further facilitating international data flows. To this end, the Commission will
create a European analytical framework for measuring data flows (Q4 2021). This should
be a durable framework that provides the tools to conduct a continuous analysis of data flows
and the economic development of the EU’s data processing sector, including a robust
methodology, economic valuation and data flows collection mechanisms. It will serve to
better understand patterns of data flows and centres of gravity, both within the EU and
between the EU and the rest of the world, and can be a basis for adequate policy responses by
the Commission, if necessary. It should also help to drive adequate investments to overcome
possible infrastructure gaps preventing data flows. The Commission will therefore seek in due
course cooperation with relevant financial and international organisations on the data flow
measurement framework (e.g. EIB, EBRD, OECD, IMF).
The EU should take advantage of its effective data regulatory and policy framework to attract
the storage and processing of data from other countries and regions, and to increase the high-
value-added innovation that arises from these data spaces. Companies from around the world
will be welcome to avail of the European data space, subject to compliance with applicable
standards, including those developed relative to data sharing. The The Connecting Europe
Facility (CEF 2) programme as well as t the new external instruments, the Neighbourhood,
Development and International Cooperation Instrument and the Instrument for Pre-accession
Assistance, will support the connectivity of third countries with Europe, which will in turn
increase the attractivness of data interchange between the EU and the relevant partner
countries.
In parallel, the EU will also actively promote its standards and its values with its partners
around the world55. It will work in multilateral fora to fight abuses such as the
disproportionate access of governments to data, for example access to personal data that is not
in line with the EU’s data protection rules. In order to promote the European model around
the world, the EU will work with trusted partners sharing the same standards and values, to
support others who wish to give their citizens greater control over their data, in line with
values they share with Europe. For instance, the EU will support Africa in creating an African
data economy for the benefit of its citizens and businesses.
55
Following examples such as the adoption of rules modelled on the GDPR by Brazil and Kenya.
24
Key action
Create a framework to measure data flows and estimate their economic value within Europe,
as well as between Europe and the rest of the world, Q4 2021.
7. Conclusion
This Communication puts forward a European data strategy whose ambition is to enable the
EU to become the most attractive, most secure and most dynamic data-agile economy in the
world – empowering Europe with data to improve decisions and better the lives of all of its
citizens. It enumerates a number of policy measures and investments needed to achieve this
goal.
The stakes are high, since the EU’s technological future depends on whether it manages to
harness its strengths and seize the opportunities offered by the ever-increasing production and
use of data. A European way for handling data will ensure that more data becomes available
for addressing societal challenges and for use in the economy, while respecting and promoting
our European shared values.
In order to secure its digital future, the EU has to seize its window of opportunity in the data
economy.
25
APPENDIX to the Communication ‘A European strategy for data’
Common European data spaces in in strategic sectors and domains of public interest
The Communication ‘A European strategy for data’ announces the creation of sector- and
domain-specific data spaces.
This document gives additional background on the sector-specific policies and legislation
underpinning the creation of such spaces in the different sectors and domains.
1. Common European industrial (manufacturing) data space
Europe has a strong industrial base, and manufacturing in particular is an area where the
generation of and use of data can make a significant difference to the performance and
competitiveness of European industry. A 2018 study estimated the potential value of use of
non-personal data in manufacturing at € 1,5 trillion by 202756.
In order to unleash this potential, the Commission will:
Address issues related to the usage rights on co-generated industrial data (IoT data
created in industrial settings), as part of a wider Data Act (Q4 2021).
Gather key players from the manufacturing sector to agree – in a manner compliant with
competition rules as well as principles of fair contracts – the conditions under which they
would be ready to share their data and how to further boost data generation, notably via
smart connected products (Q2 2020 onwards). Where data generated by individuals are
concerned, their interests should be fully taken into account in such a process and
compliance with data protection rules must be ensured.
2. Common European Green Deal data space
Europe’s Green Deal has set out the ambitious goal for Europe to become the world's first
climate-neutral continent by 2050. The Commission’s Communication clearly underlines the
importance of data for achieving this goal. A European green data space can exploit the major
potential of data in support of the Green Deal priority actions on climate change, circular
economy, zero-pollution, biodiversity, deforestation and compliance assurance.
In this context the Commission will:
Initiate a ‘GreenData4All’ initiative. This consists in evaluating and possibly reviewing
the Directive establishing an Infrastructure for Spatial Information in the EU (INSPIRE),
together with the Access to Environment Information Directive (Q4 2021 or Q1 2022). It
will modernise the regime in line with technological and innovation opportunities,
making it easier for EU public authorities, businesses and citizens to support the
transition to a greener and carbon-neutral economy, and reducing administrative burden.
56
Deloitte 2018.
26
Roll out re-usable data-services on a large scale to assist in collecting, sharing, processing
and analysing large volumes of data relevant for assuring compliance with environmental
legislation and rules related to the priority actions set in the Green Deal.(Q4 2021)
Establish a common European data space for smart circular applications making available
the most relevant data for enabling circular value creation along supply chains. A
particular focus will be concentrated at the outset on the sectors targeted by the Circular
Economy Action Plan, such as the built environment, packaging, textiles, electronics,
ICT and plastics. Digital ‘product passports’ will be developed, that will provide
information on a product’s origin, durability, composition, reuse, repair and dismantling
possibilities, and end-of-life handling. Development of architecture and governance
(2020), sectoral data strategies (2021), adoption of a sustainable product policy with
product passport (2021) and resource mapping and waste shipments tracking (2021).
Initiate a pilot for early implementation of the data strategy in the context of the ‘zero
pollution ambition’ to harvest the potential of an already data-rich policy domain with
data on chemicals, air, water and soil emission, hazardous substances in consumer
products, etc. which is underexploited and where early results can benefit consumers and
the Planet directly (Q4 2021).
Launch the ‘Destination Earth’ initiative
The ‘Destination Earth’ initiative will bring together European scientific and industrial
excellence to develop a very high precision digital model of the Earth. This ground-
breaking initiative will offer a digital modelling platform to visualize, monitor and
forecast natural and human activity on the planet in support of sustainable development
thus supporting Europe’s efforts for a better environment as set out in the Green Deal.
The digital twin of the Earth will be constructed progressively, starting in 2021.
3. Common European mobility data space
Transport and mobility are at the forefront of the debate on data sharing, an area where the
EU has many assets. This concerns the automotive sector, where connected cars critically
depend on data, as well as other transport modes. Digitisation and data in all modes of
transport and in logistics will be an essential component of further work on the ‘European
Transport System’ and in particular in the upcoming ‘Smart and Sustainable Transport
Strategy’ (Q4 2020). This will include actions in all transport sectors as well as for cross-
modal data sharing logistics and passengers ecosystems.
Automotive
Today, modern vehicles generate around 25 gigabytes of data every hour and autonomous
cars will generate terabytes of data that can be used for innovative mobility-related services
and for repair and maintenance services. Innovation in this area requires that car data are
shared, in a secure and well-framed way, in line with competition rules amongst many
different economic players. The access to in-vehicle data is regulated since 2007 in the EU
27
vehicle approval legislation57 to ensure fair access to certain car data by independent repairers.
This legislation is now being updated to take into account the increasing use of connectivity
(3G-4G, so-called remote diagnostics)58, that the rights and interests of the car-owners
generating the data are respected and compliance with data protection rules is ensured.
The full transport system
Passenger transport activity is projected to grow by 35% during 2015-2050. Freight traffic for
inland modes is expected to grow faster than for passenger at 53% by 205059. Digitalisation
and data play an increasing role in supporting transport sustainability. Several legislative
frameworks already contain data-sharing obligations, which establishes a list of datasets
(including datasets concerning public transport). Moreover, the Digital Transport and
Logistics Forum is working on a concept of ‘federated platforms’ to define what needs to be
done at the EU level to facilitate data-sharing/re-use by connecting different public and
private platforms. Furthermore, networks of national access points to make data available
exist in the Member States where the data are made available with a view to serving road
safety, traffic and multi-modal travel information services, with data generated by the public
and the private sector. Wide availability and use of data in public transport systems has the
potential to make them more efficient, green and customer friendly. Data use to improve
transport systems is also a central feature of smart cities.
The Commission will:
Review the current EU type approval legislation for motor vehicles (currently focused on
wireless data sharing for repair and maintenance), to open it up to more car data based
services (Q1 2021). The review will inter alia look at how data is made accessible by the
car manufacturer, what procedures are necessary to obtain it in full compliance with data
protection rules and the role and rights of the car owner.
Review the Directive on harmonised river information services60 and the Directive on
Intelligent Transport Systems61, including its delegated regulations to further contribute to
data availability, reuse and interoperability (both in 2021) and establish a stronger
coordination mechanism to federate the National Access Points established under the ITS
Directive through a EU wide CEF Programme Support Action (2020).
Amend the proposal for a Regulation on the Single European Sky62 to include new
provisions on data availability and market access of data service providers in order to
promote the digitalisation and automation of air traffic management (2020). This will
improve safety, efficiency and capacity in air traffic.
57
Regulation (EC) 715/2007.
58
As required by Article 61 of Regulation (EU) 2018/858.
59
In-depth analysis in support of Commission Communication COM(2018) 773 ‘A Clean Planet for all: A
European long-term strategic vision for a prosperous, modern, competitive and climate neutral economy’.
60
Directive 2005/44/EC.
61
Directive 2010/40/EU.
62
COM(2013) 410 final.
28
Review the regulatory framework for interoperable data-sharing in rail transport in 2022.
Establish common data sets as foreseen in the Regulation on Maritime Single Window63
and, subject to its final adoption, in the Regulation on electronic freight transport
information regulations64 (the first such act to be adopted by Q3 2021 and Q4 2022
respectively) to facilitate digital exchange and data reuse between businesses and
administration.
4. Common European health data space
The current regulatory and research models rely on access to health data, including individual
level data from patients. Strengthening and extending the use and re-use of health data is
critical for innovation in the healthcare sector. It also helps healthcare authorities to take
evidence-based decisions to improve the accessibility, effectiveness and sustainability of the
healthcare systems. It also contributes to the competitiveness of the EU’s industry. Better
access to health data can significantly support the work of regulatory bodies in the healthcare
system, the assessment of medical products and demonstration of their safety and efficacy.
Citizens have the right in particular to access and control their personal health data and to
request their portability, but implementation of this right is fragmented. Working towards
making sure that every citizen has secure access to their Electronic Health Record (EHR) and
can ensure the portability of his/her data – within and across borders – will improve access to
and quality of care, cost effectiveness of care delivery and contribute to the modernisation of
health systems.
Citizens also need to be reassured that, once they have given consent for their data to be
shared, the healthcare systems uses such data in an ethical manner and ensure that the given
consent can be withdrawn at any time.
Health is an area where the EU can benefit from the data revolution, increasing the quality of
healthcare, while decreasing costs. Progress will often depend on the willingness of Member
States and healthcare providers to join forces and find ways to use and combine data, in a
manner compliant with the GDPR, under which health data merit specific protection. While
the GDPR has created a level playing field for the use of health personal data, fragmentation
remains within and between Member States and the governance models for accessing data are
diverse. The landscape of digital health services remains fragmented, especially when
provided cross-border.
The Commission will:
Develop sector-specific legislative or non-legislative measures for the European health
data space, complementing the horizontal framework of the common data space. Take
measures to strengthen citizens’ access to health data and portability of these data and
63
Regulation (EU) 2019/1239.
64
The negotiations with the co-legislators are concluded, adoption is foreseen mid-2020.
29
tackle barriers to cross-border provision of digital health services and products. Facilitate
the establishment, in accordance with Article 40 of the GDPR, of a Code of Conduct for
processing of personal data in health sector. These actions will build upon an ongoing
mapping of the use of personal health data in Member States and the results of the Joint
Action in the context of the Health programme (2020-2023)65.
Deploy the data infrastructures, tools and computing capacity for the European health
data space, more specifically support the development of national electronic health
records (EHRs) and interoperability of health data through the application of the
Electronic Health Record Exchange Format. Scale up cross-border exchange of health
data; link and use, through secure, federated repositories, specific kinds of health
information, such as EHRs, genomic information (for at least 10 million people by 2025),
and digital health images, in compliance with the GDPR. Enable the exchange of
electronic patient summaries and ePrescriptions between 22 Member States participating
in the eHealth Digital Service Infrastructure (eHDSI) by 2022; start cross-border
electronic exchanges through eHDSI of medical images, laboratory results and discharge
reports and enhance the virtual consultation model and registries of European Reference
Networks; support big data projects promoted by the network of regulators. These actions
will support prevention, diagnosis and treatment (in particular for cancer, rare diseases
and common and complex diseases), research and innovation, policy-making and
regulatory activities of Member States in the area of public health.
5. Common European financial data space
In the financial sector, EU legislation requires financial institutions to disclose a significant
amount of data products, transactions and financial results. Moreover, the revised Payment
Services Directive marks an important step towards open banking, where innovative payment
services can be offered to consumers and businesses on the basis of the access to their bank
account data. Going forward, enhancing data sharing would contribute to stimulating
innovation as well as achieving other important policy objectives at EU level.
The Commission will set out concrete initiatives on this in its upcoming Digital Finance
Strategy in Q3 2020 along the following considerations:
The Commission will further facilitate access to public disclosures of financial data or
supervisory reporting data, currently mandated by law, for example by promoting the use
of common pro-competitive technical standards. This would facilitate more efficient
processing of such publicly accessible data to the benefit of a number of other policies of
public interest, such as enhancing access to finance for European businesses through more
integrated capital markets, improving market transparency and supporting sustainable
finance in the EU.
65
https://ec.europa.eu/health/funding/programme_en.
30
On the basis of recent market developments on open finance, the Commission will
continue to ensure full implementation of the revised Payment Services Directive and
explore additional steps and initiatives building on this approach.
6. Common European energy data space
In the energy sector, several Directives establish customer access to and portability of their
meter and energy consumption data on a transparent, non-discriminatory basis and in
compliance with data protection law. The specific governance frameworks are to be defined at
the national level. Legislation also introduced data-sharing obligations for electricity network
operators. Regarding cybersecurity, work is ongoing to address energy-specific challenges,
notably: real-time requirements, cascading effects and the mix of legacy technologies with
smart/state-of-the-art technology .
The availability and cross-sector sharing of data, in a secure and trustworthy manner can
facilitate innovative solutions and support the decarbonisation of the energy system. The
Commission will address these issues as part of the smart sector integration strategy to be
adopted in the second quarter of this year as announced in the Communication on the
European Green Deal.
The Commission will:
Adopt implementing act(s)66 setting out the interoperability requirements and non-
discriminatory and transparent procedures for access to data, building on existing national
practices on the basis of the Electricity Directive 2019/944 (2021/2022).
Consider actions for improving the interoperability in smart buildings and products, with a
view to improve their energy efficiency, optimise local consumption and broaden the
integration of renewable energy sources (Q4 2020).
7. Common European agricultural data space
Data is one key element to enhance the sustainability performance and competitiveness of the
agricultural sector. Processing and analysing production data, especially in combination with
other data on the supply chain and other types of data, such as earth observation or
meteorological data, allows for precise and tailored application of production approaches at
farm level. A code of conduct for sharing of agricultural data by contractual agreement was
developed in 2018 by EU stakeholders, involving – among others – the farming as well as the
machinery sector.
A common data space for agricultural data based on existing approaches towards data sharing
could lead to a neutral platform for sharing and pooling agricultural data, including both
private and public data. This could support the emergence of an innovative data-driven
ecosystem based on fair contractual relations as well as strengthen the capacities for
monitoring and implementing common policies and reducing administrative burden for
66
Article 24 Directive (EU) 2019/944.
31
government and beneficiaries. In 2019, Member States have joined forces and signed a
declaration of cooperation ‘A smart and sustainable digital future for European agriculture
and rural areas’67, which recognises the potential of digital technologies for the agricultural
sector and rural areas and supports the setting up of data spaces.
The Commission will:
Take stock with Member States and stakeholder organisations of experiences gained with
the stakeholder code of conduct on agricultural data sharing by contractual agreement,
also on the basis of the current market for digital farm solutions and their requirements in
terms of data availability and use (Q3/Q4 2020).
Take stock of agricultural data spaces in current use, including funded under the Horizon
2020 programme, with stakeholders and Member State organisations and take decision on
an EU approach (Q4 2020/Q1 2021).
8. Common European data spaces for public administrations
Public administrations are big producers and also users of data in different areas. The data
spaces for public administrations will reflect this. Actions in this areas will focus on law and
public procurement data and other areas of public interest such as data use for improving law
enforcement in the EU in line with EU law, including the principle of proportionality and data
protection rules.
Public procurement data are essential to improve transparency and accountability of public
spending, fighting corruption and improving spending quality. Public procurement data is
spread over several systems in the Member States, made available in different formats and is
not easily possible to use for policy purposes in real-time. In many cases, the data quality
needs to be improved.
Similarly, seamless access to and easy reuse of EU and Member State legislation,
jurisprudence as well as information on e-justice services is critical not only for the effective
application of EU law but also enables innovative ‘legal tech’ applications supporting
practitioners (judges, public officials, corporate counsel and lawyers in private practice).
The Commission will:
Elaborate a data initiative for public procurement data covering both the EU dimension
(EU datasets, such as TED68) and the national ones (Q4 2020). It will be complemented
by a procurement data governance framework (Q2 2021);
Issue guidance on common standards as well as interoperable frameworks for legal
information69 held at European and national level, in close cooperation with Member
States (Q1 2021);
67
The declaration has been signed by 25 Member States. For further information on the declaration, see
https://ec.europa.eu/digital-single-market/en/news/eu-member-states-join-forces-digitalisation-european-
agriculture-and-rural-areas.
68
Tenders Electronic Daily.
32
work with Member States to ensure that data sources related to the implementation of the
EU budget are Findable, Accessible, Interoperable and Reusable (FAIR).
9. Common European skills data space
The skills of its people are Europe’s strongest asset. In a global race for talent, the European
education and training systems and labour markets need to quickly adapt to new and emerging
skills needs. This requires high-quality data on qualifications, learning opportunities, jobs and
the skill sets of people. Over the past years, the Commission has put in place a range of open
standards, reference frameworks and semantic assets to increase data quality and
interoperability70. As announced in the Digital Education Action Plan71, the Commission also
developed the Europass Digital Credentials framework to issue credentials to learners in a
secure and interoperable digital format.
The Commission will:
Support Member States in the development of digital credential transformation plans and
in the preparation of re-usable data-sets of qualifications and learning opportunities
(2020-2022);
Establish a governance model for the on-going management of the Europass Digital
Credentials Framework in close cooperation with Member States and key stakeholders
(by 2022).
10. European Open Science Cloud
In addition to the creation of nine Common European data spaces, work will continue on the
European Open Science Cloud, which provides seamless access and reliable re-use of
research data to European researchers, innovators, companies and citizens through a trusted
and open distributed data environment and related services. The European Open Science
Cloud is therefore the basis for a science, research and innovation data space that will bring
together data resulting from research and deployment programmes and will be connected and
fully articulated with the sectoral data spaces.
The Commission will:
Deploy European Open Science Cloud operations to serve EU researchers by 2025;
Steer the underpinning development of a stakeholder-driven EOSC governance
structures, possibly in connection with the launch of the corresponding EOSC
European partnership by end 2020;
69
E.g. on the use of the ELI and ECLI identifiers and on publishing law online with an official translation in
order to support the further use of machine translation.
70
E.g. Europass Learning Model; European Qualifications Framework for lifelong learning (EQF); European
Skills, Competences, Qualifications and Occupations (ESCO), Digital Competence Framework (DigComp).
71
COM(2018)22 final.
33
In the medium term, open up, connect and articulate EOSC beyond the research
communities, with the wider public sector and the private sector from 2024 onwards.
34
Saatja: Teele Tohver <
[email protected]>
Saadetud: 06.03.2020 17:33
Adressaat: Lembi Tasane <
[email protected]>
Teema: FW: Euroopa Komisjoni digipakett - palume teie arvamust, tähtaeg 13. märts
Manused: Shaping Europe's digital future.pdf; A European Strategy for Data.pdf; On Artificial
Intelligence - A European approach to excellence and trust.pdf
Lembi palun rega ja suuna mulle.
Tänud!
From: Kristina Vaksmaa-Tammaru <
[email protected]>
Sent: Thursday, February 27, 2020 4:17 PM
To: Teele Tohver <
[email protected]>
Subject: FW: Euroopa Komisjoni digipakett - palume teie arvamust, tähtaeg 13. märts
Hei, Teele!
Ma saadan selle pöördumise sinule edasi. Kui see puudutab teisi meie majast, palun saada edasi.
Tervitades
Kristina
From: TTJA <
[email protected]>
Sent: Thursday, February 27, 2020 1:38 PM
To: Kristina Vaksmaa-Tammaru <
[email protected]>
Subject: FW: Euroopa Komisjoni digipakett - palume teie arvamust, tähtaeg 13. märts
Kuhu ja mis sarja registeerime?
From: Kadi Avingo <
[email protected]>
Sent: Thursday, February 27, 2020 1:13 PM
To: TTJA <
[email protected]>
Subject: Euroopa Komisjoni digipakett - palume teie arvamust, tähtaeg 13. märts
Tere!
19. veebruaril avalikustas Euroopa Komisjon digipaketi „Digiajastu nõudmistele vastav Euroopa“, mis
koosneb digistrateegiast, andmestrateegiast ja tehisintellekti valgest raamatust (manuses, märksõnad
sisu kohta all).
MKMi eestvedamisel hakatakse koostama Eesti seisukohti paketi kohta. Selleks palume ka teie arvamust
hiljemalt 13. märtsiks.
1. Digistrateegia „Shaping Europe’s digital future“
üldine ülevaade Euroopa Komisjoni tulevikuplaanidest, sh tulevastest eelnõudest,
tegevuskavadest, strateegiatest, investeeringute fookusest, ELi globaalne roll
digivaldkonnas.
2. Andmestrateegia „A European strategy for data“
eesmärgiks on tekitada Euroopas ühtne andmeruum (a single European data space) ehk
tõeline ühtne turg nii isiku- kui mitteisikuandmete jaoks;
horisontaalne valdkondadeülene haldusraamistik andmete kasutamise ja ligipääsu
tagamiseks (reeglid, standardid), sh kõrgväärtusega andmete kättesaadavuse
parandamine ja võimaliku Data Act’i välja töötamine, mis mh käsitleks ettevõtjate ja
valitsusasutuste (B2G) ning ettevõtjatevahelist (B2B) andmete jagamist;
omavahel ühendatud pilvetaristu loomine, reeglid pilveteenustele Euroopas;
valdkondlikud andmeruumid (töötlev tööstus, Green Deal, transport/liikuvus, tervishoid,
rahandus, energeetika, põllumajandus, avalik haldus (riigihanked, õiguskaitse), oskused,
teadus);
rahvusvaheline suund, andmevood kolmandate riikidega.
3. Tehisintellekti valge raamat „On Artificial Intelligence – A European approach to excellence and
trust“
Ecosystem of excellence: tehisintellekti arengute toetamine, investeeringud, tehnoloogia
testimisvõimalused, VKE-de toetamine, oskused, avaliku ja erasektori partnerluste
loomine;
Ecosystem of trust (tehisintellekti jaoks reguleeriva raamistiku loomine): põhiõigused,
ohutus ja vastutuse küsimused, mh ettepanek liigitada teatud tehisintellekti rakendused
kõrge riskiga rakendusteks, millele oleks vaja kaaluda täiendava EL tasandi regulatsiooni
loomist, rakendustele mis ei ole kõrge riskiga kaalutakse vabatahtlikku märgistamist.
Koos eelpoolmainitud dokumentidega avalikustati ka komisjoni aruanne „Report on the safety and
liability implications of Artificial Intelligence, the Internet of Things and robotics“ ja kõrgetasemelise B2G
Data Sharing ekspertgrupi aruanne (ülevaade ja link raportile kättesaadav siit).
Küsimuste korral palun pöörduge minu poole.
Heade soovidega
Kadi Avingo
EL ja rahvusvahelise koostöö osakonna nõunik
Tel: 625 6491 | Mob: 526 8648
Majandus- ja Kommunikatsiooniministeerium
www.mkm.ee | Suur-Ameerika 1, Tallinn 10122
EUROPEAN
COMMISSION
Brussels, 19.2.2020
COM(2020) 65 final
WHITE PAPER
On Artificial Intelligence - A European approach to excellence and trust
EN EN
White Paper on Artificial Intelligence
A European approach to excellence and trust
Artificial Intelligence is developing fast. It will change our lives by improving healthcare (e.g. making
diagnosis more precise, enabling better prevention of diseases), increasing the efficiency of farming,
contributing to climate change mitigation and adaptation, improving the efficiency of production
systems through predictive maintenance, increasing the security of Europeans, and in many other ways
that we can only begin to imagine. At the same time, Artificial Intelligence (AI) entails a number of
potential risks, such as opaque decision-making, gender-based or other kinds of discrimination,
intrusion in our private lives or being used for criminal purposes.
Against a background of fierce global competition, a solid European approach is needed, building on
the European strategy for AI presented in April 20181. To address the opportunities and challenges of
AI, the EU must act as one and define its own way, based on European values, to promote the
development and deployment of AI.
The Commission is committed to enabling scientific breakthrough, to preserving the EU’s
technological leadership and to ensuring that new technologies are at the service of all Europeans –
improving their lives while respecting their rights.
Commission President Ursula von der Leyen announced in her political Guidelines2 a coordinated
European approach on the human and ethical implications of AI as well as a reflection on the better
use of big data for innovation.
Thus, the Commission supports a regulatory and investment oriented approach with the twin objective
of promoting the uptake of AI and of addressing the risks associated with certain uses of this new
technology. The purpose of this White Paper is to set out policy options on how to achieve these
objectives. It does not address +the development and use of AI for military purposes.The Commission
invites Member States, other European institutions, and all stakeholders, including industry, social
partners, civil society organisations, researchers, the public in general and any interested party, to react
to the options below and to contribute to the Commission’s future decision-making in this domain.
1. INTRODUCTION
As digital technology becomes an ever more central part of every aspect of people’s lives, people
should be able to trust it. Trustworthiness is also a prerequisite for its uptake. This is a chance for
Europe, given its strong attachment to values and the rule of law as well as its proven capacity to build
safe, reliable and sophisticated products and services from aeronautics to energy, automotive and
medical equipment.
Europe’s current and future sustainable economic growth and societal wellbeing increasingly draws on
value created by data. AI is one of the most important applications of the data economy. Today most
data are related to consumers and are stored and processed on central cloud-based infrastructure. By
contrast a large share of tomorrow’s far more abundant data will come from industry, business and the
public sector, and will be stored on a variety of systems, notably on computing devices working at the
edge of the network. This opens up new opportunities for Europe, which has a strong position in
1 AI for Europe, COM/2018/237 final
2 https://ec.europa.eu/commission/sites/beta-political/files/political-guidelines-next-commission_en.pdf.
1
digitised industry and business-to-business applications, but a relatively weak position in consumer
platforms.
Simply put, AI is a collection of technologies that combine data, algorithms and computing power.
Advances in computing and the increasing availability of data are therefore key drivers of the current
upsurge of AI. Europe can combine its technological and industrial strengths with a high-quality
digital infrastructure and a regulatory framework based on its fundamental values to become a global
leader in innovation in the data economy and its applications as set out in the European data
strategy3. On that basis, it can develop an AI ecosystem that brings the benefits of the technology to
the whole of European society and economy:
for citizens to reap new benefits for example improved health care, fewer breakdowns of
household machinery, safer and cleaner transport systems, better public services;
for business development, for example a new generation of products and services in areas
where Europe is particularly strong (machinery, transport, cybersecurity, farming, the green
and circular economy, healthcare and high-value added sectors like fashion and tourism); and
for services of public interest, for example by reducing the costs of providing services
(transport, education, energy and waste management), by improving the sustainability of
products4 and by equipping law enforcement authorities with appropriate tools to ensure the
security of citizens5, with proper safeguards to respect their rights and freedoms.
Given the major impact that AI can have on our society and the need to build trust, it is vital that
European AI is grounded in our values and fundamental rights such as human dignity and privacy
protection.
Furthermore, the impact of AI systems should be considered not only from an individual perspective,
but also from the perspective of society as a whole. The use of AI systems can have a significant role
in achieving the Sustainable Development Goals, and in supporting the democratic process and social
rights. With its recent proposals on the European Green Deal6, Europe is leading the way in tackling
climate and environmental-related challenges. Digital technologies such as AI are a critical enabler for
attaining the goals of the Green Deal. Given the increasing importance of AI, the environmental
impact of AI systems needs to be duly considered throughout their lifecycle and across the entire
supply chain, e.g. as regards resource usage for the training of algorithms and the storage of data.
A common European approach to AI is necessary to reach sufficient scale and avoid the fragmentation
of the single market. The introduction of national initiatives risks to endanger legal certainty, to
weaken citizens’ trust and to prevent the emergence of a dynamic European industry.
This White Paper presents policy options to enable a trustworthy and secure development of AI in
Europe, in full respect of the values and rights of EU citizens. The main building blocks of this White
Paper are:
3 COM(2020) 66 final.
4 AI and digitalisation in general are critical enablers of Europe’s Green deal ambitions. However, the current
environmental
footprint of the ICT sector is estimated at more than 2% of all global emissions. The European digital strategy
accompanying this White Paper proposes green transformation measures for digital.
5 AI tools can provide an opportunity for better protecting EU citizens from crime and acts of terrorism.
Such tools could, for example, help identify online terrorist propaganda, discover suspicious transactions in the sales of
dangerous products, identify dangerous hidden objects or illicit substances or products, offer assistance to citizens in
emergencies and help guide first responders.
6 COM(2019) 640 final.
2
The policy framework setting out measures to align efforts at European, national and regional
level. In partnership between the private and the public sector, the aim of the framework is to
mobilise resources to achieve an ‘ecosystem of excellence’ along the entire value chain,
starting in research and innovation, and to create the right incentives to accelerate the adoption
of solutions based on AI, including by small and medium-sized enterprises (SMEs).
The key elements of a future regulatory framework for AI in Europe that will create a unique
‘ecosystem of trust’. To do so, it must ensure compliance with EU rules, including the rules
protecting fundamental rights and consumers’ rights, in particular for AI systems operated in
the EU that pose a high risk7. Building an ecosystem of trust is a policy objective in itself, and
should give citizens the confidence to take up AI applications and give companies and public
organisations the legal certainty to innovate using AI. The Commission strongly supports a
human-centric approach based on the Communication on Building Trust in Human-Centric
AI8 and will also take into account the input obtained during the piloting phase of the Ethics
Guidelines prepared by the High-Level Expert Group on AI.
The European strategy for data, which accompanies this White Paper, aims to enable Europe to
become the most attractive, secure and dynamic data-agile economy in the world – empowering
Europe with data to improve decisions and better the lives of all its citizens. The strategy sets out a
number of policy measures, including mobilising private and public investments, needed to achieve
this goal. Finally, the implications of AI, Internet of Things and other digital technologies for safety
and liability legislation are analysed in the Commission Report accompanying this White Paper.
2. CAPITALISING ON STRENGTHS IN INDUSTRIAL AND PROFESSIONAL MARKETS
Europe is well placed to benefit from the potential of AI, not only as a user but also as a creator and a
producer of this technology. It has excellent research centres, innovative start-ups, a world-leading
position in robotics and competitive manufacturing and services sectors, from automotive to
healthcare, energy, financial services and agriculture. Europe has developed a strong computing
infrastructure (e.g. high-performance computers), essential to the functioning of AI. Europe also holds
large volumes of public and industrial data, the potential of which is currently under-used. It has well-
recognised industrial strengths in safe and secure digital systems with low-power consumption that are
essential for the further development of AI.
Harnessing the capacity of the EU to invest in next generation technologies and infrastructures, as well
as in digital competences like data literacy, will increase Europe’s technological sovereignty in key
enabling technologies and infrastructures for the data economy. The infrastructures should support the
creation of European data pools enabling trustworthy AI, e.g. AI based on European values and rules.
Europe should leverage its strengths to expand its position in the ecosystems and along the value chain,
from certain hardware manufacturing sectors to software all the way to services. This is already
happening to an extent. Europe produces more than a quarter of all industrial and professional service
robots (e.g. for precision farming, security, health, logistics.), and plays an important role in
developing and using software applications for companies and organisations (business-to-business
applications such as Enterprise Resource Planning, design and engineering software) as well as
applications to support e-government and the "intelligent enterprise".
7 Although further arrangements may need to be put in place to prevent and counter misuse of AI for criminal purposes, this
is outside the scope of this white paper.
8 COM(2019) 168.
3
Europe leads the way in deploying AI in manufacturing. Over half of the top manufacturers implement
at least one instance of AI in manufacturing operations9.
One reason for Europe’s strong position in terms of research is the EU funding programme that has
proven instrumental in pooling action, avoiding duplications, and leveraging public and private
investments in the Member States. Over the past three years, EU funding for research and innovation
for AI has risen to €1.5 billion, i.e. a 70% increase compared to the previous period.
However, investment in research and innovation in Europe is still a fraction of the public and private
investment in other regions of the world. Some €3.2 billion were invested in AI in Europe in 2016,
compared to around €12.1 billion in North America and €6.5 billion in Asia10. In response, Europe
needs to increase its investment levels significantly. The Coordinated plan on AI11 developed with
Member States is proving to be a good starting point in building closer cooperation on AI in Europe
and in creating synergies to maximise investment in the AI value chain.
3. SEIZING THE OPPORTUNITIES AHEAD: THE NEXT DATA WAVE
Although Europe currently is in a weaker position in consumer applications and on online platforms,
which results in a competitive disadvantage in data access, major shifts in the value and re-use of data
across sectors are underway. The volume of data produced in the world is growing rapidly, from 33
zettabytes in 2018 to an expected 175 zettabytes in 2025 12 . Each new wave of data brings
opportunities for Europe to position itself in the data-agile economy and to become a world leader in
this area. Furthermore, the way in which data are stored and processed will change dramatically over
the coming five years. Today 80% of data processing and analysis that takes place in the cloud occurs
in data centres and centralised computing facilities, and 20% in smart connected objects, such as cars,
home appliances or manufacturing robots, and in computing facilities close to the user (“edge
computing”). By 2025 these proportions are set to change markedly13.
Europe is a global leader in low-power electronics which is key for the next generation of specialised
processors for AI. This market is currently dominated by non-EU players. This could change with the
help of initiatives such as the European Processor Initiative, which focuses on developing low-power
computing systems for both edge and next generation high-performance computing, and the work of
the Key Digital Technology Joint Undertaking, proposed to start in 2021. Europe also leads in
neuromorphic solutions14 that are ideally suited to automating industrial processes (industry 4.0) and
transport modes. They can improve energy efficiency by several orders of magnitude.
Recent advances in quantum computing will generate exponential increases in processing capacity15.
Europe can be at the forefront of this technology thanks to its academic strengths in quantum
computing, as well as European industry’s strong position in quantum simulators and programming
environments for quantum computing. European initiatives that aim to increase the availability of
quantum testing and experimentation facilities will help apply these new quantum solutions to a
number of industrial and academic sectors.
9 Followed by Japan (30%) and the US (28%). Source: CapGemini (2019).
10 10 imperatives for Europe in the age of AI and automation, McKinsey (2017).
11 COM(2018) 795.
12 IDC (2019).
13 Gartner (2017).
14 Neuromorphic solutions means any very large-scale system of integrated circuits that mimic neuro-biological architectures
present in the nervous system.
15 Quantum computers will have the capacity to process in less than seconds many fold larger data sets than today’s highest
performance computers allowing for the development of new AI applications across sectors.
4
In parallel, Europe will continue to lead progress in the algorithmic foundations of AI, building on its
own scientific excellence. There is a need to build bridges between disciplines that currently work
separately, such as machine learning and deep learning (characterised by limited interpretability, the
need for a large volume of data to train the models and learn through correlations) and symbolic
approaches (where rules are created through human intervention). Combining symbolic reasoning with
deep neural networks may help us improve explainability of AI outcomes.
4. AN ECOSYSTEM OF EXCELLENCE
To build an ecosystem of excellence that can support the development and uptake of AI across the EU
economy and public administration, there is a need to step up action at multiple levels.
A. WORKING WITH MEMBER STATES
Delivering on its strategy on AI adopted in April 2018,16 in December 2018 the Commission presented
a Coordinated Plan - prepared together with the Member States - to foster the development and use of
AI in Europe17.
This plan proposes some 70 joint actions for closer and more efficient cooperation between Member
States, and the Commission in key areas, such as research, investment, market uptake, skills and talent,
data and international cooperation. The plan is scheduled to run until 2027, with regular monitoring
and review.
The aim is to maximise the impact of investment in research, innovation and deployment, assess
national AI strategies and build on and extend the Coordinated Plan on AI with Member States:
Action 1: The Commission, taking into account the results of the public consultation on the
White Paper, will propose to the Member States a revision of the Coordinated Plan to be
adopted by end 2020
EU-level funding in AI should attract and pool investment in areas where the action required goes
beyond what any single Member State can achieve. The objective is to attract over €20 billion18 of
total investment in the EU per year in AI over the next decade. To stimulate private and public
investment, the EU will make available resources from the Digital Europe Programme, Horizon
Europe as well as from the European Structural and Investment Funds to address the needs of less-
developed regions as well as rural areas.
The Coordinated Plan could also address societal and environmental well-being as a key principle for
AI. AI systems promise to help tackling the most pressing concerns, including climate change and
environmental degradation. It is also important that this happens in an environmentally friendly
manner. AI can and should itself critically examine resource usage and energy consumption and be
trained to make choices that are positive for the environment. The Commission will consider options
to encourage and promote AI solutions that do this together with the Member States.
B. FOCUSING THE EFFORTS OF THE RESEARCH AND INNOVATION COMMUNITY
16 Artificial Intelligence for Europe, COM(2018) 237.
17 Coordinated Plan on Artificial Intelligence, COM(2018) 795.
18 COM(2018) 237.
5
Europe cannot afford to maintain the current fragmented landscape of centres of competence with
none reaching the scale necessary to compete with the leading institutes globally. It is imperative to
create more synergies and networks between the multiple European research centres on AI and to align
their efforts to improve excellence, retain and attract the best researchers and develop the best
technology. Europe needs a lighthouse centre of research, innovation and expertise that would
coordinate these efforts and be a world reference of excellence in AI and that can attract investments
and the best talents in the field.
The centres and the networks should concentrate in sectors where Europe has the potential to become
a global champion such as industry, health, transport, finance, agrifood value chains,
energy/environment, forestry, earth observation and space. In all these domains, the race for global
leadership is ongoing, and Europe offers significant potential, knowledge and expertise 19 . Equally
important is to create testing and experimentation sites to support the development and subsequent
deployment of novel AI applications.
Action 2: the Commission will facilitate the creation of excellence and testing centres that can
combine European, national and private investments, possibly including a new legal
instrument. The Commission has proposed an ambitious and dedicated amount to support
world reference testing centres in Europe under the Digital Europe Programme and
complemented where appropriate by research and innovation actions of Horizon Europe as
part of the Multiannual Financial Framework for 2021 to 2027.
C. SKILLS
The European approach to AI will need to be underpinned by a strong focus on skills to fill
competence shortages.20 The Commission will soon present a reinforcement of the Skills Agenda,
which aims to ensure that everyone in Europe can benefit from the green and digital transformations of
the EU economy. Initiatives could also include the support of sectoral regulators to enhance their AI
skills in order to effectively and efficiently implement relevant rules. The updated Digital Education
Action Plan will help make better use of data and AI-based technologies such as learning and
predictive analytics with the aim to improve education and training systems and make them fit for the
digital age. The Plan will also increase awareness of AI at all levels of education in order to prepare
citizens for informed decisions that will be increasingly affected by AI.
Developing the skills necessary to work in AI and upskilling the workforce to become fit for the AI-
led transformation will be a priority of the revised Coordinated Plan on AI to be developed with
Member States. This could include transforming the assessment list of the ethical guidelines into an
indicative “curriculum” for developers of AI that will be made available as a resource for training
institutions. Particular efforts should be undertaken to increase the number of women trained and
employed in this area.
In addition, a lighthouse centre of research and innovation for AI in Europe would attract talent from
all over the world due to the possibilities it could offer. It would also develop and spread excellence in
skills that take root and grow across Europe.
19 The future European Defence Fund and Permanent Structured Cooperation (PESCO) will also provide opportunities for
research and development in AI. These projects
should be synchronized with the wider EU civilian programmes devoted to AI.
20 https://ec.europa.eu/jrc/en/publication/academic-offer-and-demand-advanced-profiles-eu
6
Action 3: Establish and support through the advanced skills pillar of the Digital Europe
Programme networks of leading universities and higher education institutes to attract the best
professors and scientists and offer world-leading masters programmes in AI.
Beyond upskilling, workers and employers are directly affected by the design and use of AI systems in
the workplace. The involvement of social partners will be a crucial factor in ensuring a human-centred
approach to AI at work.
D. FOCUS ON SMES
It will also be important to ensure that SMEs can access and use AI. To this end, the Digital
Innovation Hubs 21 and the AI-on-demand platform 22 should be strengthened further and foster
collaboration between SMEs. The Digital Europe Programme will be instrumental in achieving this.
While all Digital Innovation Hubs should provide support to SMEs to understand and adopt AI, it will
be important that at least one innovation hub per Member State has a high degree of specialisation in
AI.
SMEs and start-ups will need access to finance in order to adapt their processes or to innovate using
AI. Building on the forthcoming pilot investment fund of €100 million in AI and blockchain, the
Commission plans to further scale up access to finance in AI under InvestEU 23 . AI is explicitly
mentioned among the eligible areas for the use of the InvestEU guarantee.
Action 4: the Commission will work with Member States to ensure that at least one digital
innovation hub per Member State has a high degree of specialisation on AI. Digital
Innovation Hubs can be supported under the Digital Europe Programme.
The Commission and the European Investment Fund will launch a pilot scheme of €100
million in Q1 2020 to provide equity financing for innovative developments in AI. Subject to
final agreement on the MFF, the Commission’s intention is to scale it up significantly from
2021 through InvestEU.
E. PARTNERSHIP WITH THE PRIVATE SECTOR
It is also essential to make sure that the private sector is fully involved in setting the research and
innovation agenda and provides the necessary level of co-investment. This requires setting up a broad-
based public private partnership, and securing the commitment of the top management of companies.
Action 5: In the context of Horizon Europe, the Commission will set up a new public private
partnership in AI, data and robotics to combine efforts, ensure coordination of research and
innovation in AI, collaborate with other public-private partnerships in Horizon Europe and
work together with the testing facilities and the Digital Innovation Hubs mentioned above.
21 ec.europe.eu/digital-single-market/en/news/digital-innovation-hubs-helping-companies-across-economy-make-most-
digital-opportunities.
22 www.Ai4eu.eu.
23 Europe.eu/investeu.
7
F. PROMOTING THE ADOPTION OF AI BY THE PUBLIC SECTOR
It is essential that public administrations, hospitals, utility and transport services, financial supervisors,
and other areas of public interest rapidly begin to deploy products and services that rely on AI in their
activities. A specific focus will be in the areas of healthcare and transport where technology is mature
for large-scale deployment.
Action 6: The Commission will initiate open and transparent sector dialogues giving priority
to healthcare, rural administrations and public service operators in order to present an action
plan to facilitate development, experimentation and adoption. The sector dialogues will be
used to prepare a specific ‘Adopt AI programme’ that will support public procurement of AI
systems, and help to transform public procurement processes themselves.
G. SECURING ACCESS TO DATA AND COMPUTING INFRASTRUCTURES
The areas for action set out in this White Paper are complementary to the plan presented in parallel
under the European data strategy. Improving access to and the management of data is fundamental.
Without data, the development of AI and other digital applications is not possible. The enormous
volume of new data yet to be generated constitutes an opportunity for Europe to position itself at the
forefront of the data and AI transformation. Promoting responsible data management practices and
compliance of data with the FAIR principles will contribute to build trust and ensure re-usability of
data24. Equally important is investment in key computing technologies and infrastructures.
The Commission has proposed more than €4 billion under the Digital Europe Programme to support
high-performance and quantum computing, including edge computing and AI, data and cloud
infrastructure. The European data strategy develops these priorities further.
H. INTERNATIONAL ASPECTS
Europe is well positioned to exercise global leadership in building alliances around shared values and
promoting the ethical use of AI. The EU's work on AI has already influenced international discussions.
When developing its ethical guidelines, the High-Level Expert Group involved a number of non-EU
organisations and several governmental observers. In parallel, the EU was closely involved in
developing the OECD’s ethical principles for AI25. The G20 subsequently endorsed these principles in
its June 2019 Ministerial Statement on Trade and Digital Economy.
In parallel, the EU recognises that important work on AI is ingoing in other multilateral fora, including
the Council of Europe, the United Nations Educational Scientific and Cultural Organization
(UNESCO), the Organisation for Economic Co-operation and Development’s (OECD), the World
Trade Organisation and the International Telecommunications Union (ITU). At the UN, the EU is
involved in the follow-up of the report of the High-Level Panel on Digital Cooperation, including its
recommendation on AI.
The EU will continue to cooperate with like-minded countries, but also with global players, on AI,
based on an approach based on EU rules and values (e.g. supporting upward regulatory convergence,
accessing key resources including data, creating a level playing field). The Commission will closely
monitor the policies of third countries that limit data flows and will address undue restrictions in
24 Findable, Accessible, Interoperable and Reusable as stated in the Final Report and Action Plan from the Commission
Expert Group on FAIR data, 2018, https://ec.europa.eu/info/sites/info/files/turning_fair_into_reality_1.pdf.
25 https://www.oecd.org/going-digital/ai/principles/
8
bilateral trade negotiations and through action in the context of the World Trade Organization. The
Commission is convinced that international cooperation on AI matters must be based on an approach
that promotes the respect of fundamental rights, including human dignity, pluralism, inclusion, non-
discrimination and protection of privacy and personal data26 and it will strive to export its values
across the world27. It is also clear that the responsible development and use of AI can be a driving
force to achieve the Sustainable Development Goals and advance the 2030 Agenda.
5. AN ECOSYSTEM OF TRUST: REGULATORY FRAMEWORK FOR AI
As with any new technology, the use of AI brings both opportunities and risks. Citizens fear being left
powerless in defending their rights and safety when facing the information asymmetries of algorithmic
decision-making, and companies are concerned by legal uncertainty. While AI can help protect
citizens' security and enable them to enjoy their fundamental rights, citizens also worry that AI can
have unintended effects or even be used for malicious purposes. These concerns need to be addressed.
Moreover, in addition to a lack of investment and skills, lack of trust is a main factor holding back a
broader uptake of AI.
That is why the Commission set out an AI strategy28 on 25 April 2018 addressing the socioeconomic
aspects in parallel with an increase in investment in research, innovation and AI-capacity across the
EU. It agreed a Coordinated Plan29 with the Member States to align strategies. The Commission also
established a High-Level Expert Group that published Guidelines on trustworthy AI in April 201930.
The Commission published a Communication31 welcoming the seven key requirements identified in
the Guidelines of the High-Level Expert Group:
Human agency and oversight,
Technical robustness and safety,
Privacy and data governance,
Transparency,
Diversity, non-discrimination and fairness,
Societal and environmental wellbeing, and
Accountability.
In addition, the Guidelines contain an assessment list for practical use by companies. During the
second half of 2019, over 350 organisations have tested this assessment list and sent feedback. The
High-Level Group is in the process of revising its guidelines in light of this feedback and will finalise
this work by June 2020. A key result of the feedback process is that while a number of the
requirements are already reflected in existing legal or regulatory regimes, those regarding transparency,
traceability and human oversight are not specifically covered under current legislation in many
economic sectors.
On top of this set of non-binding Guidelines of the High-Level Expert Group, and in line with the
President’s political guidelines, a clear European regulatory framework would build trust among
26 Under the Partnership Instrument, the Commission will finance a €2.5 million project that will facilitate cooperation with
like-minded partners, in order to promote the EU AI ethical guidelines and to adopt common principles and operational
conclusions.
27 President Von der Leyen, A Union that strives for more – My agenda for Europe, page 17.
28 COM(2018) 237.
29 COM(2018) 795.
30 https://ec.europa.eu/futurium/en/ai-alliance-consultation/guidelines#Top
31 COM(2019) 168.
9
consumers and businesses in AI, and therefore speed up the uptake of the technology. Such a
regulatory framework should be consistent with other actions to promote Europe’s innovation capacity
and competitiveness in this field. In addition, it must ensure socially, environmentally and
economically optimal outcomes and compliance with EU legislation, principles and values. This is
particularly relevant in areas where citizens’ rights may be most directly affected, for example in the
case of AI applications for law enforcement and the judiciary.
Developers and deployers of AI are already subject to European legislation on fundamental rights (e.g.
data protection, privacy, non-discrimination), consumer protection, and product safety and liability
rules. Consumers expect the same level of safety and respect of their rights whether or not a product or
a system relies on AI. However, some specific features of AI (e.g. opacity) can make the application
and enforcement of this legislation more difficult. For this reason, there is a need to examine whether
current legislation is able to address the risks of AI and can be effectively enforced, whether
adaptations of the legislation are needed, or whether new legislation is needed.
Given how fast AI is evolving, the regulatory framework must leave room to cater for further
developments. Any changes should be limited to clearly identified problems for which feasible
solutions exist.
Member States are pointing at the current absence of a common European framework. The German
Data Ethics Commission has called for a five-level risk-based system of regulation that would go from
no regulation for the most innocuous AI systems to a complete ban for the most dangerous ones.
Denmark has just launched the prototype of a Data Ethics Seal. Malta has introduced a voluntary
certification system for AI. If the EU fails to provide an EU-wide approach, there is a real risk of
fragmentation in the internal market, which would undermine the objectives of trust, legal certainty
and market uptake.
A solid European regulatory framework for trustworthy AI will protect all European citizens and help
create a frictionless internal market for the further development and uptake of AI as well as
strengthening Europe’s industrial basis in AI.
A. PROBLEM DEFINITION
While AI can do much good, including by making products and processes safer, it can also do harm.
This harm might be both material (safety and health of individuals, including loss of life, damage to
property) and immaterial (loss of privacy, limitations to the right of freedom of expression, human
dignity, discrimination for instance in access to employment), and can relate to a wide variety of risks.
A regulatory framework should concentrate on how to minimise the various risks of potential harm, in
particular the most significant ones.
The main risks related to the use of AI concern the application of rules designed to protect
fundamental rights (including personal data and privacy protection and non-discrimination), as well as
safety32 and liability-related issues.
Risks for fundamental rights, including personal data and privacy protection and non-
discrimination
32 This includes issues of cybersecurity, issues associated with AI applications in critical infrastructures, or malicious use of
AI.
10
The use of AI can affect the values on which the EU is founded and lead to breaches of fundamental
rights33, including the rights to freedom of expression, freedom of assembly, human dignity, non-
discrimination based on sex, racial or ethnic origin, religion or belief, disability, age or sexual
orientation, as applicable in certain domains, protection of personal data and private life, 34 or the right
to an effective judicial remedy and a fair trial, as well as consumer protection. These risks might result
from flaws in the overall design of AI systems (including as regards human oversight) or from the use
of data without correcting possible bias (e.g. the system is trained using only or mainly data from men
leading to suboptimal results in relation to women).
AI can perform many functions that previously could only be done by humans. As a result, citizens
and legal entities will increasingly be subject to actions and decisions taken by or with the assistance
of AI systems, which may sometimes be difficult to understand and to effectively challenge where
necessary. Moreover, AI increases the possibilities to track and analyse the daily habits of people. For
example, there is a potential risk that AI may be used, in breach of EU data protection and other rules,
by state authorities or other entities for mass surveillance and by employers to observe how their
employees behave. By analysing large amounts of data and identifying links among them, AI may also
be used to retrace and de-anonymise data about persons, creating new personal data protection risks
even in respect to datasets that per se do not include personal data. AI is also used by online
intermediaries to prioritise information for their users and to perform content moderation. The
processed data, the way applications are designed and the scope for human intervention can affect the
rights to free expression, personal data protection, privacy, and political freedoms.
Certain AI algorithms, when exploited for predicting criminal recidivism, can display gender and racial bias,
demonstrating different recidivism prediction probability for women vs men or for nationals vs foreigners.
Source: Tolan S., Miron M., Gomez E. and Castillo C. "Why Machine Learning May Lead to Unfairness:
Evidence from Risk Assessment for Juvenile Justice in Catalonia", Best Paper Award, International
Conference on AI and Law, 2019
Certain AI programmes for facial analysis display gender and racial bias, demonstrating low errors for
determining the gender of lighter-skinned men but high errors in determining gender for darker-skinned
women. Source: Joy Buolamwini, Timnit Gebru; Proceedings of the 1st Conference on Fairness,
Accountability and Transparency, PMLR 81:77-91, 2018.
Bias and discrimination are inherent risks of any societal or economic activity. Human decision-
making is not immune to mistakes and biases. However, the same bias when present in AI could have
a much larger effect, affecting and discriminating many people without the social control mechanisms
that govern human behaviour35. This can also happen when the AI system ‘learns’ while in operation.
33 Council of Europe research shows that a large number of fundamental rights could be impacted from the use of AI,
https://rm.coe.int/algorithms-and-human-rights-en-rev/16807956b5.
34 The General Data Protection Regulation and the ePrivacy Directive (new ePrivacy Regulation under negotiation) address
these risks but there might be a need to examine whether AI systems pose additional risks. The Commission will be
monitoring and assessing the application of the GDPR on a continuous basis.
35 The Commission’s Advisory Committee on Equal Opportunities for Women and Men is currently preparing an “Opinion
on Artificial Intelligence” analysing inter alia the impacts of Artificial Intelligence on gender equality which is expected
to be adopted by the Committee in early 2020. The EU Gender Equality Strategy 2020-2024 also addresses the link
between AI on gender equality; The European Network of Equality Bodies (Equinet) will publish a report (by Robin
11
In such cases, where the outcome could not have been prevented or anticipated at the design phase, the
risks will not stem from a flaw in the original design of the system but rather from the practical
impacts of the correlations or patterns that the system identifies in a large dataset.
The specific characteristics of many AI technologies, including opacity (‘black box-effect’),
complexity, unpredictability and partially autonomous behaviour, may make it hard to verify
compliance with, and may hamper the effective enforcement of, rules of existing EU law meant to
protect fundamental rights. Enforcement authorities and affected persons might lack the means to
verify how a given decision made with the involvement of AI was taken and, therefore, whether the
relevant rules were respected. Individuals and legal entities may face difficulties with effective access
to justice in situations where such decisions may negatively affect them.
Risks for safety and the effective functioning of the liability regime
AI technologies may present new safety risks for users when they are embedded in products and
services. For example, as result of a flaw in the object recognition technology, an autonomous car can
wrongly identify an object on the road and cause an accident involving injuries and material damage.
As with the risks to fundamental rights, these risks can be caused by flaws in the design of the AI
technology, be related to problems with the availability and quality of data or to other problems
stemming from machine learning. While some of these risks are not limited to products and services
that rely on AI , the use of AI may increase or aggravate the risks.
A lack of clear safety provisions tackling these risks may, in addition to risks for the individuals
concerned, create legal uncertainty for businesses that are marketing their products involving AI in
the EU. Market surveillance and enforcement authorities may find themselves in a situation where
they are unclear as to whether they can intervene, because they may not be empowered to act and/or
don’t have the appropriate technical capabilities for inspecting systems 36 . Legal uncertainty may
therefore reduce overall levels of safety and undermine the competitiveness of European companies.
If the safety risks materialise, the lack of clear requirements and the characteristics of AI technologies
mentioned above make it difficult to trace back potentially problematic decisions made with the
involvement of AI systems. This in turn may make it difficult for persons having suffered harm to
obtain compensation under the current EU and national liability legislation.37
Allen and Dee Masters) on “Regulating AI: the new role for Equality Bodies – Meeting the new challenges to equality
and non-discrimination from increased digitalisation and the use of AI”, expected early 2020.
36 An example may be the smart watch for children. This product may cause no direct harm to the child wearing it, but
lacking a minimum level of security, it can be easily used as a tool to have access to the child. Market surveillance
authorities may find it difficult to intervene in cases where the risk is not linked to the product as such.
37 The implications of AI, Internet of Things and other digital technologies for safety and liability legislation are analysed in
the Commission Report accompanying this White Paper.
12
Under the Product Liability Directive, a manufacturer is liable for damage caused by a defective product.
However, in the case of an AI based system such as autonomous cars, it may be difficult to prove that there is
a defect in the product, the damage that has occurred and the causal link between the two. In addition, there is
some uncertainty about how and to what extent the Product Liability Directive applies in the case of certain
types of defects, for example if these result from weaknesses in the cybersecurity of the product.
Thus, the difficulty of tracing back potentially problematic decisions taken by AI systems and referred
to above in relation to fundamental rights applies equally to safety and liability-related issues. Persons
having suffered harm may not have effective access to the evidence that is necessary to build a case in
court, for instance, and may have less effective redress possibilities compared to situations where the
damage is caused by traditional technologies. These risks will increase as the use of AI becomes more
widespread.
B. POSSIBLE ADJUSTMENTS TO EXISTING EU LEGISLATIVE FRAMEWORK RELATING TO AI
An extensive body of existing EU product safety and liability legislation38, including sector-specific
rules, further complemented by national legislation, is relevant and potentially applicable to a number
of emerging AI applications.
As regards the protection of fundamental rights and consumer rights, the EU legislative framework
includes legislation such as the Race Equality Directive 39 , the Directive on equal treatment in
employment and occupation40, the Directives on equal treatment between men and women in relation
to employment and access to goods and services41, a number of consumer protection rules42, as well as
rules on personal data protection and privacy, notably the General Data Protection Regulation and
other sectorial legislation covering personal data protection, such as the Data Protection Law
Enforcement Directive43. In addition, as from 2025, the rules on accessibility requirements for goods
and services, set out in the European Accessibility Act will apply44. In addition, fundamental rights
need to be respected when implementing other EU legislation, including in the field of financial
services, migration or responsibility of online intermediaries.
While the EU legislation remains in principle fully applicable irrespective of the involvement of AI, it
is important to assess whether it can be enforced adequately to address the risks that AI systems create,
or whether adjustments are needed to specific legal instruments.
38 The EU legal framework for product safety consists of the General Product Safety Directive (Directive 2001/95/EC), as a
safety net, and a number of sector-specific rules covering different categories of products ranging from machines, planes
and cars to toys and medical devices aiming to provide a high level of health and safety. Product liability law is
complemented by different systems of civil liability for damages caused by products or services.
39
Directive 2000/43/EC.
40 Directive 2000/78/EC.
41 Directive 2004/113/EC; Directive 2006/54/EC.
42 Such as the Unfair Commercial Practices Directive (Directive 2005/29/EC) and the Consumer Rights Directive (Directive
2011/83/EC).
43 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural
persons with regard to the processing of personal data by competent authorities for the purposes of the prevention,
investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free
movement of such data.
44 Directive (EU) 2019/882 on the accessibility requirements for products and services.
13
For example, economic actors remain fully responsible for the compliance of AI to existing rules that
protects consumers, any algorithmic exploitation of consumer behaviour in violation of existing rules
shall be not permitted and violations shall be accordingly punished.
The Commission is of the opinion that the legislative framework could be improved to address the
following risks and situations:
Effective application and enforcement of existing EU and national legislation: the key
characteristics of AI create challenges for ensuring the proper application and enforcement of
EU and national legislation. The lack of transparency (opaqueness of AI) makes it difficult to
identify and prove possible breaches of laws, including legal provisions that protect
fundamental rights, attribute liability and meet the conditions to claim compensation.
Therefore, in order to ensure an effective application and enforcement, it may be necessary to
adjust or clarify existing legislation in certain areas, for example on liability as further detailed
in the Report, which accompanies this White Paper.
Limitations of scope of existing EU legislation: an essential focus of EU product safety
legislation is on the placing of products on the market. While in EU product safety legislation
software, when is part of the final product, must comply with the relevant product safety rules,
it is an open question whether stand-alone software is covered by EU product safety
legislation, outside some sectors with explicit rules45. General EU safety legislation currently
in force applies to products and not to services, and therefore in principle not to services based
on AI technology either (e.g. health services, financial services, transport services).
Changing functionality of AI systems: the integration of software, including AI, into products
can modify the functioning of such products and systems during their lifecycle. This is
particularly true for systems that require frequent software updates or which rely on machine
learning. These features can give rise to new risks that were not present when the system was
placed on the market. These risks are not adequately addressed in the existing legislation
which predominantly focuses on safety risks present at the time of placing on the market.
Uncertainty as regards the allocation of responsibilities between different economic operators
in the supply chain: in general, EU legislation on product safety allocates the responsibility to
the producer of the product placed on the market, including all components e.g. AI systems.
But the rules can for example become unclear if AI is added after the product is placed on the
market by a party that is not the producer. In addition, EU product liability legislation provides
for liability of producers and leaves national liability rules to govern liability of others in the
supply chain.
Changes to the concept of safety: the use of AI in products and services can give rise to risks
that EU legislation currently does not explicitly address. These risks may be linked to cyber
threats, personal security risks (linked for example to new applications of AI such as to home
appliances), risks that result from loss of connectivity, etc. These risks may be present at the
time of placing products on the market or arise as a result of software updates or self-learning
when the product is being used. The EU should make full use of the tools at its disposal to
45 For instance software intended by the manufacturer to be used for medical purposes is considered a medical device under
the Medical Device Regulation (Regulation (EU) 2017/745).
14
enhance its evidence base on potential risks linked to AI applications, including using the
experience of the EU Cybersecurity Agency (ENISA) for assessing the AI threat landscape.
As indicated earlier, several Member States are already exploring options for national legislation to
address the challenges created by AI. This raises the risk that the single market may be fragmented.
Divergent national rules are likely to create obstacles for companies that want to sell and operate AI
systems in the single market. Ensuring a common approach at EU level would enable European
companies to benefit from smooth access to the single market and support their competitiveness on
global markets.
Report on the safety and liability implications of Artificial Intelligence, the Internet of Things and
robotics
The Report, which accompanies this White Paper, analyses the relevant legal framework. It identifies
uncertainties as to the application of this framework with respect to the specific risks posed by AI systems and
other digital technologies.
It concludes that the current product safety legislation already supports an extended concept of safety
protecting against all kind of risks arising from the product according to its use. However, provisions
explicitly covering new risks presented by the emerging digital technologies could be introduced to provide
more legal certainty.
The autonomous behaviour of certain AI systems during its life cycle may entail important product
changes having an impact on safety, which may require a new risk assessment. In addition, human
oversight from the product design and throughout the lifecycle of the AI products and systems may
be needed as a safeguard.
Explicit obligations for producers could be considered also in respect of mental safety risks of users
when appropriate (ex. collaboration with humanoid robots).
Union product safety legislation could provide for specific requirements addressing the risks to
safety of faulty data at the design stage as well as mechanisms to ensure that quality of data is
maintained throughout the use of the AI products and systems.
The opacity of systems based on algorithms could be addressed through transparency requirements.
Existing rules may need to be adapted and clarified in the case of a stand-alone software placed as it
is on the market or downloaded into a product after its placing on the market, when having an impact
on safety.
Given the increasing complexity of supply chains as regards new technologies, provisions
specifically requesting cooperation between the economic operators in the supply chain and the users
could provide legal certainty.
The characteristics of emerging digital technologies like AI, the IoT and robotics may challenge aspects of the
liability frameworks and could reduce their effectiveness. Some of these characteristics could make it hard to
trace the damage back to a person, which would be necessary for a fault-based claim in accordance with most
national rules. This could significantly increase the costs for victims and means that liability claims against
others than producers may be difficult to make or prove.
Persons having suffered harm caused with the involvement of AI systems need to enjoy the same
level of protection as persons having suffered harm caused by other technologies, whilst
technological innovation should be allowed to continue to develop.
All options to ensure this objective should be carefully assessed, including possible amendments to
the Product Liability Directive and possible further targeted harmonisation of national liability rules.
For example, the Commission is seeking views whether and to what extent it may be needed to
mitigate the consequences of complexity by adapting the burden of proof required by national
liability rules for damage caused by the operation of AI applications.
15
From the discussion above, the Commission concludes that – in addition to the possible adjustments to
existing legislation – a new legislation specifically on AI may be needed in order to make the EU legal
framework fit for the current and anticipated technological and commercial developments.
C. SCOPE OF A FUTURE EU REGULATORY FRAMEWORK
A key issue for the future specific regulatory framework on AI intelligence is to determine the scope
of its application. The working assumption is that the regulatory framework would apply to products
and services relying on AI. AI should therefore be clearly defined for the purposes of this White Paper,
as well as any possible future policy-making initiative.
In its Communication on AI for Europe the Commission provided a first definition of AI 46 . This
definition was further refined by the High Level Expert Group47.
In any new legal instrument, the definition of AI will need to be sufficiently flexible to accommodate
technical progress while being precise enough to provide the necessary legal certainty.
For the purposes of this White Paper, as
In autonomous driving for example, the algorithm uses, in
well as of any possible future discussions
real time, the data from the car (speed, engine
on policy initiatives, it seems important to
consumption, shock-absorbers, etc..) and from the sensors
clarify the main elements that compose scanning the whole environment of the car (road, signs,
AI, which are “data” and “algorithms”. AI other vehicles, pedestrians etc..) to derive which direction,
can be integrated in hardware. In case of acceleration and speed the car should take to reach a certain
machine learning techniques, which destination. Based on the data observed, the algorithm
constitute a subset of AI, algorithms are adapts to the situation of the road and to the outside
trained to infer certain patterns based on a conditions, including other drivers’ behaviour, to derive the
set of data in order to determine the actions most comfortable and safest drive.
needed to achieve a given goal. Algorithms
may continue to learn when in use. While AI-based products can act autonomously by perceiving their
environment and without following a pre-determined set of instructions, their behaviour is largely
defined and constrained by its developers. Humans determine and programme the goals, which an AI
system should optimise for.
The EU has a strict legal framework in place to ensure inter alia consumer protection, to address unfair
commercial practices and to protect personal data and privacy. In addition, the acquis contains specific
rules for certain sectors (e.g. healthcare, transport). These existing provisions of EU law will continue
to apply in relation to AI, although certain updates to that framework may be necessary to reflect the
digital transformation and the use of AI (see section B). As a consequence, those aspects that are
46 COM(2018) 237 final, p. 1: “Artificial intelligence (AI) refers to systems that display intelligent behaviour by analysing
their environment and taking actions – with some degree of autonomy – to achieve specific goals.
AI-based systems can be purely software-based, acting in the virtual world (e.g. voice assistants, image analysis software,
search engines, speech and face recognition systems) or AI can be embedded in hardware devices (e.g. advanced robots,
autonomous cars, drones or Internet of Things applications).”
47 High Level Expert Group, A definition of AI, p. 8: “Artificial intelligence (AI) systems are software (and possibly also
hardware) systems designed by humans that, given a complex goal, act in the physical or digital dimension by perceiving
their environment through data acquisition, interpreting the collected structured or unstructured data, reasoning on the
knowledge, or processing the information, derived from this data and deciding the best action(s) to take to achieve the
given goal. AI systems can either use symbolic rules or learn a numeric model, and they can also adapt their behaviour
by analysing how the environment is affected by their previous actions.”
16
already addressed by existing horizontal or sectoral legislation (e.g. on medical devices48, in transport
systems) will continue to be governed by this legislation.
As a matter of principle, the new regulatory framework for AI should be effective to achieve its
objectives while not being excessively prescriptive so that it could create a disproportionate burden,
especially for SMEs. To strike this balance, the Commission is of the view that it should follow a risk-
based approach.
A risk-based approach is important to help ensure that the regulatory intervention is proportionate.
However, it requires clear criteria to differentiate between the different AI applications, in particular in
relation to the question whether or not they are ‘high-risk’49. The determination of what is a high-risk
AI application should be clear and easily understandable and applicable for all parties concerned.
Nevertheless even if an AI application is not qualified as high-risk, it remains entirely subject to
already existing EU-rules.
The Commission is of the opinion that a given AI application should generally be considered high-risk
in light of what is at stake, considering whether both the sector and the intended use involve
significant risks, in particular from the viewpoint of protection of safety, consumer rights and
fundamental rights. More specifically, an AI application should be considered high-risk where it meets
the following two cumulative criteria:
First, the AI application is employed in a sector where, given the characteristics of the
activities typically undertaken, significant risks can be expected to occur. This first criterion
ensures that the regulatory intervention is targeted on the areas where, generally speaking,
risks are deemed most likely to occur. The sectors covered should be specifically and
exhaustively listed in the new regulatory framework. For instance, healthcare; transport;
energy and parts of the public sector.50 The list should be periodically reviewed and amended
where necessary in function of relevant developments in practice;
Second, the AI application in the sector in question is, in addition, used in such a manner that
significant risks are likely to arise. This second criterion reflects the acknowledgment that not
every use of AI in the selected sectors necessarily involves significant risks. For example,
whilst healthcare generally may well be a relevant sector, a flaw in the appointment
scheduling system in a hospital will normally not pose risks of such significance as to justify
legislative intervention. The assessment of the level of risk of a given use could be based on
the impact on the affected parties. For instance, uses of AI applications that produce legal or
similarly significant effects for the rights of an individual or a company; that pose risk of
injury, death or significant material or immaterial damage; that produce effects that cannot
reasonably be avoided by individuals or legal entities.
The application of the two cumulative criteria would ensure that the scope of the regulatory framework
is targeted and provides legal certainty. The mandatory requirements contained in the new regulatory
framework on AI (see section D below) would in principle apply only to those applications identified
as high-risk in accordance with these two cumulative criteria.
48 For example, there are different safety considerations and legal implications concerning AI systems that provide
specialized medical information to physicians, AI systems providing medical information directly to the patient and AI
systems performing medical tasks themselves directly on a patient. The Commission is examining these safety and
liability challenges that are distinct to healthcare.
49 EU legislation may categorise “risks” differently to what is described here, depending on the area, such as for example,
product safety
50 The public sector could include areas like asylum, migration, border controls and judiciary, social security and
employment services.
17
Notwithstanding the foregoing, there may also be exceptional instances where, due to the risks at stake,
the use of AI applications for certain purposes is to be considered as high-risk as such – that is,
irrespective of the sector concerned and where the below requirements would still apply. 51 As an
illustration, one could think in particular of the following:
In light of its significance for individuals and of the EU acquis addressing employment equality,
the use of AI applications for recruitment processes as well as in situations impacting workers’
rights would always be considered “high-risk” and therefore the below requirements would at
all times apply. Further specific applications affecting consumer rights could be considered.
the use of AI applications for the purposes of remote biometric identification 52 and other
intrusive surveillance technologies, would always be considered “high-risk” and therefore the
below requirements would at all times apply.
D. TYPES OF REQUIREMENTS
When designing the future regulatory framework for AI, it will be necessary to decide on the types of
mandatory legal requirements to be imposed on the relevant actors. These requirements may be further
specified through standards. As noted in section C above and in addition to already existing legislation,
those requirements would apply to high-risk AI applications only, thus ensuring that any regulatory
intervention is focused and proportionate.
Taking into account the guidelines of the High Level Expert Group and what has been set out in the
foregoing, the requirements for high-risk AI applications could consist of the following key features,
which are discussed in further detail in the subsections below:
training data;
data and record-keeping;
information to be provided;
robustness and accuracy;
human oversight;
specific requirements for certain particular AI applications, such as those used for purposes of
remote biometric identification.
To ensure legal certainty, these requirements will be further specified to provide a clear benchmark for
all the actors who need to comply with them.
a) Training data
It is more important than ever to promote, strengthen and defend the EU’s values and rules, and in
particular the rights that citizens derive from EU law. These efforts undoubtedly also extend to the
high-risk AI applications marketed and used in the EU under consideration here.
51 It is important to highlight that other pieces of EU legislation may also apply. For example, when incorporated into a
consumer product, the General Product Safety Directive may apply to the safety of AI applications.
52 Remote biometric identification should be distinguished from biometric authentication (the latter is a security process that
relies on the unique biological characteristics of an individual to verify that he/she is who he/she says he/she is). Remote
biometric identification is when the identities of multiple persons are established with the help of biometric identifiers
(fingerprints, facial image, iris, vascular patterns, etc.) at a distance, in a public space and in a continuous or ongoing
manner by checking them against data stored in a database.
18
As discussed earlier, without data, there is no AI. The functioning of many AI systems, and the actions
and decisions to which they may lead, very much depend on the data set on which the systems have
been trained. The necessary measures should therefore be taken to ensure that, where it comes to the
data used to train AI systems, the EU’s values and rules are respected, specifically in relation to safety
and existing legislative rules for the protection of fundamental rights. The following requirements
relating to the data set used to train AI systems could be envisaged:
Requirements aimed at providing reasonable assurances that the subsequent use of the
products or services that the AI system enables is safe, in that it meets the standards set in the
applicable EU safety rules (existing as well as possible complementary ones). For instance,
requirements ensuring that AI systems are trained on data sets that are sufficiently broad and
cover all relevant scenarios needed to avoid dangerous situations.
Requirements to take reasonable measures aimed at ensuring that such subsequent use of AI
systems does not lead to outcomes entailing prohibited discrimination. These requirements
could entail in particular obligations to use data sets that are sufficiently representative,
especially to ensure that all relevant dimensions of gender, ethnicity and other possible
grounds of prohibited discrimination are appropriately reflected in those data sets;
Requirements aimed at ensuring that privacy and personal data are adequately protected
during the use of AI-enabled products and services. For issues falling within their respective
scope, the General Data Protection Regulation and the Law Enforcement Directive regulate
these matters.
b) Keeping of records and data
Taking into account elements such as the complexity and opacity of many AI systems and the related
difficulties that may exist to effectively verify compliance with and enforce the applicable rules,
requirements are called for regarding the keeping of records in relation to the programming of the
algorithm, the data used to train high-risk AI systems, and, in certain cases, the keeping of the data
themselves. These requirements essentially allow potentially problematic actions or decisions by AI
systems to be traced back and verified. This should not only facilitate supervision and enforcement; it
may also increase the incentives for the economic operators concerned to take account at an early
stage of the need to respect those rules.
To this aim, the regulatory framework could prescribe that the following should be kept:
accurate records regarding the data set used to train and test the AI systems, including a
description of the main characteristics and how the data set was selected;
in certain justified cases, the data sets themselves;
documentation on the programming53 and training methodologies, processes and techniques
used to build, test and validate the AI systems, including where relevant in respect of safety
and avoiding bias that could lead to prohibited discrimination.
The records, documentation and, where relevant, data sets would need to be retained during a limited,
reasonable time period to ensure effective enforcement of the relevant legislation. Measures should be
53 For instance, documentation on the algorithm including what the model shall optimise for, which weights are designed to
certain parameters at the outset etc.
19
taken to ensure that they are made available upon request, in particular for testing or inspection by
competent authorities. Where necessary, arrangements should be made to ensure that confidential
information, such as trade secrets, is protected.
c) Information provision
Transparency is required also beyond the record-keeping requirements discussed in point c) above. In
order to achieve the objectives pursued – in particular promoting the responsible use of AI, building
trust and facilitating redress where needed – it is important that adequate information is provided in a
proactive manner about the use of high-risk AI systems.
Accordingly, the following requirements could be considered:
Ensuring clear information to be provided as to the AI system’s capabilities and limitations, in
particular the purpose for which the systems are intended, the conditions under which they can
be expected to function as intended and the expected level of accuracy in achieving the
specified purpose. This information is important especially for deployers of the systems, but it
may also be relevant to competent authorities and affected parties.
Separately, citizens should be clearly informed when they are interacting with an AI system
and not a human being. Whilst EU data protection legislation already contain certain rules of
this kind 54 , additional requirements may be called for to achieve the abovementioned
objectives. If so, unnecessary burdens should be avoided. Therefore, no such information
needs to be provided, for instance, in situations where it is immediately obvious to citizens
that they are interacting with AI systems. It is furthermore important that the information
provided is objective, concise and easily understandable. The manner in which the information
is to be provided should be tailored to the particular context.
d) Robustness and accuracy
AI systems – and certainly high-risk AI applications – must be technically robust and accurate in order
to be trustworthy. That means that such systems need to be developed in a responsible manner and
with an ex-ante due and proper consideration of the risks that they may generate. Their development
and functioning must be such to ensure that AI systems behave reliably as intended. All reasonable
measures should be taken to minimise the risk of harm being caused.
Accordingly, the following elements could be considered:
Requirements ensuring that the AI systems are robust and accurate, or at least correctly reflect
their level of accuracy, during all life cycle phases;
Requirements ensuring that outcomes are reproducible;
Requirements ensuring that AI systems can adequately deal with errors or inconsistencies
during all life cycle phases.
54 In particular, pursuant to Art. 13(2)(f) GDPR, controllers must, at the time when the personal data are obtained, provide the
data subjects with further information necessary to ensure fair and transparent processing about the existence of automated
decision-making and certain additional information.
20
Requirements ensuring that AI systems are resilient against both overt attacks and more subtle
attempts to manipulate data or algorithms themselves, and that mitigating measures are taken
in such cases.
e) Human oversight
Human oversight helps ensuring that an AI system does not undermine human autonomy or cause
other adverse effects. The objective of trustworthy, ethical and human-centric AI can only be achieved
by ensuring an appropriate involvement by human beings in relation to high-risk AI applications.
Even though the AI applications considered in this White paper for a specific legal regime are all
considered high-risk, the appropriate type and degree of human oversight may vary from one case to
another. It shall depend in particular on the intended use of the systems and the effects that the use
could have for affected citizens and legal entities. It shall also be without prejudice to the legal rights
established by the GDPR when the AI system processes personal data. For instance, human oversight
could have the following, non-exhaustive, manifestations:
the output of the AI system does not become effective unless it has been previously reviewed
and validated by a human (e.g. the rejection of an application for social security benefits may
be taken by a human only);
the output of the AI system becomes immediately effective, but human intervention is ensured
afterwards (e.g. the rejection of an application for a credit card may be processed by an AI
system, but human review must be possible afterwards);
monitoring of the AI system while in operation and the ability to intervene in real time and
deactivate (e.g. a stop button or procedure is available in a driverless car when a human
determines that car operation is not safe);
in the design phase, by imposing operational constraints on the AI system (e.g. a driverless car
shall stop operating in certain conditions of low visibility when sensors may become less
reliable or shall maintain a certain distance in any given condition from the preceding vehicle).
f) Specific requirements for remote biometric identification
The gathering and use of biometric data55 for remote identification56 purposes, for instance through
deployment of facial recognition in public places, carries specific risks for fundamental rights57. The
55 Biometric data is defined as “personal data resulting from specific technical processing relating to the physical,
physiological or behavioural characteristics of a natural person, which allow or confirm the unique authentification or
identification of that natural person, such as facial images or dactyloscopic [fingerprint] data.” (Law Enforcement
Directive, Art. 3 (13); GDPR, Art. 4 (14); Regulation (EU) 2018/1725, Art. 3 (18).
56 In connection to facial recognition, identification means that the template of a person’s facial image is compared to many
other templates stored in a database to find out if his or her image is stored there. Authentication (or verification) on the
other hand is often referred to as one-to-one matching. It enables the comparison of two biometric templates, usually
assumed to belong to the same individual. Two biometric templates are compared to determine if the person shown on the
two images is the same person. Such a procedure is, for example, used at Automated Border Control (ABC) gates used for
border checks at airports.
57 For example on people’s dignity. Relatedly, the rights to respect for private life and protection of personal data are at the
core of fundamental rights concerns when using facial recognition technology. There is also a potential impact on non-
discrimination and rights of special groups, such as children, older persons and persons with disabilities. Moreover,
freedom of expression, association and assembly must not be undermined by the use of the technology. See: Facial
recognition technology: fundamental rights considerations in the context of law enforcement,
https://fra.europa.eu/en/publication/2019/facial-recognition.
21
fundamental rights implications of using remote biometric identification AI systems can vary
considerably depending on the purpose, context and scope of the use.
EU data protection rules prohibit in principle the processing of biometric data for the purpose of
uniquely identifying a natural person, except under specific conditions 58 . Specifically, under the
GDPR, such processing can only take place on a limited number of grounds, the main one being for
reasons of substantial public interest. In that case, the processing must take place on the basis of EU or
national law, subject to the requirements of proportionality, respect for the essence of the right to data
protection and appropriate safeguards. Under the Law Enforcement Directive, there must be a strict
necessity for such processing, in principle an authorisation by EU or national law as well as
appropriate safeguards. As any processing of biometric data for the purpose of uniquely identifying a
natural person would relate to an exception to a prohibition laid down in EU law, it would be subject
to the Charter of Fundamental Rights of the EU.
It follows that, in accordance with the current EU data protection rules and the Charter of Fundamental
Rights, AI can only be used for remote biometric identification purposes where such use is duly
justified, proportionate and subject to adequate safeguards.
In order to address possible societal concerns relating to the use of AI for such purposes in public
places, and to avoid fragmentation in the internal market, the Commission will launch a broad
European debate on the specific circumstances, if any, which might justify such use, and on common
safeguards.
E. ADDRESSEES
In relation to the addressees of the legal requirements that would apply in relation to the high-risk AI
applications referred to above, there are two main issues to be considered.
First, there is the question how obligations are to be distributed among the economic operators
involved. Many actors are involved in the lifecycle of an AI system. These include the developer, the
deployer (the person who uses an AI-equipped product or service) and potentially others (producer,
distributor or importer, service provider, professional or private user).
It is the Commission’s view that, in a future regulatory framework, each obligation should be
addressed to the actor(s) who is (are) best placed to address any potential risks. For example, while the
developers of AI may be best placed to address risks arising from the development phase, their ability
to control risks during the use phase may be more limited. In that case, the deployer should be subject
to the relevant obligation. This is without prejudice to the question whether, for the purpose of liability
to end-users or other parties suffering harm and ensuring effective access to justice, which party
should be liable for any damage caused. Under EU product liability law, liability for defective
products is attributed to the producer, without prejudice to national laws which may also allow
recovery from other parties.
Second, there is the question about the geographic scope of the legislative intervention. In the view of
the Commission, it is paramount that the requirements are applicable to all relevant economic
operators providing AI-enabled products or services in the EU, regardless of whether they are
established in the EU or not. Otherwise, the objectives of the legislative intervention, mentioned
earlier, could not fully be achieved.
58 Article 9 GDPR, Article 10 Law Enforcement Directive. See also Article 10 Regulation (EU) 2018/1725 (applicable to the
EU institutions and bodies).
22
F. COMPLIANCE AND ENFORCEMENT
In order to ensure that AI is trustworthy, secure and in respect of European values and rules, the
applicable legal requirements need to be complied with in practice and be effectively enforced both by
competent national and European authorities and by affected parties. Competent authorities should be
in a position to investigate individual cases, but also to assess the impact on society.
In view of the high risk that certain AI applications pose for citizens and our society (see section A
above), the Commission considers at this stage that an objective, prior conformity assessment would
be necessary to verify and ensure that certain of the above mentioned mandatory requirements
applicable to high-risk applications (see section D above) are complied with. The prior conformity
assessment could include procedures for testing, inspection or certification59. It could include checks
of the algorithms and of the data sets used in the development phase.
The conformity assessments for high-risk AI applications should be part of the conformity assessment
mechanisms that already exist for a large number of products being placed on the EU’s internal market.
Where no such existing mechanisms can be relied on, similar mechanisms may need to be established,
drawing on best practice and possible input of stakeholders and European standards organisations.
Any such new mechanism should be proportionate and non-discriminatory and use transparent and
objective criteria in compliance with international obligations.
When designing and implementing a system relying on prior conformity assessments, particular
account should be taken of the following:
Not all requirements outlined above may be suitable to be verified through a prior conformity
assessment. For instance, the requirement about information to be provided generally does not
lend itself well for verification through such an assessment.
Particular account should be taken of the possibility that certain AI systems evolve and learn
from experience, which may require repeated assessments over the life-time of the AI systems
in question.
The need to verify the data used for training and the relevant programming and training
methodologies, processes and techniques used to build, test and validate AI systems.
In case the conformity assessment shows that an AI system does not meet the requirements for
example relating to the data used to train it, the identified shortcomings will need to be
remedied, for instance by re-training the system in the EU in such a way as to ensure that all
applicable requirements are met.
The conformity assessments would be mandatory for all economic operators addressed by the
requirements, regardless of their place of establishment60. In order to limit the burden on SMEs, some
support structure might be envisaged including through the Digital Innovation Hubs. In addition,
standards as well as dedicated online tools could facilitate compliance.
59 The system would be based on conformity assessment procedures in the EU, see Decision 768/2008/EC or on Regulation
(EU) 2019/881 (Cybersecurity Act), taking into account the specificities of AI. See the Blue Guide on the Implementation
of EU product rules, 2014.
60 As regards the relevant governance structure, including the bodies designated to carry out the conformity assessments, see
section H below.
23
Any prior conformity assessment should be without prejudice to monitoring compliance and ex post
enforcement by competent national authorities. That holds true in respect of high-risk AI applications,
but also in respect of other AI applications subject to legal requirements, although the high-risk nature
of the applications at issue may be reason for the competent national authorities to give particular
attention to the former. Ex-post controls should be enabled by adequate documentation of the relevant
AI application (see section E above) and, where appropriate, a possibility for third parties such as
competent authorities to test such applications. This may be especially important where risks to
fundamental rights arise, which are context dependent. Such monitoring of compliance should be part
of a continuous market surveillance scheme. Governance-related aspects are further discussed in
section H below.
Moreover, both for high- risk AI applications and for other AI applications, effective judicial redress
for parties negatively affected by AI systems should be ensured. Issues related to liability are further
discussed in the Report on the safety and liability framework accompanying this White Paper.
G. VOLUNTARY LABELLING FOR NO-HIGH RISK AI APPLICATIONS
For AI applications that do not qualify as ‘high-risk’ (see section C above) and that are therefore not
subject to the mandatory requirements discussed above (see sections D, E and F above), an option
would be, in addition to applicable legislation, to establish a voluntary labelling scheme.
Under the scheme, interested economic operators that are not covered by the mandatory requirements
could decide to make themselves subject, on a voluntary basis, either to those requirements or to a
specific set of similar requirements especially established for the purposes of the voluntary scheme.
The economic operators concerned would then be awarded a quality label for their AI applications.
The voluntary label would allow the economic operators concerned to signal that their AI-enabled
products and services are trustworthy. It would allow users to easily recognise that the products and
services in question are in compliance with certain objective and standardised EU-wide benchmarks,
going beyond the normally applicable legal obligations. This would help enhance the trust of users in
AI systems and promote the overall uptake of the technology.
This option would entail the creation of a new legal instrument that sets out the voluntary labelling
framework for developers and/or deployers of AI systems that are not be considered as high-risk.
While participation in the labelling scheme would be voluntary, once the developer or the deployer
opted to use the label, the requirements would be binding. The combination of ex ante and ex post
enforcement would need to ensure that all requirements are complied with.
H. GOVERNANCE
A European governance structure on AI in the form of a framework for cooperation of national
competent authorities is necessary to avoid fragmentation of responsibilities, increase capacity in
Member States, and make sure that Europe equips itself progressively with the capacity needed for
testing and certification of AI-enabled products and services. In this context, it would be beneficial to
support competent national authorities to enable them to fulfil their mandate where AI is used.
A European governance structure could have a variety of tasks, as a forum for a regular exchange of
information and best practice, identifying emerging trends, advising on standardisation activity as well
as on certification. It should also play a key role in facilitating the implementation of the legal
framework, such as through issuing guidance, opinions and expertise. To that effect, it should rely on a
network of national authorities, as well as sectorial networks and regulatory authorities, at national and
EU level. Moreover, a committee of experts could provide assistance to the Commission.
24
The governance structure should guarantee maximum stakeholders participation. Stakeholders –
consumer organisation and social partners, businesses, researchers, and civil society organisations –
should be consulted on the implementation and the further development of the framework.
Given already existing structures such as in finance, pharmaceuticals, aviation, medical devices,
consumer protection, data protection, the proposed governance structure should not duplicate existing
functions. It should instead establish close links with other EU and national competent authorities in
the various sectors to complement existing expertise and help existing authorities in monitoring and
the oversight of the activities of economic operators involving AI systems and AI-enabled products
and services.
Finally, if this option is pursued, the carrying out of conformity assessments could be entrusted to
notified bodies designated by Member States. Testing centres should enable the independent audit and
assessment of AI-systems in accordance with the requirements outlined above. Independent
assessment will increase trust and ensures objectivity. It could also facilitate the work of relevant
competent authorities.
The EU enjoys excellent testing and assessment centres and should develop its capacity also in the
area of AI. Economic operators established in third countries wanting to enter the internal market
could either make use of designated bodies established in the EU or, subject to mutual recognition
agreements with third countries, have recourse to third-country bodies designated to carry out such
assessment.
The governance structure relating to AI and the possible conformity assessments at issue here would
leave the powers and responsibilities under existing EU law of the relevant competent authorities in
specific sectors or on specific issues (finance, pharmaceuticals, aviation, medical devices, consumer
protection, data protection, etc.) unaffected.
6. CONCLUSION
AI is a strategic technology that offers many benefits for citizens, companies and society as a whole,
provided it is human-centric, ethical, sustainable and respects fundamental rights and values. AI offers
important efficiency and productivity gains that can strengthen the competitiveness of European
industry and improve the wellbeing of citizens. It can also contribute to finding solutions to some of
the most pressing societal challenges, including the fight against climate change and environmental
degradation, the challenges linked to sustainability and demographic changes, and the protection of
our democracies and, where necessary and proportionate, the fight against crime.
For Europe to seize fully the opportunities that AI offers, it must develop and reinforce the necessary
industrial and technological capacities. As set out in the accompanying European strategy for data, this
also requires measures that will enable the EU to become a global hub for data.
The European approach for AI aims to promote Europe’s innovation capacity in the area of AI while
supporting the development and uptake of ethical and trustworthy AI across the EU economy. AI
should work for people and be a force for good in society.
With this White Paper and the accompanying Report on the safety and liability framework, the
Commission launches a broad consultation of Member States civil society, industry and academics, of
concrete proposals for a European approach to AI. These include both policy means to boost
investments in research and innovation, enhance the development of skills and support the uptake of
AI by SMEs, and proposals for key elements of a future regulatory framework. This consultation will
25
allow a comprehensive dialogue with all concerned parties that will inform the next steps of the
Commission.
The Commission invites for comments on the proposals set out in the White Paper through an
open public consultation available at https://ec.europa.eu/info/consultations_en. The consultation
is open for comments until 19 May 2020.
It is standard practice for the Commission to publish submissions received in response to a public
consultation. However, it is possible to request that submissions, or parts thereof, remain
confidential. Should this be the case, please indicate clearly on the front page of your submission
that it should not be made public and also send a non-confidential version of your submission to
the Commission for publication.
26
EUROPEAN
COMMISSION
Brussels, 19.2.2020
COM(2020) 67 final
COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN
PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL
COMMITTEE AND THE COMMITTEE OF THE REGIONS
Shaping Europe's digital future
EN EN
Shaping Europe’s digital future
1. Introduction
Digital technologies are profoundly changing our daily life, our way of working and doing
business, and the way people travel, communicate and relate with each other. Digital
communication, social media interaction, e-commerce, and digital enterprises are steadily
transforming our world. They are generating an ever-increasing amount of data, which, if
pooled and used, can lead to a completely new means and levels of value creation. It is a
transformation as fundamental as that caused by the industrial revolution.
In her political guidelines, Commission President von der Leyen stressed the need for Europe
to lead the transition to a healthy planet and a new digital world. This twin challenge of a
green and digital transformation has to go hand-in-hand. It requires, as set out in the European
Green Deal, an immediate change of direction towards more sustainable solutions which are
resource-efficient, circular and climate-neutral. It requires that every citizen, every employee,
every business person has a fair chance, wherever they live, to reap the benefits of our
increasingly digitised society.
Digital solutions such as communications systems, artificial intelligence or quantum
technologies can enrich our lives in many ways. But the benefits arising from digital
technologies do not come without risks and costs. Citizens no longer feel in control over what
happens with their personal data and are increasingly overloaded by artificial solicitations of
their attention. And malicious cyberactivity may threaten our personal well-being or disrupt
our critical infrastructures and wider security interests.
This substantive societal transformation calls for a profound reflection at all levels of society
as to how Europe can best meet, and continue to meet, these risks and challenges. It will
require a huge effort, but Europe undoubtedly has the means to bring about this better digital
future for everyone.
2. Our vision and goals
The Commission wants a European society powered by digital solutions that are strongly
rooted in our common values, and that enrich the lives of all of us: people must have the
opportunity to develop personally, to choose freely and safely, to engage in society, regardless
of their age, gender or professional background. Businesses need a framework that allows
them to start up, scale up, pool and use data, to innovate and compete or cooperate on fair
1
terms. And Europe needs to have a choice and pursue the digital transformation in its own
way.
European technological sovereignty starts from ensuring the integrity and resilience of our
data infrastructure, networks and communications. It requires creating the right conditions for
Europe to develop and deploy its own key capacities, thereby reducing our dependency on
other parts of the globe for the most crucial technologies. Europe’s ability to define its own
rules and values in the digital age will be reinforced by such capacities. European
technological sovereignty is not defined against anyone else, but by focusing on the needs of
Europeans and of the European social model. The EU will remain open to anyone willing to
play by European rules and meet European standards, regardless of where they are based.
Citizens should be empowered to make better decisions based on insights gleaned from non-
personal data. And that data should be available to all – whether public or private, big or
small, start-up or giant. This will help society to get the most out of innovation and
competition and ensure that everyone benefits from a digital dividend. This digital Europe
should reflect the best of Europe - open, fair, diverse, democratic, and confident
For the next five years, the Commission will focus on three key objectives to ensure that
digital solutions help Europe to pursue its own way towards a digital transformation that
works for the benefit of people through respecting our values. It will also put Europe in a
position to be a trendsetter in the global debate.
Technology that works for people: Development, deployment and uptake of
technology that makes a real difference to people’s daily lives. A strong and
competitive economy that masters and shapes technology in a way that respects
European values.
A fair and competitive economy: A frictionless single market, where companies of
all sizes and in any sector can compete on equal terms, and can develop, market and
use digital technologies, products and services at a scale that boosts their productivity
and global competitiveness, and consumers can be confident that their rights are
respected.
An open, democratic and sustainable society: A trustworthy environment in which
citizens are empowered in how they act and interact, and of the data they provide both
online and offline. A European way to digital transformation which enhances our
democratic values, respects our fundamental rights, and contributes to a sustainable,
climate-neutral and resource-efficient economy.
2
For Europe to truly influence the way in which digital solutions are developed and used on a
global scale, it needs to be a strong, independent and purposeful digital player in its own right.
In order to achieve this, a clear framework that promotes trustworthy, digitally enabled
interactions across society, for people as well as for businesses, is needed. Without this focus
on trustworthiness, the vital process of digital transformation cannot succeed.
Creating a Europe fit for the digital age is a complex puzzle with many interconnected pieces;
as with any puzzle, the whole picture cannot be seen without putting all the pieces together.
The following sections will describe how the Commission intends to complete this puzzle and
turn its vision into reality.
A. Technology that works for people
Europe has a long and successful history of technology and creativity. Europe is strongest
when it acts together and joins forces between the EU and its Member States; involving
regions and municipalities, academia, civil society, financial institutions, businesses and
social enterprises. Europe needs to pool its investments in research and innovation, to share
experiences, and to cooperate across countries. Recent agreements to work together in areas
such as supercomputing and micro-electronics have shown that collaboration can be highly
3
effective. Similar initiatives on key areas of the next wave of innovative technologies will
follow. Promoting the digital transformation of public administrations throughout Europe is
also crucial in this regard.
Europe must invest more in the strategic capacities that allow us to develop and use digital
solutions at scale and to strive for interoperability in key digital infrastructures, such as
extensive 5G (and future 6G) networks and deep tech.1 To take just one example: connectivity
is the most fundamental building block of the digital transformation. It is what enables data to
flow, people to collaborate wherever they are, and to connect more objects to the Internet,
transforming manufacturing, mobility and logistic chains. Gigabit connectivity2, powered
with secure fibre and 5G infrastructures, is vital if we are to tap into Europe’s digital growth
potential. To this end, adequate investments at EU, national and regional levels are necessary
to achieve the EU 2025 connectivity objectives.,3
The new EU Multiannual Financial Framework will contribute to these objectives. The aim is
to achieve more and better strategic capacity where it matters – through targeted funding
programmes4, and making use of the InvestEU guarantee and of structural and rural
development funds5. This public funding has to be used to leverage private investment,
because only together can we plug the investment gaps. The Capital Markets Union will
facilitate the access of innovative and high-tech companies to market-based financing across
the whole EU. We therefore need to ensure there is a broad array of private and public equity
available to finance digital innovation.
Europe needs to invest in connectivity, deep tech and human capital, as well as in smart
energy and transport infrastructures. For digital infrastructure and networks alone, the EU has
an investment gap of EUR 65 billion per year.6 Implementing reforms and stepping up
investments in Research and Development and technological deployment could yield 14% of
cumulative additional GDP growth by 2030. Acting quickly (for example by stepping up
investments and adopting measures by 2022 rather than by 2025) would bring an additional
1
Supercomputing, quantum technologies, blockchain and secure, pan-European cloud capacities
2
Commission Communication “Connectivity for a Competitive Digital Single Market - Towards a European
Gigabit Society”, COM/2016/0587 final.
3
These objectives require for all European households, rural or urban, an internet connectivity of at least "100
Mbps, upgradable to Gigabit speed". This reflects the Commission’s expectation that, as the decade progresses,
households will increasingly need 1 Gbps. This is in line with the Commission’s observation of exponentially
growing network capacity demands and the need to ensure sustainable investments into networks capable of
offering symmetric (i.e. upload and download) Gigabit speeds to cater for the European data economy beyond
2025. All main socio-economic drivers, such as schools, hospitals, businesses should already benefit from
Gigabit connectivity with equally fast upload and download speeds at the latest by 2025.
4
The Digital Europe Programme (DEP), Connecting Europe Facility (CEF 2), Horizon Europe, the Space
Programme.
5
ERDF, EARDF.
6
Restoring EU competitiveness, EIB 2016. The EIB Investment Report 2019/20, Accelerating Europe’s
Transformation, confirms the large-scale public investment needed to support infrastructure digitalisation.
4
3.2% increase in GDP and positive job creation by 2030.7 This is a socio-economic boost that
Europe cannot afford to miss.
Investing in innovation is only part of the issue, however. A true digital transformation has to
start from European citizens and businesses trusting that their applications and products are
secure. The more interconnected we are, the more we are vulnerable to malicious cyber
activity. To tackle this growing threat, we need to work together at every stage: setting
consistent rules for companies and stronger mechanisms for proactive information-sharing;
ensuring operational cooperation between Member States, and between the EU and Member
States; building synergies between civilian cyber resilience and the law enforcement and
defence dimensions of cybersecurity8; ensuring that law enforcement and judicial authorities
can work effectively by developing new tools to use against cybercriminals; and last but by no
means least, it means raising the awareness of EU citizens on cybersecurity9.
Feeling safe and secure is not just a question of cybersecurity. Citizens need to be able to trust
the technology itself, as well as the way in which it is used. This is particularly important
when it comes to the issue of artificial intelligence. In this respect, the European Commission
is presenting a White Paper on creating ecosystems of excellence and trust in the field of AI,
based on European values.
Improving education and skills is a key part of the overall vision for digital transformation in
Europe. European companies need digitally savvy employees to thrive in the global
technology-driven marketplace. In turn, workers need digital competences to succeed in an
increasingly digitalised and fast changing labour market10. More women can and must have
rewarding careers in tech, and European tech needs to benefit from women’s skills and
competences.
The need for digital skills goes well beyond the jobs market, however. As digital technologies
permeate our professional and private lives, having at least basic digital literacy and skills has
become a precondition for participating effectively in today's society.
As more processes are automated, digitisation will lead to changes beyond the tech sector.
Numerous occupations will be entirely transformed. The digital transition must be fair and
just and encourage women to fully take part. Social partners have a crucial role to play in this
context. At the same time, promoting innovation and technological diffusion are a prerequisite
7
Shaping the digital transformation, Study conducted for the European Commission, McKinsey Global Institute
(to be published in Q2 2020).
8
The recently published EU toolbox for 5G security constitutes an important milestone as it puts in place a set of
robust and comprehensive measures for an EU coordinated approach to secure 5G networks.
9
Enhancing cybersecurity will make a key contribution towards building a genuine and effective Security Union.
10
Over 90% of jobs already require at least basic digital skills, yet 43% of European citizens and over a third of
the EU labour force lack them.
5
for a good quality of life, employment opportunities and to close existing participation gaps,
notably in rural and remote areas suffering from population ageing and decline.
New challenges are also emerging as regards working conditions. The growing number of
online platforms has created new opportunities for people to earn income, enter or remain in
the labour market. At the same time, it has raised new questions as regards legal protections
for people who do not have a worker status yet who share some of the vulnerabilities of
workers. The Commission will therefore propose an enhanced framework for platform
workers.
6
Key actions
- White Paper on Artificial Intelligence setting out options for a legislative framework for
trustworthy AI (adopted together with this Communication), with a follow-up on safety,
liability, fundamental rights and data (Q4 2020).
- Building and deploying cutting-edge joint digital capacities in the areas of AI, cyber,
super- and quantum computing, quantum communication and blockchain. European
Strategies on Quantum and blockchain (Q2 2020) as well as a revised EuroHPC
Regulation11 on supercomputing.
- Accelerating investments in Europe’s Gigabit connectivity, through a revision of the
Broadband Cost Reduction Directive12, an updated Action Plan on 5G and 6G, a new
Radio Spectrum Policy Programme (2021). 5G corridors for connected and automated
mobility, including railway corridors, will be rolled out (2021-2030) (2021-2023).
- A European cybersecurity strategy, including the establishment of a joint Cybersecurity
Unit, a Review of the Security of Network and Information Systems (NIS) Directive13 and
giving a push to the single market for cybersecurity.
- A Digital Education Action Plan to boost digital literacy and competences at all levels of
education (Q2 2020).
- A reinforced Skills Agenda to strengthen digital skills throughout society and a reinforced
Youth Guarantee to put a strong focus on digital skills in early career transitions (Q2
2020).
- Initiative to improve labour conditions of platform workers (2021).
- A reinforced EU governments interoperability strategy to ensure coordination and
common standards for secure and borderless public sector data flows and services. (2021)
B. A fair and competitive economy
In an ever-shrinking world where technology is gaining in importance, Europe needs to
continue to act and decide independently and reduce over-reliance on digital solutions created
elsewhere.
For the development of many products and services, data needs to be widely and easily
available, easily accessible, and simple to use and process. Data has become a key factor of
production, and the value it creates has to be shared back with the entire society participating
in providing the data. This is why we need to build a genuine European single market for data
- a European data space based on European rules and values.
11
Council Regulation (EU) 2018/1488 of 28 September 2018.
12
Directive 2014/61/EU of the European Parliament and of the Council of 15 May 2014.
13
Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016.
7
Many European companies – and SMEs in particular – have been slow at taking up digital
solutions, and therefore have not benefitted from them and missed opportunities to scale up.
The Commission will seek to address this issue with a new EU Industrial Strategy that will set
out actions to facilitate the transition towards a more digital, clean, circular and globally
competitive EU industry. It will also include a strategy for SMEs, a vital part of the European
economy, often hampered by lack of available skills, access to finance and markets.
To start up and grow in Europe, SMEs need a frictionless single market, unhampered by
diverging local or national regulations that increase administrative burdens for smaller
companies in particular. They need clear and proportionate rules that are effectively and
uniformly enforced across the EU, providing them with an immensely powerful home market
from which to launch themselves on the world stage.
In the digital age, ensuring a level playing field for businesses, big and small, is more
important than ever. This suggests that rules applying offline – from competition and single
market rules, consumer protection, to intellectual property, taxation and workers’ rights –
should also apply online. Consumers need to be able to trust digital products and service just
as much as they would any other. There is a need to pay attention to the most vulnerable
consumers and to ensure the enforcement of safety laws, also in relation to goods originating
from third countries. Some platforms have acquired significant scale, which effectively allows
them to act as private gatekeepers to markets, customers and information. We must ensure
that the systemic role of certain online platforms and the market power they acquire will not
put in danger the fairness and openness of our markets.
With specific respect to EU competition law, its foundations are as relevant for digital as for
traditional industries. EU competition law serves Europe well by contributing to a level
playing field where markets serve consumers. At the same time, it is important that the
competition rules remain fit for a world that is changing fast, is increasingly digital and must
become greener. With this in mind, the Commission is currently reflecting on the
effectiveness of the way in which the current rules are applied, for example in relation to anti-
trust remedies, and also conducting an evaluation and review of the rules themselves to ensure
that they meet today’s digital and green challenges.
Reviews are already underway of the rules governing horizontal and vertical agreements and
of the market definition notice, as is a “fitness” check of various state aid guidelines. Among
the key issues for Europe’s digital future are data access, pooling and sharing, and the balance
between online and offline commerce. The review of the market definition notice will also
take account of new digital business models - such as “free” services that users access while
providing their data – and their implications for competitive constraints. The ongoing fitness
check of the Commission’s 2014 Important Projects of Common European Interest (IPCEI)
Communication is designed to assess whether an update is necessary to further clarify the
8
conditions under which major Member State-led projects in key, strategic sectors for the
digital and green future of Europe can proceed effectively.
The Commission is also planning to launch a sector inquiry with a strong focus on these new
and emerging markets that are shaping our economy and society.
However, competition policy alone cannot address all the systemic problems that may arise in
the platform economy. Based on the single market logic, additional rules may be needed to
ensure contestability, fairness and innovation and the possibility of market entry, as well as
public interests that go beyond competition or economic considerations.
Ensuring fairness in the digital economy is a major challenge. In the borderless digital world,
a handful of companies with the largest market share get the bulk of the profits on the value
that is created in a data-based economy. Those profits are often not taxed where they are
generated as a result of outdated corporate tax rules, distorting competition. This is why the
Commission will look to address the tax challenges arising from the digitisation of the
economy.
9
Key actions
- A European Data Strategy to make Europe a global leader in the data-agile economy
(February 2020), announcing a legislative framework for data governance (Q4 2020) and a
possible Data Act (2021).
- Ongoing evaluation and review of the fitness of EU competition rules for the digital age
(2020-2023), and launch of a sector inquiry (2020).
- The Commission will further explore, in the context of the Digital Services Act package, ex
ante rules to ensure that markets characterised by large platforms with significant network
effects acting as gate-keepers, remain fair and contestable for innovators, businesses, and
new market entrants. (Q4 2020).
-
- Propose an Industrial Strategy Package putting forward a range of actions to facilitate the
transformation towards clean, circular, digital and globally competitive EU industries,
including SMEs and the reinforcement of single market rules.
- Create a framework to enable convenient, competitive and secure Digital Finance, including
legislative proposals on crypto assets, and on digital operational and cyber resilience in the
financial sector and a strategy towards an integrated EU payments market that supports pan-
European digital payment services and solutions (Q3 2020);
- Communication on Business Taxation for the 21st century, taking into account the
progress made in the context of the Organisation for Economic Co-operation and
Development (OECD) to address the tax challenges arising from the digitisation of the
economy.
- Delivering a new Consumer Agenda, which will empower consumers to make informed
choices and play an active role in the digital transformation (Q4 2020).
C. An open, democratic and sustainable society
People are entitled to technology that they can trust. What is illegal offline must also be illegal
online. While we cannot predict the future of digital technology, European values and ethical
rules and social and environmental norms must apply also in the digital space.
In recent years, Europe has led the way towards an open, fair, inclusive and people-centric
internet with its standard-setting General Data Protection Regulation and its rules for
platform-to-business cooperation. In order to protect European democracies and the values
underpinning them, the Commission will continue to develop and implement innovative and
proportionate rules for a trustworthy digital society. Such a digital society should be fully
inclusive, fair and accessible for all.
10
In this context, it is essential that the rules applicable to digital services across the EU are
strengthened and modernised, clarifying the roles and responsibilities of online platforms. The
sale of illicit, dangerous or counterfeit goods, and dissemination of illegal content must be
tackled as effectively online as it is offline.
Trust in the online world also means helping consumers take greater control of and
responsibility for their own data and identity. Clearer rules on the transparency, behaviour and
accountability of those who act as gatekeepers to information and data flows are needed, as is
effective enforcement of existing rules. People should also be able to control their online
identity, when authentication is needed to access certain online services. A universally
accepted public electronic identity (eID) is necessary for consumers to have access to their
data and securely use the products and services they want without having to use unrelated
platforms to do so and unnecessarily sharing personal data with them. Europeans can also
benefit from use of data to improve public as well as private decision-making.
In a world where much of the public debate and political advertising has moved online, we
must also be prepared to act to forcefully defend our democracies. Citizens want meaningful
answers to attempted manipulations of the information space, often in the form of targeted
and coordinated disinformation campaigns. Europe needs greater transparency on the ways in
which information is shared and managed on the internet. Trustworthy quality media is key
for democracy as well as for cultural diversity. With these in mind, the Commission will
present a European Democracy Action Plan and a specific action plan for the media and
audiovisual sector.
The digital component will also be key in reaching the ambitions of the European Green
Deal14 and the Sustainable Development Goals15. As powerful enablers for the sustainability
transition, digital solutions can advance the circular economy, support the decarbonisation of
all sectors and reduce the environmental and social footprint of products placed on the EU
market. For example, key sectors such as precision agriculture, transport and energy can
benefit immensely from digital solutions in pursuing the ambitious sustainability objectives of
the European Green Deal.
Digital solutions, and data in particular, will also enable a fully integrated life-cycle approach,
from design through sourcing of energy, raw materials and other inputs to final products until
the end-of-life stage. For example, by tracking when and where electricity is most needed, we
can increase energy efficiency and use fewer fossil fuels.
14
The European Green Deal, COM(2019) 640 final, 11 Dec. 2019:
https://ec.europa.eu/info/sites/info/files/european-green-deal-communication_en.pdf
15
The Sustainable Development Goals (SDG) are a collection of 17 global goals designed to be a “blueprint to
achieve a better and more sustainable future for all”. They were set by the UN General Assembly, as part of UN
resolution 70/1, in 2015: https://www.un.org/sustainabledevelopment/sustainable-development-goals/.
11
Yet it is also clear that the ICT sector also needs to undergo its own green transformation. The
environmental footprint of the sector is significant, estimated at 5-9% of the world's total
electricity use and more than 2% of all emissions.16 Data centres and telecommunications will
need to become more energy efficient, reuse waste energy, and use more renewable energy
sources. They can and should become climate neutral by 2030.
How ICT equipment is designed, bought, consumed and recycled also matters. Beyond the
energy efficiency requirements of Ecodesign, ICT equipment must become fully circular -
designed to last longer, to be properly maintained, to contain recycled material and to be
easily dismantled and recycled.
The power of data is essential also in the health sector. Digitised health records, gathered in a
European health data space, can lead to better treatment for major chronic conditions,
including cancer and rare diseases, but also to equal access to high quality health services for
all citizens.
Key actions
- New and revised rules to deepen the Internal Market for Digital Services, by increasing
and harmonising the responsibilities of online platforms and information service providers
and reinforce the oversight over platforms’ content policies in the EU. (Q4 2020, as part of
the Digital Services Act package).
- Revision of eIDAS Regulation to improve its effectiveness, extend its benefits to the
private sector and promote trusted digital identities for all Europeans (Q4 2020)
-
- Media and audiovisual Action Plan to support digital transformation and competitiveness
of the audiovisual and media sector, to stimulate access to quality content and media
pluralism (Q4 2020)
- European Democracy Action Plan to improve the resilience of our democratic systems,
support media pluralism and address the threats of external intervention in European
elections (Q4 2020)
- Destination Earth, initiative to develop a high precision digital model of Earth (a “Digital
Twin of the Earth”) that would improve Europe’s environmental prediction and crisis
management capabilities (Timing: from 2021).
- A circular electronics initiative, mobilising existing and new instruments in line with the
policy framework for sustainable products of the forthcoming circular economy action plan,
16
World Energy Forum: https://www.enerdata.net/publications/executive-briefing/expected-world-energy-
consumption-increase-from-digitalization.html.
12
to ensure that devices are designed for durability, maintenance, dismantling, reuse and
recycling and including a right to repair or upgrade to extend the lifecycle of electronic
devices and to avoid premature obsolescence (2021).
- Initiatives to achieve climate-neutral, highly energy-efficient and sustainable data centres by
no later than 2030 and transparency measures for telecoms operators on their environmental
footprint.
- The promotion of electronic health records based on a common European exchange
format to give European citizens secure access to and exchange of health data across the
EU . A European health data space to improve safe and secure accessibility of health data
allowing for targeted and faster research, diagnosis and treatment ( from 2022).
3. The international dimension – Europe as a global player
The European model has proved to be an inspiration for many other partners around the world
as they seek to address policy challenges, and this should be no different when it comes to
digital.
In geopolitical terms, the EU should leverage its regulatory power, reinforced industrial and
technological capabilities, diplomatic strengths and external financial instruments to advance
the European approach and shape global interactions. This includes the work done under
association and trade agreements, as well as agreements reached in international bodies such
the United Nations, the OECD, ISO and the G20, with the support of EU Member States.
A strong digital presence in the EU’s enlargement, neighbourhood and development policy
will enable growth and drive sustainable development, including the uptake of green ICT in
partner countries and regions, in accordance with Europe’s commitment to the 2030 Agenda
for Sustainable Development. The conclusions of the EU-African Union Digital Economy
Task Force will underpin the support for the digital transformation in Africa, including the
creation of a single African Digital Market as funding becomes available under the EU’s new
Multiannual Financial Framework.
Many countries around the world have aligned their own legislation with the EU’s strong data
protection regime. Mirroring this success, the EU should actively promote its model of a safe
and open global Internet.
In terms of standards, our trading partners have joined the EU-led process that successfully set
global standards for 5G and the Internet of Things. Europe must now lead in the adoption and
standardisation process of the new generation of technology: blockchain, supercomputing,
quantum technologies, algorithms and tools to allow data sharing and data usage.17
17
For example, the use of the EU eInvoicing standard in Australia, New Zealand and Singapore, has been a
success, acting as a trade facilitator for EU businesses and is being considered for use at international level.
13
As regards trade and investment, the Commission will continue to address unjustified
restrictions for European companies in third countries, such as data localisation requirements,
and pursue ambitious goals in terms of market access, respect of intellectual property,
research and development and standardisation programmes. The ongoing discussions about
building a trustworthy data alliance with like-minded partners who share our values and high
standards could enhance data flows and the pool of available high-quality data.
The European Union is and will remain the most open region for trade and investment in the
world, provided that anyone who comes to do business here accepts and respects our rules.
The Commission will use all instruments at its disposal to ensure that everyone respects EU
legislation and international rules to maintain a level playing field in the digital sector. It will
also propose new rules where necessary, such as the ongoing work to develop a legal
instrument to deal with the distortive effects of foreign subsidies in the internal market.
A Global Digital Cooperation Strategy will put forward a European approach to the digital
transformation that builds on our long and successful history of technology, innovation and
ingenuity, vested in European values, including openness, and will project them onto the
international stage and engage with our partners. It will also reflect the EU's work in Africa
and elsewhere with respect to the Sustainable Development Goals, "Digital4Development"
and capacity building.
Europe is at the forefront in addressing manipulative interference in its information space and
has developed important approaches and instruments. It will continue to work closely with its
international partners, such as the G7, to find common approaches with a view to developing
international norms and standards.
Key actions
- A Global Digital Cooperation Strategy (2021).
- A White Paper on an instrument on foreign subsidies (Q2 2020).
- A Digital for Development Hub that will build and consolidate a whole-of-EU approach
promoting EU values and mobilising EU member states and EU industry, Civil Society
Organisations (CSOs), financial institutions, expertise and technologies in digitisation.
- A strategy for standardisation, which will allow for the deployment of interoperable
technologies respecting Europe’s rules, and promote Europe’s approach and interests on the
global stage (Q3 2020).
- Mapping of opportunities and action plan to promote the European approach in bilateral
relations and multilateral fora (Q2 2020).
14
4. Conclusion
Digital technologies, as advanced as they may be, are just a tool. They cannot solve all of our
problems. Yet they are making things possible which were unthinkable a generation ago. The
success of Europe’s digital strategy will be measured in how well we are able to put these
tools to work in delivering public goods to European citizens.
The data-agile economy and its enormous transformative potential will affect all of us and
Europe stands ready to make full use of the advantages it will bring. Yet for this digital
transformation to be fully successful, we will need to create the right frameworks to ensure
trustworthy technology and to give businesses the confidence, competences and means to
digitalise. Coordination of efforts between the EU, Member States, regions, civil society and
the private sector is key to achieving this and strengthening European digital leadership.
Europe can own this digital transformation and set the global standards when it comes to
technological development. More importantly still, it can do so while ensuring the inclusion
and respect of every single human being. The digital transformation can only work if it works
for all and not for only a few. It will be a truly European project – a digital society based on
European values and European rules - that can truly inspire the rest of the world.
15