Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market

Similar documents
ANNEX: cross border electronic transactions. The old framework the e Signature Directive of 1999 was a big step. However, the European

European Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the EU internal market

COMMISSION STAFF WORKING DOCUMENT EXECUTIVE SUMMARY OF THE IMPACT ASSESSMENT. Accompanying the document

eidas Regulation (EU) 910/2014 Gábor Bartha DG CONNECT, European Commission Unit "e-government and Trust"

Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (eidas)

eidas Regulation (EU) 910/2014 " eidas Regulation: Boosting trust in the Digital Single Market"

eidas Regulation (EU) 910/2014 "Boosting trust in the digital market"

Francesco Martini Manager Risk Advisory Deloitte Luxembourg

Remote e-identification and e-signatures Trusting someone you have never seen

Feasibility study on an electronic identification, authentication and signature policy (IAS)

2.2 SEMANTIC INTEROPERABILITY FOR REPRESENTATION POWERS AND MANDATES ( )

Legal Aspects of Identity Management

ILAC Mutual Recognition Arrangement: Policy and Management ILAC-P4:06/2017

Digital Transport and Logistics Forum (DTLF) Electronic Freight Transport Information (EFTI) European Maritime Single Window environment (EMSWe)

eidas Regulation: validation

Overcoming Barriers in the field of Authentication and Identification

Regulation beyond the Postal Directive. Impact and Opportunities for Postal Operators. Seminar on Postal Economics WiK

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING PAPER. Annex to the COMMUNICATION FROM THE COMMISSION

E-invoicing in public procurement

European Parliament resolution of 8 March 2011 on the revision of the General Product Safety Directive and market surveillance (2010/2085(INI))

Fitness Check of environmental monitoring and reporting

Recommendation for a COUNCIL DECISION

ERPB REACTION TO THE EUROPEAN COMMISSION S GREEN PAPER ON RETAIL FINANCIAL SERVICES

Proposal for a COUNCIL DECISION

CORA - MODERNIZING PUBLIC ADMINISTRATION IN SPAIN

Challenges of eid Interoperability: The STORK Project

COMMISSION STAFF WORKING DOCUMENT EXECUTIVE SUMMARY OF THE IMPACT ASSESSMENT. Accompanying the document

EUROLAB European Federation of National Associations of Measurement, Testing and Analytical Laboratories

CATALOGUE OF SERVICES ( ) IDENTIFICATION OF THE ACTION EXECUTIVE SUMMARY

e-sens white paper D3.4 Preliminary Proposal for a governance body Instruments Deliverable 3.4, version 3

7800/16 AFG/evt 1 DG G 3 C

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING DOCUMENT. accompanying document to the COMMUNICATION FROM THE COMMISSION

Standards and accreditation. Tools for policy makers and regulators

Council of the European Union Brussels, 19 February 2015 (OR. en)

COMMISSION DECISION. of

Copyright 2008 by Peter Sonntagbauer

EBA/RTS/2017/ December Final Report. Draft regulatory technical standards. on central contact points under Directive (EU) 2015/2366 (PSD2)

A scheme for a sustainable e-id interoperability

COMMISSION OF THE EUROPEAN COMMUNITIES

Product Safety and Market Surveillance Package

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING DOCUMENT

Official Journal C 271 A. of the European Union. Information and Notices. Announcements. Volume 60. English edition. 17 August 2017.

Open Science policy: Results of the consultation on "Science 2.0: Science in transition and possible follow up. J.C. Burgelman

Intelligent Transport Systems Action Plan and Directive

Background paper. Consulting the public when preparing EU law

2. The Competitiveness Council hereby submits this Key Issues Paper as its contribution to the Spring European Council 2008.

Proposal for a COUNCIL DECISION

Clean Power for Transport. The Directive on the deployment of alternative fuels infrastructure

Explanatory Note on the CSM Assessment Body in Regulation (EU) N 402/2013 and in OTIF UTP GEN-G of on the CSM for risk assessment

Success factors for governments and business in standards-based cross-border implementations: the case of e-procurement

REFIT Platform Opinion

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL

A new Directive on Energy Efficiency and latest information about the Intelligent Energy Europe programme

Common methodology for environmental footprinting: status and future

Explanatory Note on the CSM Assessment Body in Regulation (EU) N 402/2013 and in OTIF UTP GEN- G of on the CSM for risk assessment

Common methodology for environmental footprinting: status and future

Trusted KYC Data Sharing Standards Scope and Governance Oversight

INTERNATIONAL IDENTITY LAW

Explanatory Note on the CSM Assessment Body in Regulation (EU) N 402/2013 and in OTIF UTP GEN- G of on the CSM for risk assessment

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL. Results of the final evaluation of the ISA programme. {SWD(2016) 279 final}

SWIFT Response to The European Commission s Green Paper on Retail Financial Services

Explanatory Note on the CSM Assessment Body in Regulation (EU) N 402/2013 and in OTIF UTP GEN- G of on the CSM for risk assessment

FRAMEWORK BORDER-CROSSING AGREEMENT

ICT Security Certification 2017

ROADMAP. A. Context, Subsidiarity Check and Objectives

COMMISSION OF THE EUROPEAN COMMUNITIES COMMUNICATION FROM THE COMMISSION. Completing SEPA: a Roadmap for

The EU Single Market for Green Products initiative (SMGP)

COUNCIL OF THE EUROPEAN UNION. Brussels, 26 November 2013 (OR. en) 16162/13 Interinstitutional File: 2013/0213 (COD)

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION RECOMMENDATION. of

COMMISSION OF THE EUROPEAN COMMUNITIES

CEMR RESPONSE. Green Paper on e-procurement. Brussels, January 2011

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Principles & Guidance for eidas interoperability track eidas and IAM working side by side 14 November 2017

Clean Power for Transport. Implementaton of Directive 2014/94/EU on the deployment of alternative fuels infrastructure

The Austrian Citizen Card

1. Analysis of the factual situation presented in the Green Paper

On the Way to a Europe-wide FinTech Regulatory Sandbox?

COMMISSION OF THE EUROPEAN COMMUNITIES COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL

Framework for the deployment of ITS in Europe State of Play

COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS

Council of the European Union Brussels, 11 June 2018 (OR. en)

EVALUATION ROADMAP DATE OF THIS ROADMAP PLANNED START DATE PLANNED COMPLETION DATE PLANNING CALENDAR

Conclusions on clean and energy-efficient vehicles for a competitive automotive industry and decarbonised road transport

14828/18 CDP/LM/rcg 1 ECOMP 3.B. LIMITE EN

SUMMARY OF THE IMPACT ASSESSMENT

Shifting Gears for a New EU Industrial Partnership. A Manifesto

EA MULTILATERAL AGREEMENT Facilitating cross border trade with reliable goods and services

DGE 2 EUROPEAN UNION. Brussels, 21 March 2018 (OR. en) 2016/0149 (COD) PE-CONS 69/17

What is known about implementation of the new directive in national legislation? Directive 2001/115/EC

the council initiative on public engagement

ROLE OF THE APEC SPECIALIST REGIONAL BODIES ELEMENTS OF THE STANDARDS AND CONFORMANCE INFRASTRUCTURE

ERAC 1206/16 MI/evt 1 DGG 3 C

The implementation of the Energy Efficiency Directive in Europe

15050/17 VK/nc 1 DGE 2A

Working Party on Information Security and Privacy

COMMISSION RECOMMENDATION. of on the professionalisation of public procurement

The next step in creating Electronicc Ticketing Interoperability for Europe

Connecting dots Can we collaborate better on digital health?

Online Platforms. Opportunities and Challenges for the DSM

Transcription:

ehealth Governance Initiative eid Workshop Brussels, 11-12th February 2013 Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market Gábor Bartha Policy Officer Legislation Team (eidas) European Commission - DG ConNECT gabor.bartha@ec.europa.eu 1

What is the proposal's ambition? Strengthen EU Single Market by boosting TRUST and CONVENIENCE in secure and seamless cross-border electronic transactions

Who will benefit from the proposal? 13 million EU citizens work in another EU country 21 millions of SMEs of which a significant part is working internationally Some 150 million EU citizens shop online. However, only 20% of them buy goods and services from another EU state

How? 1. By ensuring that people and businesses can use and leverage across borders their national eids to access at least public services in other EU countries.

How? 2. By removing the barriers to the internal market for e-signatures and related online trust services across borders i.e. by ensuring that trust services have the same legal value as in traditional paper based processes.

What is our political commitment? Digital Agenda for Europe, 19.5.10, COM(2010)245 European egov Action Plan 2011-15, 15.12.10, COM(2010)743 Single Market Act, 13.4.11, COM(2011)206 A roadmap to stability and growth, 12.10.11, COM(2011)669 Commission Work Programme 2012, 15.11.11, COM(2011)777 6

Consultation process Informal consultations and discussions: from launch of Action Plan on esig. and eid, 28.11.08, COM(2008)798 European Parliament EU Member States Multialteral meetings Services Directive technical group on e-procedures Stakeholders FESA (Forum of European Supervisory Authorities) meetings Public online consultation Feb-Apr 2011 SME survey Oct-Dec 2011 Liaison with large scale project, especially STORK Participation to public conferences Numerous bilateral meetings with stakeholders Studies (IAS Study, Crobies, IDABC studies, ) 12 years of operation of esig Directive (infringements, ) 7

What is the scope of the proposed Regulation? 1. Mutual recognition of electronic identification 2. Electronic trust services: Electronic signatures interoperability and usability Electronic seals interoperability and usability Cross-border dimension of: 1.Time stamping, 2.Electronic delivery service, 3.Electronic documents admissibility, 4.Website authentication. 8

Mutual recognition and acceptance of eid A EU Member State: 1. May notify to European Commission the national electronic identification scheme(s) used at home, at least, for access to public services; 2. Must recognise and accept notified eids of other Member States for cross-border access to its online services which require e-identification by national law; 3. Must provide online free ID data authentication facility; 4. Is liable for unambiguous identification of persons and for authentication; 5. May allow the private sector to use notified eid 9

What is not covered? eid Member States are not obliged to have an e- identification scheme Member States are not obliged to notify their e- identification scheme(s) «Notified» eids are not necessarily ID cards No "EU database" of any kind No "EU eid" No coverage «soft ID» (ex. Facebook); only «official eid» 10

Why will it make a difference? Comprehensive toolbox of trust building instruments One single legislation across EU Foster eid usage ( world premiere ): Leverage eid cards and mobile ID infrastructure Reliable eid to allow cross border ebusiness and enable egov services Private sector is invited to build on «notified» eid schemes Leverage Large Scale Pilot project STORK 11

Electronic identification Art 5: Mutual recognition and acceptance Mutual recognition and acceptance Art. 5 Subsidiarity respected, not harmonisation but mutual recognition Mandatory acceptance if electronic identification is required by law Only on-line use (not on the spot) Trust model: between Member States, therefore no minimum technical requirements, no supervision at EU level 12

Electronic identification Art 6: Conditions of notification of electronic identification schemes (1/2) Conditions Art. 6(1) a) Art. 6(1) b) Issued by, on behalf or under the responsibility "issued by" a Member State if a public body is responsible for the issuance "on behalf of" refers to the issuance under the control and in the name of the Member State. "under the responsibility": the Member State recognises the existence and the legal effect of the electronic identification means issued by the issuer and takes the responsibility for damages and ensures that the other conditions are fulfilled Used to access at least public services in the notifying Member State Use for private services is not excluded Art. 6(1) c) Unambiguous identification Does not require a single "unique" identifier, Citizens (businesses) can possess multiple eid means if those are unambiguously linked to that person Details of how unambiguous attribution is provided remains within 13 Member State competence

Electronic identification Art 6: Conditions of notification of electronic identification schemes (2/2) Art. 6(1) d) Authentication Free online authentication business model national competence, avoid barriers Prohibits the introduction at national level of any additional specific technical requirements (such as certificates or hardware) on relying parties established outside of their territory necessary for cross border authentication Member States are free to choose if cross border authentication is through gateways, middleware (like in STORK) or any other national solution In case of compromise of the whole scheme: withdrawal Partial data compromise: negative result of validation Member States cannot refuse accepting an eid scheme in case of data compromise 14

Electronic identification Art 6: Conditions of notification of electronic identification schemes (2/2) Art. 6(1) e) and (2) Liability not an absolute one (fault based) no responsibility for the whole transaction, only for unambiguous attribution and authentication liability remains regulated by national law 15

Electronic identification Art 7: Notification Notification Art. 7 (1) Basic information on the eid scheme Art. 7 (2)- (3) Commission publishes, but checks only formalities 6 months first bunch then within 3 months 16

Electronic identification Art 8: Coordination Coordination Art. 8(1) All MSs cooperate, in a free form Art. 8(2) Peer review modalities facilitated by Commission through a formal expert group as per C(2010)7649 of 10.11.10 Art. 8(3) Minimum technical requirements if necessary Security levels if necessary different assurance levels for various sectors possible 17

Indicative process Legislative process Commission Proposal 4.6.2012 Cyprus Presidency report Parliament + Council adoption Standardisation mandate m460 Standards Delegated/Implementing acts Commission Decisions 2011 2012 2013 2014 2015 2016 NB. Dates are indicative 18