Author

Parlamentul European și Consiliul Uniunii Europene

5 reading cards from 5 books · 2016–2024.

Book
Shelf

5 cards

  1. Regulamentul general privind protecția datelor (GDPR) · 2016

    Pseudonymised still means personal data — only the key lives in another room.

    The regulation's definition, read as architecture, is a three-part schema. The identity vault: name, e-mail, national identifier, address — encrypted, access-restricted, in its own system. The token map: the link between a person and a pseudonym, either a random surrogate or an HMAC with a secret key; a plain hash of the e-mail is not enough, it is reversed with a dictionary. The warehouse: the facts, keyed by token. Analysts see tokens and behaviour, never identities; the join back is possible only for whoever holds the key, and is audited. What you gain: erasing a person becomes deleting the row from the vault — the facts remain, but lead to no one; access to identity is granted separately from access to analysis; "where is this person's data" is answered from provenance (lesson 15). What you do not gain: pseudonymised data is still personal data, because the additional information exists. All obligations remain; the risk drops. Real anonymisation is a different threshold, with traps of its own — lesson 20.

    'pseudonymisation' means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person

    Open the card

  2. Regulamentul (UE) 2022/2554 privind reziliența operațională digitală a sectorului financiar · 2022

    DORA asks for proof that resilience works, not proof that it was planned.

    Regulation (EU) 2022/2554 applies directly to financial entities from 17 January 2025 and rests on five pillars: management of information and communication technology risk, incident handling and reporting, digital operational resilience testing, third-party technology provider risk, and information sharing on threats. Two requirements have no equivalent in a classic management system. The first is the register of information: every contractual arrangement for technology services, with the function it supports, in a form the supervisor can demand in full. The second is advanced threat-led testing, mandatory at least once every three years for entities identified by the competent authority — a simulation against live systems, not a vulnerability scan. Above them, providers designated as critical fall under the direct oversight of the European supervisory authorities. A certified system covers the first pillar well and much of the second; the rest asks for new things.

    Financial entities shall have in place an internal governance and control framework that ensures an effective and prudent management of ICT risk, in accordance with Article 6(4), in order to achieve a high level of digital operational resilience.

    Open the card

  3. Directiva (UE) 2022/2555 privind măsuri pentru un nivel comun ridicat de securitate cibernetică în Uniune · 2022

    Management approves the measures and answers for them: NIS2 no longer leaves security at the level of the technical department.

    Directive (EU) 2022/2555, NIS2 for short, is transposed in Romania by Emergency Ordinance 155/2024, published in the Official Gazette no. 1332 of 31 December 2024; the competent authority is the National Cyber Security Directorate. Covered entities split into essential and important, and the difference lies in the supervisory regime and the ceiling on fines, not in the set of measures. Article 21 requires appropriate and proportionate measures, on an all-hazards approach, and lists ten minimum categories: risk analysis, incident handling, continuity, supply chain security, secure acquisition and development, assessment of effectiveness, cyber hygiene and training, cryptography, human resources security and access control, multi-factor authentication. Article 23 sets the tempo: early warning within 24 hours, notification within 72, final report within one month. Article 20 says the management body approves the measures and can be held liable.

    Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.

    Open the card

  4. Regulamentul (UE) 2024/1689 de stabilire a unor norme armonizate privind inteligența artificială · 2024

    The harmonized structure allows one management system with two risk registers, not two parallel systems.

    Regulation (EU) 2024/1689 applies in tiers. The prohibited practices and the general provisions apply from 2 February 2025, the duties for general-purpose models from 2 August 2025, and the regulation's general application from 2 August 2026. For the high-risk systems of Annex III, the "digital omnibus" package deferred the obligations to 2 December 2027 — the state of play in September 2026. Article 9 requires a risk management system established, implemented, documented and maintained across the whole life cycle of the high-risk system: an iterative process, not a folder. This is where the harmonized structure of management system standards pays off. ISO/IEC 42001:2023, the standard for artificial intelligence management systems, uses the same clauses 4-10 as ISO/IEC 27001, so context, roles, internal audit and management review are run once. What is added is specific: the inventory of systems, the impact assessment on people, training data, human oversight.

    A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.

    Open the card

  5. Regulamentul (UE) 2024/2847 privind cerințe orizontale de securitate cibernetică pentru produsele cu elemente digitale · 2024

    From 11 September 2026, the 24-hour clock starts the moment the manufacturer learns of an actively exploited vulnerability.

    Regulation (EU) 2024/2847, the cyber resilience act for short, moves liability onto the manufacturer: the product must be designed, developed and produced against the essential requirements of Part I of Annex I, and the risk is assessed and documented across the whole support period. In practice that means shipping with no known exploitable vulnerabilities, secure default configuration, security updates and a software bill of materials covering top-level dependencies. The calendar is tiered. The reporting duties of Article 14 apply from 11 September 2026: an actively exploited vulnerability is announced by an early warning within 24 hours, a notification within 72 hours and a final report within 14 days. The rest of the regulation applies from 11 December 2027. For anyone who already holds a certified system, the secure development controls of Annex A, 8.25-8.28, from the secure life cycle to secure coding, are exactly where to start.

    When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I.

    Open the card