This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Amendments to the National Cybersecurity Law
- A private legal entity performing delegated tasks of public administration is not automatically a legal subject of the law. Private legal entities performing delegated tasks are excluded from the list of state and municipal institutions subject to legal requirements. - A commercial company important to national security is a legal subject of the law (except for those with a status of a company significant to national security based on ownership of forest or agricultural land). Commercial companies, associations, and foundations important to national security, considering their role in societal safety and national defense, meet the criteria of essential service providers. To clarify and make more effective the list of essential and critical service providers, all related issues are transferred to the Center’s competence – the Center assesses and decides on the compliance of persons with the status of a legal subject, compiles and approves the list of essential and critical service providers. The Center also has the right to exclude from the list a state or municipal institution whose disruption cannot significantly affect societal safety, national defense, public health, or create a substantial systemic risk. Security requirements for personnel are established – entities have the right to obtain information from the Criminal Records Register about the criminal history of certain ICT sector employees to identify and assess security risks and the suitability of persons for the position. Entities are required to identify and evaluate security risks when hiring persons granted privileged access rights to systems or information and communication technology resources that directly impact the entity’s core activities.