19.7.2016
EN
Official Journal of the European Union
L 194/11
(71)
The Commission should periodically review this Directive, in consultation with interested stakeholders, in
particular with a view to determining the need for modification in the light of changes to societal, political,
technological or market conditions.
(72)
The sharing of information on risks and incidents within the Cooperation Group and the CSIRTs network and
the compliance with the requirements to notify incidents to the national competent authorities or the CSIRTs
might require processing of personal data. Such processing should comply with Directive 95/46/EC of the
European Parliament and the Council (1) and Regulation (EC) No 45/2001 of the European Parliament and of the
Council (2). In the application of this Directive, Regulation (EC) No 1049/2001 of the European Parliament and
of the Council (3) should apply as appropriate.
(73)
The European Data Protection Supervisor was consulted in accordance with Article 28(2) of Regulation (EC)
No 45/2001 and delivered an opinion on 14 June 2013 (4).
(74)
Since the objective of this Directive, namely to achieve a high common level of security of network and
information systems in the Union, cannot be sufficiently achieved by the Member States but can rather, by reason
of the effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with
the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the
principle of proportionality as set out in that Article, this Directive does not go beyond what is necessary in
order to achieve that objective.
(75)
This Directive respects the fundamental rights, and observes the principles, recognised by the Charter of
Fundamental Rights of the European Union, in particular the right to respect for private life and communications,
the protection of personal data, the freedom to conduct a business, the right to property, the right to an effective
remedy before a court and the right to be heard. This Directive should be implemented in accordance with those
rights and principles,
HAVE ADOPTED THIS DIRECTIVE:
CHAPTER I
GENERAL PROVISIONS
Article 1
Subject matter and scope
1.
This Directive lays down measures with a view to achieving a high common level of security of network and
information systems within the Union so as to improve the functioning of the internal market.
2.
To that end, this Directive:
(a) lays down obligations for all Member States to adopt a national strategy on the security of network and information
systems;
(b) creates a Cooperation Group in order to support and facilitate strategic cooperation and the exchange of
information among Member States and to develop trust and confidence amongst them;
(c) creates a computer security incident response teams network (‘CSIRTs network’) in order to contribute to the
development of trust and confidence between Member States and to promote swift and effective operational
cooperation;
(1) Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to
the processing of personal data and on the free movement of such data (OJ L 281, 23.11.1995, p. 31).
(2) Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with
regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (OJ L 8,
12.1.2001, p. 1).
(3) Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European
Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).
(4) OJ C 32, 4.2.2014, p. 19.