After the traditional August lull, the EU is back in full swing with a frenzy of activity around digital law-making! Three major digital consultations have deadlines within a week, so don’t miss the boat.
With the Brussels machine back up to speed, this is a good moment to take stock of where your input can still make a difference. From shaping the EU’s approach to emerging technologies to feeding into the rules that will govern Europe’s digital future, the window to weigh in is closing fast. Here are the consultations you’ll want on your radar.
Tuning in to Europe’s telecoms future
The European Commission is preparing for its involvement at next year’s World Radiocommunication Conference (WRC) in October 2027 in Shanghai.
To help shape the EU position, it has asked stakeholders for input. Through this call for evidence, the Commission is gathering views ahead of the planned proposal for a Council decision in the first quarter of 2027. Hence the early deadline of 11 September.
The WRC is organised every three or four years by the International Telecommunication Union, the United Nations’ specialised agency for telecommunications. It reviews and sometimes revises the international rules governing the use of the radio-frequency spectrum. The treaty also governs the use of geostationary and non-geostationary satellite orbits.
The 2027 agenda includes items that could impact Copernicus and IRIS², as well as a plethora of EU laws covering telecoms and broadband connectivity.
Who watches the cyber-watchers?
The European Union Agency for Cybersecurity (ENISA) is consulting on its draft certification scheme for managed security services, with responses due by 13 September.
The scheme will certify outsourced cybersecurity providers and support the EU Cybersecurity Reserve.
Managed security services (MSS) are specialised third-party companies that outsource and manage cybersecurity operations, threat monitoring, and regulatory compliance for organisations operating in the EU.
They help organisations comply with EU rules such as the General Data Protection Regulation (GDPR), the Network and Information Security Directive (NIS) and the Digital Operational Resilience Act (DORA). MSS providers run 24/7 security operations to monitor threats and block cyber attacks in real time. They also perform vulnerability assessments, fix flaws and investigate breaches.
As such, they themselves must adhere to high standards. ENISA has been tasked with coming up with a way to certify them.
The draft of the scheme builds on existing European cybersecurity certification practices and assessment methodologies. It is designed to provide a harmonised framework that will support “cross-border service provision and Union-level crisis response capabilities”.
“It is of utmost importance that the agency, with assistance of trusted MSS, can support member states to prepare as well as respond to an incident. Certifying MSS is essential to ensure a certain level of quality and security of services offered in the single market,” ENISA Executive Director Juhan Lepassaar said. “Taking this step will not only foster confidence and trust within the EU but it can also significantly facilitate the selection of trusted providers for the EU Cybersecurity Reserve.”
Keeping Europe’s data in safe hands
The Commission also opened yet another public consultation on how to safeguard the EU’s data sovereignty on 8 July. This “targeted” consultation asks “actors in the data value chain across different sectors” to examine the risks linked to third-country access to sensitive data.
The Data Union Strategy and the Sovereignty Package already covered a much of this ground last year. But the Commission still wants to know whether organisations encountered barriers, restrictions, risks or other issues when sharing or using data in a third country.
This covers a huge number of possibilities, legal, technical and organisational such as “authorisation, licensing or certification requirements, administrative delays, forced data transfers or access, lack of transparency, discriminatory treatment, contractual or administrative restrictions, informal expectations, legal uncertainty, data leakage to third parties, public-authority or judicial access risks, or unauthorised reuse”.
The Commission also asks respondents to rate the impact on a scale from “very limited” to “ very significant.”
The next big question is whether, in the last three years, an organisation been required, formally or informally, to provide access to sensitive non-personal data to a public authority in a third country “as a condition for market access, authorisation, certification, public procurement, security review or regulatory approval”.
These are important questions and the deadline for responses is 15 September.