This report has been prepared in the context of the research and innovation programme entitled ‘SEcurity and RIghts in the CyberSpace- SERICS’ - theme 7 ‘Cybersecurity, new technologies and protection of rights’ and in particular for the project: ‘Digital sovereignty’ (DISE), financed, following the call ‘Human, social, and legal aspects’, to carry out activities in Spoke 1, no. 2, CUP: B53C22003950001, of Mission 4 ‘Education and Research’, component 2, (PE 0000014) of PNRR. Within the DISE project, the project proposal ‘Enforcement and Monitoring of Data Sovereignty policies’ (EMDAS) was funded, for the benefit of the partnership composed of the lead partner University of Naples Parthenope and the partner University of Trento (UNITN). The project was placed in WP1 of DISE. As indicated in the EMDAS project, the partnership’s activities aim at enhancing the cybersecurity and resilience of digital infrastructures, by enabling trust mechanisms in the data exchange, which is vital for their development, given the importance of data sharing for innovative business and public administration services in Italy and in the European Union. The research considers the complexity of ensuring high standards of confidentiality and reliability throughout the life cycle of such data. EMDAS includes the study, research and experimentation activities on: legal aspects of cybersecurity and privacy and digital technologies (Task 1.1. Analysis of the requirements deriving from the study of laws and regulations on digital sovereignty); tools and technologies for digital and data sovereignty (Task 1.2 Technologies to support digital sovereignty in particular for the definition and semi-automatic understanding of regulations); technologies for network security, technologies for security and data protection in the energy and transport domains (Task 1.3 Analysis of some socio-economic aspects of digital sovereignty). This report is included in Task 1.1. and is the result of research work carried out at the University of Trento. In particular this report explores the apparent paradox of digital sovereignty with regard to the twin transition in the energy sector. The main argument is that the multiple meanings of digital sovereignty allow the EU and the Member States to implement regulatory measures that shape their industrial policies. A distinction between the collective and the individual dimension of digital sovereignty is proposed to analyse the contents of such regulatory choices in two domains: cybersecurity and data protection. Reference is made to both EU horizontal legislation and to legislation in the energy sector. Italian legislation is analysed to assess how sovereignty concerns are taken up at Member State level. The report concludes with four policy recommendations, related to the joint assessment of the collective and individual dimensions, the geopolitical relevance of sustainability standards, the mechanisms to control supply chains, and the conflicting sovereignty claims in the energy sector.
Giuseppe Bellantuono (Thu,) studied this question.