“Pravova derzhava”. Issue 35 (2024), pages 667–682.
DOI: 10.33663/0869-2491-2024-35-667-682
Falalieieva Liudmyla, Strilets Bohdan
Paradigm of cybersecurity in European Union law: modern realities in the context of digitalisation
The study analyses the current paradigm of cybersecurity in the law of the European Union in the context of digitalisation. The authors highlight the doctrinal approaches to the defi nition of cybersecurity within this integration association. They analyse the EU acts which emphasise the importance of cybersecurity for ensuring the functioning of the EU internal market rather than ensuring the observance of human rights, especially fundamental rights, which cannot be considered justifi ed. It is noted that EU law does not explicitly defi ne the dichotomy of the cybersecurity paradigm, but it does allow for the distinction between its private and public components. The private component of cybersecurity is focused on protecting the rights and interests of individuals and companies from interference in their social, economic and other private relations. At the same time, the public component of cybersecurity focuses on protecting against cyber threats that threaten the national interests of EU Member States, the interests of the EU itself, and critical infrastructure. The outlined dual nature of cybersecurity requires adequate legislative regulation, especially given the diff erent approaches and capabilities of Member States in ensuring cybersecurity. The authors believe that in this context, the experience of Ukraine, as a country that has not only achieved an extremely high level of digitalization but also constantly counteracts cyber threats, is worthy of attention. At the same time, Ukraine should adopt the experience of legal regulation of cybersecurity in the EU, especially in such innovative areas as cryptocurrency markets. The authors prefer a broad approach to the defi nition of cybersecurity in EU law. In this case, it is possible to formulate the right to cybersecurity, which includes not only the state of technical security, but also appropriate legal and institutional guarantees of protection and compensation for damage. However, in this context, it is noted that the development of eff ective compensation mechanisms, especially in cryptoasset markets, will take a long time due to the complex legal nature of cryptocurrencies and their huge number. It is concluded that the introducing the right to cybersecurity into EU law, as well as the current realities of digitalisation, require a transformation of the structure and powers of the European Union Agency for Cybersecurity (ENISA). In addition to coordination functions, ENISA should be given basic control functions and mechanisms for responding to violations of the right to cybersecurity. In addition, this agency should be granted a number of powers aimed at protecting the rights and interests of crypto-asset users. The extent of their use in the international economy shows that they are gradually becoming a signifi cant component of the EU internal market.
Key words: EU law, EU acts, EU citizens, cybersecurity, cyber defence, digitalisation, information and communication technologies, EU internal market, free movement of capital in the EU, European integration.
References
- Сommunication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions. A Digital Single Market Strategy for Europe. COM/2015/0192 fi nal. URL: https://eur-lex.europa.eu/ legal-content/EN/TXT/?uri=celex%3A52015DC0192
- Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certifi cation and repealing Regulation (EU) No 526/2013 (Cybersecurity Act). Offi cial Journal of the European Union. L 151. 07.06.2019. Р. 15–69. URL: https://eur-lex.europa. eu/eli/reg/2019/881/oj
- Europol report. Cybercrime areas. Europol: website. URL: https:// www.europol.europa.eu/crime-areas-and-statistics/crime-areas/cybercrime
- Zvozdetska O. Ya. Kiberbezpeka YeS v umovakh posylennia kiberzahroz v suchasnomu hlobalizovanomu sviti. Mediaforum: analityka, prohnozy, informatsiinyi menedzhment. 2019. T. 7. S. 29. URL: http://nbuv.gov.ua/UJRN/mfapim_2019_7_4
- Hrubinko A. V. Osoblyvosti formuvannia polityky kiberbezpeky Yevropeiskoho Soiuzu: pravovi aspekty. Aktualni problemy pravoznavstva. 2021. Vyp. 1. S. 6. URL: http://nbuv.gov.ua/UJRN/aprpr_2021_1_3
- Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certifi cation and repealing Regulation (EU) No 526/2013 (Cybersecurity Act). Offi cial Journal of the European Union. L 151. 07.06.2019. Р. 15–69. URL: https://eur-lex.europa.eu/eli/reg/2019/881/oj
- Papakonstantinou V. Cybersecurity as Praxis and as a State: the EU Law Path Towards Acknowledgement of a New Right to Cybersecurity? Computer Law & Security Review. 2022. Vol. 44. P. 3. URL: https://www.sciencedirect.com/science/article/pii/S0267364922000012?via%3Dihub
- Cybersecurity. Cambridge Dictionary: website. URL: https://dictionary.cambridge.org/ dictionary/english/cybersecurity
- Seemma P.S., Nandhini S., Sowmiya M. Overview of Cyber Security. International Journal of Advanced Research in Computer and Communication Engineering. 2018. Vol. 7. Issue 11. P. 125. URL: https://www.researchgate.net/ publication/329678338_Overview_of_Cyber_Security 10. Papakonstantinou V. Op. cit. Р. 3
- Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certifi cation and repealing Regulation (EU) No 526/2013 (Cybersecurity Act). Offi cial Journal of the European Union. L 151. 07.06.2019. Р. 15–69. URL: https://eur-lex.europa.eu/eli/reg/2019/881/oj
- European Commission and the High Representative of the Union for Foreign Aff airs and Security Policy. The EU’s Cybersecurity Strategy for the Digital Decade, 2020. European Commission: website. URL: https://digital-strategy.ec.europa.eu/en/library/euscybersecurity-strategy-digital-decade-0
- Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union. Offi cial Journal of the European Union. L 194. 19.07.2016. Р. 1–30. URL: https://eur-lex.europa.eu/eli/ dir/2016/1148/oj
- Consolidated version of the Treaty on European Union. Offi cial Journal of the European Union. C 326. 26.10.2012. Р. 13–390. URL: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=celex%3A12012M%2FTXT
- Mazurier P.A. Cybersecurity Landscape: Technological Perspectives and Certifi cation Framework, Products, and Services. European Cybersecurity in Context A Policy-Oriented Comparative Analysis. 2022. P. 3. URL: https://liberalforum.eu/wp-content/uploads/2022/08/EuropeanCybersecurity-in-Context_ELF-Study_Techno-Politics.pdf
- Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the fi nancial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (Text with EEA relevance). Offi cial Journal of the European Union. L 333. 27.12.2022. Р. 1–79. URL: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- Today’s Cryptocurrency Prices by Market Cap. Coinmarketcap: website. URL: https:// coinmarketcap.com/
- Chan T. The nature of property in cryptoassets. Legal studies. Published online by Cambridge University Press: 18 January 2023. URL: https://www. cambridge.org/core/journals/legal-studies/article/nature-of-property-in-cryptoassets/6B882 C05BD3D9A7A924FBE41C359E92E
- See: Kerr D.S., Loveland K.A., Smith K.T., Smith, L.M. Cryptocurrency risks, fraud cases, and fi nancial performance. Risks. 2023. Vol. 11. No. 51. Р. 1-15. URL: https://www.mdpi.com/2227-9091/11/3/51
- Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 (Text with EEA relevance). Offi cial Journal of the European Union. L 150. 09.06.2023. Р. 40–205. URL: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX%3A32023R1114
- European Supervisory Authorities (EBA, ESMA and EIOPA). EU fi nancial regulators warn consumers on the risks of cryptoassets, 2022. ENISA: website. P. 2. URL: https://www.esma.europa.eu/sites/default/fi les/ library/esa_2022_15_joint_esas_warning_on_crypto-assets.pdf
- See: European Union Agency for Cybersecurity. Crypto Assets: Introduction to Digital Currencies and Distributed Ledger Technologies. 2021. ENISA: website. URL: https://www.enisa.europa.eu/ publications/crypto-assets-introduction-to-digital-currencies-and-distributed-ledgertechnologies
- European Supervisory Authorities (EBA, ESMA and EIOPA). EU fi nancial regulators warn consumers on the risks of crypto-assets, 2022. ENISA: website. P. 2. URL: https://www.esma.europa.eu/sites/default/fi les/library/esa_2022_15_joint_esas_warning_ on_crypto-assets.pdf
- Joint motion for a resolution on recognising the Russian Federation as a state sponsor of terrorism. (2022-2896(RSP). European Parliament: website. URL: https://www.europarl.europa.eu/doceo/document/RC-9-2022-0482_EN.html
- Pro osnovni zasady zabezpechennia kiberbezpeky Ukrainy: Zakon Ukrainy vid 5 zhovtnia 2017 roku № 2163-VIII. URL: https://zakon.rada.gov.ua/laws/show/2163-19#Text 26. Pro Natsionalnu prohramu informatyzatsii: Zakon Ukrainy vid 1 hrudnia 2022 roku № 2807-IX. URL: https://zakon.rada.gov.ua/laws/show/2807-20#Text
- Pro osnovni zasady zabezpechennia kiberbezpeky Ukrainy: Zakon Ukrainy vid 5 zhovtnia 2017 roku № 2163-VIII. URL: https://zakon.rada.gov.ua/laws/show/2163-19#Text
- Pro osnovni zasady zabezpechennia kiberbezpeky Ukrainy: Zakon Ukrainy vid 5 zhovtnia 2017 roku № 2163-VIII. URL: https://zakon.rada.gov.ua/laws/show/2163-19#Text
- «Tsyfrova Ukraina»: konstytutsiino-pravova model / za red.: R. O. Stefanchuka, O. L. Kopylenka. Kyiv: Instytut zakonodavstva Verkhovnoi Rady Ukrainy, 2021. S. 121.
- Bendiek A., Maat E.P. The EU’s Regulatory Approach to Cybersecurity. Stiftung Wissenschaft und Politik, 2019. P. 21. URL: https://www.swp-berlin.org/publications/products/arbeitspapiere/WP_ Bendiek_Pander_Maat_EU_Approach_Cybersecurity.pdf
- Uhoda mizh Ukrainoiu ta Yevropeiskym Soiuzom pro uchast Ukrainy u prohrami Yevropeiskoho Soiuzu «Tsyfrova Yevropa» (2021-2027). URL: https://zakon.rada.gov.ua/laws/show/984_005-22#Text
- Martino L., Gamal N. Editorial: European Cybersecurity in Context. European Cybersecurity in Context A Policy-Oriented Comparative Analysis. 2022. P. VIII. URL: https://liberalforum.eu/wp-content/uploads/2022/08/European-Cybersecurity-in-Context_ ELF-Study_Techno-Politics.pdf
- Pro osnovni zasady zabezpechennia kiberbezpeky Ukrainy: Zakon Ukrainy vid 5 zhovtnia 2017 roku № 2163-VIII. URL: https://zakon.rada. gov.ua/laws/show/2163-19#Text
- Pro vnesennia zmin do deiakykh zakoniv Ukrainy shchodo zabezpechennia formuvannia ta realizatsii derzhavnoi polityky u sferi aktyvnoi protydii ahresii u kiberprostori: Zakon Ukrainy vid 28 lypnia 2022 roku № 2470-IX. URL: https://zakon.rada.gov.ua/laws/show/2470-20#n21