Date: 2023-07-21Category: Not ApplicableState: Union GovernmentCountry: Europe
Commission Implementing Regulation (EU) 2023/1507 of 20 July 2023 laying down the technical specifications of data requirements and the deadlines for submission of metadata and quality reports for the topic of ICT usage and e-commerce for the reference year 2024, pursuant to Regulation (EU) 2019/2152 of the European Parliament and of the Council (Text with EEA relevance)
Executive Summary:
Commission Implementing Regulation (EU) 2023/1507 lays down technical specifications for data requirements, metadata, and quality reports on ICT usage and e-commerce for the reference year 2024, pursuant to Regulation (EU) 2019/2152. Member States must transmit the data to Eurostat according to the Annex of this regulation. The annual metadata report is due by May 31, 2024, and the annual quality report by November 5, 2024.
Key Points / Main Content:
* **Data Transmission:**
* Member States shall transmit data for the reference year 2024 to the Commission (Eurostat) according to the specifications in the Annex.
* **Reporting Deadlines:**
* Annual metadata report: May 31, 2024.
* Annual quality report: November 5, 2024.
* **Annex Specifications:**
* Mandatory and optional variables are defined for enterprises based on scope filters such as all enterprises, enterprises with employees, enterprises using fixed internet connections, enterprises with web sales, enterprises with EDI-type sales, enterprises recruiting ICT specialists, and enterprises using AI.
* Mandatory variables include main economic activity, number of employees, turnover, internet access, employment of ICT specialists, training, recruitment, and performance of ICT functions.
* Optional variables cover portable device usage, internet advertising, web sales to specific geographic areas, difficulties in recruiting ICT specialists, documentation on ICT security, and the use and consideration of AI technologies.
* **Statistical Scope:**
* Activity coverage: NACE Rev. 2 Sections C to J, L to N and group 95.1.
* Size class coverage: Enterprises with 10 or more employees and self-employed persons (enterprises with less than 10 employees may be covered optionally).
Impact Analysis:
**Member States:**
* *Impact:* Required to collect and transmit data on ICT usage and e-commerce according to the defined technical specifications.
* *Action Required:* Implement data collection mechanisms, prepare and submit metadata and quality reports by the specified deadlines (May 31, 2024, and November 5, 2024, respectively), and ensure data transmission to Eurostat.
**European Commission (Eurostat):**
* *Impact:* Receives and processes data from Member States to monitor the EU's digital targets and inform digital policies.
* *Action Required:* Provide guidance and support to Member States on data collection and reporting, analyze the received data, and use it for policy-making and monitoring purposes.
**Businesses:**
* *Impact:* May be required to provide data on their ICT usage and e-commerce activities.
* *Action Required:* Cooperate with national statistical authorities in providing the required data.
Key Entities Referenced
European Union: A political and economic union of member states located primarily in Europe.
European Commission: An institution of the European Union, responsible for proposing legislation, implementing decisions, upholding the EU treaties and managing the day-to-day business of the EU.
Treaty on the Functioning of the European Union: One of the primary treaties of the European Union, detailing the organisation and operation of the EU.
Regulation EU 2019/2152: A regulation of the European Parliament and of the Council on European business statistics.
European Parliament: The parliamentary body of the European Union.
Council of the European Union: A component of the EU legislative branch representing the governments of the member states.
Digital Compass: A framework for the EU's digital transformation by 2030.
Brussels: The capital of Belgium and a major administrative centre for the European Union, where the regulation was adopted.
L 184/8 EN Official Journal of the European Union 21.7.2023
COMMISSION IMPLEMENTING REGULATION (EU) 2023/1507
of 20 July 2023
laying down the technical specifications of data requirements and the deadlines for submission of
metadata and quality reports for the topic of ICT usage and e-commerce for the reference year 2024,
pursuant to Regulation (EU) 2019/2152 of the European Parliament and of the Council
(Text with EEA relevance)
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) 2019/2152 of the European Parliament and of the Council of 27 November 2019 on
European business statistics, repealing 10 legal acts in the field of business statistics(1), and in particular Article 7(1) and
Article 17(6) thereof,
Whereas:
(1) The topic of ICT usage and e-commerce provides the data required by the Digital Compass for the EU’s Digital
Decade to monitor the EU’s digital targets for 2030, such as the Digital Intensity Indicator reflecting the digital
transformation of businesses. It also provides information for various other Union policies related to Europe’s
digital performance and to the priority of the European Commission – A Europe fit for the digital age.
(2) To be able to assess the quality of the data and to ensure that data on ICT usage and e-commerce are comparable and
harmonised, metadata and quality reports are required to be provided before the data are released.
(3) The measures provided for in this Regulation are in accordance with the opinion of the European Statistical System
Committee,
HAS ADOPTED THIS REGULATION:
Article 1
For the topic of ICT usage and e-commerce, as referred to in Annex I to Regulation (EU) 2019/2152, Member States shall
transmit to the Commission (Eurostat) the data for reference year 2024 in accordance with the Annex to this Regulation.
Article 2
1. The annual metadata report for the topic of ICT usage and e-commerce for reference year 2024 shall be transmitted
to the Commission (Eurostat) by 31 May 2024.
2. The annual quality report for the topic of ICT usage and e-commerce for reference year 2024 shall be transmitted to
the Commission (Eurostat) by 5 November 2024.
Article 3
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the
European Union.
(1) OJ L 327, 17.12.2019, p. 1.21.7.2023 EN Official Journal of the European Union L 184/9
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 20 July 2023.
For the Commission
The President
Ursula VON DER LEYENANNEX
Technical specifications of data requirements for the topic ICT usage and e-commerce
Mandatory/optional Scope (filter) Variable
Mandatory variables (i) for all enterprises (1) main economic activity of the enterprise, in the previous calendar year
(2) average number of employees and self-employed persons, in the previous calendar year
(3) total value of turnover (in monetary terms, excluding VAT), in the previous calendar year
(4) number of employees and self-employed persons or percentage of the total number of employees and self-
employed persons who have access to the internet for business purposes
(5) employment of ICT specialists
(6) provision of any type of training to develop ICT-related skills for ICT specialists employed by the enterprise, in
the previous calendar year
(7) provision of any type of training to develop ICT-related skills for other persons employed, in the previous
calendar year
(8) recruitment of or the attempt to recruit ICT specialists in the previous calendar year
(9) performance of ICT functions (such as maintenance of ICT infrastructure, support for office software,
development or support of business management software/systems and/or web solutions, security and data
protection) by own employees (including those employed in parent or affiliate enterprises), in the previous
calendar year
(10) performance of ICT functions (such as maintenance of ICT infrastructure, support for office software,
development or support of business management software/systems and/or web solutions, security and data
protection) by external suppliers, in the previous calendar year
(ii) for enterprises with employees and (11) use of any type of fixed connection to the internet
self-employed persons who have (12) having remote access (via computers or portable devices such as smartphones) of persons employed to email
access to the internet for business system of the enterprise
purposes (13) having remote access (via computers or portable devices such as smartphones) of persons employed to
documents of the enterprise (such as files, spreadsheets, presentations, charts, photos)
(14) having remote access (via computers or portable devices such as smartphones) of persons employed to
business applications or software of the enterprise (such as access to accounting, sales, orders, Customer
Relationship Management (CRM)), excluding applications used for internal communication
(15) conduct of remote meetings
(16) having web sales of goods or services via the enterprise’s websites or apps (including extranets), in the
previous calendar year
(17) having web sales of goods or services via e-commerce marketplace websites or apps used by several
enterprises for trading goods or services, in the previous calendar year
(18) having Electronic Data Interchange (EDI)-type sales (receipt of orders placed via EDI-type messages) of goods
or services, in the previous calendar year
L
184/10
EN
Official
Journal
of
the
European
Union
21.7.2023Mandatory/optional Scope (filter) Variable
(19) application of the ICT security measures on enterprise’s ICT systems: authentication via strong password (such
as minimum length, use of numbers and special characters, changed periodically)
(20) application of the ICT security measures on enterprise’s ICT systems: authentication via biometric methods
used to access the enterprise’s ICT system (such as authentication based on fingerprints, voice, face)
(21) application of the ICT security measures on enterprise’s ICT systems: authentication based on a combination
of at least two authentication mechanisms (i.e. combination of for example user-defined password, one-time
password (OTP), code generated via a security token or received via a smartphone, biometric method (such
as based on fingerprints, voice, face))
(22) application of the ICT security measures on enterprise’s ICT systems: encryption of data, documents or e-mails
(23) application of the ICT security measures on enterprise’s ICT systems: data backup to a separate location
(including backup to the cloud)
(24) application of the ICT security measures on enterprise’s ICT systems: network access control (management of
user rights in enterprise’s network)
(25) application of the ICT security measures on enterprise’s ICT systems: Virtual Private Network (VPN), which
extends the private network across a public network to enable secure exchange of data over public network
(26) application of the ICT security measures on enterprise’s ICT systems: ICT security monitoring system used to
detect suspicious activity (such as intrusion detection or prevention systems that monitors users’ or devices’
behaviour, network traffic), excluding anti-virus software and default firewall solution included in the
operating system of personal computers and routers
(27) application of the ICT security measures on enterprise’s ICT systems: maintaining log files that enable analysis
after ICT security incidents
(28) application of the ICT security measures on enterprise’s ICT systems: ICT risk assessment, i.e. periodical
assessment of probability and consequences of ICT security incidents
(29) application of the ICT security measures on enterprise’s ICT systems: ICT security tests (such as performing
penetration tests, testing security alert system, reviewing security measures, testing of backup systems)
(30) making persons employed aware of their obligations in ICT security related issues through voluntary training
or internally available information (such as information on the intranet)
(31) making persons employed aware of their obligations in ICT security related issues through compulsory
training courses or viewing compulsory material
(32) making persons employed aware of their obligations in ICT security related issues through a contract (such as
contract of employment)
(33) having document(s) on measures, practices or procedures on ICT security, such as documents on ICT security
and confidentiality of data covering employee training in ICT use, ICT security measures, the evaluation of ICT
security measures, plans for updating ICT security documents
21.7.2023
EN
Official
Journal
of
the
European
Union
L
184/11Mandatory/optional Scope (filter) Variable
(34) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
unavailability of ICT services due to hardware or software failures
(35) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
unavailability of ICT services due to attack from outside, such as ransomware attacks, Denial of Service attacks
(36) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
destruction or corruption of data due to hardware or software failures
(37) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
destruction or corruption of data due to infection of malicious software or unauthorised intrusion
(38) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
disclosure of confidential data due to intrusion, pharming, phishing attack, intentional actions by own
employees
(39) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
disclosure of confidential data due to unintentional actions by own employees
(40) use of Artificial Intelligence technologies performing analysis of written language (such as text mining)
(41) use of Artificial Intelligence technologies converting spoken language into machine-readable format (speech
recognition)
(42) use of Artificial Intelligence technologies generating written or spoken language (natural language generation,
speech synthesis)
(43) use of Artificial Intelligence technologies identifying objects or persons based on images or videos (image
recognition, image processing)
(44) use of machine learning (such as deep learning) for data analysis
(45) use of Artificial Intelligence technologies automating different workflows or assisting in decision-making
(such as Artificial Intelligence based software robotic process automation)
(46) use of Artificial Intelligence technologies enabling physical movement of machines via autonomous decisions
based on observation of surroundings (autonomous robots, self-driving vehicles, autonomous drones)
(iii) for enterprises using any type of (47) maximum contracted download speed of the fastest fixed internet connection in the ranges: [0 Mbit/s, < 30
fixed internet connection Mbit/s], [30 Mbit/s, < 100 Mbit/s], [100 Mbit/s, < 500 Mbit/s], [500 Mbit/s, < 1 Gbit/s], [≥ 1 Gbit/s]
(48) sufficiency of the speed of fixed connection(s) to the internet for the actual needs of the enterprise
L
184/12
EN
Official
Journal
of
the
European
Union
21.7.2023Mandatory/optional Scope (filter) Variable
(iv) for enterprises which had web (49) value of web sales of goods or services, or percentage of total turnover generated by web sales of goods and
sales of goods and services via services, in the previous calendar year
the enterprise’s websites or apps (50) percentage of value of web sales generated by web sales to private consumers (Business to Consumers: B2C), in
or via e-commerce marketplace the previous calendar year
websites or apps used by several (51) percentage of value of web sales generated by web sales to other enterprises (Business to Business: B2B) and to
enterprises for trading goods or public sector (Business to Government: B2G), in the previous calendar year
services, in the previous calendar (52) web sales to customers located in the enterprise’s own country, in the previous calendar year
year: (53) web sales to customers located in other Member States, in the previous calendar year
(54) web sales to customers located in the rest of the world, in the previous calendar year
(v) for enterprises which had web sales (55) percentage of value of web sales of goods or services generated by sales via the enterprise’s websites or apps
of goods and services via the enter (including extranets), in the previous calendar year
prise’s websites or apps and via (56) percentage of value of web sales of goods or services generated by sales via e-commerce marketplace websites
e-commerce marketplace websites or apps used by several enterprises for trading goods or services, in the previous calendar year
or apps used by several enterprises
for trading goods or services, in the
previous calendar year
(vi) for enterprises which had EDI- (57) value of EDI-type sales of goods or services or percentage of the total turnover generated by EDI-type sales of
type sales of goods and services, goods or services, in the previous calendar year
in the previous calendar year:
(vii) for enterprises which have re (58) having vacancies for ICT specialists that were difficult to fill
cruited or tried to recruit ICT spe
cialists in the previous calendar
year
(viii) for enterprises using Artificial In (59) use of Artificial Intelligence software or systems for marketing or sales (such as customer profiling, price
telligence technologies, referring optimisation, personalised marketing offers, market analysis based on machine learning, chatbots based on
specifically to mandatory vari natural language processing for customer support, autonomous robots for orders processing)
ables (40) to (46) (60) use of Artificial Intelligence software or systems for production or service processes (such as predictive
maintenance or process optimization based on machine learning, tools to classify products or find defects in
products based on computer vision, autonomous drones for production surveillance, security or inspection
tasks, assembly works performed by autonomous robots)
21.7.2023
EN
Official
Journal
of
the
European
Union
L
184/13Mandatory/optional Scope (filter) Variable
(61) use of Artificial Intelligence software or systems for organisation of business administration processes or
management (such as business virtual assistants based on machine learning and/or natural language
processing (for example for document drafting), data analysis or strategic decision making based on machine
learning (for example risk assessment), planning or business forecasting based on machine learning, human
resources management based on machine learning or natural language processing (for example candidates
pre-selection screening, employee profiling or performance analysis)
(62) use of Artificial Intelligence software or systems for logistics (such as autonomous robots for pick-and-pack
solutions in warehouses for parcel shipping, tracing, distribution or sorting, route optimization based on
machine learning)
(63) use of Artificial Intelligence software or systems for ICT security (such as face recognition based on computer
vision for authentication of ICT users, detection and prevention of cyber-attacks based on machine learning)
(64) use of Artificial Intelligence software or systems for accounting, controlling or finance management (such as
machine learning to analyse data that helps to make financial decisions, invoice processing based on machine
learning, machine learning or natural language processing used for bookkeeping tasks)
(65) use of Artificial Intelligence software or systems for research and development (R & D) or innovation activity,
excluding research on Artificial Intelligence (such as analysis of data for conducting research, solving research
problems, developing a new or significantly improved product/service based on machine learning)
Optional variables (i) for enterprises with employees and (1) number of persons employed, or percentage of the total number of persons employed, using a portable device
self-employed persons who have provided by the enterprise that allows connection to the internet via mobile telephone networks for business
access to the internet for business purposes
purposes (2) pay to advertise on the internet (such as adverts on search engines, on social media, on other websites or apps)
(ii) for enterprises paying to advertise (3) use of targeted advertising based on content or keywords searched by internet users
on the internet (4) use of targeted advertising based on the tracking of internet users’ past activities or profile
(5) use of targeted advertising based on the geolocation of internet users
(6) use of any other method of targeted advertising on the internet than the ones specified in optional variables (3),
(4) or (5)
(iii) for enterprises which had web (7) percentage of value of web sales generated by web sales to customers located in enterprise’s own country, in the
sales to customers located in at previous calendar year
least two of the following geo (8) percentage of value of web sales generated by web sales to customers located in other Member States, in the
graphic areas: own country, other previous calendar year
Member State or rest of the world, (9) percentage of value of web sales generated by web sales to customers located in the rest of the world, in the
in the previous calendar year previous calendar year
L
184/14
EN
Official
Journal
of
the
European
Union
21.7.2023Mandatory/optional Scope (filter) Variable
(iv) for enterprises with vacancies for (10) difficulties to recruit ICT specialists due to lack of applications, in the previous calendar year
ICT specialists that were difficult (11) difficulties to recruit ICT specialists due to applicants’ lack of relevant ICT related qualifications from education
to fill, when trying to recruit ICT and/or training, in the previous calendar year
specialists in the previous calendar (12) difficulties to recruit ICT specialists due to applicants’ lack of relevant work experience, in the previous
year calendar year
(13) difficulties to recruit ICT specialists due to applicants’ too high salary expectations, in the previous calendar
year
(v) for enterprises which have docu (14) time of definition or most recent review of enterprise’s document(s) on measures, practices or procedures on
ment(s) on measures, practices or ICT security: within the last 12 months, more than 12 months and up to twenty-four months ago, more than
procedures on ICT security twenty-four months ago
(vi) for enterprises using Artificial In (15) Artificial Intelligence software and systems were developed by own employees (including those employed in
telligence technologies, referring parent or affiliate enterprise)
specifically to mandatory vari (16) commercial Artificial Intelligence software or systems were modified by own employees (including those
ables (40) to (46) employed in parent or affiliate enterprise)
(17) open-source Artificial Intelligence software or systems were modified by own employees (including those
employed in parent or affiliate enterprise)
(18) commercial Artificial Intelligence software or systems ready to use were purchased (including examples where
they were already incorporated in a purchased item or system)
(19) external providers were contracted to develop or modify Artificial Intelligence software and systems
(20) processing data (such as sex, age, racial or ethnic origin, disability, religion or belief, sexual orientation, facial
images, record of purchases, occupation or address) on individuals (such as employees, job applicants or
customers) using Artificial Intelligence technologies
(vii) for enterprises which used Artifi (21) having measures (such as analysing the results of various machine learning models, examining the dataset that
cial Intelligence technologies to was used to train the machine learning model, data augmentation which involves techniques to artificially
process data on individuals generate additional data points from existing data, i.e. synthetic data) to check the results generated by
Artificial Intelligence technologies for possible biases towards individuals based on sex, age, racial or ethnic
origin, disability, religion or belief, sexual orientation
(viii) for enterprises which did not use (22) consideration of using any of Artificial Intelligence technologies, referring specifically to mandatory variables
any Artificial Intelligence tech (40) to (46)
nologies, referring specifically
to mandatory variables (40) to
(46)
21.7.2023
EN
Official
Journal
of
the
European
Union
L
184/15Mandatory/optional Scope (filter) Variable
(ix) for enterprises which did not use (23) Artificial Intelligence technologies not used because the costs seem too high
but considered to use Artificial In (24) Artificial Intelligence technologies not used because there is a lack of relevant expertise in the enterprise
telligence technologies, referring (25) Artificial Intelligence technologies not used because of incompatibility with existing equipment, software or
specifically to mandatory vari systems
ables (40) to (46) (26) Artificial Intelligence technologies not used because of difficulties with availability or quality of the necessary
data
(27) Artificial Intelligence technologies not used because of concerns regarding violation of data protection and
privacy
(28) Artificial Intelligence technologies not used because of lack of clarity about the legal consequences (such as
liability in case of damage caused by the use of Artificial Intelligence)
(29) Artificial Intelligence technologies not used because of ethical considerations
(30) Artificial Intelligence technologies not used because they are not useful for the enterprise
Measurement unit Absolute figures, except for characteristics related to turnover in national currency (thousands) or percentage of (total) turnover
Statistical population Activity coverage
NACE Rev. 2 Sections C to J, L to N and group 95.1
Size class coverage
Enterprises with 10 or more employees and self-employed persons. Enterprises with less than 10 employees and self-employed persons may be covered
optionally.
Breakdowns Activity breakdown
for calculation of national aggregates
— aggregates of NACE Rev. 2 sections and group C+D+E+F+G+H+I+J+L+M+N+95.1, D+E
— NACE Rev. 2 sections: C, F, G, H, I, J, L, M, N
— NACE Rev. 2 divisions: 47, 55
— aggregates of NACE Rev. 2 divisions: 10 + 11 + 12 + 13 + 14 + 15 + 16 + 17 + 18, 19 + 20 + 21 + 22 + 23, 24 + 25,
26 + 27 + 28 + 29 + 30 + 31 + 32 + 33
— aggregate of the NACE Rev. 2 divisions and groups: 26.1 + 26.2 + 26.3 + 26.4 + 26.8 + 46.5 + 58.2 + 61 + 62 + 63.1 + 95.1
for contribution to the European totals only
— NACE Rev. 2 sections: D, E
— NACE Rev. 2 divisions: 19, 20, 21, 26, 27, 28, 45, 46, 61, 72, 79
— NACE Rev. 2 group: 95.1
— aggregates of NACE Rev. 2 divisions: 10 + 11 + 12, 13 + 14 + 15, 16 + 17 + 18, 22 + 23, 29 + 30, 31 + 32 + 33, 58 + 59 + 60, 62 + 63, 69 + 70 + 71,
73 + 74 + 75, 77 + 78 + 80 + 81 + 82
Size class of number of employees and self-employed persons: 10+, 10-49, 50-249, 250+; optional: 0-9, 0-1, 2-9
Data transmission deadline 5 October 2024
L
184/16
EN
Official
Journal
of
the
European
Union
21.7.2023