See Full Document Text
Official Journal EN
of the European Union L series
2025/1310 4.7.2025
COMMISSION IMPLEMENTING REGULATION(EU) 2025/1310
of 3 July 2025
laying down the technical specifications of data requirements and the deadlines for submission of
annual metadata and quality reports for the topic ‘ICT usage and e-commerce’ for the reference year
2026, pursuant to Regulation (EU) 2019/2152 of the European Parliament and of the Council
(Text with EEA relevance)
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) 2019/2152 of the European Parliament and of the Council of 27 November 2019 on
European business statistics, repealing 10 legal acts in the field of business statistics(1), and in particular Article 7(1)
and 17(6) thereof,
Whereas:
(1) Data for the topic ‘ICT usage and e-commerce’, as referred to in Annex I to Regulation (EU) 2019/2152, is required by
the Digital Decade Policy Programme(2)to monitor the Union’s digital targets for 2030, such as the Digital Intensity
Indicator for the digital transformation of businesses or the take-up of cloud computing services, big data analysis
(data analytics) or artificial intelligence. That topic also provides information for various other Union policies related
to the political guidelines for the European Commission 2024-2029, such as the new plan for Europe’s sustainable
prosperity and competitiveness and the Communication on a comprehensive EU Toolbox for Safe and Sustainable
E-commerce.
(2) In order to make it possible to assess the quality of the data and to ensure that data for the topic ‘ICT usage and
e-commerce’ are comparable and harmonised, deadlines for metadata and quality reports have to be specified.
(3) The measures set out for in this Regulation are in accordance with the opinion of the European Statistical System
Committee,
HAS ADOPTED THIS REGULATION:
Article 1
For reference year 2026, Member States shall transmit to the Commission (Eurostat) data for the topic ‘ICT usage and
e-commerce’, as referred to in Annex I to Regulation (EU) 2019/2152, that comply with the technical specifications in the
Annex to this Regulation.
Article 2
1. The annual metadata report for the topic ‘ICT usage and e-commerce’ for the reference year 2026 shall be transmitted
to the Commission (Eurostat) by 31 May 2026.
2. The annual quality report for the topic ‘ICT usage and e-commerce’ for the reference year 2026 shall be transmitted to
the Commission (Eurostat) by 5 November 2026.
(1) OJ L 327, 17.12.2019, p. 1, ELI: http://data.europa.eu/eli/reg/2019/2152/oj.
(2) Decision (EU) 2022/2481 of the European Parliament and of the Council of 14 December 2022 establishing the Digital Decade Policy
Programme 2030 (OJ L 323, 19.12.2022, p. 4, ELI: http://data.europa.eu/eli/dec/2022/2481/oj).
ELI: http://data.europa.eu/eli/reg_impl/2025/1310/oj 1/10EN
OJ L, 4.7.2025
Article 3
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the
European Union.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 3 July 2025.
For the Commission
The President
Ursula VON DER LEYEN
2/10 ELI: http://data.europa.eu/eli/reg_impl/2025/1310/ojANNEX
TECHNICAL SPECIFICATIONS OF DATA REQUIREMENTS FOR THE TOPIC ‘ICT USAGE AND E-COMMERCE’
Mandatory/optional Scope (filter) Variable
Mandatory variables (i) for all enterprises: (1) main economic activity of the enterprise, in the previous calendar year
(2) average number of employees and self-employed persons, in the previous calendar year
(3) total value of turnover (in monetary terms, excluding VAT), in the previous calendar year
(4) number of employees and self-employed persons or percentage of the total number of employees and self-employed
persons who have access to the internet for business purposes
(5) employment of ICT specialists
(6) provision of any type of training to develop ICT-related skills for ICT specialists employed by the enterprise, in the
previous calendar year
(7) provision of any type of training to develop ICT-related skills for other persons employed, in the previous calendar
year
(8) recruitment of or the attempt to recruit ICT specialists in the previous calendar year
(ii) for enterprises with (9) use of any type of fixed connection to the internet
employees and self- (10) having a website
employed persons who (11) use of social media (i.e. having a user profile or an account)
have access to the internet (12) having web sales of goods or services via the enterprise’s websites or apps (including extranets), in the previous
for business purposes: calendar year
(13) having web sales of goods or services via e-commerce marketplace websites or apps used by several enterprises for
trading goods or services, in the previous calendar year
(14) having Electronic Data Interchange (EDI)-type sales of goods or services, in the previous calendar year
(15) use of Enterprise Resource Planning (ERP) software to manage resources by sharing information among different
functional areas such as accounting, planning, production, marketing
(16) use of Customer Relationship Management (CRM) software for managing information about customers such as
relations or transactions
(17) use of Business Intelligence (BI) software for accessing and analysing data such as from data warehouses or data
lakes from internal IT systems and/or external sources and for presenting analytical findings in reports, summaries,
dashboards, graphs, charts or maps to provide users with detailed insights for decision-making or strategic
planning
(18) sharing data electronically with suppliers or customers within the supply chain, for example via websites or apps,
EDI-type systems, real-time sensors or tracking
(19) performing data analytics (from internal and external data sources) by own employees
(20) having data analytics performed by an external enterprise or organisation for the enterprise (including data
analytics based on data from internal and external sources)
(21) use of Artificial Intelligence (AI) technologies performing analysis of written language (such as text mining)
(22) use of AI technologies converting spoken language into machine-readable format (speech recognition)
(23) use of AI technologies generating written, spoken language or programming codes (natural language generation,
speech synthesis)
ELI:
http://data.europa.eu/eli/reg_impl/2025/1310/oj
3/10
OJ
L,
4.7.2025
ENMandatory/optional Scope (filter) Variable
(24) use of AI technologies generating pictures, videos, sound/audio
(25) use of AI technologies identifying objects or persons based on images or videos (image recognition, image
processing)
(26) use of machine learning (such as deep learning) for data analysis
(27) use of AI technologies automating different workflows or assisting in decision-making (such as AI based software
robotic process automation)
(28) use of AI technologies enabling physical movement of machines via autonomous decisions based on observation
of surroundings (autonomous robots, self-driving vehicles, autonomous drones)
(29) use of paid cloud computing services
(30) application of the ICT security measures on enterprise’s ICT systems: authentication based on a combination of at
least two authentication mechanisms (i.e. combination of for example user-defined password, one-time password
(OTP), code generated via a security token or received via a smartphone, biometric method (such as based on
fingerprints, voice, face)
(31) application of the ICT security measures on enterprise’s ICT systems: encryption of data, documents or e-mails
(32) application of the ICT security measures on enterprise’s ICT systems: data backup to a separate location (including
backup to the cloud)
(33) application of the ICT security measures on enterprise’s ICT systems: ICT security monitoring system used to
detect suspicious activity (such as intrusion detection or prevention systems that monitors users’ or devices’
behaviour, network traffic), excluding anti-virus software and default firewall solution included in the operating
system of personal computers and routers
(34) application of the ICT security measures on enterprise’s ICT systems: ICT risk assessment, i.e. periodical assessment
of probability and consequences of ICT security incidents
(35) making persons employed aware of their obligations in ICT security related issues through voluntary training or
internally available information (such as information on the intranet)
(36) making persons employed aware of their obligations in ICT security related issues through compulsory training
courses or viewing compulsory material
(37) making persons employed aware of their obligations in ICT security related issues through a contract (such as
contract of employment)
(38) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
unavailability of ICT services due to attack from outside, such as ransomware attacks, Denial of Service attacks
(39) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
destruction or corruption of data due to infection of malicious software or unauthorised intrusion
(40) ICT related security incidents experienced in the previous calendar year leading to the following consequences:
disclosure of confidential data due to intrusion, pharming, phishing attack, intentional actions by own employees
4/10
ELI:
http://data.europa.eu/eli/reg_impl/2025/1310/oj
EN
OJ
L,
4.7.2025Mandatory/optional Scope (filter) Variable
(iii) for enterprises using any (41) maximum contracted download speed of the fastest fixed internet connection in the ranges: [0 Mbit/s, < 30 Mbit/
type of fixed internet s], [30 Mbit/s, < 100 Mbit/s], [100 Mbit/s, < 500 Mbit/s], [500 Mbit/s, < 1 Gbit/s], [≥ 1 Gbit/s]
connection:
(iv) for enterprises which had (42) value of web sales of goods or services, or percentage of total turnover generated by web sales of goods and
web sales of goods and services, in the previous calendar year
services via the (43) percentage of value of web sales generated by web sales to private consumers (Business to Consumers: B2C), in the
enterprise’s websites or previous calendar year
apps and/or via (44) percentage of value of web sales generated by web sales to other enterprises (Business to Business: B2B) and to
e-commerce marketplace public sector (Business to Government: B2G), in the previous calendar year
websites or apps used by
several enterprises for
trading goods or services,
in the previous calendar
year:
(v) for enterprises which had (45) percentage of value of web sales of goods or services generated by sales via the enterprise’s websites or apps
web sales of goods and (including extranets), in the previous calendar year
services via the enterprise’s (46) percentage of value of web sales of goods or services generated by sales via e-commerce marketplace websites or
websites or apps and via apps used by several enterprises for trading goods or services, in the previous calendar year
e-commerce marketplace
websites or apps used by
several enterprises for trading
goods or services, in the
previous calendar year:
(vi) for enterprises which had (47) value of EDI-type sales of goods or services or percentage of the total turnover generated by EDI-type sales of
EDI-type sales of goods goods or services, in the previous calendar year
and services, in the
previous calendar year:
(vii) for enterprises which have (48) having vacancies for ICT specialists that were difficult to fill
recruited or tried to recruit
ICT specialists in the
previous calendar year:
ELI:
http://data.europa.eu/eli/reg_impl/2025/1310/oj
5/10
OJ
L,
4.7.2025
ENMandatory/optional Scope (filter) Variable
(viii) for enterprises performing (49) performing data analytics on data from transaction records such as sale details, payments records (for example
data analytics (from from ERP, enterprise’s webshop)
internal and external data (50) performing data analytics on data about customers such as customer purchasing information, location,
sources) by own preferences, customer reviews, searches (for example from CRM system or enterprise’s website)
employees: (51) performing data analytics on data from social media, including from enterprise’s own social media profiles (such
as personal information, comments, video, audio, images)
(52) performing data analytics on web data (such as search engine trends, web scraping data)
(53) performing data analytics on location data from the use of portable devices or vehicles (such as portable devices
using mobile telephone networks, wireless connections or GPS)
(54) performing data analytics on data from smart devices or sensors (such as Machine to Machine (M2M)
communications, sensors installed in machinery, manufacturing sensors, smart meters, Radio frequency
identification (RFID) tags)
(55) performing data analytics on government authorities’ open data (such as enterprise public records, weather
conditions, topographic conditions, transport data, housing data, buildings data)
(56) performing data analytics on satellite data (such as satellite imagery, navigation signals, position signals), including
data acquired from enterprise’s own infrastructure or from externally provided service (for example AWS Ground
Station) and excluding location data from the use of portable devices or vehicles using GPS)
(ix) for enterprises using AI (57) software/system developed by own employees (including those employed in parent or affiliate enterprise)
technologies, referring (58) software/system developed by external providers for the enterprise
specifically to mandatory (59) open-source software was used free of charge or for a fee
variables (21) to (28), (60) closed-source software was used free of charge or for a fee
acquistion of AI:
(x) for enterprises using open or (61) modification of AI software or systems by own employees (including those employed in parent or affiliate
closed-source software: enterprise) and/or external providers
(xi) for enterprises using paid (62) use of email as a paid cloud computing service
cloud computing services: (63) use of office software (such as word processors or spreadsheets) as a paid cloud computing service
(64) use of finance or accounting software applications as a paid cloud computing service
(65) use of ERP software applications as paid cloud computing service
(66) use of CRM software applications as a paid cloud computing service
(67) use of security software applications (such as antivirus program, network access control) as paid cloud computing
service
(68) use of hosting the enterprise’s database(s) as a paid cloud computing service
(69) use of storage of files as a paid cloud computing service
(70) use of computing power to run the enterprise’s own software as a paid cloud computing service
6/10
ELI:
http://data.europa.eu/eli/reg_impl/2025/1310/oj
EN
OJ
L,
4.7.2025Mandatory/optional Scope (filter) Variable
(71) use of computing platform providing a hosted environment for application development, testing or deployment
(such as reusable software modules, application programming interfaces (APIs)) as a paid cloud computing service
(72) use of AI software and systems generating text, images, video, audio content or codes as paid cloud computing
service
Optional variables (i) for all enterprises: (1) performance of ICT functions (such as maintenance of ICT infrastructure, support for office software, development or
support of business management software/systems and/or web solutions, security and data protection) by own
employees (including those employed in parent or affiliate enterprises), in the previous calendar year
(2) performance of ICT functions (such as maintenance of ICT infrastructure, support for office software, development or
support of business management software/systems and/or web solutions, security and data protection) by external
suppliers, in the previous calendar year
(ii) for enterprises with (3) pay to advertise on the internet (such as adverts on search engines, on social media, on other websites or apps)
employees and self- (4) selling (access to) any of the enterprise’s own data (such as data about the enterprise’s customers’ preferences, data
employed persons who from the enterprise’s smart devices or sensors), in the previous calendar year
have access to the internet (5) purchasing (access to) any data (such as data about other enterprise’s customers’ preferences, data from other
for business purposes: enterprise’s smart devices or sensors), in the previous calendar year
(6) application of the ICT security measures on enterprise’s ICT systems: authentication via strong password (such as
minimum length, use of numbers and special characters, changed periodically)
(7) application of the ICT security measures on enterprise’s ICT systems: authentication via biometric methods used to
access the enterprise’s ICT system (such as authentication based on fingerprints, voice, face)
(8) application of the ICT security measures on enterprise’s ICT systems: network access control (management of user
rights in enterprise’s network)
(9) application of the ICT security measures on enterprise’s ICT systems: Virtual Private Network (VPN), which extends
the private network across a public network to enable secure exchange of data over public network
(10) application of the ICT security measures on enterprise’s ICT systems: maintaining log files that enable analysis after
ICT security incidents
(11) application of the ICT security measures on enterprise’s ICT systems: ICT security tests (such as performing
penetration tests, testing security alert system, reviewing security measures, testing of backup systems)
(12) invoices sent in electronic form, in a standard structure suitable for automated processing (e-invoices), excluding
the transmission of PDF files, in the previous calendar year
(13) invoices sent in electronic form not suitable for automated processing, including the transmission of PDF files, in
the previous calendar year
(14) invoices sent in paper form, in the previous calendar year
ELI:
http://data.europa.eu/eli/reg_impl/2025/1310/oj
7/10
OJ
L,
4.7.2025
ENMandatory/optional Scope (filter) Variable
(iii) for enterprises paying to (15) use of targeted advertising based on content or keywords searched by internet users
advertise on the internet: (16) use of targeted advertising based on the tracking of internet users’ past activities or profile
(17) use of targeted advertising based on the geolocation of internet users
(18) use of any other method of targeted advertising on the internet than the ones specified in optional variables (15),
(16) or (17)
(iv) for enterprises with (19) difficulties to recruit ICT specialists due to lack of applications, in the previous calendar year
vacancies for ICT (20) difficulties to recruit ICT specialists due to applicants’ lack of relevant ICT related qualifications from education
specialists that were and/or training, in the previous calendar year
difficult to fill, when trying (21) difficulties to recruit ICT specialists due to applicants’ lack of relevant work experience, in the previous calendar
to recruit ICT specialists in year
the previous calendar (22) difficulties to recruit ICT specialists due to applicants’ too high salary expectations, in the previous calendar year
year:
(v) for enterprises using AI (23) use of AI software or systems for marketing or sales (such as customer profiling, price optimisation, personalised
technologies, referring marketing offers, market analysis based on machine learning, chatbots based on natural language processing for
specifically to mandatory customer support, autonomous robots for orders processing, robo-advisor for automated planning, for example of
variables (21) to (28), type of investment(1))
purposes: (24) use of AI software or systems for production or service processes (such as predictive maintenance or process
optimization based on machine learning, tools to classify products or find defects in products based on computer
vision, autonomous drones for production surveillance, security or inspection tasks, assembly works performed
by autonomous robots, credit scoring based on machine learning(2))
(25) use of AI software or systems for organisation of business administration processes or management (such as
business virtual assistants based on machine learning and/or natural language processing (for example for
document drafting), data analysis or strategic decision making based on machine learning (for example risk
assessment), planning or business forecasting based on machine learning, human resources management based on
machine learning or natural language processing (for example candidates pre-selection screening, employee
profiling or performance analysis)
(26) use of AI software or systems for logistics (such as autonomous robots for pick-and-pack solutions in warehouses
for parcel shipping, tracing, distribution or sorting, route optimization based on machine learning)
(27) use of AI software or systems for ICT security (such as face recognition based on computer vision for
authentication of ICT users, detection and prevention of cyber-attacks based on machine learning)
(28) use of AI software or systems for accounting, controlling or finance management (such as machine learning to
analyse data that helps to make financial decisions, invoice processing based on machine learning, machine
learning or natural language processing used for bookkeeping tasks)
8/10
ELI:
http://data.europa.eu/eli/reg_impl/2025/1310/oj
EN
OJ
L,
4.7.2025Mandatory/optional Scope (filter) Variable
(29) use of AI software or systems for research and development (R & D) or innovation activity, excluding research on
Artificial Intelligence (such as analysis of data for conducting research, solving research problems, developing a
new or significantly improved product/service based on machine learning)
(30) processing data (such as sex, age, racial or ethnic origin, disability, religion or belief, sexual orientation, facial
images, record of purchases, occupation or address) on individuals (such as employees, job applicants or
customers) using AI technologies
(vi) for enterprises which used (31) having measures (such as analysing the results of various machine learning models, examining the dataset that was
AI technologies to process used to train the machine learning model, data augmentation which involves techniques to artificially generate
data on individuals: additional data points from existing data, i.e. synthetic data) to check the results generated by AI technologies for
possible biases towards individuals based on sex, age, racial or ethnic origin, disability, religion or belief, sexual
orientation
(vii) for enterprises which did (32) consideration of using any of AI technologies, referring specifically to mandatory variables (21) to (28)
not use any AI
technologies, referring
specifically to mandatory
variables (21) to (28):
(viii) for enterprises which did (33) AI technologies not used because the costs seem too high
not use but considered to (34) AI technologies not used because there is a lack of relevant expertise in the enterprise
use AI technologies, (35) AI technologies not used because of incompatibility with existing equipment, software or systems
referring specifically to (36) AI technologies not used because of difficulties with availability or quality of the necessary data
mandatory variables (21) (37) AI technologies not used because of concerns regarding violation of data protection and privacy
to (28): (38) AI technologies not used because of lack of clarity about the legal consequences (such as liability in case of damage
caused by the use of Artificial Intelligence)
(39) AI technologies not used because of ethical considerations
(40) AI technologies not used because they are not useful for the enterprise
(ix) for enterprises having sent (41) percentage of e-invoices out of all invoices sent, or percentage of e-invoices out of all invoices sent in the following
invoices in electronic ranges: [0,< 10], [10,< 25], [25,< 50], [50,< 75], [>=75], in the previous calendar year
form, in a standard
structure suitable for
automated processing
(e-invoices), excluding the
transmission of PDF files,
in the previous calendar
year:
(1) The example ‘robo-advisor for automated planning, for example of investment’ should be added if the optional NACE Rev. 2.1 section L is included.
(2) The example ‘credit scoring based on machine learning’ should be added if the optional NACE Rev. 2.1 section L is included.
ELI:
http://data.europa.eu/eli/reg_impl/2025/1310/oj
9/10
OJ
L,
4.7.2025
ENMeasurement unit Absolute figures, except for characteristics related to turnover in national currency (thousands) or percentage of (total) turnover
Statistical population Activity coverage:
NACE Rev. 2.1 Sections C to K, M to O and group 95.1, optional: NACE Rev. 2.1 section L for mandatory variables (1), (2), (5)-(8), (15)-(40), (48)-(72) and
optional variables (1), (2), (4)-(11), (19)-(40)
Size class coverage:
Enterprises with 10 or more employees and self-employed persons. Enterprises with less than 10 employees and self-employed persons may be covered
optionally.
Breakdowns Activity breakdown
for calculation of national aggregates:
— aggregates of NACE Rev. 2.1 sections and group: C+D+E+F+G+H+I+J+K+M+N+O+95.1, D+E
— NACE Rev. 2.1 sections: C, F, G, H, I, J, K, M, N, O, optional: NACE Rev. 2.1 section L for mandatory variables (1), (2), (5)-(8), (15)-(40), (48)-(72) and
optional variables (1), (2), (4)-(11), (19)-(40)
— NACE Rev. 2.1 divisions: 47, 55
— aggregates of NACE Rev. 2.1 divisions: 10 + 11 + 12 + 13 + 14 + 15 + 16 + 17 + 18, 19 + 20 + 21 + 22 + 23, 24 + 25,
26 + 27 + 28 + 29 + 30 + 31 + 32 + 33
— aggregate of the NACE Rev. 2.1 divisions and groups: 26.1 + 26.2 + 26.3 + 26.4 + 46.5 + 58.2 + 61 + 62 + 63.1 + 95.1, optional: NACE Rev. 2.1
divisions and groups 64 + 66.1 + 66.3, 65 + 66.2 for mandatory variables (1), (2), (5)-(8), (15)-(40), (48)-(72) and optional variables (1), (2), (4)-(11),
(19)-(40)
for contribution to the European totals only
— NACE Rev. 2.1 sections: D, E
— NACE Rev. 2.1 divisions: 19, 20, 21, 26, 27, 28, 46, 61, 72, 79, optional: NACE Rev. 2.1 divisions: 64, 65, 66 for mandatory variables (1), (2), (5)-(8),
(15)-(40), (48)-(72) and optional variables (1), (2), (4)-(11), (19)-(40)
— NACE Rev. 2.1 group: 95.1
— aggregates of NACE Rev. 2.1 divisions: 10 + 11 + 12, 13 + 14 + 15, 16 + 17 + 18, 22 + 23, 29 + 30, 31 + 32 + 33, 62 + 63, 69 + 70 + 71, 73 + 74 + 75,
77 + 78 + 80 + 81 + 82
Size class of number of employees and self-employed persons:10+, 10-49, 50-249, 250+; optional: 0-9, 0-1, 2-9
Data transmission deadline 5 October 2026
10/10
ELI:
http://data.europa.eu/eli/reg_impl/2025/1310/oj
EN
OJ
L,
4.7.2025