Towards Cyber Security Regulation of Software in the European Union
摘要
Under European Union law, software, the defining asset class of the twenty-first century, carries broad rights. It is subject to only a limited and fragmented set of responsibilities or obligations in relation to quality generally and security in particular. Other than in respect of select situations where software may pose a danger to consumers, there is no generally recognised expectaton of security when procuring software. In most cases this means that security must be pursued deliberately and relies on custom contractually arrangements for enforcement. In this chapter we discuss a selection of existing and leading EU regulatory initiatives that deal with software and its security. The core of the paper is a discussion and analysis of norms in the GDPR relevant for software and security. We highlight how these different initiatives leave significant gaps in the governance of security for the information society, and how this may be problematic.