FOR PREVIEWING & TESTING PURPOSES ONLY.
This notification will disappear once the page will be published.
This link is available for less than 30 minutes.
  • Snadné čtení
  • Velikost textu

Chcete podat stížnost na orgán či instituci EU?

  • Vývoz
Zvolený jazyk: 
  • English
Dostupné jazyky: 
Překlad této stránky bude k dispozici za několik minut. Jakmile bude hotový, budeme vás informovat. Vezměte prosím na vědomí, že vzhledem k velmi vysokému zatížení nástroje strojového překladu eTranslation to může trvat mnohem déle než obvykle.

Third Interinstitutional Seminar on Public Access to Documents

Speech by Ombudswoman Teresa Anjinho at the Third Interinstitutional Seminar on Public Access to Documents

Dear colleagues,

It is great to be here. Let me begin by expressing my sincere thanks for this invitation to Emer Finnegan, the Director-General of the Council’s Legal Service as well as Preben Aamann, Director-General for Communication and Information.

Over the next twenty minutes, I will be pleased to share my thoughts and perspective as European Ombudswoman on the seminar’s key topics, as well as on the more specific issue, that is access to documents. Afterwards, I will be happy to take your questions.

But before I do so, allow me to highlight the importance of events like this for discussing among us and reflecting on advancing good administration. This seminar not only reflects an internal commitment to refining the handling of access requests, but also a broader willingness on the part of the EU institutions to continuously improve our administrative procedures for the benefit of citizens.

Such a reflex for self-improvement resonates in an increasingly chaotic and uncertain world, a world in which many people feel unheard or unrepresented. It shows our commitment that European public institutions remain devoted to improving citizens’ lives and protecting their fundamental rights, in this case, public access to documents.

Improvements in the handling of access to documents and the provision of information play a particularly valuable role in earning and retaining citizen’s trust in a democratic society.

Democracy, after all, depends on the continuous consent of the governed, and that consent requires information and a clear understanding of how decisions are made.

We cannot expect citizens to accept the actions of their public institutions without being able to find out what those institutions are up to and why their views were not sought or considered. To put it simply, when important decisions are taken, people want to know who was at the table, what evidence was considered, and on whose behalf.

For the most part, I believe the EU institutions do a good job of providing citizens with information. But we all know – and as past inquiries carried out by my Office demonstrate – the current system formalised back in 2001 with the adoption of Regulation 1049, is still far from perfect.

There are gaps and growing cracks that are more than visible and can affect the stability of the whole transparency structure. And one of the most visible weaknesses in the overall stability of the 1049 framework is without doubt the challenges faced by almost all IBOAs – of course, some more than others – when it comes to sharing information and replying to citizens’ requests in a timely manner.

Twenty-five years ago, the Regulation was designed for a world of paper trails, physical archives, and analog processes. Twenty-five years later, we operate in an era where digital systems dominate almost entirely our daily lives and work, where negotiations may happen via text messages, where governance increasingly relies on data flows that leave no traditional paper trail behind, and where decisions can even be made by algorithms.

The way the EU administration works has fundamentally and irreversibly changed. No one is going back to a paper-based world.

Digital and AI-assisted tools have transformed how decisions are made, while information governance has shifted from being controlled exclusively by institutions to increasingly involving the corporate world and external stakeholders.

The question we must ask ourselves is: can a transparency framework which was built 25 years ago still deliver accountability in our new digital and AI-centred age?

Over the years, the Court of Justice of the EU and the European Ombudsman have developed a substantial body of case law and 'ombudsprudence', namely addressing novel legal and factual challenges posed by digitalisation when it comes to the exercise of the fundamental right of public access.

From the expansive interpretation of what constitutes a 'document' to the evolving boundaries of its exceptions, the Court's rulings and my Office's recommendations and suggestions for improvement have sought to adapt a pre-digital framework to today's realities.

Yet, nowhere has this adaptation proven more contentious, or more consequential, than in the reappraisal of the very concept of a 'document' – a term once assumed to be self-evident but now at the heart of some of the most significant debates in EU transparency law.

And that is precisely where I will focus today: on how this key concept, once so straightforward, has become a battleground for determining the scope and effectiveness of the right to access in the digital age.

The Regulation defines a document in terms deliberately chosen to survive change: any content – whatever its medium, paper, electronic, sound, image – concerning a matter relating to the policies, activities and decisions falling within the institution's sphere of responsibility.

Twenty-five years on, that choice looks almost prophetic. The definition has not needed to be rewritten. What has changed is everything around it: how institutions communicate, how they store what they know, and, increasingly nowadays, who – or what – drafts their decisions.

So, what counts as a document when communication itself has gone digital? What does access mean when a decision has been shaped, in part, by a machine? And, one more question pops up: how can we ensure that EU activities – be they legislative, policy, or purely administrative – are not conducted outside documentary records and related safeguards, and hence escape accountability?

Start with the simplest case: an email or a text message. The principle we are required to apply consistently is that content decides, not medium. But, to apply that principle, we need first to keep in mind four distinct but essential concepts.

Let me be clear. Content, registration, retention and access to a document are four different concepts although intrinsically linked.

Content is what is actually written (however one defines the verb “to write” – by hand, typing on a keyboard, dictating a voice message). It is the substance itself, and it exists the moment it is created, independently of anything an institution later decides to do with it. Whether that content is considered a 'document' depends on what it relates to – and this is a legal question. That is, the existence of the content does not depend on any administrative choice, such as whether someone decided to formally register it, kept it somewhere in a ‘private location’ or subsequently deleted it.

Registration is an institution's internal act of filing that content in its record-keeping systems – a consequence of the recognition that the content qualifies as a document, but never a precondition for the existence of a document.

Retention is the follow up, separate, practical question of how long that content, when there’s no decision to register it as a document, is kept available: for days, years, or not at all.

And finally, access is the institutional choice of disclosing the document, fully or partially, or not.

Four distinct concepts; four different potential failure points.

This might sound obvious in theory. In practice, it has been contested case after case. Institutional registration and record-keeping have become a real challenge to the EU's transparency framework.

Much of what I am about to briefly describe is, at root, about institutions treating the absence of one element – usually registration – as if it erased the other three. It seems that a document is a document not because of its content but because of the mere act of someone deciding to register it.

The examples.

A journalist asked for text messages between the Commission President and a pharmaceutical CEO at the height of a vaccine negotiation the whole world was watching. The search that followed looked only for what had already been registered – which is to say, it was designed not to find what it was asked to find. My Office found maladministration and that case ultimately reached the General Court, which confirmed that the institutions cannot deprive of all substance the right of access to documents which they hold by failing to register the documentation relating to their activities.

Already this year, my Office opened an inquiry concerning a text message from a head of state to the Commission President on a trade negotiation – a case that touches the issue of disappearing messages, cybersecurity policy, and record-keeping all at once.

When institutions treat registration as a precondition for the definition and thus existence of a document, they risk – at least when it comes to text messages – creating grey accountability zones where critical decisions may leave no trace behind.

None of this is about distrust of institutions and their adoption of modern digital tools. Disappearing messages on smartphones exist for real reasons – cybersecurity and the protection of officials who are, today, genuine targets. My Office has always emphasised that transparency and security are not opposites. But the reasoning cannot run the other way: an institution cannot let a security architecture quietly decide what is a document in the first place. If the content is relevant to an EU policy, and activity, or the decision-making process, it should survive long enough to be assessed, whatever channel it travelled through.

This is, fundamentally, a question about accountability – and about how we manage the transition from an analogue administration to a digital one and beyond. An administration that embraces modern tools cannot by any means end up being less accountable. The transition has to be principled.

Retention is exactly where those principles become more concrete. Keeping relevant content – created and exchanged in one’s official capacity – for a reasonable period is not bureaucratic caution. It is what makes traceability possible, what makes proper record-keeping possible, what makes an institution's conduct predictable rather than arbitrary, and what makes real oversight possible at all, whether by this Office, by the Court of Justice, or by the public itself. Without it, none of those things can function, however well-drafted or equipped the rest of the framework is.

And there is one point on which I strongly believe we cannot compromise. Once a document, or a piece of content, has been requested or the decision on access challenged, it must be preserved – automatically, and irrespective of whatever the institution ultimately concludes about whether it should be disclosed. It is only then that the question of access to such a document can be debated, appealed, reviewed. What should never happen is for that document to simply cease to exist while the debate, the review is under way.

It cannot be good administration if we end up with accountability-free zones – when whether by design or by accident, nothing survives long enough to be checked. An administration that can make its own conduct unreviewable, by the timing of its own registration or retention settings, is not accountable in any meaningful sense.

And because we are focusing on the impact of technology, I need also to draw your attention to another question, one we are only beginning to face: what happens to access when a decision, or a draft, or a summary, has been produced with the help of AI?

Here, the gaps are starkest. The Regulation was adopted on the assumption that the 'documents' falling within its scope are human-generated. That is not entirely the case anymore. AI-assisted decision-making – automated visa processing, for instance, or algorithmic regulatory tools – can generate no retrievable 'document' at all.

When algorithms assist in drafting laws or making regulatory decisions, sometimes no 'document' exists to request. And since the Court's case law confirms that database extracts count as documents only where preprogrammed searches exist, AI outputs that leave no fixed record may fall entirely outside the Regulation's scope.

My Office has not yet received a complaint specifically about this. But we have not waited for one. In our inquiry into how the Commission decides to use artificial intelligence, we concluded that transparency and public participation cannot be an afterthought bolted onto AI systems – they have to be designed in from the start.

Institutions need to know, and be able to explain, why an AI tool produced the output it did. Staff need to be trained to question AI suggestions, not simply permitted to confirm them. And where AI has assisted in a decision or a reply, the public should be told – not buried in a footnote, but stated plainly: research, drafting, or something more.

This is clearly work in progress, but it is important to be aware.

So, everything so far has been about reacting well when someone asks.

But one other prominent solution to the workload and resource issue when it comes to access to documents is today’s second key topic – proactive transparency.

In recent years, we have seen EU policymaking expand into a variety of new areas or into old areas in new ways – defence, international trade framework, energy and food security, digital sovereignty, all areas that people care deeply about and in which they want to have a say. The result has been – and will continue to be – a rise in demand for information.

I recognise that, just like with AI - i.e. increased accessibility –, this too has made your work more difficult. But it is important not to lose sight of the bigger picture. What we do as EU institutions is vital for upholding citizens’ rights and the democratic life of our Union.

In these circumstances, investing heavily in a culture of proactive transparency can not only make the institutions more open and accountable in the eyes of citizens but also help reduce the administrative burden of dealing with access requests.

It is important that the EU’s institutions, bodies, offices and agencies anticipate recurring or foreseeable requests. For instance, where an institution regularly receives requests for the same types of documents, it should consider the possibility of publishing them proactively rather than repeatedly processing individual requests.

I’m happy to say that we have seen real progress on this front over the years, namely in the Commission and in the Council.

But in addition to the positives, we have also seen some puzzling cases in which more transparency, and perhaps more proactive transparency, was warranted but not provided.

For instance, my Office dealt with an inquiry where the Commission refused to provide access to various documents concerning the evaluation of two Members States’ national plans under the RRF. It argued that disclosure could undermine the financial, monetary, or economic policy of not only the EU but also the Member States concerned. Yet, when they were consulted by the Commission, the two countries had not identified any risk. In addition, they later provided the complainant with documents concerning their RRF plans in response to national access requests.

More recently, we had a case where the Commission refused to follow our recommendation for possible disclosure of a report by a very large social media platform on its compliance with EU digital rules. There were several issues with how this access request was handled, but what’s interesting to note in the context of this discussion is that the platform in question had made the report public, albeit with redactions, by the time we issued our recommendation.

I acknowledge that different institutions or organisations can hold differing opinions on disclosure, but these types of inconsistencies should justify a review of current transparency practices.

It is difficult for citizens to understand, for example, why documents that are already published elsewhere are not being disclosed by the EU institutions, whether that be proactively or in response to an access request.

And indeed, this requires not only a change in policy but also a shift in mindset. In certain situations, my impression is that transparency is seen as a hindrance to action – that it will somehow undermine decision making or the ability for institutions or Member States to find compromise.

We should remember that, within our democratic Union, transparency is what actually enables action. It is what ensures that law-making is done not only for citizens, but with them. It is what ultimately gives law-making its legitimacy.

Regulation 1049/2001 has proved resilient. But resilience is not the same as effectiveness. A framework that has now become heavily dependent on case-by-case litigation to decide whether a text message is a document, whether an AI output is accessible or how an AI-assisted decision should be explained, is not a legal framework citizens can rely on with any degree of certainty.

So, before I take your questions, allow me to touch on one crucial aspect about the future of access to documents – the need to revise the Regulation.

I recognise that this view can be somewhat controversial, but I believe the time for a debate has come.

We have a regulation that is now a quarter-of-a-century old, and which was designed for a data environment that has changed beyond recognition. EU policymaking itself has also evolved in ways that would have been difficult to foresee at the turn of the century.

And while much of the law may still look good on paper, we need to admit that it is not functioning as it should. I have already spoken about the challenges related to new technologies, but there are other problems.

For instance, inquiries carried out by my Office show that the legal deadlines for handling access requests and confirmatory applications are frequently missed. When and if access is finally granted, the documents obtained can often be obsolete – for journalists, for academics, and for citizens wanting to have their say in EU decision making. This is neither good administration nor good for effective oversight.

There is also the issue of how exceptions are used. Regulation 1049 provides for a variety of exceptions to deny or partially deny access to certain documents. These exist for valid reasons, but they are frequently interpreted far too broadly. In past Ombudsman inquiries, we have seen EU institutions use vague, abstract, and unsubstantiated arguments for applying exceptions. We have also seen them use reasoning that has already been dismissed by the Court of Justice, such as that disclosure would result in external pressure or public misinterpretation.

I would further add that, under the current system, the burden placed on citizens to obtain documents they are entitled to is becoming increasingly unreasonable. Institutions are still too often handling requests through the lens of risk management, requiring citizens to find and/or cite past court judgments, the results of Ombudsman inquiries, and internal institutional guidelines just to make their case.

This is not in line with the spirt of the law and does not further transparency. One should not have to become an EU law expert to effectively request access to documents held by the EU administration. Or to be dependent on lodging a complaint to the Ombudsman or to bring an action before the General Court. Both routes are time consuming, resource-intensive, and legally complex.

Overall, our system today desperately lacks clarity – not only for individuals but also for institutions struggling between interpretation and governance challenges.

We need clearer, more comprehensive, and more modern rules – rules adapted to today’s technology and to how decisions are actually taken, rules that enshrine good governance and proactive transparency as the norm rather than the exception.

I know that some people are reluctant to reopen this legislation, fearing that a revised regulation could either impose more onerous and hard-to-comply obligations or result in a less transparent system than the current one. These fears are understandable, but they also underestimate the long-term costs of keeping things the same – the steadily rising price we pay for inertia.

To quote one of Europe’s founding fathers, Jean Monnet: “Obviousness and necessity, when they meet, should leave no room for hesitation or respite.”

I think we have indeed reached the point where the need for reform has become both necessary and obvious. And in such circumstances, we must not fear a legislative debate. We should instead embrace the opportunity to build a new and improved transparency framework – one that puts the citizen and their right to information at the very centre.

Thank you. I look forward to your questions and to the discussion.

  • Vývoz