Subject: Safeguarding digital sovereignty in Italy’s national recovery and resilience plan: the case of Starlink
As digital sovereignty is a cornerstone of EU security, the deployment of EU resources, in particular through the Recovery and Resilience Facility (RRF), should ensure a secure and effective digital transition. According to recent news, the Italian Government intends to entrust SpaceX/Starlink technologies with providing internet connectivity in remote areas as part of Italy’s national recovery and resilience plan (NRRP).
Against this background:
1. In light of Article 18 of Regulation EU 2021/2411, how does the Commission intend to evaluate a potential request to include SpaceX/Starlink technologies in Italy’s NRRP and ensure that the required security self-assessment – based on objective common criteria – properly addresses risks posed to digital sovereignty and data management by a non-EU company?
2. Will the Commission ensure that the technical standards outlined in the NRRP, such as minimum connection speeds and infrastructure resilience, are fully maintained, and that there will be no reduction in these standards in the case of technologies such as those proposed by SpaceX/Starlink?
Submitted: 13.1.2025
1 Regulation (EU) 2021/241 of the European Parliament and of the Council of 12 February 2021 establishing
the Recovery and Resilience Facility, OJ L 57, 18.2.2021, p. 17, ELI:
http://data.europa.eu/eli/reg/2021/241/oj.
Answer given by Executive Vice-President Fitto on behalf of the European Commission (13 March 2025)
To date, the Commission has not received any proposal from the Italian Government to entrust SpaceX/Starlink technologies with providing Internet connectivity in remote areas as part of Italy’s national recovery and resilience plan. In the absence of any such proposal, the Commission cannot indicate how it would intend to evaluate it.
Pursuant to Article 18, paragraph 4, point (g) of Regulation EU 2021/241 (1), in case of submission of an amended plan including such a measure related to investments in digital capacities and connectivity, the plan shall include, where appropriate, a security self-assessment based on common objective criteria identifying any security issues, and detailing how those issues will be addressed in order to comply with relevant Union and national law.
1 1Regulation (EU) 2021/241 of the European Parliament and of the Council of 12 February 2021 establishing the Recovery and Resilience Facility, OJ L 57,
18.2.2021, p. 17, ELI: http://data.europa.eu/eli/reg/2021/241/oj. 1 ∙ ⸱
Regulation (EU) 2021/241 of the European Parliament and of the Council of 12 February 2021 establishing the Recovery and Resilience Facility (OJ L 57, 18.2.2021).