My bookmarksSign up free

Council Regulation (EC) No 515/97 TITLE V

Article 23–Article 41 · 19 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Article 23

1. An automated information system, the 'Customs Information System`, hereinafter referred to as the 'CIS`, is hereby established to meet the requirements of the administrative authorities responsible for applying the legislation on customs or agricultural matters, as well as those of the Commission. 2. The aim of the CIS, in accordance with the provisions of this Regulation, shall be to assist in preventing, investigating and prosecuting operations which are in breach of customs or agricultural legislation, by increasing, through more rapid dissemination of information, the effectiveness of the cooperation and control procedures of the competent authorities referred to in this Regulation. 3. The customs authorities of the Member States may use the technical infrastructure of the CIS in the performance of their duties in the framework of the customs cooperation referred to in Article K.1 (8) of the Treaty on European Union. In such a case, the Commission shall ensure the technical management of the infrastructure. 4. Those operations in connection with the application of agricultural regulations which require the introduction of information into the CIS shall be determined by the Commission in accordance with the procedure set out in Article 43 (2). 5. The exchange of information provided for under Articles 17 and 18 is not covered by the provisions of this Title. 6. The Member States and the Commission, hereinafter referred to as the 'CIS partners`, shall take part in the CIS under the conditions laid down in this Title. Chapter 2 Operation and use of the CIS

Article 24

The CIS shall consist of a central database facility and it shall be accessible via terminals in each Member State and at the Commission. It shall comprise exclusively data necessary to fulfil its aim as stated in Article 23 (2), including personal data, in the following categories: (a) commodities; (b) means of transport; (c) businesses; (d) persons; (e) fraud trends; (f) availability of expertise.

Article 25

The items to be included in the CIS relating to each of categories (a) to (f) in Article 24 shall be determined in accordance with the procedure provided for in Article 43 (2) to the extent that this is necessary to achieve the aim of the System. No items of personal data shall be included in any event in categories (e) and (f) of Article 24. In categories (a) to (d) of Article 24 the items to be included in respect of personal data shall comprise no more than: (a) name, maiden name, forenames and aliases; (b) date and place of birth; (c) nationality; (d) sex; (e) any particular objective and permanent physical characteristics; (f) reason for inclusion of data; (g) suggested action; (h) a warning code indicating any history of being armed, violent or escaping; (i) registration number of the means of transport. In all cases, personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership and data concerning the health or sex life of an individual shall not be included.

Article 26

The following principles must be observed in the implementation of the CIS where personal data are concerned: (a) collection and any other operation for processing personal data must be carried out fairly and lawfully; (b) data must be collected for the purposes defined in Article 23 (2) and not subsequently processed in a manner incompatible with those purposes; (c) data must be adequate, relevant and not excessive in relation to the purposes for which they are processed; (d) data must be accurate and, where necessary, kept up to date; (e) data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes in view.

Article 27

1. Data in categories (a) to (d) of Article 24 shall be included in the CIS only for the purpose of sighting and reporting, discreet surveillance or specific checks. 2. For the purposes of the actions referred to in paragraph 1, personal data within any of categories (a) to (d) of Article 24 may be included in the CIS only if, especially on the basis of prior illegal activities, there is evidence to suggest that the person concerned has committed, is committing or will commit actions which are in breach of customs or agricultural legislation and which are of particular relevance at Community level.

Article 28

1. If the actions referred to in Article 27 (1) are carried out, the following information may, in whole or in part, be collected and transmitted to the CIS partner which suggested the actions: (a) the fact that the commodity, means of transport, business or person reported has been found; (b) the place, time and reason for the check; (c) route and destination of the journey; (d) persons accompanying the person concerned or occupants of the means of transport; (e) means of transport used; (f) objects carried; (g) the circumstances under which the commodity, means of transport, business or person was found. When such information is collected in the course of discreet surveillance, steps must be taken to ensure that the secret nature of the surveillance is not jeopardized. 2. In the context of the specific checks referred to in Article 27 (1), persons, means of transport and objects may be searched to the extent permissible and in accordance with the laws, regulations and procedures of the Member State in which the search takes place. If the specific checks are not permitted by the law of a Member State, they shall automatically be converted by that Member State into sighting and reporting or discreet surveillance.

Article 29

1. Direct access to data included in the CIS shall be reserved exclusively for the national authorities designated by each Member State and the departments designated by the Commission. These national authorities shall be customs administrations, but may also include other authorities competent, according to the laws, regulations and procedures of the Member State in question, to act in order to achieve the aim stated in Article 23 (2). 2. Each Member State shall send the Commission a list of its designated competent authorities which have direct access to the CIS stating, for each authority, to which data it may have access and for what purposes. The Commission shall inform the other Member States accordingly. It shall also inform all the Member States of the corresponding details concerning the Commission departments authorized to have access to the CIS. The list of national authorities and Commission departments thus designated shall be published for information by the Commission in the Official Journal of the European Communities. 3. Notwithstanding the provisions of paragraphs 1 and 2, the Council, acting on a proposal from the Commission, may decide to permit access to the CIS by international or regional organizations, provided that, where relevant, a protocol is at the same time concluded with those organizations in conformity with Article 7 (3) of the Convention between Member States of the Community on the use of information technology for customs purposes. In reaching the decision account shall be taken in particular of any existing bilateral or Community arrangements and of the adequacy of the level of data protection.

Article 30

1. CIS partners may use data obtained from the CIS only in order to achieve the aim stated in Article 23 (2); however, they may use it for administrative or other purposes with the prior authorization of the CIS partner which introduced the data into the system subject to conditions imposed by it or, where applicable, the Commission, which included it in the System. Such other use shall be in accordance with the laws, regulations and procedures of the Member State which seeks to use it and, where appropriate, the corresponding provisions applicable to the Commission in this connection and should take into account the principles set out in the Annex. 2. Without prejudice to paragraphs 1 and 4 of this Article and Article 29 (3), data obtained from the CIS shall be used only by national authorities or departments in each Member State and by departments designated by the Commission competent, in accordance with the laws, regulations and procedures applicable to them, to act in order to achieve the aim stated in Article 23 (2). 3. Each Member State shall send the Commission a list of the authorities or departments referred to in paragraph 2. The Commission shall inform the other Member States accordingly. It shall also inform all the Member States of the corresponding details concerning the Commission departments authorized to have access to the CIS. The list of the authorities or departments thus designated shall be published for information by the Commission in the Official Journal of the European Communities. 4. Data obtained from the CIS may, with the prior authorization of, and subject to any conditions imposed by, the Member State which included them in the System, be communicated for use by national authorities other than those referred to in paragraph 2, third countries and international or regional organizations wishing to make use of them. Each Member State shall take special measures to ensure the security of such data when they are being transmitted or supplied to departments located outside its territory. The provisions referred to in the first subparagraph shall apply mutatis mutandis to the Commission where it has entered the data in the System.

Article 31

1. The inclusion of data in the CIS shall be governed by the laws, regulations and procedures of the supplying Member State and, where appropriate, the corresponding provisions applicable to the Commission in this connection, unless this Regulation lays down more stringent provisions. 2. The processing of data obtained from the CIS, including their use or performance of any action under Article 27 (1) suggested by the supplying CIS partner, shall be governed by the laws, regulations and procedures of the Member State processing or using such data and the corresponding provisions applicable to the Commission in this connection, unless this Regulation lays down more stringent provisions. Chapter 3 Amendment of data

Article 32

1. Only the supplying CIS partner shall have the right to amend, supplement, correct or delete data which it has included in the CIS. 2. Should a supplying CIS partner note, or have drawn to its attention, that the data it included are factually inaccurate or were included or are stored contrary to this Regulation, it shall amend, supplement, correct or delete the data, as appropriate, and shall advise the other CIS partners accordingly. 3. If a CIS partner has evidence to suggest that an item of data is factually inaccurate, or was included or is stored in the CIS contrary to this Regulation, it shall advise the supplying CIS partner as soon as possible. The latter shall check the data concerned and, if necessary, correct or delete the item without delay. The supplying CIS partner shall advise the other partners of any correction or deletion affected. 4. If, when including data in the CIS, a CIS partner notes that its report conflicts with a previous report with regard to content or suggested action, it shall immediately advise the partner which made the previous report. The two partners shall then attempt to resolve the matter. In the event of disagreement, the first report shall stand but those parts of the new report which do not conflict shall be included in the System. 5. Subject to the other provisions of this Regulation, where in any Member State a court, or other authority designated for the purpose within that Member State, makes a final decision to amend, supplement, correct or delete data in the CIS, the CIS partners shall align their action thereon. In the event of conflict between such decisions of courts or other authorities designated for the purpose including those referred to in Article 36 concerning correction or deletion, the Member State which included the data in question shall delete them from the System. The provisions in the first subparagraph shall apply mutatis mutandis where a Commission decision on data contained in the CIS is declared void by the Court of Justice. Chapter 4 Retention of data

Article 33

1. Data included in the CIS shall be kept only for the time necessary to achieve the purpose for which they were included. The need for their retention shall be reviewed at least annually by the supplying CIS partner. 2. The supplying CIS partner may, within the review period, decide to retain data until the next review if their retention is necessary for the purposes for which they were included. Without prejudice to Article 36, if there is no decision to retain data they shall automatically be transferred to that part of the CIS to which access shall be limited in accordance with paragraph 4. 3. The CIS shall automatically inform the supplying CIS partner of a scheduled transfer of data from the CIS under paragraph 2, giving one month's notice. 4. Data transferred under paragraph 2 shall continue to be retained for one year within the CIS but, without prejudice to Article 36, shall be accessible only to a representative of the Committee referred to in Article 43 in connection with the application of the seventh, eighth and ninth indents of paragraph 4 thereof, and paragraph 5 thereof, or to the supervisory authorities referred to in Article 37. During that period the data may be consulted only for the purposes of checking their accuracy and lawfulness. They must thereafter be deleted. Chapter 5 Personal-data protection

Article 34

1. Each CIS partner intending to receive personal data from, or include them in, the CIS shall, no later than the date of application of this Regulation, adopt national legislation, or internal rules applicable to the Commission, guaranteeing the protection of the rights and freedoms of individuals with regard to the processing of personal data. 2. A CIS partner may receive personal data from, or include them in, the CIS only where the arrangements for the protection of such data provided for in paragraph 1 have entered into force. Each Member State shall also have previously designated a national supervisory authority or authorities as provided for in Article 37. 3. In order to ensure the proper application of the personal-data protection provisions in this Regulation, each Member State and the Commission shall regard the CIS as a system for processing personal data subject to the provisions referred to in paragraph 1 and the more stringent provisions contained in this Regulation. The internal rules applicable to the Commission, as referred to in paragraph 1, shall be published in the Official Journal of the European Communities.

Article 35

1. Subject to Article 30 (1), CIS partners shall be prohibited from using personal data from the CIS other than for the purpose stated in Article 23 (2). 2. Data may be duplicated only for technical purposes, provided that such duplication is necessary for searching by the authorities referred to in Article 29. Subject to Article 30 (1), personal data included by other Member States or the Commission may not be copied from the CIS into other data files for which the Member States or the Commission have responsibility.

Article 36

1. The rights of persons with regard to the personal data in the CIS, in particular their right of access, shall be put into effect: - in accordance with the laws, regulations and procedures of the Member State in which such rights are invoked, - in accordance with the internal rules applicable to the Commission referred to in Article 34 (1). If laid down in the laws, regulations and procedures of the Member State concerned, the national supervisory authority provided for in Article 37 shall decide whether information is to be communicated and the procedure for doing so. 2. A CIS partner to which an application for access to personal data is made may refuse access if communication would be likely to prejudice the prevention, investigation and prosecution of operations which are in breach of customs or agricultural legislation. A Member State may also refuse access as provided for in its laws, regulations and procedures in relation to cases where such refusal constitutes a measure necessary to safeguard national security, defence, public safety and the rights and freedoms of others. The Commission may refuse access where such refusal constitutes a measure necessary to safeguard the rights and freedoms of others. Access shall be refused in any event during the period in which action is taken for the purposes of sighting and reporting or discreet surveillance. 3. If the personal data for which an application for access has been made have been supplied by another CIS partner, access shall be permitted only if the supplying partner has been given the opportunity to state its position. 4. Any person may, in accordance with the laws, regulations and procedures of each Member State or with the internal rules applicable to the Commission, have personal data relating to himself corrected or deleted by each CIS partner if those data are factually inaccurate, or were included or are stored in the CIS contrary to the aim stated in Article 23 (2) or if the principles of Article 26 have not been observed. 5. In the territory of each Member State, any person may, in accordance with the laws, regulations and procedures of the Member State in question, bring an action or, if appropriate, a complaint before the courts or the authority designated for the purpose, in accordance with those laws, regulations and procedures, in connection with personal data relating to himself in the CIS, in order to: (a) correct or delete factually inaccurate personal data; (b) correct or delete personal data included or stored in the CIS contrary to this Regulation; (c) obtain access to personal data; (d) obtain compensation under Article 40 (2). With regard to data included by the Commission, an action may be brought before the Court of Justice in accordance with Article 173 of the Treaty. The Member States and the Commission undertake mutually to enforce the final decisions taken by a court, the Court of Justice or another authority designated to that end which concern points (a), (b) and (c) of the first subparagraph. 6. The references in this Article and in Article 32 (5) to a 'final decision` do not imply any obligation on the part of any Member State or the Commission to appeal against a decision taken by a court or other authority designated for the purpose. Chapter 6 Personal-data protection supervision

Article 37

1. Each Member State shall designate a national supervisory authority or authorities responsible for personal-data protection to carry out independent supervision of such data included in the CIS. The supervisory authorities, in conformity with their respective national legislations, shall carry out independent supervision and checks to ensure that the processing and use of data held in the CIS do not violate the rights of data subjects. For this purpose the supervisory authorities shall have access to the CIS. 2. Any person may ask any national supervisory authority to check personal data relating to himself in the CIS and the use which has been or is being made of those data. The right shall be governed by the laws, regulations and procedures of the Member State in which the request is made. If the data have been included by another Member State or the Commission, the check shall be carried out in close coordination with that Member State's national supervisory authority or with the authority provided for in paragraph 4. 3. The Commission shall take every step within its departments to ensure personal-data protection supervision which offers safeguards of a level equivalent to that resulting from paragraph 1. 4. Pending the appointment of any authority or authorities set up for the Community institutions and bodies, the Commission's activities as regards the data-protection rules laid down in Article 34 (1), Article 36 (1) and Article 37 (3) shall be supervised by the Ombudsman provided for in Article 138e of the Treaty establishing the European Community in the context of the task allotted to him by that Treaty. Chapter 7 Security of the CIS

Article 38

1. All appropriate technical and organizational measures necessary to maintain security shall be taken: (a) by the Member States and the Commission, each insofar as it concerns them, in respect of the terminals of the CIS located on their respective territories and in the Commission's offices; (b) by the Committee referred to in Article 43 in respect of the CIS and the terminals located on the same premises as the CIS and used for technical purposes and the checks required by paragraph 3. 2. In particular, the Member States, the Commission and the Committee referred to in Article 43 shall take measures: (a) to prevent any unauthorized person from having access to installations used for the processing of data; (b) to prevent data and data media from being read, copied, modified or deleted by unauthorized persons; (c) to prevent the unauthorized entry of data and any unauthorized consultation, modification or deletion of data; (d) to prevent data in the CIS from being accessed by unauthorized persons by means of data-transmission equipment; (e) to guarantee that, with respect to the use of the CIS, authorized persons have right of access only to data for which they have competence; (f) to guarantee that it is possible to check and establish to which authorities data may be transmitted by data-transmission equipment; (g) to guarantee that it is possible to check and establish ex post facto what data have been introduced into the CIS, when and by whom, and to monitor interrogation; (h) to prevent the unauthorized reading, copying, modification or deletion of data during the transmission of data and the transport of data media. 3. In accordance with Article 43, the Committee shall verify that the searches carried out were authorized and were carried out by authorized users. At least 1 % of all searches made shall be verified. A record of such searches and verifications shall be entered into the system and shall be used only for the said verifications. It shall be deleted after six months.

Article 39

1. Each of the Member States shall designate a department which shall be responsible for the security measures set out in Article 38, in relation to the terminals located in its territory, the review functions set out in Article 33 (1) and (2), and, in general, for the proper implementation of this Regulation insofar as is necessary under its laws, regulations and procedures. 2. The Commission, for its part, shall designate those of its departments which are to be responsible for the measures referred to in paragraph 1. Chapter 8 Responsibilities and publication

Article 40

1. Each CIS partner that has included data in the System shall be responsible for the accuracy, currency and lawfulness of those data. Each Member State or, where applicable, the Commission shall also be responsible for complying with the provisions of Article 26 of this Regulation. 2. Each CIS partner shall be liable, in accordance with national laws, regulations and procedures or the equivalent Community provisions, for injury caused to a person through the use of the CIS in the Member State concerned or at the Commission. This shall also be the case where the injury was caused by the supplying CIS partner entering inaccurate data or entering data contrary to this Regulation. 3. If the CIS partner against which an action in respect of inaccurate data is brought did not supply them, the partners concerned shall seek agreement as to what proportion, if any, of the sums paid out in compensation shall be reimbursed by the supplying partner to the other partner. Any such sums agreed shall be reimbursed on request.

Article 41

The Commission shall publish a communication in the Official Journal of the European Communities concerning the implementation of the CIS. TITLE VI PROTECTION OF DATA DURING THE NON-AUTOMATIC EXCHANGE OF DATA

Back to Council Regulation (EC) No 515/97 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next