Protection of personal data
Article 68
1. Member States and the Commission shall take all necessary measures to prevent any unauthorised disclosure of, or access to, the information referred to in Article 40(1), information collected by the Commission in the course of its audits, and the information referred to in Chapter VIII. 2. The information referred to in Article 40(1), of this Regulation together with information collected by the Commission in the course of its audits, shall be used by the Commission for the sole purpose of fulfilling its responsibilities provided for in Article 72 of the basic Regulation. The European Court of Auditors and the European Anti-Fraud Office shall have access to that information. 3. The information referred to in Chapter VIII shall not be sent to persons, other than those in the Member States or within the Community institutions whose duties require that they have access to it, unless the Member State supplying such information has expressly so agreed. 4. Any personal data included in the information referred to in point (d) of the second paragraph of Article 31 shall only be processed for the purposes specified in that Article.