Article 20
Framework Decision 2008/977/JHA shall apply to the protection of the data exchange in accordance with this Decision unless otherwise provided in this Decision.
Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗
Framework Decision 2008/977/JHA shall apply to the protection of the data exchange in accordance with this Decision unless otherwise provided in this Decision.
1. Data may be duplicated only for technical purposes, provided that such duplication is necessary for direct searching by the authorities referred to in Article 7. 2. Subject to Article 8(1), personal data entered by other Member States may not be copied from the Customs Information System into other national data files, except those copies held in systems of risk management used to direct national customs controls or copies held in an operational analysis system used to coordinate actions. Such copies may be made to the extent necessary for specific cases or investigations. 3. In the two exceptional cases provided for in paragraph 2, only the analysts authorised by the national authorities of each Member State shall be empowered to process personal data obtained from the Customs Information System within the framework of a risk management system used to direct customs controls by national authorities or of an operational analysis system used to coordinate actions. 4. Each Member State shall send other Member States and the Committee referred to in Article 27 a list of the risk-management departments whose analysts are authorised to copy and process personal data entered in the Customs Information System. 5. Personal data copied from the Customs Information System shall be kept only for the time necessary to achieve the purpose for which they were copied. The need for their retention shall be reviewed at least annually by the Member State which carried out the copying. The storage period shall not exceed ten years. Personal data which are not necessary for the continuation of the operational analysis shall be erased immediately or have any identifying factors removed.
The rights of persons with regard to personal data in the Customs Information System, in particular their right of access, to rectification, erasure or blocking shall be exercised in accordance with the laws, regulations and procedures of the Member State implementing Framework Decision 2008/977/JHA in which such rights are invoked. Access shall be refused to the extent that such refusal is necessary and proportionate in order not to jeopardise any ongoing national investigations, or during the period of discreet surveillance or sighting and reporting. When the applicability of such an exemption is assessed, the legitimate interests of the person concerned shall be taken into account.
1. In the territory of each Member State, any person may, in accordance with the laws, regulations and procedures of the Member State in question, bring an action or, if appropriate, a complaint before the courts or the authority competent under the laws, regulations and procedures of that Member State concerning personal data relating to himself on the Customs Information System, in order to: (a) rectify or erase factually inaccurate personal data; (b) rectify or erase personal data entered or stored in the Customs Information System contrary to this Decision; (c) obtain access to personal data; (d) block personal data; (e) obtain compensation pursuant to Article 30(2). 2. Without prejudice to the provisions of Article 31, the Member States concerned undertake mutually to enforce the final decisions taken by a court, or other competent authority, pursuant to points (a) to (c) of paragraph 1 of this Article.
Each Member State shall designate a national supervisory authority or authorities responsible for personal data protection to carry out independent supervision of such data included in the Customs Information System in accordance with Framework Decision 2008/977/JHA.
1. A Joint Supervisory Authority shall be set up, consisting of two representatives from each Member State’s respective independent national supervisory authority or authorities. 2. The Joint Supervisory Authority shall monitor and ensure the application of the provisions of this Decision and Framework Decision 2008/977/JHA as concerns the protection of natural persons with respect to the processing of personal data through the Customs Information System. 3. To that end, the Joint Supervisory Authority shall be competent to supervise operation of the Customs Information System, to examine any difficulties of application or interpretation which may arise during its operation, to study problems which may arise with regard to the exercise of independent supervision by the national supervisory authorities of the Member States, or in the exercise of rights of access by individuals to the System, and to draw up proposals for the purpose of finding joint solutions to problems. 4. For the purpose of fulfilling its responsibilities, the Joint Supervisory Authority shall have access to the Customs Information System. 5. Reports drawn up by the Joint Supervisory Authority shall be forwarded to the authorities to which the national supervisory authorities submit their reports, to the European Parliament and the Council.
1. The European Data Protection Supervisor shall supervise the activities of the Commission regarding the Customs Information System. The duties and powers referred to in Articles 46 and 47 of Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data ( 7 ) shall apply accordingly. 2. The Joint Supervisory Authority and the European Data Protection Supervisor, each acting within the scope of their respective competences, shall cooperate in the framework of their responsibilities and shall ensure coordinated supervision of the Customs Information System, including for issuing relevant recommendations. 3. The Joint Supervisory Authority and the European Data Protection Supervisor shall meet for that purpose at least once a year. The costs and servicing of these meetings shall be for the account of the European Data Protection Supervisor.
Articles on this page are reproduced verbatim from official open data. See the attribution line.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.