My bookmarksSign up free

Commission Implementing Regulation (EU) No 433/2012 CHAPTER VI — DATA

Article 16–Article 19 · 4 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

SECTION 1 — Data communication

Communication to the NEAFC Secretary

Article 16

The data exchange formats and protocols referred to in Article 12(2) of Regulation (EU) No 1236/2010 to be used for transmission of reports and information to the NEAFC Secretary shall comply with the rules set out in Annex X; the corresponding codes to be used in communication with the NEAFC Secretary are as set out in Annex XI.

SECTION 2 — Data security and confidentiality

Common provisions on data security and confidentiality

Article 17

1.   This Section lays down detailed rules on confidentiality for the implementation of Article 45 of Regulation (EU) No 1236/2010. It shall apply to all electronic reports and messages under this Regulation with the exception of the global reporting of catches referred to in Article 6 of this Regulation. 2.   Each Member State shall, where necessary, at the request of the NEAFC Secretary, rectify or erase electronic reports or messages the processing of which does not comply with Regulation (EU) No 1236/2010 and this Regulation. 3.   The electronic reports and messages shall be used only for the purposes specified in the Scheme laid down by Regulation (EU) No 1236/2010.

Data from inspections

Article 18

1.   Member States carrying out an inspection may retain and store electronic reports and messages transmitted by the NEAFC Secretary within 24 hours of the departure of the vessels, to which the data pertain, from the Regulatory Area without re-entry. Departure shall be deemed to have been effected six hours after the transmission of the intention to exit from the Regulatory Area. 2.   Member States carrying out an inspection shall ensure the secure processing of electronic reports and messages in their respective electronic data processing systems, in particular where the processing involves transmission over a network. 3.   Member States shall adopt appropriate technical and organisational measures to protect electronic reports and messages against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access and against all inappropriate forms of processing. 4.   Member States carrying out an inspection shall make the electronic reports and messages available for inspection purposes and only to inspectors assigned to the Scheme laid down by Regulation (EU) No 1236/2010.

Data processing systems

Article 19

1.   Data processing systems used by Member States, the Commission and the Agency shall comply with the minimum security requirements set out in Part A of Annex XII. 2.   For their main computer systems Member States shall meet the criteria set out in Part B of Annex XII. 3.   The https protocol shall be used for communication of data covered by the Scheme laid down by Regulation (EU) No 1236/2010. When such data are communicated, appropriate encryption protocols shall be applied to ensure confidentiality and authenticity. 4.   Access limitation to the data shall be secured via a flexible user identification and password mechanism. Each user shall be given access only to the data necessary for his/her task. 5.   The technical standards for electronic data exchange between Member States, the Commission and the Agency may be laid down in consultation with the Member States, the Commission and the Agency.

Back to Commission Implementing Regulation (EU) No 433/2012 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next