General data protection principles
1. Personal data shall be:
(a)
processed fairly and lawfully;
(b)
collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes. Further processing of personal data for historical, statistical or scientific research purposes shall not be considered incompatible provided that Europol provides appropriate safeguards, in particular to ensure that data are not processed for any other purposes;
(c)
adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed;
(d)
accurate and kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
(e)
kept in a form which permits identification of data subjects for no longer than necessary for the purposes for which the personal data are processed; and
(f)
processed in a manner that ensures appropriate security of personal data.
2. Europol shall make publicly available a document setting out in an intelligible form the provisions regarding the processing of personal data and the means available for the exercise of the rights of data subjects.
Assessment of reliability of the source and accuracy of information
1. The reliability of the source of information originating from a Member State shall be assessed as far as possible by the providing Member State using the following source evaluation codes:
(A): where there is no doubt as to the authenticity, trustworthiness and competence of the source, or if the information is provided by a source which has proved to be reliable in all instances;
(B): where the information is provided by a source which has in most instances proved to be reliable;
(C): where the information is provided by a source which has in most instances proved to be unreliable;
(X): where the reliability of the source cannot be assessed.
2. The accuracy of information originating from a Member State shall be assessed as far as possible by the providing Member State using the following information evaluation codes:
(1): information the accuracy of which is not in doubt;
(2): information known personally to the source but not known personally to the official passing it on;
(3): information not known personally to the source but corroborated by other information already recorded;
(4): information not known personally to the source and which cannot be corroborated.
3. Where Europol, on the basis of information already in its possession, comes to the conclusion that the assessment provided for in paragraphs 1 or 2 needs to be corrected, it shall inform the Member State concerned and seek to agree on an amendment to the assessment. Europol shall not change the assessment without such agreement.
4. Where Europol receives information from a Member State without an assessment in accordance with paragraphs 1 or 2, it shall attempt to assess the reliability of the source or the accuracy of information on the basis of information already in its possession. The assessment of specific data and information shall take place in agreement with the providing Member State. A Member State may also agree with Europol in general terms on the assessment of specified types of data and specified sources. If no agreement is reached in a specific case, or no agreement in general terms exists, Europol shall assess the information or data and shall attribute to such information or data the evaluation codes (X) and (4) referred to in paragraphs 1 and 2 respectively.
5. This Article shall apply mutatis mutandis where Europol receives data or information from a Union body, third country, international organisation or private party.
6. Information from publicly available sources shall be assessed by Europol using the evaluation codes set out in paragraphs 1 and 2.
7. Where information is the result of an analysis made by Europol in the performance of its tasks, Europol shall assess such information in accordance with this Article, and in agreement with the Member States participating in the analysis.
Processing of special categories of personal data and of different categories of data subjects
1. Processing of personal data in respect of victims of a criminal offence, witnesses or other persons who can provide information concerning criminal offences, or in respect of persons under the age of 18, shall be allowed if it is strictly necessary and proportionate for preventing or combating crime that falls within Europol's objectives.
2. Processing of personal data, by automated or other means, revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership and processing of genetic data or data concerning a person's health or sex life shall be prohibited, unless it is strictly necessary and proportionate for preventing or combating crime that falls within Europol's objectives and if those data supplement other personal data processed by Europol. The selection of a particular group of persons solely on the basis of such personal data shall be prohibited.
3. Only Europol shall have direct access to personal data as referred to in paragraphs 1 and 2. The Executive Director shall duly authorise a limited number of Europol officials to have such access if it is necessary for the performance of their tasks.
4. No decision by a competent authority which produces adverse legal effects concerning a data subject shall be based solely on automated processing of data as referred to in paragraph 2, unless the decision is expressly authorised pursuant to national or Union legislation.
5. Personal data as referred to in paragraphs 1 and 2 shall not be transmitted to Member States, Union bodies, third countries or international organisations unless such transmission is strictly necessary and proportionate in individual cases concerning crime that falls within Europol's objectives and in accordance with Chapter V.
6. Every year Europol shall provide to the EDPS a statistical overview of all personal data as referred to in paragraph 2 which it has processed.
Time-limits for the storage and erasure of personal data
1. Personal data processed by Europol shall be stored by Europol only for as long as is necessary and proportionate for the purposes for which the data are processed.
2. Europol shall in any event review the need for continued storage no later than three years after the start of initial processing of personal data. Europol may decide on the continued storage of personal data until the following review, which shall take place after another period of three years, if continued storage is still necessary for the performance of Europol's tasks. The reasons for the continued storage shall be justified and recorded. If no decision is taken on the continued storage of personal data, that data shall be erased automatically after three years.
3. If personal data as referred to in Article 30(1) and (2) are stored for a period exceeding five years, the EDPS shall be informed accordingly.
4. Where a Member State, a Union body, a third country or an international organisation has indicated any restriction as regards the earlier erasure or destruction of the personal data at the moment of transfer in accordance with Article 19(2), Europol shall erase the personal data in accordance with those restrictions. If continued storage of the data is deemed necessary, on the basis of information that is more extensive than that possessed by the data provider, in order for Europol to perform its tasks, Europol shall request the authorisation of the data provider to continue storing the data and shall present a justification for such request.
5. Where a Member State, a Union body, a third country or an international organisation erases from its own data files personal data provided to Europol, it shall inform Europol accordingly. Europol shall erase the data unless the continued storage of the data is deemed necessary, on the basis of information that is more extensive than that possessed by the data provider, in order for Europol to perform its tasks. Europol shall inform the data provider of the continued storage of such data and present a justification of such continued storage.
6. Personal data shall not be erased if:
(a)
this would damage the interests of a data subject who requires protection. In such cases, the data shall be used only with the express and written consent of the data subject;
(b)
their accuracy is contested by the data subject, for a period enabling Member States or Europol, where appropriate, to verify the accuracy of the data;
(c)
they have to be maintained for purposes of proof or for the establishment, exercise or defence of legal claims; or
(d)
the data subject opposes their erasure and requests the restriction of their use instead.
Security of processing
1. Europol shall implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, accidental loss or unauthorised disclosure, alteration and access or any other unauthorised form of processing.
2. In respect of automated data processing, Europol and each Member State shall implement measures designed to:
(a)
deny unauthorised persons access to data-processing equipment used for processing personal data (equipment access control);
(b)
prevent the unauthorised reading, copying, modification or removal of data media (data media control);
(c)
prevent the unauthorised input of data and the unauthorised inspection, modification or deletion of stored personal data (storage control);
(d)
prevent the use of automated data-processing systems by unauthorised persons using data-communication equipment (user control);
(e)
ensure that persons authorised to use an automated data-processing system have access only to data covered by their access authorisation (data access control);
(f)
ensure that it is possible to verify and establish to which bodies personal data may be or have been transmitted using data-communication equipment (communication control);
(g)
ensure that it is possible to verify and establish which personal data have been input into automated data-processing systems and when and by whom the data were input (input control);
(h)
ensure that it is possible to verify and establish what data have been accessed by which member of personnel and at what time (access log);
(i)
prevent the unauthorised reading, copying, modification or deletion of personal data during transfers of personal data or during the transportation of data media (transport control);
(j)
ensure that it is possible, in the event of interruption, to restore installed systems immediately (recovery); and
(k)
ensure that the functions of the system perform faultlessly, that the occurrence of faults in the functions is immediately reported (reliability) and that stored data cannot be corrupted by system malfunctions (integrity).
3. Europol and Member States shall establish mechanisms to ensure that security needs are taken on board across information system boundaries.
Data protection by design
Europol shall implement appropriate technical and organisational measures and procedures in such a way that the data processing will comply with this Regulation and protect the rights of the data subjects concerned.
Notification of a personal data breach to the authorities concerned
1. In the event of a personal data breach, Europol shall without undue delay notify the EDPS, as well as the competent authorities of the Member States concerned, of that breach, in accordance with the conditions laid down in Article 7(5),as well as the provider of the data concerned.
2. The notification referred to in paragraph 1 shall, as a minimum:
(a)
describe the nature of the personal data breach including, where possible and appropriate, the categories and number of data subjects concerned and the categories and number of data records concerned;
(b)
describe the likely consequences of the personal data breach;
(c)
describe the measures proposed or taken by Europol to address the personal data breach; and
(d)
where appropriate, recommend measures to mitigate the possible adverse effects of the personal data breach.
3. Europol shall document any personal data breaches, including the facts surrounding the breach, its effects and the remedial action taken, thereby enabling the EDPS to verify compliance with this Article.
Communication of a personal data breach to the data subject
1. Subject to paragraph 4 of this Article, where a personal data breach as referred to in Article 34 is likely to severely and adversely affect the rights and freedoms of the data subject, Europol shall communicate the personal data breach to the data subject without undue delay.
2. The communication to the data subject referred to in paragraph 1 shall describe, where possible, the nature of the personal data breach, recommend measures to mitigate the possible adverse effects of the personal data breach, and contain the identity and contact details of the Data Protection Officer.
3. If Europol does not have the contact details of the data subject concerned, it shall request the provider of the data to communicate the personal data breach to the data subject concerned and to inform Europol about the decision taken. Member States providing the data shall communicate the breach to the data subject concerned in accordance with the procedures of their national law.
4. The communication of a personal data breach to the data subject shall not be required if:
(a)
Europol has applied to the personal data concerned by that breach appropriate technological protection measures that render the data unintelligible to any person who is not authorised to access it;
(b)
Europol has taken subsequent measures which ensure that the data subject's rights and freedoms are no longer likely to be severely affected; or
(c)
such communication would involve disproportionate effort, in particular owing to the number of cases involved. In such a case, there shall instead be a public communication or similar measure informing the data subjects concerned in an equally effective manner.
5. The communication to the data subject may be delayed, restricted or omitted where this constitutes a necessary measure with due regard for the legitimate interests of the person concerned:
(a)
to avoid obstructing official or legal inquiries, investigations or procedures;
(b)
to avoid prejudicing the prevention, detection, investigation and prosecution of criminal offences or for the execution of criminal penalties;
(c)
to protect public and national security;
(d)
to protect the rights and freedoms of third parties.
Right of access for the data subject
1. Any data subject shall have the right, at reasonable intervals, to obtain information on whether personal data relating to him or her are processed by Europol.
2. Without prejudice to paragraph 5, Europol shall provide the following information to the data subject:
(a)
confirmation as to whether or not data related to him or her are being processed;
(b)
information on at least the purposes of the processing operation, the categories of data concerned, and the recipients or categories of recipients to whom the data are disclosed;
(c)
communication in an intelligible form of the data undergoing processing and of any available information as to their sources;
(d)
an indication of the legal basis for processing the data;
(e)
the envisaged period for which the personal data will be stored;
(f)
the existence of the right to request from Europol rectification, erasure or restriction of processing of personal data concerning the data subject.
3. Any data subject wishing to exercise the right of access to personal data relating to him or her may make a request to that effect, without incurring excessive costs, to the authority appointed for that purpose in the Member State of his or her choice. That authority shall refer the request to Europol without delay, and in any case within one month of receipt.
4. Europol shall confirm receipt of the request under paragraph 3. Europol shall answer it without undue delay, and in any case within three months of receipt by Europol of the request from the national authority.
5. Europol shall consult the competent authorities of the Member States, in accordance with the conditions laid down in Article 7(5), and the provider of the data concerned, on a decision to be taken. A decision on access to personal data shall be conditional on close cooperation between Europol and the Member States and the provider of the data directly concerned by the access of the data subject to such data. If a Member State or the provider of the data objects to Europol's proposed response, it shall notify Europol of the reasons for its objection in accordance with paragraph 6 of this Article. Europol shall take the utmost account of any such objection. Europol shall subsequently notify its decision to the competent authorities concerned, in accordance with the conditions laid down in Article 7(5), and to the provider of the data.
6. The provision of information in response to any request under paragraph 1 may be refused or restricted if such refusal or restriction constitutes a measure that is necessary in order to:
(a)
enable Europol to fulfil its tasks properly;
(b)
protect security and public order or prevent crime;
(c)
guarantee that any national investigation will not be jeopardised; or
(d)
protect the rights and freedoms of third parties.
When the applicability of an exemption is assessed, the fundamental rights and interests of the data subject shall be taken into account.
7. Europol shall inform the data subject in writing of any refusal or restriction of access, of the reasons for such a decision and of his or her right to lodge a complaint with the EDPS. Where the provision of such information would deprive paragraph 6 of its effect, Europol shall only notify the data subject concerned that it has carried out the checks, without giving any information which might reveal to him or her whether or not personal data concerning him or her are processed by Europol.
Right to rectification, erasure and restriction
1. Any data subject having accessed personal data concerning him or her processed by Europol in accordance with Article 36 shall have the right to request Europol, through the authority appointed for that purpose in the Member State of his or her choice, to rectify personal data concerning him or her held by Europol if they are incorrect or to complete or update them. That authority shall refer the request to Europol without delay and in any case within one month of receipt.
2. Any data subject having accessed personal data concerning him or her processed by Europol in accordance with Article 36 shall have the right to request Europol, through the authority appointed for that purpose in the Member State of his or her choice, to erase personal data relating to him or her held by Europol if they are no longer required for the purposes for which they are collected or are further processed. That authority shall refer the request to Europol without delay and in any case within one month of receipt.
3. Europol shall restrict rather than erase personal data as referred to in paragraph 2 if there are reasonable grounds to believe that erasure could affect the legitimate interests of the data subject. Restricted data shall be processed only for the purpose that prevented their erasure.
4. If personal data as referred to in paragraphs 1, 2 and 3 held by Europol have been provided to it by third countries, international organisations or Union bodies, have been directly provided by private parties or have been retrieved by Europol from publicly available sources or result from Europol's own analyses, Europol shall rectify, erase or restrict such data and, where appropriate, inform the providers of the data.
5. If personal data as referred to in paragraphs 1, 2 and 3 held by Europol have been provided to Europol by Member States, the Member States concerned shall rectify, erase or restrict such data in collaboration with Europol, within their respective competences.
6. If incorrect personal data have been transferred by another appropriate means or if the errors in the data provided by Member States are due to faulty transfer or transfer in breach of this Regulation or if they result from data being input, taken over or stored in an incorrect manner or in breach of this Regulation by Europol, Europol shall rectify or erase such data in collaboration with the provider of the data concerned.
7. In the cases referred to in paragraphs 4, 5 and 6, all addressees of the data concerned shall be notified forthwith. In accordance with the rules applicable to them, the addressees shall then rectify, erase or restrict those data in their systems.
8. Europol shall inform the data subject in writing without undue delay, and in any case within three months of receipt of a request in accordance with paragraph 1 or 2, that data concerning him or her have been rectified, erased or restricted.
9. Within three months of receipt of a request in accordance with paragraph 1 or 2, Europol shall inform the data subject in writing of any refusal of rectification, erasure or restricting, of the reasons for such a refusal and of the possibility of lodging a complaint with the EDPS and of seeking a judicial remedy.
Responsibility in data protection matters
1. Europol shall store personal data in a way that ensures that their source, as referred to in Article 17, can be established.
2. The responsibility for the quality of personal data as referred to in point (d) of Article 28(1) shall lie with:
(a)
the Member State or the Union body which provided the personal data to Europol;
(b)
Europol in respect of personal data provided by third countries or international organisations or directly provided by private parties; of personal data retrieved by Europol from publicly available sources or resulting from Europol's own analyses; and of personal data stored by Europol in accordance with Article 31(5).
3. If Europol becomes aware that personal data provided pursuant to points (a) and (b) of Article 17(1) are factually incorrect or have been unlawfully stored, it shall inform the provider of those data accordingly.
4. Europol shall be responsible for compliance with the principles referred to in points (a), (b), (c), (e) and (f) of Article 28(1).
5. The responsibility for the legality of a data transfer shall lie with:
(a)
the Member State which provided the personal data to Europol;
(b)
Europol in the case of personal data provided by it to Member States, third countries or international organisations.
6. In the case of a transfer between Europol and a Union body, the responsibility for the legality of the transfer shall lie with Europol.
Without prejudice to the first subparagraph, where the data are transferred by Europol following a request from the recipient, both Europol and the recipient shall be responsible for the legality of such a transfer.
7. Europol shall be responsible for all data processing operations carried out by it, with the exception of the bilateral exchange of data using Europol's infrastructure between Member States, Union bodies, third countries and international organisations to which Europol has no access. Such bilateral exchanges shall take place under the responsibility of the entities concerned and in accordance with their law. The security of such exchanges shall be ensured in accordance with Article 32.
Prior consultation
1. Any new type of processing operations to be carried out shall be subject to prior consultation where:
(a)
special categories of data as referred to in Article 30(2) are to be processed;
(b)
the type of processing, in particular using new technologies, mechanisms or procedures, presents specific risks for the fundamental rights and freedoms, and in particular the protection of personal data, of data subjects.
2. The prior consultation shall be carried out by the EDPS following receipt of a notification from the Data Protection Officer that shall contain at least a general description of the envisaged processing operations, an assessment of the risks to the rights and freedoms of data subjects, the measures envisaged to address those risks, safeguards and security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation, taking into account the rights and legitimate interests of the data subjects and other persons concerned.
3. The EDPS shall deliver his or her opinion to the Management Board within two months following receipt of the notification. That period may be suspended until the EDPS has obtained any further information that he or she may have requested.
If the opinion has not been delivered after four months it shall be deemed to be favourable.
If the opinion of the EDPS is that the notified processing may involve a breach of any provision of this Regulation, he or she shall, where appropriate, make proposals to avoid such a breach. Where Europol does not modify the processing operation accordingly, the EDPS may exercise the powers granted to him or her under Article 43(3).
4. The EDPS shall keep a register of all processing operations that have been notified to him or her pursuant to paragraph 1. The register shall not be made public.
Logging and documentation
1. For the purpose of verifying the lawfulness of data processing, self-monitoring and ensuring proper data integrity and security, Europol shall keep records of the collection, alteration, access, disclosure, combination or erasure of personal data. Such logs or documentation shall be deleted after three years, unless the data which they contain are further required for ongoing control. There shall be no possibility of modifying the logs.
2. Logs or documentation prepared pursuant to paragraph 1 shall be communicated upon request to the EDPS, to the Data Protection Officer and, if required for a specific investigation, to the national unit concerned. The information thus communicated shall only be used for the control of data protection and for ensuring proper data processing as well as data integrity and security.
Data Protection Officer
1. The Management Board shall appoint a Data Protection Officer, who shall be a member of the staff. In the performance of his or her duties, he or she shall act independently.
2. The Data Protection Officer shall be selected on the basis of his or her personal and professional qualities and, in particular, the expert knowledge of data protection.
It shall be ensured in the selection of the Data Protection Officer that no conflict of interest may result from the performance of his or her duty in that capacity and from any other official duties, in particular those relating to the application of this Regulation.
3. The Data Protection Officer shall be appointed for a term of four years. He or she shall be eligible for reappointment up to a maximum total term of eight years. He or she may be dismissed from his or her function as Data Protection Officer by the Management Board only with the consent of the EDPS, if he or she no longer meets the conditions required for the performance of his or her duties.
4. After his or her appointment, the Data Protection Officer shall be registered with the EDPS by the Management Board.
5. With respect to the performance of his or her duties, the Data Protection Officer shall not receive any instructions.
6. The Data Protection Officer shall, in particular, have the following tasks with regard to personal data, with the exception of administrative personal data:
(a)
ensuring, in an independent manner, the internal application of this Regulation concerning the processing of personal data;
(b)
ensuring that a record of the transfer and receipt of personal data is kept in accordance with this Regulation;
(c)
ensuring that data subjects are informed of their rights under this Regulation at their request;
(d)
cooperating with Europol staff responsible for procedures, training and advice on data processing;
(e)
cooperating with the EDPS;
(f)
preparing an annual report and communicating that report to the Management Board and to the EDPS;
(g)
keeping a register of personal data breaches.
7. The Data Protection Officer shall also carry out the functions provided for by Regulation (EC) No 45/2001 with regard to administrative personal data.
8. In the performance of his or her tasks, the Data Protection Officer shall have access to all the data processed by Europol and to all Europol premises.
9. If the Data Protection Officer considers that the provisions of this Regulation concerning the processing of personal data have not been complied with, he or she shall inform the Executive Director and shall require him or her to resolve the non-compliance within a specified time.
If the Executive Director does not resolve the non-compliance of the processing within the time specified, the Data Protection Officer shall inform the Management Board. The Data Protection Officer and the Management Board shall agree a specified time for a response by the latter. If the Management Board does not resolve the non-compliance within the time specified, the Data Protection Officer shall refer the matter to the EDPS.
10. The Management Board shall adopt implementing rules concerning the Data Protection Officer. Those implementing rules shall, in particular, concern the selection procedure for the position of the Data Protection Officer and his or her dismissal, tasks, duties and powers, and safeguards ensuring the independence of the Data Protection Officer.
11. Europol shall provide the Data Protection Officer with the staff and resources needed in order for him or her to be able to carry out his or her duties. Those staff members shall have access to all the data processed at Europol and to Europol premises only to the extent necessary for the performance of their tasks.
12. The Data Protection Officer and his or her staff shall be bound by the obligation of confidentiality in accordance with Article 67(1).
Supervision by the national supervisory authority
1. Each Member State shall designate a national supervisory authority. The national supervisory authority shall have the task of monitoring independently, in accordance with its national law, the permissibility of the transfer, the retrieval and any communication to Europol of personal data by the Member State concerned, and of examining whether such transfer, retrieval or communication violates the rights of the data subjects concerned. For that purpose, the national supervisory authority shall have access, at the national unit or at the liaison officers' premises, to data submitted by its Member State to Europol in accordance with the relevant national procedures and to logs and documentation as referred to in Article 40.
2. For the purpose of exercising their supervisory function, national supervisory authorities shall have access to the offices and documents of their respective liaison officers at Europol.
3. National supervisory authorities shall, in accordance with the relevant national procedures, supervise the activities of national units and the activities of liaison officers, insofar as such activities are relevant to the protection of personal data. They shall also keep the EDPS informed of any actions they take with respect to Europol.
4. Any person shall have the right to request the national supervisory authority to verify the legality of any transfer or communication to Europol of data concerning him or her in any form and of access to those data by the Member State concerned. That right shall be exercised in accordance with the national law of the Member State in which the request is made.
Supervision by the EDPS
1. The EDPS shall be responsible for monitoring and ensuring the application of the provisions of this Regulation relating to the protection of fundamental rights and freedoms of natural persons with regard to the processing of personal data by Europol, and for advising Europol and data subjects on all matters concerning the processing of personal data. To that end, he or she shall fulfil the duties set out in paragraph 2 and exercise the powers laid down in paragraph 3, while closely cooperating with the national supervisory authorities in accordance with Article 44.
2. The EDPS shall have the following duties:
(a)
hearing and investigating complaints, and informing the data subject of the outcome within a reasonable period;
(b)
conducting inquiries either on his or her own initiative or on the basis of a complaint, and informing the data subject of the outcome within a reasonable period;
(c)
monitoring and ensuring the application of this Regulation and any other Union act relating to the protection of natural persons with regard to the processing of personal data by Europol;
(d)
advising Europol, either on his or her own initiative or in response to a consultation, on all matters concerning the processing of personal data, in particular before it draws up internal rules relating to the protection of fundamental rights and freedoms with regard to the processing of personal data;
(e)
keeping a register of new types of processing operations notified to him or her by virtue of Article 39(1) and registered in accordance with Article 39(4);
(f)
carrying out a prior consultation on processing notified to him or her.
3. The EDPS may pursuant to this Regulation:
(a)
give advice to data subjects on the exercise of their rights;
(b)
refer a matter to Europol in the event of an alleged breach of the provisions governing the processing of personal data, and, where appropriate, make proposals for remedying that breach and for improving the protection of the data subjects;
(c)
order that requests to exercise certain rights in relation to data be complied with where such requests have been refused in breach of Articles 36 and 37;
(d)
warn or admonish Europol;
(e)
order Europol to carry out the rectification, restriction, erasure or destruction of personal data which have been processed in breach of the provisions governing the processing of personal data and to notify such actions to third parties to whom such data have been disclosed;
(f)
impose a temporary or definitive ban on processing operations by Europol which are in breach of the provisions governing the processing of personal data;
(g)
refer a matter to Europol and, if necessary, to the European Parliament, the Council and the Commission;
(h)
refer a matter to the Court of Justice of the European Union under the conditions provided for in the TFEU;
(i)
intervene in actions brought before the Court of Justice of the European Union.
4. The EDPS shall have the power to:
(a)
obtain from Europol access to all personal data and to all information necessary for his or her enquiries;
(b)
obtain access to any premises in which Europol carries on its activities when there are reasonable grounds for presuming that an activity covered by this Regulation is being carried out there.
5. The EDPS shall draw up an annual report on the supervisory activities of Europol, after consulting the national supervisory authorities. That report shall be part of the annual report of the EDPS referred to in Article 48 of Regulation (EC) No 45/2001.
The report shall include statistical information regarding complaints, inquiries, and investigations carried out in accordance with paragraph 2, as well as regarding transfers of personal data to third countries and international organisations, cases of prior consultation, and the use of the powers laid down in paragraph 3.
6. The EDPS, the officials and the other staff members of the EDPS's Secretariat shall be bound by the obligation of confidentiality laid down in Article 67(1).
Cooperation between the EDPS and national supervisory authorities
1. The EDPS shall act in close cooperation with the national supervisory authorities on issues requiring national involvement, in particular if the EDPS or a national supervisory authority finds major discrepancies between the practices of Member States or potentially unlawful transfers in the use of Europol's channels for exchanges of information, or in the context of questions raised by one or more national supervisory authorities on the implementation and interpretation of this Regulation.
2. The EDPS shall use the expertise and experience of the national supervisory authorities in carrying out his or her duties as set out in Article 43(2). In carrying out joint inspections together with the EDPS, members and staff of national supervisory authorities shall, taking due account of the principles of subsidiarity and proportionality, have powers equivalent to those laid down in Article 43(4) and be bound by an obligation equivalent to that laid down in Article 43(6). The EDPS and the national supervisory authorities shall, each acting within the scope of their respective competences, exchange relevant information and assist each other in carrying out audits and inspections.
3. The EDPS shall keep national supervisory authorities fully informed of all issues directly affecting or otherwise relevant to them. Upon the request of one or more national supervisory authorities, the EDPS shall inform them of specific issues.
4. In cases relating to data originating from one or more Member States, including the cases referred to in Article 47(2), the EDPS shall consult the national supervisory authorities concerned. The EDPS shall not decide on further action to be taken before those national supervisory authorities have informed the EDPS of their position, within a deadline specified by him or her which shall not be shorter than one month and not longer than three months. The EDPS shall take the utmost account of the respective positions of the national supervisory authorities concerned. In cases where the EDPS intends not to follow the position of a national supervisory authority, he or she shall inform that authority, provide a justification and submit the matter for discussion to the Cooperation Board established by Article 45(1).
In cases which the EDPS considers to be extremely urgent, he or she may decide to take immediate action. In such cases, the EDPS shall immediately inform the national supervisory authorities concerned and justify the urgent nature of the situation as well as the action he or she has taken.
Cooperation Board
1. A Cooperation Board with an advisory function is hereby established. It shall be composed of a representative of a national supervisory authority of each Member State and of the EDPS.
2. The Cooperation Board shall act independently when performing its tasks pursuant to paragraph 3 and shall neither seek nor take instructions from any body.
3. The Cooperation Board shall have the following tasks:
(a)
discussing general policy and strategy of data protection supervision of Europol and the permissibility of the transfer, the retrieval and any communication to Europol of personal data by the Member States;
(b)
examining difficulties of interpretation or application of this Regulation;
(c)
studying general problems relating to the exercise of independent supervision or the exercise of the rights of data subjects;
(d)
discussing and drawing up harmonised proposals for joint solutions on matters referred to in Article 44(1);
(e)
discussing cases submitted by the EDPS in accordance with Article 44(4);
(f)
discussing cases submitted by any national supervisory authority; and
(g)
promoting awareness of data protection rights.
4. The Cooperation Board may issue opinions, guidelines, recommendations and best practices. The EDPS and the national supervisory authorities shall, without prejudice to their independence and each acting within the scope of their respective competences, take the utmost account of them.
5. The Cooperation Board shall meet whenever necessary, and at least twice a year. The costs and servicing of its meetings shall be borne by the EDPS.
6. Rules of procedure of the Cooperation Board shall be adopted at its first meeting by a simple majority of its members. Further working methods shall be developed jointly as necessary.
Administrative personal data
Regulation (EC) No 45/2001 shall apply to all administrative personal data held by Europol.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.