My bookmarksSign up free

Regulation (EU) 2019/1896 SECTION 2 — Processing of personal data by the European Border and Coast Guard

Article 86–Article 92 · 7 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

General rules on processing of personal data by the Agency

Article 86

1.   The Agency shall apply Regulation (EU) 2018/1725 when processing personal data. 2.   The management board shall adopt internal rules on the application of Regulation (EU) 2018/1725 by the Agency, including rules concerning the data protection officer of the Agency. The Agency may, in accordance with Article 25 of Regulation (EU) 2018/1725, adopt internal rules restricting the application of Articles 14 to 22, 35 and 36 of that Regulation. In particular, the Agency may, for the performance of its tasks in the area of return, provide for internal rules restricting the application of those provisions on a case-by-case basis as long as the application of those provisions would risk jeopardising return procedures. Such restrictions shall respect the essence of the fundamental rights and freedoms, shall be necessary and proportionate to the objectives pursued and shall contain specific provisions, where relevant, as referred to in Article 25(2) of Regulation (EU) 2018/1725. 3.   The Agency may transfer the personal data referred to in Articles 49, 88 and 89 to a third country or to an international organisation in accordance with Chapter V of Regulation (EU) 2018/1725 insofar as such transfer is necessary for the performance of the Agency's tasks. The Agency shall ensure that personal data that are transferred to a third country or to an international organisation are only processed for the purpose for which they were provided. The Agency shall indicate, at the moment of transferring personal data to a third country or to an international organisation, any restrictions on access to or use of those data, in general or specific terms, including as regards transfer, erasure or destruction. Where the need for such restrictions becomes apparent after the transfer of personal data, the Agency shall inform the third country or the international organisation accordingly. The Agency shall ensure that the third country or international organisation concerned complies with such restrictions. 4.   Transfers of personal data to third countries shall not prejudice the rights of applicants for international protection and of beneficiaries of international protection, in particular as regards non-refoulement and the prohibition against disclosing or obtaining information set out in Article 30 of Directive 2013/32/EU of the European Parliament and of the Council  ( 43 ) . 5.   Member States and the Agency, as appropriate, shall ensure that information that is transferred or disclosed to third countries pursuant to this Regulation is not transmitted onward to other third countries or third parties. Provisions to that effect shall be included in any agreement or arrangement concluded with a third country providing for the exchange of information.

Purposes of processing of personal data

Article 87

1.   The Agency may process personal data only for the following purposes: (a) performing its tasks of organising and coordinating joint operations, pilot projects, rapid border interventions and in the framework of the migration management support teams as referred to in Articles 37 to 40; (b) performing its tasks of supporting Member States and third countries in pre-return and return activities, operating return management systems, as well as coordinating or organising return operations and providing technical and operational assistance to Member States and third countries in accordance with Article 48; (c) facilitating the exchange of information with Member States, the Commission, the EEAS and the following Union bodies, offices and agencies and international organisations: EASO, the European Union Satellite Centre, EFCA, EMSA, EASA and the Network Manager of the EATMN, in accordance with Article 88; (d) facilitating the exchange of information with the law enforcement authorities of the Member States, Europol or Eurojust in accordance with Article 90; (e) risk analysis by the Agency in accordance with Article 29; (f) performing its tasks in the framework of EUROSUR in accordance with Article 89; (g) operating the FADO system in accordance with Article 79; (h) administrative tasks. 2.   Member States and their law enforcement authorities, the Commission, the EEAS, and those Union bodies, offices and agencies and international organisations referred to in points (c) and (d) of paragraph 1, that provide personal data to the Agency shall determine the purpose or the purposes for which those data are to be processed as referred to in paragraph 1. The Agency may decide to process such personal data for a different purpose which also falls under paragraph 1 only on a case-by-case basis after having determined that such processing is compatible with the initial purpose for which the data were collected and if authorised by the provider of the personal data. The Agency shall keep written records of case-by-case compatibility assessments. 3.   The Agency, the Member States and their law enforcement authorities, the Commission, the EEAS, and those Union bodies, offices and agencies and international organisations referred to in points (c) and (d) of paragraph 1, may indicate, at the moment of transmitting personal data, any restrictions on access to those data or use of such data, in general or specific terms, including as regards the transfer, erasure or destruction of such data. Where the need for such restrictions becomes apparent after the transfer of personal data, they shall inform the recipients accordingly. The recipients shall comply with such restrictions.

Processing of personal data collected during joint operations, return operations, return interventions, pilot projects, rapid border interventions, and migration management support team deployments

Article 88

1.   Before each joint operation, return operation, return intervention, pilot project, rapid border intervention or migration management support team deployment, the Agency and the host Member State shall determine in a transparent manner the responsibilities for compliance with the data protection obligations. When the purpose and the means of processing are jointly determined by the Agency and the host Member State, they shall be joint controllers by means of concluding an arrangement between them. For the purposes referred to in points (a), (b), (c), (e) and (f) of Article 87(1), the Agency shall only process the following categories of personal data collected by the Member States, by members of the teams, by its staff or by EASO that have been transmitted to it in the context of joint operations, return operations, return interventions, pilot projects, rapid border interventions, and migration management support team deployments: (a) the personal data of persons who cross the external borders without authorisation; (b) personal data that are necessary to confirm the identity and nationality of third-country nationals within the framework of the return activities, including passenger lists; (c) licence plate numbers, vehicle identification numbers, telephone numbers or ship and aircraft identification numbers which are linked to the persons referred to in point (a), and which are necessary for analysing routes and methods used for illegal immigration. 2.   The personal data referred to in paragraph 1 may be processed by the Agency in the following cases: (a) where the transmission of those data to the authorities of the relevant Member States which are responsible for border control, migration, asylum or return, or to relevant Union bodies, offices and agencies, is necessary for those authorities or Union bodies, offices and agencies to fulfil their tasks in accordance with Union and national law; (b) where transmission of those data to the authorities of relevant Member States, relevant Union bodies, offices and agencies, third countries of return or international organisations is necessary for the purpose of identifying third-country nationals, acquiring travel documents or enabling or supporting return; (c) where necessary for the preparation of risk analyses.

Processing of personal data in the framework of EUROSUR

Article 89

1.   Where the national situational picture requires the processing of personal data, those data shall be processed in accordance with Regulation (EU) 2016/679 and, where applicable, Directive (EU) 2016/680. Each Member State shall designate the authority which is to be considered as controller within the meaning of point 7 of Article 4 of Regulation (EU) 2016/679 or point (8) of Article 3 of Directive (EU) 2016/680, as applicable, and which shall have central responsibility for the processing of personal data by that Member State. Each Member State shall notify the details of that authority to the Commission. 2.   Ship and aircraft identification numbers shall be the only personal data that are permitted to be accessed in the European situational and specific situational pictures and the EUROSUR fusion services. 3.   Where the processing of information in EUROSUR exceptionally requires the processing of personal data other than ship and aircraft identification numbers, any such processing shall be strictly limited to what is necessary for the purposes of EUROSUR in accordance with Article 18. 4.   Any exchange of personal data with third countries in the framework of EUROSUR shall be strictly limited to what is absolutely necessary for the purposes of this Regulation. It shall be carried out in accordance with Chapter V of Regulation (EU) 2018/1725 by the Agency, and in accordance with Chapter V of Regulation (EU) 2016/679, with Chapter V of Directive (EU) 2016/680, as applicable, and with the relevant national provisions on data protection transposing that Directive, by the Member States. 5.   Any exchange of information under Articles 72(2), 73(3) and 74(3) which provides a third country with data that could be used to identify persons or groups of persons whose request for access to international protection is under examination or who are under a serious risk of being subjected to torture, inhuman and degrading treatment or punishment, or any other violation of fundamental rights, shall be prohibited. 6.   Member States and the Agency shall keep records of processing activities in accordance with, Article 30 of Regulation (EU) 2016/679, Article 24 of Directive (EU) 2016/680, and Article 31 of Regulation (EU) 2018/1725, as applicable.

Processing of operational personal data

Article 90

1.   Where the Agency, in the performance of its tasks under point (q) of Article 10(1) of this Regulation, processes personal data which it has collected while monitoring migratory flows, carrying out risk analyses or in the course of operations for the purpose of identifying suspects of cross-border crime, it shall process such personal data in accordance with Chapter IX of Regulation (EU) 2018/1725. Personal data processed for that purpose, including licence plate numbers, vehicle identification numbers, telephone numbers and ship or aircraft identification numbers which are linked to such persons, shall relate to natural persons whom the competent authorities of the Member States, Europol, Eurojust, or the Agency have reasonable grounds to suspect are involved in cross-border crime. Such personal data may include personal data of victims or witnesses where those personal data supplement the personal data of suspects processed by the Agency in accordance with this Article. 2.   The Agency shall only exchange personal data as referred to in paragraph 1 of this Article with: (a) Europol or Eurojust where they are strictly necessary for the performance of their respective mandates and in accordance with Article 68; (b) the competent law enforcement authorities of the Member States where they are strictly necessary for those authorities for the purposes of preventing, detecting, investigating or prosecuting serious cross-border crime.

Data retention

Article 91

1.   The Agency shall delete personal data as soon as they have been transmitted to the competent authorities of Member States, other Union bodies, offices and agencies, in particular EASO, or transferred to third countries or international organisations or used for the preparation of risk analyses. The retention period shall, in any event, not exceed 90 days after the date of the collection of those data. Data shall be anonymised in the results of risk analyses. 2.   Personal data processed for the purpose of performing return-related tasks shall be deleted as soon as the purpose for which they have been collected has been achieved, and shall be deleted no later than 30 days after the end of those tasks. 3.   Operational personal data processed for the purposes of Article 90 shall be deleted as soon as the purpose for which they have been collected has been achieved by the Agency. The Agency shall continuously review the necessity of storing such data, in particular the personal data of victims and witnesses. In any case, the Agency shall review the necessity of storing such data no later than three months after the start of initial processing of such data, and every six months thereafter. The Agency shall decide on the continued storage of personal data, in particular the personal data of victims and witnesses, until the following review, only if such storage is still necessary for the performance of the Agency's tasks under Article 90. 4.   This Article does not apply to personal data collected in the context of the FADO system.

Security rules on the protection of classified information and sensitive non-classified information

Article 92

1.   The Agency shall adopt its own security rules that shall be based on the principles and rules laid down in the Commission's security rules for protecting European Union classified information (EUCI) and sensitive non-classified information including, inter alia, provisions for the exchange of such information with third countries, and processing and storage of such information as set out in Commission Decisions (EU, Euratom) 2015/443  ( 44 ) and (EU, Euratom) 2015/444  ( 45 ) . Any administrative arrangement on the exchange of classified information with the relevant authorities of a third country or, in the absence of such arrangement, any exceptional ad hoc release of EUCI to those authorities, shall be subject to the Commission's prior approval. 2.   The management board shall adopt the Agency's security rules following approval by the Commission. When assessing the proposed security rules, the Commission shall ensure that they are compatible with Decisions (EU, Euratom) 2015/443 and (EU, Euratom) 2015/444. 3.   Classification shall not preclude information being made available to the European Parliament. The transmission and handling of information and documents transmitted to the European Parliament in accordance with this Regulation shall comply with the rules concerning the forwarding and handling of classified information which are applicable between the European Parliament and the Commission.

Back to Regulation (EU) 2019/1896 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next