My bookmarksSign up free

Regulation (EU) 2020/1056 CHAPTER III — eFTI PLATFORMS AND eFTI SERVICE PROVIDERS

Article 9–Article 13 · 5 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

SECTION 1 — Requirements for eFTI platforms and eFTI service providers

Functional requirements for eFTI platforms

Article 9

1.   The eFTI platforms used for processing regulatory information shall provide functionalities that ensure that: (a) personal data can be processed in accordance with Regulation (EU) 2016/679; (b) commercial data can be processed in accordance with Article 6; (c) competent authorities can access and process data in accordance with the specifications adopted by means of delegated and implementing acts referred to in Articles 7 and 8; (d) the economic operators concerned can make information available to competent authorities in accordance with Article 4; (e) a unique electronic identifying link can be established between a shipment and the related data elements, including a structured reference to the eFTI platform where the data is made available, such as a unique reference identifier; (f) data can be processed solely on the basis of authorised and authenticated access; (g) all data processing is duly recorded in operation logs in order to allow, as a minimum, the identification of each distinct processing operation, the natural or legal person having made the operation and the sequencing of the operations on each individual data element; if an operation involves modifying or erasing an existing data element, the original data element shall be preserved; (h) data can be archived and remain accessible for competent authorities in accordance with the relevant Union legal acts and national law laying down the respective regulatory information requirements; (i) the operation logs referred to in point (g) of this paragraph are archived and remain accessible for competent authorities for auditing purposes for the period of time specified in the relevant Union legal acts and national law laying down the respective regulatory information requirements and, for monitoring purposes, for the periods of time referred to in Article 17; (j) data is protected against corruption and theft; (k) the data elements processed correspond to the eFTI common data set and to eFTI data subsets as established by the delegated acts referred to in Article 7, and can be processed in any of the official languages of the Union as provided for by the relevant Union legal acts and national law laying down the respective regulatory information requirements. 2.   The Commission shall adopt implementing acts laying down detailed specifications regarding the requirements set out in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 15(2). When adopting those specifications, the Commission shall: (a) seek to ensure the interoperability of the eFTI platforms; (b) take into account relevant existing technical solutions and standards; (c) ensure that those specifications remain, to the largest extent possible, technologically neutral. The first such implementing act shall cover all the elements referred to in paragraph 1 of this Article and shall be adopted no later than 21 August 2023.

Requirements for eFTI service providers

Article 10

1.   eFTI service providers shall ensure that: (a) data is processed only by authorised users and in accordance with clearly defined and assigned processing rights within the eFTI platform, in accordance with the relevant regulatory information requirements; (b) data is stored and accessible in accordance with the Union legal acts and national law laying down the respective regulatory information requirements; (c) competent authorities have immediate access to regulatory information concerning a freight transport operation processed by means of their eFTI platforms, free of any charges or fees; (d) data is appropriately secured, including against unauthorised or unlawful processing and against accidental loss, destruction or damage. 2.   The Commission shall adopt implementing acts laying down detailed rules regarding the requirements set out in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 15(2). The first such implementing act covering all the elements referred to in paragraph 1 of this Article shall be adopted no later than 21 August 2023.

SECTION 2 — Certification

Conformity assessment bodies

Article 11

1.   Conformity assessment bodies shall be accredited in accordance with Regulation (EC) No 765/2008 for the purposes of performing the certification of eFTI platforms and eFTI service providers as set out in Articles 12 and 13 of this Regulation. 2.   For the purposes of accreditation, conformity assessment bodies shall meet the requirements laid down in Annex II. National accreditation bodies shall communicate to the national authority designated in accordance with paragraph 3 of this Article the address of the website where they make publicly available the information on the accredited conformity assessment bodies, including an up-to-date list of these bodies. 3.   Each Member State shall designate an authority that shall maintain an up-to-date list of the accredited conformity assessment bodies, eFTI platforms and eFTI service providers which hold a valid certification on the basis of the information provided pursuant to paragraph (2) of this Article and to Article 12(2) and Article 13(2). Those designated national authorities shall make that list publicly available on an official government website. 4.   By 31 March each year, those designated national authorities shall notify to the Commission the list referred to in paragraph 3 together with the address of the website where that list is publicly available. The Commission shall publish those website addresses on its official website.

Certification of eFTI platforms

Article 12

1.   Upon application by an eFTI platform developer, a conformity assessment body shall assess the compliance of the eFTI platform with the requirements laid down in Article 9(1). In the case of a positive assessment, the conformity assessment body shall issue a compliance certificate for that eFTI platform. In the case of a negative assessment, the conformity assessment body shall provide the reasons for the negative assessment to the applicant. 2.   Each conformity assessment body shall maintain an up-to-date list of the eFTI platforms that it has certified and for which it has withdrawn or suspended certification. It shall make that list publicly available on its website and shall communicate the address of that website to the designated national authority referred to in Article 11(3). 3.   Information made available to competent authorities by means of a certified eFTI platform shall be accompanied by a certification mark. 4.   The eFTI platform developer shall apply for a reassessment of its certification if the technical specifications laid down in the implementing acts referred to in Article 9(2) are revised. 5.   The Commission is empowered to adopt delegated acts in accordance with Article 14 to supplement this Regulation by laying down rules on the certification of eFTI platforms and on the use of the certification mark, including rules on the renewal, suspension and withdrawal of certification.

Certification of eFTI service providers

Article 13

1.   Upon application by an eFTI service provider, a conformity assessment body shall assess the compliance of the eFTI service provider with the requirements laid down in Article 10(1). In the case of a positive assessment, the conformity assessment body shall issue a compliance certificate. In the case of a negative assessment, the conformity assessment body shall provide the reasons for the negative assessment to the applicant. 2.   Each conformity assessment body shall maintain an up-to-date list of the eFTI service providers that it has certified and for which it has withdrawn or suspended certification. It shall make that list publicly available on its website and shall communicate the address of that website to the designated national authority referred to in Article 11(3). 3.   The Commission is empowered to adopt delegated acts in accordance with Article 14 to supplement this Regulation by laying down rules on certification of eFTI service providers, including rules on the renewal, suspension and withdrawal of certification.

Back to Regulation (EU) 2020/1056 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next