My bookmarksSign up free

Commission Decision (EU) 2021/2243 of 15 December 2021 laying down internal rules concerning the provision of information to data subjects and the restriction of certain of their rights in the context of the processing of personal data for the purposes of the security of information and communication systems of the Commission

Commission Decision (EU) 2021/2243 of 15 December 2021 laying down internal rules concerning the provision of information to data subjects and the restriction of certain of their rights in the context of the processing of personal data for the purposes of the security of information and communication systems of the Commission

Decision (EU) 2021/2243 · Decision · 10 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Subject-matter and scope

Article 1

1.   This Decision lays down the rules that the Commission must follow to inform data subjects of the processing of their personal data in accordance with Articles 14, 15 and 16 of Regulation (EU) 2018/1725 when carrying out its tasks pursuant to Decision (EU, Euratom) 2017/46. It also lays down the conditions under which the Commission may restrict the application of Articles 4, 14 to 17, 19, 20 and 35 of Regulation (EU) 2018/1725, in accordance with Article 25(1)(c), (d) and (h), of that Regulation, when carrying out its tasks pursuant to Decision (EU, Euratom) 2017/46. 2.   This Decision applies to the processing of personal data either by or on behalf of the Commission for the purpose of, or in relation to activities carried out to ensure the IT security of persons, assets and information in the Commission pursuant to Decision (EU, Euratom) 2017/46.

Applicable exceptions and restrictions

Article 2

1.   Where the Commission exercises its duties with respect to data subjects’ rights under Regulation (EU) 2018/1725, it shall consider whether any of the exceptions laid down in that Regulation apply. 2.   Subject to Articles 3 to 7 of this Decision, where the exercise of the rights and obligations provided for in Articles 14 to 17, 19, 20 and 35 of Regulation (EU) 2018/1725 in relation to personal data processed by the Commission which would undermine the purpose of providing IT security operations and services, inter alia, by revealing the Commission’s investigative tools, vulnerabilities and methods, or would adversely affect the rights and freedoms and the security of other data subjects, in particular for the processing of personal data in order to: — communicate alerts and warnings relating to IT security events and incidents; — respond to and contain IT security events and incidents; — facilitate tools and operations through security audits, security assessments and vulnerability management; — increase the awareness of Commission staff in the field of cybersecurity; — monitor, detect and prevent the occurrence of IT security events and incidents; — review privileged user accounts. the Commission may restrict the application of: (a) Articles 14 to 17, 19, 20 and 35 of Regulation (EU) 2018/1725; (b) the principle of transparency laid down in Article 4(1)(a), of Regulation (EU) 2018/1725, in so far as its provisions correspond to the rights and obligations provided for in Articles 14 to 17, 19 and 20 of Regulation (EU) 2018/1725. The Commission may do so in line with Article 25(1)(c), (d) and (h) of Regulation (EU) 2018/1725. 3.   Subject to Articles 3 to 7, the Commission may restrict the rights and obligations referred to in paragraph 2 of this Article: (a) where the exercise of those rights and obligations in respect of the personal data obtained from another EU institution, body, agency or office could be restricted by that other EU institution, body, agency or office on the basis of legal acts provided for in Article 25 of Regulation (EU) 2018/1725, or pursuant to Chapter IX of that Regulation, in accordance with Regulation (EU) 2016/794 of the European Parliament and of the Council  ( 4 ) or in accordance with Council Regulation (EU) 2017/1939  ( 5 ) ; (b) where the exercise of those rights and obligations in respect of the personal data obtained from the competent authority of a Member State could be restricted by competent authorities of that Member State on the basis of legislative measures referred to in Article 23 of Regulation (EU) 2016/679 of the European Parliament and of the Council  ( 6 ) , or under national measures transposing Article 13(3), Article 15(3) or Article 16(3) of Directive (EU) 2016/680 of the European Parliament and of the Council  ( 7 ) ; (c) where the exercise of those rights and obligations would undermine the Commission’s cooperation with non-EU countries or international organisations on common cybersecurity threats. Before applying restrictions in the circumstances referred to in the first subparagraph, (a) and (b), the Commission shall consult the relevant EU institutions, bodies, agencies, offices or Member State authorities concerning the potential grounds for imposing restrictions and the necessity and proportionality of the restrictions concerned, unless this would undermine the activities of the Commission and unless it is clear to the Commission that the application of a restriction is provided for by one of the acts referred to in those points or that consultation would undermine the purpose of its activities under Decision (EU, Euratom) 2017/46. The first subparagraph, (c), shall not apply where the interests or fundamental rights and freedoms of the data subject override the interest of the Commission to cooperate with non-EU countries or international organisations. 4.   Paragraphs 1, 2 and 3 shall be without prejudice to the application of other Commission Decisions laying down internal rules governing the provision of information to data subjects and the restriction of application of certain rights under Article 25 of Regulation (EU) 2018/1725. 5.   Any restriction of the rights and obligations, referred to in paragraph 2 shall be necessary and proportionate to the risks to the rights and freedoms of data subjects. 6.   A necessity and proportionality test shall be carried out on a case-by-case basis before restrictions are applied and restrictions shall be limited to what is strictly necessary to achieve the intended purpose.

Provision of information to data subjects

Article 3

1.   The Commission shall publish on its website a data protection notice that informs all data subjects of its activities that involve processing their personal data for the purpose of fulfilling its tasks pursuant to Decision (EU, Euratom) 2017/46, including a description of the categories of personal data involved. Where it is possible to do so without compromising IT security, the Commission shall ensure that the data subjects are informed individually in an appropriate format. 2.   Where the Commission restricts, wholly or partly, the provision of information to data subjects, whose personal data it processes for the purpose of fulfilling its tasks pursuant to Decision (EU, Euratom) 2017/46 it shall record and register the reasons for the restriction in accordance with Article 6 of this Decision.

Right of access by the data subject, right to erasure and right to restrict data processing

Article 4

1.   Where the Commission restricts, wholly or partly, the right of access to personal data by data subjects, the right to erasure, or the right to restrict data processing, as referred to in Articles 17, 19 and 20 of Regulation (EU) 2018/1725, it shall inform the data subject concerned, in its reply to the request for access, erasure or restriction of data processing: (a) of the restriction applied and of the principal reasons for doing so; (b) of how to lodge a complaint with the European Data Protection Supervisor or how to seek judicial remedy in the Court of Justice of the European Union. 2.   The Commission may defer, omit or deny the provision of information on the reasons for the restriction referred to in paragraph 1 for as long as this would undermine the purpose of the restriction. 3.   The Commission shall record and register the reasons for the restriction in accordance with Article 6. 4.   Where the right of access is wholly or partly restricted, data subjects may exercise their right of access by contacting the European Data Protection Supervisor, in accordance with Article 25(6), (7) and (8) of Regulation (EU) 2018/1725.

Communication of a personal data breach to data subjects

Article 5

Where the Commission restricts the communication of a personal data breach to the data subject, as referred to in Article 35 of Regulation (EU) 2018/1725, it shall record and register the reasons for the restriction in accordance with Article 6 of this Decision. The Commission shall communicate the record to the EDPS at the time of the notification of the personal data breach.

Recording and registering of restrictions

Article 6

1.   The Commission shall record the reasons for any restriction applied pursuant to this Decision including a reference to the legal ground(s) applied for the restriction and an assessment of the necessity and proportionality of the restriction, taking into account the relevant elements set out in Article 25(2) of Regulation (EU) 2018/1725. 2.   The record shall state how the exercise of a right by the data subject would undermine the purpose of providing IT security operations and services to the Commission in line with Decision (EU, Euratom) 2017/46, or of restrictions applied pursuant to Article 2(2) or (3) of this Decision, or would adversely affect the rights and freedoms of other data subjects. 3.   The Commission shall register these records and any documents containing underlying factual and legal elements. They shall be made available to the European Data Protection Supervisor on request.

Duration of restrictions

Article 7

1.   The restrictions referred to in Articles 3, 4 and 5 shall continue to apply as long as the reasons for them remain valid. 2.   When the reasons for a restriction referred to in Articles 3, 4 and 5 are no longer valid, the Commission shall: (a) lift the restriction; (b) inform the data subject of the principal reasons for the restriction; (c) inform the data subject of how they can lodge a complaint with the European Data Protection Supervisor at any time or seek judicial remedy in the Court of Justice of the European Union.

Safeguards and storage periods

Article 8

1.   The Commission shall review the application of the restrictions referred to in Articles 3, 4 and 5 6 months after their adoption, and at the closure of the individual IT security operation. Thereafter, the Commission shall review and monitor the need to maintain any restriction on an annual basis. The review shall include an assessment of the necessity and proportionality of the restriction, taking into account the relevant elements set out in Article 25(2) of Regulation (EU) 2018/1725. 2.   The Commission has adopted technical and organisational measures to avoid any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed such as access rights management, backup policy and any other measure in line with the Decision (EU, Euratom) 2017/46. 3.   The Commission shall record the applicable retention periods in line with the Common Commission-Level Retention List and shall make available to the data subjects the relevant retention periods for these processing activities in its data protection notice.

Review by the Data Protection Officer of the Commission

Article 9

1.   The Commission’s Data Protection Officer shall be informed, without undue delay, whenever data subjects’ rights are restricted in accordance with this Decision. Upon request, the Data Protection Officer shall be given access to the record and any documents containing underlying factual and legal elements. 2.   The Data Protection Officer may request a review of the restrictions and shall be informed of the outcome of the requested review. 3.   The Commission shall document the involvement of the Data Protection Officer whenever data subjects’ rights are restricted in accordance with this Decision.

Entry into force

Article 10

This Decision shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union .

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next