My bookmarksSign up free

Commission Implementing Regulation (EU) 2021/581 CHAPTER III — GENERAL PROVISIONS

Article 27–Article 41 · 15 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

SECTION 1 — Entities responsible for the technical aspects

Technical components of EUROSUR

Article 27

1.   The technical components of EUROSUR shall include national components and a European component. 2.   Each national component shall be composed of the national systems and networks used by Member States for the establishment of the situational pictures, reporting, situational awareness, risk analysis, and for supporting the planning and conduct of border control operations, including the infrastructure, organisation, personnel and information resources needed to support it. The interconnections among and between components inside a Member State as well as between Member States shall be part of the national components. 3.   The European component shall complement the national components. It shall include the interconnection with the national components. It shall comprise the Communication Network and the systems and networks used by the Agency for the establishment of the situational pictures, reporting, situational awareness, risk analysis, and for supporting the planning and conduct of border control operations.

Technical responsibilities of the Agency

Article 28

The Agency shall be responsible for managing the European component, which shall include: (a) the definition of technical standards for interconnecting networks, systems, applications and equipment of the national and external components with those of the European component; (b) the certification process of the networks, systems, applications and equipment with a view to connecting them to EUROSUR, in close cooperation with the responsible authorities; (c) the service management of the systems and networks used by the Agency for the establishment of the situational pictures, reporting, situational awareness and risk analysis and for supporting the planning and conduct of border control operations; (d) the reporting of the operation, the quality service and the service management aspects of the systems and networks referred to in point (c), as provided for in Article 23; (e) the data security of the European component.

Technical responsibilities of the Member States

Article 29

1.   Each Member State shall be responsible for: (a) managing its national component, including service management, ensuring the coordination of the connection of national systems and networks used for the establishment of the situational pictures, reporting, situational awareness, risk analysis and for supporting the planning and conduct of border control operations; (b) reporting the operation and the quality of service and the service management aspects of the systems and networks referred to in point (a), as provided for in Article 23; (c) the compliance with the technical standards established by the Agency; (d) the data security of the national component. 2.   The national coordination centre shall: (a) support the coordination, planning and implementation of the national component; (b) contribute to the regular monitoring of the quality of service and quality of data, and report it to the Agency; (c) ensure the operational reporting on the systems and networks of the European component.

External components

Article 30

1.   An external component of EUROSUR shall be composed of the systems and networks, including the infrastructure, organisation, personnel and information resources needed to support it, that are not part of EUROSUR and which: (a) exchange data and information with EUROSUR; (b) support the establishment of a specific situational picture. 2.   The interconnection of an external component to EUROSUR belongs to the external component. It shall be specified in the rules establishing the relevant specific situational picture.

SECTION 2 — Data security and data protection rules for EUROSUR

General principles of EUROSUR data security

Article 31

1.   EUROSUR data security shall encompass the management and the technical activities necessary to achieve an appropriate level of protection for handling EUROSUR data and information, cope with the evolving threat environment and enable the various national bodies and agencies involved in EUROSUR and the Agency to fulfil their mission. EUROSUR data security shall include information assurance, physical security, personal security and industrial security. 2.   EUROSUR data security shall comprise: (a) security risk management, including security controls and plans, and associated monitoring, evaluation, maintenance, improvement, reporting, awareness and training; (b) business continuity and disaster recovery, including impact assessment, continuity and recovery controls and plans, and associated monitoring evaluation, maintenance, improvement, reporting, awareness and training; (c) security incident response and cooperative response between the Agency and the Member States for security incidents; (d) security accreditation; (e) user access control; (f) data security related aspects of the planning of border operations and of the planning of information systems; (g) security aspects of the interconnections of components; (h) handling of classified information for the purpose of EUROSUR.

Governance of EUROSUR data security

Article 32

1.   The Agency shall ensure the overall security of EUROSUR, duly taking into account the need for oversight and integration of security requirements in each component of EUROSUR. 2.   The Agency shall be responsible for the data security of the European component. 3.   Each Member State shall be responsible for the data security of its national component. 4.   The Agency and the Member States shall ensure alignment of the controls, the processes and the plans, so that the data security of EUROSUR is horizontally and effectively assured, based on a global security risk management process. 5.   The responsibilities for the data security of the external component shall be set out in the agreements, arrangements and operational plans establishing the specific situational picture, as provided for in Article 26. 6.   The Agency shall adopt standards laying down the security functional requirements and the security assurance requirements for controlling the access to, and handling of, technologies that provide security to EUROSUR. 7.   Each Member State and the Agency shall ensure that the necessary steps are taken to comply with the standards referred to in paragraph 6, that adequate reasoning for fulfilment of the requirements and for controlling of the risks is documented and that any further requirements related to the security of the systems are met, taking full account of expert advice. 8.   Each Member State and the Agency shall report in EUROSUR any security incident affecting the data security of EUROSUR as part of the reporting on data quality and quality of service. 9.   Wherever the security of the Union or its Member States may be affected by the operation of EUROSUR: (a) the Agency shall immediately inform the relevant national coordination centres; (b) the executive director of the Agency may decide to take any appropriate measure to remedy the situation, in close coordination with the Member States concerned, including the disconnection of certain systems and networks from the European component of EUROSUR.

Application of security rules in EUROSUR

Article 33

1.   When handling EUROSUR data and information, each Member State and the Agency shall ensure that security controls, processes and plans are in place, ensuring a degree of protection which shall at least be equivalent to that guaranteed by the Commission’s rules on security set out in Decision (EU, Euratom) 2015/444 and Commission Decision (EU, Euratom) 2015/443  ( 16 ) . 2.   Member States shall immediately inform the Commission and the Agency of the adoption of national security rules relevant for EUROSUR as referred to in paragraph 1. 3.   Natural persons resident in third countries and legal entities established in third countries may deal with EUROSUR data only where they are subject, in those countries, to security rules ensuring a degree of protection at least equivalent to that guaranteed by the equivalent rules on security of the Commission. 4.   The equivalence of security rules applied in a third country may be recognised in an agreement with that country. 5.   As part of the implementation of the European component of EUROSUR, the Agency shall support the corresponding exchange of EUROSUR reports and the interconnection of national components both at unclassified level and at classified level.

Principles of security accreditation in EUROSUR

Article 34

The security accreditation activities shall be carried out in accordance with the following principles: (a) security accreditation activities and decisions are to be undertaken in a context of collective responsibility for the security of the Union and of the Member States; (b) efforts shall be made for decisions to be reached by consensus and for all relevant parties with an interest in security issues to be involved; (c) tasks shall be carried out in respect of relevant security rules and accreditation standards applicable to the Agency, the Member States’ authorities and the Commission; (d) a permanent monitoring process shall ensure that security risks are known, security measures are defined to reduce such risks to an acceptable level in accordance with the basic principles and minimum standards set out in the applicable security rules and that these measures are applied in line with the concept of defence in depth. The effectiveness of such measures shall be continuously evaluated; (e) security accreditation decisions shall, following the process defined in the security accreditation strategy, be based on local security accreditation decisions taken by the respective national Security Accreditation Authorities (SAAs) of the Member States; (f) the technical security accreditation activities shall be entrusted to professionals who are duly qualified in the field of accrediting complex systems, who have an appropriate level of security clearance, and who shall act objectively; (g) security accreditation decisions shall be taken independently of the Agency and of the entities responsible for implementing the national components of EUROSUR. The data security accreditation authority for EUROSUR shall be, within the Agency, an autonomous body that takes its decisions independently; (h) security accreditation activities shall be carried out while reconciling the requirement for independence with the need for adequate coordination between the Agency and the national authorities responsible for implementing security provisions in Member States.

EUROSUR Security Accreditation Board

Article 35

1.   A EUROSUR Security Accreditation Board (‘the Accreditation Board’) is established within the Agency. 2.   As security accreditation authority, the Accreditation Board shall, with regard to security accreditation for EUROSUR, be responsible for: (a) defining and approving a security accreditation strategy for EUROSUR including the European component; (b) Member States shall report to the Accreditation Board regarding the accreditation of their national components, so as to ensure that the Accreditation Board can take relevant interconnection decisions; (c) taking security accreditation decisions for the European component, taking into account the advice provided by national entities competent in security matters and the overall security risks; (d) approving relevant documentation relating to security accreditation; (e) advising, within its field of competence, the Agency and the Member States in the establishment of security operating procedures (‘SecOps’), and providing a statement with its concluding position; (f) examining and approving the security risk assessment cooperating with the Agency, Member States and the Commission to define risk mitigation measures; (g) checking the implementation of security measures in relation to the security accreditation of the European component by undertaking or sponsoring security assessments, inspections or reviews; (h) endorsing the selection of approved products and measures and of approved cryptographic products used to provide security for the European component of EUROSUR and for interconnection; (i) approving or, where relevant, together with the relevant entity competent in security matters, participating in the joint approval of: (i) the interconnection of the European component with national components, (ii) the interconnection of the external components to EUROSUR; (j) agreeing with the relevant Member State the procedures relating to access control; (k) on the basis of the security risk reports, informing the Agency of its risk assessment and providing advice to the Agency on residual security risk treatment options for a given security accreditation decision; (l) carrying out the consultations which are necessary to perform its tasks. 3.   In the security accreditation strategy referred to in point (a) of paragraph 2, the Accreditation Board shall set out the following: (a) the scope of the activities necessary to perform and maintain the accreditation of the European component of EUROSUR, and their potential interconnection with other components; (b) a security accreditation process for the European component with a degree of detail commensurate with the required level of assurance and clearly stating the approval conditions; (c) the role of relevant stakeholders involved in the accreditation process; (d) an accreditation schedule compliant with the deployment of the EUROSUR standards, in particular as regards the deployment of infrastructure, service provision and evolution; (e) the principles of the security accreditation of the national components to be performed by national entities of the Member States competent in security matters; (f) the provisions related to data security of the external components of EUROSUR. 4.   The Accreditation Board shall perform its tasks independently when handling files, performing system security audits, preparing decisions and organising its meetings.

Functioning of the Security Accreditation Board

Article 36

1.   The Accreditation Board shall be composed of one representative per Member State and two representatives from the Commission. 2.   The security officer of the Agency shall be a designated secretary of the Accreditation Board. 3.   The Accreditation Board shall establish its rules of procedure and appoint its chairperson. 4.   If there is no consensus, the Accreditation Board shall have recourse to majority voting. 5.   The Accreditation Board may set up subgroups to investigate technical matters. 6.   The Accreditation Board shall keep the management board of the Agency and the executive director of the Agency and the Commission informed of any of its decisions.

Role of Member States and the Agency with regard to the Accreditation Board

Article 37

Member States and the executive director of the Agency shall: (a) transmit to the Accreditation Board all information they consider relevant for the purposes of security accreditation; (b) permit duly authorised persons appointed by the Accreditation Board to have access to any classified information and to any areas/sites related to the security of systems falling within their jurisdiction, in accordance with their national laws and regulations, and without any discrimination on ground of nationality, including for the purposes of security audits and tests as decided by the Accreditation Board; (c) be responsible for the accreditation of their components of EUROSUR, and report, to this end, to the Accreditation Board.

User access

Article 38

1.   Without prejudice to Article 35, the entity responsible for a component of EUROSUR shall manage user access to its systems networks and application. 2.   In case a national staff member would be given direct access to a system or application of the Agency used for the purpose of EUROSUR, the Agency shall coordinate access rights with the relevant National Coordination Centre. 3.   In case, an Agency staff member would be given direct access to a national system or application used for the purpose of EUROSUR, the responsible Member State shall coordinate access rights with the executive director of the Agency.

Data security of the external components of EUROSUR

Article 39

1.   The external components may be connected to EUROSUR only if their data security is equivalent to the data security of EUROSUR. 2.   The rules for establishing and sharing a specific situational picture referred to in Article 26 shall include provisions for data security, specifying the type of information that may be exchanged and the level of classification. 3.   Any interconnection of an external component to EUROSUR shall be subject to the prior approval of the Accreditation Board.

Data protection rules for EUROSUR

Article 40

1.   Although data processed by EUROSUR may exceptionally contain information relating to indirectly identifiable natural persons, such data shall not be processed in the framework of EUROSUR to identify these natural persons. 2.   Where the processing of information in EUROSUR exceptionally requires the processing of personal data other than ship and aircraft identification numbers, these personal data shall be deleted as soon as the purpose for which they have been collected has been achieved.

Entry into force

Article 41

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union .

Back to Commission Implementing Regulation (EU) 2021/581 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next