My bookmarksSign up free

Commission Implementing Decision (EU) 2023/729 of 30 March 2023 on the establishment of the technical architecture, technical specifications for entering and storing information and the procedures for controlling and verifying information contained in the European Border and Coast Guard False and Authentic Documents Online system (‘EBCG FADO’)

Commission Implementing Decision (EU) 2023/729 of 30 March 2023 on the establishment of the technical architecture, technical specifications for entering and storing information and the procedures for controlling and verifying information contained in the European Border and Coast Guard False and Authentic Documents Online system (‘EBCG FADO’)

Implementing Decision (EU) 2023/729 · Decision · 3 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Article 1

The technical architecture of the FADO system, the technical specifications for entering and storing information in the FADO system and the procedures for controlling and verifying the information contained in the FADO system shall be as set out in the Annex.

Article 2

This Decision shall enter into force on the day following that of its publication in the Official Journal of the European Union .

Supplementary provisions

ANNEXSupplementary provisions

ANNEX PART 1 1.    Objectives This Part of the Annex provides a description of the technical architecture of the European Border and Coast Guard Agency’s (‘the Agency’) False and Authentic Documents Online system (‘EBCG FADO system’) and its components. The technical architecture of the new ‘EBCG FADO’ system will be developed in an incremental manner, following the releases of the new system and possible future requirements. 2.    Description of the architecture of the EBCG FADO system The technical architecture enables the Agency to determine the different levels of access to the information stored in the system. The Agency will enter the information obtained in the EBCG FADO system in a timely and efficient manner and to guarantee the uniformity and quality of that information. The EBCG FADO system will be the overarching application for all access levels, providing a single point of access to users who want to manage information or search for EBCG FADO content. The technical architecture of the EBCG FADO system will have the capacity to host: (a) a public domain containing a subset of basic information about specimens of authentic documents and authentic documents; (b) a EU sensitive non-classified domain subject to access control allowing: — different categories of users to explore information according to the defined access rights; — a selected number of users to provide and validate sensitive non-classified information prior to making this information available to end-users (consumers of EU sensitive-non-classified information); — an archive to store part of the sensitive non-classified information for statistical and historical purposes once the purpose of retrieving such information no longer exists. (c) a EU classified (Restricted) domain subject to access control for authorised users allowing: — to explore classified information; — a selected number of users to provide and validate classified information prior to making this information available to other end-users authorised to access the classified network (consumers of classified information). Furthermore, the technical architecture of the system will have the capacity to: (a) ensure a high level of cyber-security; (b) support extensive search and reporting capabilities, and apply advanced analytical services including artificial intelligence; (c) be integrated with external entities and their systems and provide data exchange capabilities via automated interfaces, such as Frontex INTERPOL Electronic Library Document System (FIELDS), with Document Information System Civil Status (DISCS), etc.; (d) work on a cloud-based infrastructure for EU non-classified, sensitive and public domains, as long as it ensures compliance with personal data protection requirements; (e) implement state-of-the-art technologies and modern technical approaches, including availability, reliability, flexibility for new functions, products and modifications as well as be able to scale up to accommodate large numbers of users; (f) allow integration with hardware and support access to the system offline or in limited connectivity scenarios from mobile devices. PART 2 1.    Objectives This second part of the Annex provides a description of the technical specifications for entering and storing information in the European Border and Coast Guard Agency’s (‘the Agency’) False and Authentic Documents Online system (‘EBCG FADO system’) in accordance with high standards. The EBCG FADO will also contribute to the fight against identity fraud by sharing information with other actors, including the general public. Personal data processing is included in these technical specifications. Entering and storing information in the system will be done according to the purpose of the processing. 2.    Description of the process for entering and storing information in the EBCG FADO SYSTEM Information will be provided by authorised users in a dedicated module of the EBCG FADO system for validation purposes prior to making this information available to other users. The validation process applies to all information entered in the EBCG FADO system or created within the system. The validation process of such information is controlled by the Agency and implemented in consultation with the provider of information. In order to ensure high standards, the Agency may decide to consult with selected document experts or with the Agency’s data protection officer. Once validated, information will be translated and stored in the EBCG FADO system domains. 3.    Controlling and verifying information in THE EBCG FADO SYSTEM In the EBCG FADO system, the document data (hereinafter ‘information’) will be verified and processed for administrative purposes only by electronic and material means, depending on the format in which information is supplied to the Agency. In the EBCG FADO system, there is no processing of operational personal data within the meaning of Article 3(2) of Regulation (EU) 2018/1725 of the European Parliament and of the Council  ( 1 ) . Information processed undergoes the business processes designed to enter and store information in the EBCG FADO system. Only published documents formerly validated are made available to the users. Information processing in the EBCG FADO system will be subject to continuous improvement in order to ensure a progressive revision and adaptation of the technical and organisational measures in line with the technological evolution and to eliminate flaws in the underlying business processes. The Agency specifies: (a) the categories of data subjects whose personal data are processed in the system; (b) the categories of personal data processed; (c) the controller or categories of controllers, including joint controllerships; (d) the recipients of personal data; (e) the safeguards to prevent abuse or unlawful access or transfer of personal data; (f) the retention period related to personal data processing activities for the purposes of operating the EBCG FADO system and of carrying out administrative tasks; (g) the methodology of data collection, including whether it comes from Member States and/or third countries; (h) the dissemination and the recipients of the personal data. 4.    Personal data processing for entering and storing information in the EBCG FADO system The Agency will implement specific organisational and technical measures during the process for entering and storing information in the EBCG FADO system by: (a) providing guidance to the authorised users about redaction – minimisation and pseudonymisation – of personal data before delivering information to the Agency and during the validation process; (b) implementing appropriate technical measures to ensure necessary safeguards to protect the rights of data subjects during the validation process, before making information available to end-users; (c) restricting access to the module dedicated to the validation process to a minimum number of users; (d) making available information stored in the sensitive-non-classified and classified domains on a need-to-know basis to a known number of users. PART 3 1.    Objectives The third part of the Annex provides a description of the procedures for controlling and verifying information in the European Border and Coast Guard Agency’s (‘the Agency’) False and Authentic Documents Online system (‘EBCG FADO system’). Personal data processing will be included in the procedures for controlling and verifying information in the EBCG FADO system. The Commission supervises, inter alia, the implementation of the measures contained in this Decision. The Commission is assisted by the committee established by Article 6 of Council Regulation (EC) No 1683/95  ( 2 ) . The Agency participates without decisional power in the meetings of the Article 6 committee. The Agency will apply quality assurance and quality control techniques for controlling and verifying information contained in the EBCG FADO system. 2.    Quality assurance and quality control In accordance with the Annex Part 2 of this Commission Implementing Decision establishing the technical specifications for entering and storing information in the EBCG FADO system  ( 3 ) , the Agency will establish procedures to implement: (a) quality assurance: — before information is inserted in the FADO system for validation purposes; — during the validation process; (b) quality control: — after publication, once information has been made available to the public and other end-users (consumers). 3.    Quality assurance i.   Access management The purpose of access management to the FADO system is to: (a) grant access on a need-to-know basis to the FADO system; (b) revoke access rights; The Agency will set up procedures for access management to the FADO system where the following minimum requirements shall be observed: (a) users shall receive information about the processing of their personal data; (b) users shall manage their user accounts in the FADO system; (c) personal data shall be communicated to the Agency directly by the data subjects or by their points of contacts; (d) a limited number of users in the Agency belonging to the FADO system organisation shall be authorised to perform access management. ii.   Validation of information inserted into the FADO system The purpose of validation of information is to reduce the risk of flaws in the system, ensuring the uniformity and quality of information. Only a selected number of authorised and trained document experts shall provide and validate information in the system. Before starting to enter information in the system, these users will be: (a) trained to enter information in the system; (b) provided with guidance material and/or tutorials to enter information in the system; (c) informed about the business processes set up by the Agency for validation purposes. The Agency will implement a dedicated module of the EBCG FADO system for validation purposes prior to make this information available to other users. During the validation process, this module shall allow: (a) a selected number of users to insert or correct information in the EBCG FADO system; (b) a limited number of users to process validation of information in the system, including optional consultation with selected users other than those inserting or correcting information; (c) a limited number of users to provide translation if necessary; (d) a limited number of users to approve and publish the information. iii.   Publication of information After the validation process, information will be published. 4.    Quality control The Agency will establish an annual quality control plan in the EBCG FADO system. The plan will ensure that controls on an adequate amount of information are regularly performed every year, verifying inter alia: (a) relevance of information contained in the EBCG FADO system; (b) quality of information contained in the EBCG FADO system; (c) compliance of the EBCG FADO system management, including personal data protection requirements. The results of audits will be delivered to the Commission, the Agency’s management board and the Agency’s data protection officer. 5.    User contribution to quality Users may be involved in the process for controlling and verifying information contained in the EBCG FADO system. ( 1 )   Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC ( OJ L 295, 21.11.2018, p. 39 ). ( 2 )   Council Regulation (EC) No 1683/95 of 29 May 1995 laying down a uniform format for visas ( OJ L 164 14.7.1995, p. 1 ). ( 3 )   Commission Implementing Decision establishing the technical architecture of the European Border and Coast Guard (EBCG) FADO system in accordance with Article 6(1)(a) of Regulation (EU) 2020/493.

Other acts of the same type
Council Decision (EU) 2018/1676 of 15 October 2018 on the signing, on behalf of the European Union, of the Investment Protection Agreement between the European Union and its Member States, of the one part, and the Republic of Singapore, of the other partCouncil Decision (EU) 2019/116 of 15 October 2018 on the conclusion of an Agreement in the form of an Exchange of Letters between the European Union and the Kingdom of Norway on the cumulation of origin between the European Union, the Swiss Confederation, the Kingdom of Norway and the Republic of Turkey in the framework of the Generalised System of PreferencesCouncil Decision (EU) 2019/131 of 15 October 2018 on the conclusion of an Agreement in the form of an Exchange of Letters between the European Union and the Swiss Confederation on the cumulation of origin between the European Union, the Swiss Confederation, the Kingdom of Norway and the Republic of Turkey in the framework of the Generalised System of PreferencesCouncil Decision (EU) 2020/1420 of 15 October 2018 on the signing, on behalf of the European Union and its Member States, and provisional application of a Protocol to the Euro-Mediterranean Agreement establishing an association between the European Communities and their Member States, of the one part, and the Republic of Tunisia, of the other part, to take account of the accession of the Republic of Croatia to the European UnionCommission Implementing Decision (EU) 2018/1522 of 11 October 2018 laying down a common format for national air pollution control programmes under Directive (EU) 2016/2284 of the European Parliament and of the Council on the reduction of national emissions of certain atmospheric pollutants (notified under document C(2018) 6549) (Text with EEA relevance.)Commission Implementing Decision (EU) 2018/1523 of 11 October 2018 establishing a model accessibility statement in accordance with Directive (EU) 2016/2102 of the European Parliament and of the Council on the accessibility of the websites and mobile applications of public sector bodies (Text with EEA relevance.)Commission Implementing Decision (EU) 2018/1524 of 11 October 2018 establishing a monitoring methodology and the arrangements for reporting by Member States in accordance with Directive (EU) 2016/2102 of the European Parliament and of the Council on the accessibility of the websites and mobile applications of public sector bodies (notified under document C(2018) 6560) (Text with EEA relevance.)Council Decision (EU) 2018/1528 of 11 October 2018 on the signing, on behalf of the Union, of the Voluntary Partnership Agreement between the European Union and the Socialist Republic of Viet Nam on forest law enforcement, governance and tradeCommission Implementing Decision (EU) 2018/1538 of 11 October 2018 on the harmonisation of radio spectrum for use by short-range devices within the 874-876 and 915-921 MHz frequency bands (notified under document C(2018) 6535) (Text with EEA relevance.)Council Decision (EU) 2018/1549 of 11 October 2018 on the signing, on behalf of the Union, of the Arrangement between the European Union, of the one part, and the Kingdom of Norway, the Republic of Iceland, the Swiss Confederation and the Principality of Liechtenstein, of the other part, on the participation by those States in the European Agency for the operational management of large-scale IT systems in the area of freedom, security and justiceCommission Implementing Decision of 10 October 2018 laying down the final import response on behalf of the Union concerning the future import of certain chemicals pursuant to Regulation (EU) No 649/2012 of the European Parliament and of the Council and amending Commission Implementing Decision C(2016) 747Commission Implementing Decision (EU) 2018/1521 of 10 October 2018 amending Decision 2009/11/EC authorising methods for grading pig carcasses in Spain (notified under document C(2018) 6507)

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

Contents

What to look at next