My bookmarksSign up free

Regulation (EU) 2023/969 CHAPTER IV — SECURITY AND LIABILITY

Article 19–Article 20 · 2 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Security

Article 19

1.   eu-LISA shall take the necessary technical and organisational measures to ensure a high level of cybersecurity of the JITs collaboration platform and the information security of data within the JITs collaboration platform, in particular in order to ensure the confidentiality and integrity of operational and non-operational data stored in the centralised information system. 2.   eu-LISA shall prevent unauthorised access to the JITs collaboration platform and shall ensure that persons authorised to access the JITs collaboration platform have access only to the data covered by their access authorisation. 3.   For the purposes of paragraphs 1 and 2 of this Article, eu-LISA shall adopt a security plan and a business continuity and disaster recovery plan, in order to ensure that the centralised information system can be restored in the event of interruption. eu-LISA shall provide for a working arrangement with the computer emergency response team for the Union’s institutions, bodies and agencies established by the Arrangement between the European Parliament, the European Council, the Council of the European Union, the European Commission, the Court of Justice of the European Union, the European Central Bank, the European Court of Auditors, the European External Action Service, the European Economic and Social Committee, the European Committee of the Regions and the European Investment Bank on the organisation and operation of a computer emergency response team for the Union’s institutions, bodies and agencies (CERT-EU)  ( 17 ) . When adopting that security plan, eu-LISA shall take into account the possible recommendations of the security experts present in the Advisory Group referred to in Article 12 of this Regulation. 4.   eu-LISA shall monitor the effectiveness of all the measures described in this Article and shall take the necessary organisational measures related to self-monitoring and supervision to ensure compliance with this Regulation.

Liability

Article 20

1.   Where a Member State, Eurojust, Europol, the EPPO, OLAF or any other competent Union body, office or agency, as a consequence of a failure on their part to comply with their obligations under this Regulation, cause damage to the JITs collaboration platform, that Member State, Eurojust, Europol, the EPPO, OLAF or other competent Union body, office or agency, respectively, shall be held liable for such damage, unless and insofar as eu-LISA fails to take reasonable measures to prevent the damage from occurring or to minimise its impact. 2.   Claims for compensation against a Member State for the damage referred to in paragraph 1 shall be governed by the law of that Member State. Claims for compensation against Eurojust, Europol, the EPPO, OLAF or any other competent Union body, office or agency for such damage shall be governed by the relevant legal acts establishing them.

Back to Regulation (EU) 2023/969 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next