Retention period for storage of operational data
1. Operational data pertaining to each JIT collaboration space shall be stored in the centralised information system for as long as required for all JITs collaboration platform users concerned to complete the process of its downloading. The retention period shall not exceed four weeks from the date of the upload of such data to the JITs collaboration platform.
2. As soon as the process of downloading has been completed by all intended JITs collaboration platform users or, at the latest, upon expiry of the retention period referred to in paragraph 1, the data shall be automatically and permanently erased from the centralised information system.
Retention period for storage of non-operational data
1. Where an evaluation of a JIT is envisaged, non-operational data pertaining to each JIT collaboration space shall be stored in the centralised information system until the relevant JIT evaluation has been completed. The retention period shall not exceed five years from the date of entry of such data in the JITs collaboration platform.
2. If it is decided not to conduct an evaluation upon the closure of a JIT or, at the latest, upon expiry of the retention period referred to in paragraph 1, the data shall be automatically erased from the centralised information system.
Data controller and data processor
1. Each competent national authority of a Member State and, where appropriate, Eurojust, Europol, the EPPO, OLAF or any other competent Union body, office or agency shall be considered to be data controllers in accordance with applicable Union data protection rules, for the processing of operational personal data under this Regulation.
2. With regard to data uploaded to the JITs collaboration platform by the competent authorities of third countries or representatives of international judicial authorities, one of the JIT space administrators shall be designated in the relevant JIT agreement as data controller as regards the personal data exchanged through, and stored in, the JITs collaboration platform.
No data from third countries or international judicial authorities shall be uploaded prior to the designation of the data controller.
3. eu-LISA shall be considered to be a data processor in accordance with Regulation (EU) 2018/1725 as regards the personal data exchanged through, and stored in, the JITs collaboration platform.
4. The JITs collaboration platform users shall be joint controllers, within the meaning of Article 28 of Regulation (EU) 2018/1725, for the processing of non-operational personal data in the JITs collaboration platform.
Purpose of the processing of personal data
1. The data entered into the JITs collaboration platform shall only be processed for the purposes of:
(a)
the exchange of operational data between the JITs collaboration platform users for the purpose for which the relevant JIT has been set up;
(b)
the exchange of non-operational data between the JITs collaboration platform users, for the purposes of managing the relevant JIT.
2. Access to the JITs collaboration platform shall be limited to duly authorised staff of the competent authorities of Member States and of third countries, Eurojust, Europol, the EPPO, OLAF and other competent Union bodies, offices or agencies, or representatives of international judicial authorities, to the extent necessary for the performance of their tasks in accordance with the purposes referred to in paragraph 1, and to what is strictly necessary and proportionate to the objectives pursued.
Technical logs
1. eu-LISA shall ensure that a technical log is kept of all access to the centralised information system and all data processing operations in the centralised information system, in accordance with paragraph 2.
2. The technical logs shall show:
(a)
the date, time zone and exact time of accessing the centralised information system;
(b)
the identifying mark of each individual JITs collaboration platform user who accessed the centralised information system;
(c)
the date, time zone and access time of each operation carried out by each individual JITs collaboration platform user;
(d)
the operation carried out by each individual JITs collaboration platform user.
The technical logs shall be protected by appropriate technical measures against modification and unauthorised access. The technical logs shall be kept for three years or for such longer period as required for the termination of ongoing monitoring procedures.
3. On request, eu-LISA shall make the technical logs available to the competent authorities of the Member States which participated in a particular JIT without undue delay.
4. Within the limits of their competences and for the purpose of fulfilling their duties, the national supervisory authorities responsible for monitoring the lawfulness of data processing shall have access to the technical logs upon request.
5. Within the limits of its competences and for the purpose of fulfilling its supervisory duties in accordance with Regulation (EU) 2018/1725, the European Data Protection Supervisor shall have access to the technical logs upon request.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.