My bookmarksSign up free

Regulation (EU) 2023/1543 CHAPTER V — DECENTRALISED IT SYSTEM

Article 19–Article 26 · 8 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Secure digital communication and data exchange between competent authorities and service providers and between competent authorities

Article 19

1.   Written communication between competent authorities and designated establishments or legal representatives under this Regulation, including the exchange of forms provided for in this Regulation and the data requested under a European Production Order or a European Preservation Order, shall be carried out through a secure and reliable decentralised IT system (‘the decentralised IT system’). 2.   Each Member State shall ensure that the designated establishments or legal representatives of service providers located in that Member State are provided with access to the decentralised IT system via their respective national IT system. 3.   Service providers shall ensure that their designated establishments or legal representatives can use the decentralised IT system via the respective national IT system in order to receive EPOCs and EPOC-PRs, send the requested data to the issuing authority and communicate in any other way with the issuing authority and the enforcing authority, as provided for in this Regulation. 4.   Written communication between competent authorities under this Regulation, including the exchange of forms provided for in this Regulation, and of the requested data under the procedure for enforcement as provided for in Article 16, as well as written communication with competent Union agencies or bodies, shall be carried out through the decentralised IT system. 5.   Where communication through the decentralised IT system in accordance with paragraph 1 or 4 is not possible due to, for instance, the disruption of the decentralised IT system, the nature of the transmitted material, technical limitations, such as data size, legal constraints relating to the admissibility as evidence of the requested data or to forensic requirements applicable to the requested data, or exceptional circumstances, the transmission shall be carried out by the most appropriate alternative means, taking into account the need to ensure an exchange of information which is swift, secure and reliable, and allows the recipient to establish authenticity. 6.   Where a transmission is carried out by alternative means as provided for in paragraph 5, the originator of the transmission shall record the transmission, including, as appropriate, the date and time of transmission, the sender and recipient, the file name and its size, in the decentralised IT system, without undue delay.

Legal effects of electronic documents

Article 20

Documents transmitted as part of electronic communication shall not be denied legal effect or be considered inadmissible in the context of cross-border judicial procedures under this Regulation solely on the ground that they are in electronic form.

Electronic signatures and seals

Article 21

1.   The general legal framework for the use of trust services set out in Regulation (EU) No 910/2014 shall apply to electronic communication under this Regulation. 2.   Where a document transmitted as part of the electronic communication under Article 19(1) or (4) of this Regulation requires a seal or a signature in accordance with this Regulation, the document shall feature a qualified electronic seal or qualified electronic signature as defined in Regulation (EU) No 910/2014.

Reference implementation software

Article 22

1.   The Commission shall be responsible for the creation, maintenance and development of reference implementation software which Member States may choose to apply as their back-end system instead of a national IT system. The creation, maintenance and development of the reference implementation software shall be financed from the general budget of the Union. 2.   The Commission shall provide, maintain and support the reference implementation software free of charge.

Costs of the decentralised IT system

Article 23

1.   Each Member State shall bear the costs of the installation, operation and maintenance of the access points of the decentralised IT system for which that Member State is responsible. 2.   Each Member State shall bear the costs of establishing and adjusting its relevant national IT systems to make them interoperable with the access points, and shall bear the costs of administering, operating and maintaining those systems. 3.   Union agencies and bodies shall bear the costs of the installation, operation and maintenance of the components comprising the decentralised IT system under their responsibility. 4.   Union agencies and bodies shall bear the costs of establishing and adjusting their case-management systems to make them interoperable with the access points, and shall bear the costs of administering, operating and maintaining those systems. 5.   Service providers shall bear all costs necessary in order for them to successfully integrate or otherwise interact with the decentralised IT system.

Transition period

Article 24

Before the obligation to carry out written communication through the decentralised IT system referred to in Article 19 becomes applicable (‘transition period’), the written communication between competent authorities and designated establishments or legal representatives under this Regulation shall take place by the most appropriate alternative means, taking into account the need to ensure a swift, secure and reliable exchange of information. Where service providers, Member States or Union agencies or bodies have established dedicated platforms or other secure channels for the handling of requests for data by law enforcement authorities and judicial authorities, issuing authorities may also choose to transmit an EPOC or an EPOC-PR via those channels to designated establishments or legal representatives during the transition period.

Implementing acts

Article 25

1.   The Commission shall adopt implementing acts necessary for the establishment and use of the decentralised IT system for the purposes of this Regulation, setting out the following: (a) the technical specifications defining the methods of communication by electronic means for the purposes of the decentralised IT system; (b) the technical specifications for communication protocols; (c) the information security objectives and relevant technical measures ensuring minimum information security standards and a high level of cybersecurity for the processing and communication of information within the decentralised IT system; (d) the minimum availability objectives and possible related technical requirements for the services provided by the decentralised IT system. 2.   The implementing acts referred to in paragraph 1 of this Article shall be adopted in accordance with the examination procedure referred to in Article 26. 3.   The implementing acts referred to in paragraph 1 shall be adopted by 18 August 2025.

Committee procedure

Article 26

1.   The Commission shall be assisted by a committee. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011. 2.   Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.

Back to Regulation (EU) 2023/1543 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next