Central system in scope
1. The CBAM Transitional Registry shall be interoperable with:
(a)
the Uniform User Management and Digital Signature (UUM&DS) system for the purposes of users registration and access management for the Commission, Member States, and reporting declarants, as referred to in Article 16 of Implementing Regulation (EU) 2023/1070;
(b)
the Economic Operator Registration and Identification (EORI) for the purpose of validating and retrieving the Economic Operator Identity Information, as referred to in Article 30 of Implementing Regulation (EU) 2023/1070, for the data laid out Annex V to this Regulation;
(c)
the Surveillance system for the purpose of retrieving information on Customs Imports Declarations for goods listed in Annex I to Regulation (EU) 2023/956 for checks of the CBAM reports and compliance, developed through the UCC Surveillance 3 (SURV3), as referred to in Article 99 of Implementing Regulation (EU) 2023/1070;
(d)
the TARIC System as referred to in Regulation (EEC) No 2658/87.
2. The CBAM Transitional Registry shall be interoperable with decentralised systems as developed or upgraded through the Implementing Decision (EU) 2019/2151, for the purpose of retrieving information on Customs Imports Declarations for goods listed in Annex I to Regulation (EU) 2023/956, as specified in Annex VI and Annex VII to this Regulation, and for checking the CBAM reports and ensuring compliance of the reporting declarants when that information is not available in the SURV3 system.
Contact points for the electronic systems
The Commission and Member States shall designate contact points for each of the electronic systems referred to in Article 17 of this Regulation, for the purposes of exchanging information to ensure a coordinated development, operation, and maintenance of those electronic systems.
The Commission and Member States shall communicate the details of these contact points to each other and inform each other immediately of any changes to those details.
SECTION 2 — CBAM Transitional Registry
Structure of the CBAM Transitional Registry
The CBAM Transitional Registry shall consist of the following common components (‘common components’):
(a)
the CBAM Trader Portal (CBAM TP);
(b)
the CBAM Competent Authorities Portal (CBAM CAP) with two segregated spaces:
(1)
one for the National Competent Authorities (CBAM CAP/N); and
(2)
another for the Commission (CBAM CAP/C);
(c)
the CBAM User Access Management;
(d)
the CBAM Registry Back End Services (CBAM BE);
(e)
the public CBAM page on the Europa website.
Terms of collaboration in the CBAM Transitional Registry
1. The Commission shall propose the Terms of Collaboration, Service Level Agreement, and security Plan, for agreement with the competent authorities. The Commission shall operate the CBAM Transitional Registry in compliance with the terms agreed.
2. The CBAM Transitional Registry shall be used with respect to the CBAM reports and to the Import Declarations Records to which these reports relate.
The CBAM User Access Management
1. The authentication and access verification of the reporting declarant for the goods listed in Annex I to Regulation (EU) 2023/956, for the purposes of access to the components of the CBAM Registry shall be done using the UUM&DS system as referred to in Article 17(1), point (a).
2. The Commission shall provide the authentication services allowing the users of the CBAM Transitional Registry to securely access that Registry.
3. The Commission shall use UUM&DS to grant the authorisation to access the CBAM Transitional Registry to its staff and to provide the delegations to the competent authorities to issue their authorisations.
4. The competent authorities shall use UUM&DS to grant the authorisation to access the CBAM Transitional Registry to their staff and to the reporting declarants established in their Member State.
5. A competent authority may opt to use an identity and access management system set up in their Member State pursuant to Article 26 of this Regulation (national Customs eIDAS system) to provide the necessary credentials to access the CBAM Transitional Registry.
CBAM Trader Portal
1. The CBAM Trader Portal shall be the unique entry point to the CBAM Transitional Registry for the reporting declarants. The portal shall be accessible from the internet.
2. The CBAM Trader Portal shall interoperate with the CBAM Registry Back End services.
3. The CBAM Trader Portal shall be used by the reporting declarant for:
(a)
the submission of the CBAM reports via a web interface or a System-to-System interface; and
(b)
receiving notifications related to their CBAM compliance obligations.
4. The CBAM Trader Portal shall offer facilities for the reporting declarants to store the information about third countries installations and embedded emissions for their later re-use.
5. The access to the CBAM Trader Portal shall be exclusively managed by the CBAM Access Management referred to in Article 26.
CBAM Competent Authorities Portal (CBAM CAP) for the CBAM National Competent Authorities (CBAM CAP/N)
1. The CBAM Competent Authorities Portal for the National Competent Authorities shall be the unique entry point to the CBAM Transitional Registry for the competent authorities. The portal shall be accessible from the internet.
2. The CBAM Competent Authorities Portal for the National Competent authorities shall interoperate with the CBAM Registry Back End services via the internal network of the Commission.
3. The CBAM Competent Authorities Portal for the National Competent Authorities shall be used by the competent authorities to carry out the tasks laid down in this Regulation and in Regulation (EU) 2023/956.
4. The access to the CBAM Competent Authorities Portal for the National Competent Authorities shall be exclusively managed by the CBAM Access Management referred to in Article 26.
CBAM Competent Authorities Portal (CBAM CAP) for the Commission (CBAM CAP/C)
1. The CBAM Competent Authorities Portal for the Commission shall be the unique entry point to the CBAM Transitional Registry for the Commission. The portal shall be accessible on the Commission internal network and the internet.
2. The CBAM Competent Authorities Portal for the Commission shall interoperate with the CBAM Registry Back End services over the internal network of the Commission.
3. The CBAM Competent Authorities Portal for the Commission shall be used by the Commission to perform the tasks laid down in this Regulation and in Regulation (EU) 2023/956.
4. The access to the CBAM Competent Authorities Portal for the Commission shall be exclusively managed by the CBAM Access Management referred to in Article 26.
The CBAM Registry Back End Services (CBAM BE)
1. The CBAM Registry Back End Services shall serve all requests placed by:
(a)
the reporting declarants via the CBAM Trader Portal;
(b)
the competent authorities via the CBAM Competent Authority Portal/N;
(c)
the Commission via the CBAM Competent Authority Portal/C.
2. The CBAM Registry Back End Services shall store centrally and manage all the information entrusted to the CBAM Transitional Registry. It shall guarantee their persistence, integrity, and coherence of that information.
3. The CBAM Registry Back End Services shall be managed by the Commission.
4. The access to the CBAM Registry Back End Services shall be exclusively managed by the CBAM Access Management referred to in Article 26.
Access management system
The Commission shall set up the access management system to validate the access requests submitted by reporting declarants and other persons within the UUM&DS system as referred to in Article 17(1), point (a) by connecting the Member States’ identity and the EU identity and access management systems pursuant to Article 27.
Administration management system
The Commission shall set up the administration management system to manage the authentication and authorisation, the identification data of reporting declarants and other persons for the purposes of allowing access to the electronic systems.
Member States’ identity and access management systems
The Member States shall set up or use existing an identity and access management systems to ensure:
(a)
a secure registration and storage of identification data of reporting declarants and other persons;
(b)
a secure exchange of signed and encrypted identification data of reporting declarants and other persons.
SECTION 3 — Functioning of the electronic systems and training in the use thereof
Development, testing, deployment, and management of the electronic systems
1. The CBAM Transitional Registry common components shall be developed, tested, deployed, and managed by the Commission, and may be tested by the Member States. The competent authority of the Member State of establishment of the reporting declarant shall communicate the decisions on penalties with the respective outcome of that process to the Commission, by electronic systems developed at national level, linked to enforcement and penalties, or by other means.
2. The Commission shall design and maintain the common specifications of the interfaces with components of electronic systems developed at national level in close cooperation with the Member States.
3. Where appropriate, common technical specifications shall be defined by the Commission in close cooperation with, and subject to review by the Member States, with a view to deploying them in due time. The Member States and, where appropriate, the Commission shall engage in the development and deployment of the systems. The Commission and the Member States shall also collaborate with reporting declarants and other stakeholders.
Maintenance and changes to the electronic systems
1. The Commission shall perform the maintenance of the common components and the Member States shall perform the maintenance of their national components.
2. The Commission shall ensure uninterrupted operation of the electronic systems.
3. The Commission may change the common components of the electronic systems to correct malfunctions, to add new functionalities or to alter existing ones.
4. The Commission shall inform the Member States of changes and updates to the common components.
5. The Commission shall make the information on the changes and updates to the electronic systems set out in paragraphs 3 and 4 publicly available.
Temporary failure of the electronic systems
1. In the event of a temporary failure of the CBAM Transitional Registry, reporting declarants and other persons shall submit the information required to fulfil the required formalities by the means determined by the Commission, including by means other than electronic data-processing techniques.
2. The Commission shall inform Member States and reporting declarants about any unavailability of the electronic systems resulting from a temporary failure.
3. The Commission shall prepare a CBAM business continuity plan to be agreed between the Member States and the Commission. In case of temporary failure of the CBAM Transitional Registry, the Commission shall evaluate the conditions to activate it.
Training support on the use and functioning of the common components
The Commission shall support the Member States on the use and functioning of the common components of the electronic systems by providing the appropriate training material.
SECTION 4 — Data protection, data management and the ownership and security of the electronic systems
Personal data protection
1. The personal data registered in the CBAM Transitional Registry, and the components of electronic systems developed at national level shall be processed for the purposes of implementing the Regulation (EU) 2023/956 having regard to the specific objectives of those databases as set out in this Regulation. The purposes for which the personal data could be processed shall be the following:
(a)
authentication purposes and access management;
(b)
monitoring, checks and review of CBAM reports;
(c)
communication and notifications;
(d)
compliance and judicial proceedings;
(e)
functioning of the IT infrastructure, including interoperability with decentralised systems under this Regulation;
(f)
statistics and review of the functioning of Regulation (EU) 2023/956 and this Regulation.
2. The Member States’ national supervisory authorities in the field of personal data protection and the European Data Protection Supervisor shall cooperate, in accordance with Article 62 of Regulation (EU) 2018/1725, to ensure coordinated supervision of the processing of personal data registered in the CBAM Transitional Registry and the components of electronic systems developed at national level.
3. The provisions contained in this Article shall be without prejudice to the right to rectification of personal data in accordance with Article 16 of Regulation (EU) 2016/679.
Limitation of data access and data processing
1. The data registered in the CBAM Transitional Registry by a reporting declarant may be accessed or otherwise processed by that reporting declarant. It may also be accessed and otherwise processed by the Commission and competent authorities.
2. Where incidents and problems in the operational processes are identified in the provision of the services of the systems where the Commission act as a processor, the Commission may have access to the data in these processes only for the purpose of resolving a registered incident or problem. The Commission shall ensure the confidentiality of such data.
System ownership
The Commission shall be the system owner of the CBAM Transitional Registry.
System security
1. The Commission shall ensure the security of the CBAM Transitional Registry.
2. For those purposes, the Commission and Member States shall take the necessary measures to:
(a)
prevent any unauthorised person from having access to installations used for the processing of data;
(b)
prevent the entry of data and any consultation, modification, or deletion of data by unauthorised persons;
(c)
detect any of the activities referred to in points (a) and (b).
3. The Commission and the Member States shall inform each other of any activities that might result in a breach or a suspected breach of the security of the CBAM Transitional Registry.
4. The Commission and the Member States shall establish security plans concerning the CBAM Transitional Registry.
Controller for the CBAM Transitional Registry
For the CBAM Transitional Registry and in relation to the processing of personal data, the Commission and Member States shall act as joint controllers as defined in Article 4, point (7), of Regulation (EU) 2016/679 and as defined in Article 3, point (8) of Regulation (EU) 2018/1725.
Data retention period
1. In order to achieve the objectives pursued under this Regulation and Regulation (EU) 2023/956, in particular Article 30 thereof, the data retention period for the data in the CBAM Transitional Registry shall be limited to 5 years from the reception of the CBAM report.
2. Notwithstanding paragraph 1, where an appeal has been lodged or where court proceedings have begun involving data stored in the CBAM Transitional Registry, those data shall be retained until the appeal procedure or court proceedings are terminated and shall only be used for the purpose of the aforementioned appeal procedure or court proceedings.
Assessment of the electronic systems
The Commission and the Member States shall conduct assessments of the components they are responsible for and shall, in particular, analyse the security and integrity of those components and the confidentiality of the data processed within those components.
The Commission and the Member States shall inform each other of the results of those assessments.
Entry into force
This Regulation shall enter into force on the day following that of its publication in the Official Journal of the European Union .
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.