My bookmarksSign up free

Commission Implementing Regulation (EU) 2023/2117 CHAPTER III — RULES ON THE INFORMATION STORED IN THE REPOSITORY

Article 6–Article 11 · 6 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Formats and standards of the information

Article 6

1.   The authorised users shall transmit, regularly update and exchange information through the repository based on commonly agreed information formats proposed by the Agency. 2.   The information formats shall be standardised per information category. The authorised users shall only transmit information objects to the repository in the information format specific to that information category. 3.   The list of the information objects categories is laid down in Annex I.

Classification of information

Article 7

1.   The Agency, in cooperation with the Commission and the national competent authorities, shall classify the information object categories according to the following markings: (a) privacy: non personal data, non-sensitive or sensitive personal data; (b) confidentiality: no impact, limited, significant, catastrophic; (c) integrity: no impact, limited, significant, catastrophic; (d) availability: no impact, limited, significant, catastrophic. 2.   The detailed definitions of the markings referred to in paragraph 1 are laid down in Annex II. 3.   The Agency, in cooperation with the Commission and the national competent authorities, shall, whenever it deems necessary, re-evaluate the classification of information to ensure that it is still appropriate based on the changes in the use of information.

Arrangements for the dissemination of information

Article 8

1.   The Agency may, upon request of an interested party, provide such interested party with the information contained in the repository subject to the specific conditions of use set out in this Article. 2.   A request for a dissemination of information contained in the repository shall be submitted in a form and manner established by the Agency. 3.   When receiving a request, the Agency shall verify that: (a) the request is made by an interested party; and (b) the interested party demonstrates that the requested information is strictly necessary to the interested party’s own operations. 4.   The Agency shall evaluate whether the request is justified and if the conditions laid down in paragraph 5 are met, it shall provide the interested party with the information requested. 5.   The Agency shall provide the requested information to the interested party only under the following conditions: (a) the interested party does not receive access to the entire content of the repository; (b) the information is strictly necessary for the interested party’s own operations; (c) no personal data is disseminated unless such data concerns the interested party itself or if such dissemination is strictly necessary to perform the operations of the interested party. 6.   The Agency shall make available to the authorised users an updated list of requests received and action taken by the Agency. 7.   The interested party shall: (a) use the information only for the purpose specified in the request form; (b) not disclose the information received without the authorisation of the authorised users; (c) take the necessary measures to ensure the confidentiality of the information received.

Logging of data-processing operations

Article 9

1.   The Agency shall ensure that all data-processing operations are logged. The logs shall provide the following information: (a) the purpose of the request for access to the repository; (b) the identification of the authorised user that retrieves the data; (c) the date and exact time of the data-processing operations; (d) the identification of the authorised staff that carry out the search. 2.   The Agency shall use the logs of the data-processing operations only for the monitoring of the lawfulness of the access to the information and for ensuring data integrity and security. The logs shall contain the data that is strictly necessary for that purpose, complying with the principle of data minimisation as laid down in Article 89 of Regulation (EU) 2016/679 and in Article 13 of Regulation (EU) 2018/1725. Logs shall be erased after the end of the monitoring procedure or at the latest after one year. 3.   Upon request, the Commission and the national competent authorities shall be granted access to the logs for the purpose of assessing the lawfulness of the access to the information, monitoring the lawfulness of the data-processing operations and for ensuring data integrity and security.

Access to the repository

Article 10

1.   The authorised users shall ensure that only authorised staff have access to the repository. 2.   The authorised users shall ensure that its staff receives access to the information on the basis of the privacy and confidentiality markings of the information object category in accordance with Article 7. 3.   The authorised users shall establish and maintain: (a) a list of authorised staff; (b) procedures regarding access to the repository; such procedures shall comply with the legal requirements applied to the access and processing of information laid down in Union and national law. They shall document the terms and conditions for authorised staff to access the repository. 4.   The national aeromedical examiners and aeromedical centres shall ensure that only staff authorised by their national competent authority have access to the repository.

Security management of the repository

Article 11

1.   The Agency shall protect the infrastructure of the repository and its information, and shall develop: (a) a security management plan; (b) a business continuity plan; (c) a disaster recovery plan. 2.   The Agency shall prevent the unauthorised processing of information and any unauthorised reading, copying, modification, removal or deletion of information contained in the repository or during the dissemination to or from the repository or during the transmission, in particular by means of appropriate encryption techniques. 3.   The Agency shall ensure that the persons authorised to access the repository have access only to the information covered by their access authorisation, by means of individual user identities and confidential access modes only. 4.   The authorised users shall manage the security of their information before and during the transmission to the repository and shall protect their infrastructure by ensuring: (a) the establishment of interfaces between their systems and the repository; (b) the operation and maintenance of the interfaces; (c) that authorised staff are properly trained in information security, applicable data protection legislation and fundamental rights before they are allowed to process information stored in the repository. 5.   The authorised users shall cooperate to ensure the security management of the repository.

Back to Commission Implementing Regulation (EU) 2023/2117 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next