My bookmarksSign up free

Regulation (EU) 2024/982 CHAPTER 3 — Architecture

Article 35–Article 46 · 12 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Section 1 — Router

Router

Article 35

1.   A router is established for the purpose of facilitating the establishment of connections between Member States, and between Member States and Europol, for querying with, retrieving and scoring biometric data and for retrieving alphanumeric data in accordance with this Regulation. 2.   The router shall be composed of: (a) a central infrastructure, including a search tool enabling the simultaneous querying of the national databases referred to in Articles 5, 10 and 19 and of Europol data; (b) a secure communication channel between the central infrastructure, the competent authorities authorised to use the router pursuant to Article 36 and Europol; (c) a secure communication infrastructure between the central infrastructure and the European Search Portal, established by Article 6 of Regulation (EU) 2019/817 and Article 6 of Regulation (EU) 2019/818, for the purposes of Article 39.

Use of the router

Article 36

The use of the router shall be reserved to the Member States’ competent authorities that are authorised to access and exchange DNA profiles, dactyloscopic data and facial images in accordance with this Regulation and to Europol in accordance with this Regulation and Regulation (EU) 2016/794.

Processes

Article 37

1.   The competent authorities authorised to use the router pursuant to Article 36 or Europol shall request a query by submitting biometric data to the router. The router shall dispatch the request for a query to databases of all or specific Member States and Europol data simultaneously with the data submitted by the user in accordance with his or her access rights. 2.   Upon receipt of a request for a query from the router, each requested Member State shall launch a query of their databases in an automated manner and without delay. Upon receipt of a request for a query from the router, Europol shall launch a query of Europol data in an automated manner and without delay. 3.   Any matches resulting from queries as referred to in paragraph 2 shall be sent back in an automated manner to the router. The requesting Member State shall be notified in an automated manner where there is no match. 4.   The router shall rank, where the requesting Member State so decides and where applicable, the replies by comparing the biometric data used for querying and the biometric data supplied in the replies from the requested Member State or Member States or Europol. 5.   The router shall return the list of matching biometric data and their ranking to the router user. 6.   The Commission shall adopt implementing acts specifying the technical procedure for the router to query Member States’ databases and Europol data, the format in which the router answers such queries and the technical rules for comparing and ranking the correspondence between biometric data. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 77(2).

Quality check

Article 38

The requested Member State shall check the quality of the transmitted data by means of an automated procedure. The requested Member State shall, without delay, inform the requesting Member State via the router where the data are unsuitable for automated comparison.

Interoperability between the router and the Common Identity Repository for the purposes of law enforcement access

Article 39

1.   Where designated authorities as defined in Article 4, point (20), of Regulation (EU) 2019/817 and Article 4, point (20), of Regulation (EU) 2019/818 are authorised to use the router pursuant to Article 36 of this Regulation, they may launch a query to Member States’ databases and Europol data simultaneously with a query to the Common Identity Repository, established by Article 17 of Regulation (EU) 2019/817 and Article 17 of Regulation (EU) 2019/818, provided that the relevant conditions under Union law have been fulfilled and that the query is launched in accordance with their access rights. For that purpose, the router shall query the Common Identity Repository via the European Search Portal. 2.   Queries to the Common Identity Repository for law enforcement purposes shall be carried out in accordance with Article 22 of Regulation (EU) 2019/817 and Article 22 of Regulation (EU) 2019/818. Any result from such queries shall be transmitted via the European Search Portal. Simultaneous queries of the Member States’ databases and Europol data and the Common Identity Repository shall be launched only where there are reasonable grounds to believe that data on a suspect, perpetrator or victim of a terrorist offence or other serious criminal offence as defined in Article 4, points (21) and (22), respectively, of Regulation (EU) 2019/817 and Article 4, points (21) and (22), respectively, of Regulation (EU) 2019/818 are stored in the Common Identity Repository.

Keeping of logs

Article 40

1.   eu-LISA shall keep logs of all data processing operations in the router. Those logs shall include the following: (a) whether it was a Member State or Europol that launched the request for a query; where it was a Member State that launched the request for a query, the Member State in question; (b) the date and time of the request; (c) the date and time of the reply; (d) the national databases or Europol data to which a request for a query was sent; (e) the national databases or Europol data that provided a reply; (f) where applicable, the fact that there was a simultaneous query to the Common Identity Repository. 2.   Each Member State shall keep logs of queries that the staff of its competent authorities duly authorised to use the router make and logs of queries requested by other Member States. Europol shall keep logs of queries that its duly authorised staff make. 3.   The logs referred to in paragraphs 1 and 2 shall be used only for the collection of statistics, for data protection monitoring, including checking the admissibility of a query and the lawfulness of data processing, and for ensuring data security and integrity. Those logs shall be protected by appropriate measures against unauthorised access and erased three years after their creation. If, however, they are required for monitoring procedures that have already begun, they shall be erased once the monitoring procedures no longer require the logs. 4.   For the purposes of data protection monitoring, including checking the admissibility of a query and the lawfulness of data processing, the data controllers shall have access to the logs for self-monitoring as referred to in Article 55.

Notification procedures where it is technically impossible to use the router

Article 41

1.   Where it is technically impossible to use the router to query one or several national databases or Europol data because of a failure of the router, eu-LISA shall notify the router users referred to Article 36 in an automated manner. eu-LISA shall take appropriate measures to address the technical impossibility to use the router without delay. 2.   Where it is technically impossible to use the router to query one or several national databases because of a failure of the national infrastructure in a Member State, that Member State shall notify the other Member States, the Commission, eu-LISA and Europol in an automated manner. The Member State concerned shall take appropriate measures to address the technical impossibility to use the router without delay. 3.   Where it is technically impossible to use the router to query Europol data because of a failure of Europol’s infrastructure, Europol shall notify the Member States, the Commission and eu-LISA in an automated manner. Europol shall take appropriate measures to address the technical impossibility to use the router without delay.

Section 2 — EPRIS

EPRIS

Article 42

1.   The European Police Record Index System (EPRIS) is hereby established. For the automated searching of national police record indexes referred to in Article 26, Member States and Europol shall use EPRIS. 2.   EPRIS shall be composed of: (a) a decentralised infrastructure in the Member States, including a search tool enabling the simultaneous querying of national police record indexes, based on national databases; (b) a central infrastructure, supporting the search tool, enabling the simultaneous querying of national police record indexes; (c) a secure communication channel between the central infrastructure, Member States and Europol.

Use of EPRIS

Article 43

1.   For the purpose of searching national police record indexes via EPRIS, at least two of the following sets of data shall be used: (a) first name or names; (b) family name or names; (c) date of birth. 2.   Where available, the following sets of data may also be used: (a) alias or aliases and previously used name or names; (b) nationality or nationalities; (c) country of birth; (d) gender. 3.   The data referred to in paragraph 1, points (a) and (b), and paragraph 2, point (a), shall be pseudonymised.

Processes

Article 44

1.   Where a Member State or Europol requests a query, it shall submit the data referred to in Article 43. EPRIS shall dispatch the request for a query to the Member States’ national police record indexes with the data submitted by the requesting Member State or Europol and in accordance with this Regulation. 2.   Upon receipt of a request for a query from EPRIS, each requested Member State shall launch a query of their national police record index in an automated manner and without delay. 3.   Any matches resulting from queries as referred to in paragraph 1 in each requested Member State’s police records indexes shall be sent back in an automated manner to EPRIS. 4.   The list of matches shall be returned to the requesting Member State or Europol by EPRIS in an automated manner. The list of matches shall indicate the quality of the match and the Member State or Member States whose police record indexes contain data that resulted in the match or matches. 5.   Upon receipt of the list of matches, the requesting Member State shall decide the matches for which a follow-up is necessary and send a reasoned follow-up request containing the data referred to in Articles 25 and 27 and any additional relevant information to the requested Member State or Member States via SIENA. The requested Member State or Member States shall process such requests without delay in order to decide whether to share the data stored in its or their database. 6.   The Commission shall adopt implementing acts specifying the technical procedure for EPRIS to query Member States’ police record indexes and the format and maximum number of replies. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 77(2).

Keeping of logs

Article 45

1.   Each participating Member State and Europol shall keep logs of all data processing operations in EPRIS. Those logs shall include the following: (a) whether it was a Member State or Europol that launched the request for a query; where it was a Member State that launched the request for a query, the Member State in question; (b) the date and time of the request; (c) the date and time of the reply; (d) the national databases to which a request for a query was sent; (e) the national databases that provided a reply. 2.   Each participating Member State shall keep logs of the requests for queries that the staff of its competent authorities duly authorised to use EPRIS make. Europol shall keep logs of requests for queries that its duly authorised staff make. 3.   The logs referred to in paragraphs 1 and 2 shall be used only for the collection of statistics, for data protection monitoring, including checking the admissibility of a query and the lawfulness of data processing, and for ensuring data security and integrity. Those logs shall be protected by appropriate measures against unauthorised access and shall be erased three years after their creation. If, however, they are required for monitoring procedures that have already begun, they shall be erased once the monitoring procedures no longer require the logs. 4.   For the purposes of data protection monitoring, including checking the admissibility of a query and the lawfulness of data processing, the data controllers shall have access to the logs for self-monitoring as referred to in Article 55.

Notification procedures where it is technically impossible to use EPRIS

Article 46

1.   Where it is technically impossible to use EPRIS to query one or several national police record indexes because of a failure of Europol’s infrastructure, Europol shall notify Member States in an automated manner. Europol shall take measures to address the technical impossibility of using EPRIS without delay. 2.   Where it is technically impossible to use EPRIS to query one or several national police record indexes because of a failure of the national infrastructure in a Member State, that Member State shall notify the other Member States, the Commission and Europol in an automated manner. Member States shall take measures to address the technical impossibility of using EPRIS without delay.

Back to Regulation (EU) 2024/982 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next