My bookmarksSign up free

Regulation (EU) 2024/982 CHAPTER 6 — Data protection

Article 50–Article 61 · 12 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Purpose of the data processing

Article 50

1.   Processing of personal data received by a Member State or Europol shall be permitted solely for the purposes for which the data were supplied by the Member State which provided the data in accordance with this Regulation. Processing for other purposes shall be permitted solely with the prior authorisation of the Member State which provided the data. 2.   Processing of data supplied by a Member State or Europol pursuant to Article 6, 11, 16, 20 or 26 shall be permitted solely where necessary for the purpose of: (a) establishing whether the compared DNA profiles, dactyloscopic data, vehicle registration data, facial images or police records match; (b) exchanging a set of core data in accordance with Article 47; (c) preparing and submitting a police or judicial request for legal assistance where those data match; (d) keeping logs as provided for in Articles 18, 40 and 45. 3.   The data received by a Member State or Europol shall be deleted immediately following automated replies to searches unless further processing is necessary for the purposes referred to in paragraph 2 or is authorised in accordance with paragraph 1. 4.   Prior to connecting their national databases to the router or EPRIS, Member States shall conduct a data protection impact assessment as referred to in Article 27 of Directive (EU) 2016/680 and, where appropriate, consult the supervisory authority as provided for in Article 28 of that Directive. The supervisory authority may use any of the powers it has under Article 47 of that Directive, in accordance with Article 28(5) of that Directive.

Accuracy, relevance and data retention

Article 51

1.   Member States and Europol shall ensure the accuracy and relevance of personal data which are processed pursuant to this Regulation. Where a Member State or Europol become aware that data which are incorrect or no longer up to date or data which should not have been supplied have been supplied, it shall notify the Member State which received the data or Europol of that fact without undue delay. All Member States concerned or Europol shall correct or delete the data accordingly without undue delay. Where the Member State which received the data or Europol has reason to believe that the data supplied are incorrect or should be deleted, it shall inform the Member State which provided the data without undue delay. 2.   Member States and Europol shall put in place appropriate measures for updating data relevant for the purposes of this Regulation. 3.   Where a data subject contests the accuracy of data in the possession of a Member State or Europol, where the accuracy cannot be reliably established by the Member State concerned or Europol and where requested by the data subject, the data concerned shall be marked with a flag. Where such a flag exists, Member States or Europol may remove it only with the permission of the data subject or based on a decision of the competent court, of the supervisory authority or of the European Data Protection Supervisor, as relevant. 4.   Data which should not have been supplied or received shall be deleted. Data which are lawfully supplied and received shall be deleted: (a) where they are not or no longer necessary for the purpose for which they were supplied; (b) upon the expiry of the maximum period for keeping data laid down by the national law of the Member State which provided the data where that Member State informed the Member State which received the data or Europol of that maximum period at the time of supplying the data; or (c) upon the expiry of the maximum period for keeping data laid down in Regulation (EU) 2016/794. Where there is reason to believe that the deletion of data would prejudice the interests of the data subject, the processing of those data shall be restricted instead of being deleted. Where the processing of data has been restricted, they shall be processed solely for the purpose which prevented their deletion.

Data processor

Article 52

1.   eu-LISA shall be the processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the processing of personal data via the router. 2.   Europol shall be the processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the processing of personal data via EPRIS.

Security of processing

Article 53

1.   The Member States’ competent authorities, eu-LISA and Europol shall ensure the security of the processing of personal data under this Regulation. The Member States’ competent authorities, eu-LISA and Europol shall cooperate on security-related tasks. 2.   Without prejudice to Article 33 of Regulation (EU) 2018/1725 and Article 32 of Regulation (EU) 2016/794, eu-LISA and Europol shall take the necessary measures to ensure the security of the router and EPRIS, respectively, and of their related communication infrastructure. 3.   eu-LISA shall adopt the necessary measures concerning the router, and Europol shall adopt the necessary measures concerning EPRIS, in order to: (a) physically protect data, including by making contingency plans for the protection of critical infrastructure; (b) deny unauthorised persons access to data-processing equipment and installations; (c) prevent the unauthorised reading, copying, modification or removal of data media; (d) prevent the unauthorised input of data and the unauthorised inspection, modification or deletion of recorded personal data; (e) prevent the unauthorised processing of data and any unauthorised copying, modification or deletion of data; (f) prevent the use of automated data-processing systems by unauthorised persons using data communication equipment; (g) ensure, by means of individual user identities and confidential access modes only, that persons authorised to access the router or EPRIS, as applicable, have access only to the data covered by their access authorisation; (h) ensure that it is possible to verify and establish to which bodies personal data can be supplied using data communication equipment; (i) ensure that it is possible to verify and establish which data have been processed in the router or EPRIS, as applicable, and when, by whom and for what purpose they have been processed; (j) prevent the unauthorised reading, copying, modification or deletion of personal data during the transmission of personal data to or from the router or EPRIS, as applicable, or during the transport of data media, in particular by means of appropriate encryption techniques; (k) ensure that, in the event of interruption, installed systems can be restored to normal operation; (l) ensure reliability by making sure that any faults in the functioning of the router or EPRIS, as applicable, are properly reported; (m) monitor the effectiveness of the security measures referred to in this paragraph and take the necessary organisational measures related to internal monitoring to ensure compliance with this Regulation and to assess those security measures in the light of new technological developments. The necessary measures referred to in the first subparagraph shall include a security plan, a business continuity plan and a disaster recovery plan.

Security incidents

Article 54

1.   Any event that has or may have an impact on the security of the router or EPRIS and may cause damage to or loss of data stored in the router or EPRIS shall be considered to be a security incident, in particular where unauthorised access to data may have occurred or where the availability, integrity and confidentiality of data has or may have been compromised. 2.   In the event of a security incident concerning the router, eu-LISA and the Member States concerned or, where applicable, Europol shall cooperate with one another in order to ensure a swift, effective and proper response. 3.   In the event of a security incident concerning EPRIS, the Member States concerned and Europol shall cooperate with one another in order to ensure a swift, effective and proper response. 4.   Member States shall notify their competent authorities of any security incidents without undue delay. Without prejudice to Article 92 of Regulation (EU) 2018/1725, in the event of a security incident in relation to the central infrastructure of the router, eu-LISA shall notify the Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU) of significant cyber threats, significant vulnerabilities and significant incidents without undue delay and, in any event, no later than 24 hours after becoming aware of them. Actionable and appropriate technical details of cyber threats, vulnerabilities and incidents that enable proactive detection, incident response or mitigating measures shall be disclosed to CERT-EU without undue delay. Without prejudice to Article 34 of Regulation (EU) 2016/794 and Article 92 of Regulation (EU) 2018/1725, in the event of a security incident in relation to the EPRIS central infrastructure, Europol shall notify CERT-EU of significant cyber threats, significant vulnerabilities and significant incidents without undue delay and, in any event, no later than 24 hours after becoming aware of them. Actionable and appropriate technical details of cyber threats, vulnerabilities and incidents that enable proactive detection, incident response or mitigating measures shall be disclosed to CERT-EU without undue delay. 5.   Information regarding a security incident that has or may have an impact on the operation of the router or on the availability, integrity and confidentiality of the data shall be provided by the Member States and Union agencies concerned to the Member States and Europol without delay and reported in compliance with the incident management plan to be provided by eu-LISA. 6.   Information regarding a security incident that has or may have an impact on the operation of EPRIS or on the availability, integrity and confidentiality of the data shall be provided by the Member States and Union agencies concerned to the Member States without delay and reported in compliance with the incident management plan to be provided by Europol.

Self-monitoring

Article 55

1.   Member States shall ensure that each authority entitled to use the Prüm II framework takes the measures necessary to monitor its compliance with this Regulation and cooperates, where necessary, with the supervisory authority. Europol shall take the measures necessary to monitor its compliance with this Regulation and shall cooperate, where necessary, with the European Data Protection Supervisor. 2.   Data controllers shall implement the necessary measures to effectively monitor the compliance of data processing with this Regulation, including by frequently verifying the logs referred to in Articles 18, 40 and 45. They shall cooperate, where necessary and as appropriate, with the supervisory authorities or with the European Data Protection Supervisor.

Penalties

Article 56

Member States shall ensure that any misuse of data, processing of data or exchange of data contrary to this Regulation is punishable in accordance with national law. The penalties provided shall be effective, proportionate and dissuasive.

Liability

Article 57

If any failure of a Member State or, when performing queries in accordance with Article 49, Europol to comply with its obligations under this Regulation causes damage to the router or EPRIS, that Member State or Europol shall be liable for such damage, unless and in so far as eu-LISA, Europol or another Member State bound by this Regulation failed to take reasonable measures to prevent the damage from occurring or to minimise its impact.

Audits by the European Data Protection Supervisor

Article 58

1.   The European Data Protection Supervisor shall ensure that an audit of personal data processing operations by eu-LISA and Europol for the purposes of this Regulation is carried out in accordance with relevant international auditing standards at least every four years. A report of that audit shall be sent to the European Parliament, to the Council, to the Commission, to the Member States and to the Union agency concerned. eu-LISA and Europol shall be given an opportunity to make comments before the reports are adopted. 2.   eu-LISA and Europol shall supply information requested by the European Data Protection Supervisor to it, grant the European Data Protection Supervisor access to all the documents it requests and to their logs referred to in Articles 40 and 45 and allow the European Data Protection Supervisor access to all their premises at any time. This paragraph is without prejudice to the powers of the European Data Protection Supervisor under Article 58 of Regulation (EU) 2018/1725 and, with regard to Europol, under Article 43(3) of Regulation (EU) 2016/794.

Cooperation between supervisory authorities and the European Data Protection Supervisor

Article 59

1.   The supervisory authorities and the European Data Protection Supervisor shall, each acting within the scope of their respective competences, cooperate actively within the framework of their respective responsibilities to ensure a coordinated supervision of the application of this Regulation, in particular if the European Data Protection Supervisor or a supervisory authority finds major discrepancies between practices of Member States or finds potentially unlawful transfers using the communication channels of the Prüm II framework. 2.   In the cases referred to in paragraph 1 of this Article, coordinated supervision shall be ensured in accordance with Article 62 of Regulation (EU) 2018/1725. 3.   Two years after the start of operations of the router and EPRIS and every two years thereafter, the European Data Protection Board shall send a report of its activities under this Article to the European Parliament, to the Council, to the Commission, to eu-LISA and to Europol. That report shall include a chapter on each Member State prepared by the supervisory authority of the Member State concerned.

Transfer of personal data to third countries and international organisations

Article 60

A Member State shall only transfer personal data obtained under this Regulation to a third country or an international organisation in accordance with Chapter V of Directive (EU) 2016/680 and where the requested Member State has granted its authorisation prior to the transfer. Europol shall only transfer personal data obtained under this Regulation to a third country or an international organisation where the conditions laid down in Article 25 of Regulation (EU) 2016/794 have been fulfilled and where the requested Member State has granted its authorisation prior to the transfer.

Relation to other legal acts on data protection

Article 61

Any processing of personal data for the purposes of this Regulation shall be carried out in accordance with this Chapter and with Directive (EU) 2016/680 or Regulation (EU) 2018/1725, (EU) No 2016/794 or (EU) 2016/679, as applicable.

Back to Regulation (EU) 2024/982 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next