Responsibility for data processing
1. The Member State of origin shall be responsible for ensuring that:
(a)
biometric data and the other data referred to in Article 17(1) and (2), Article 19(1), Article 21(1), Article 22(2) and (3), Article 23(2) and (3), Article 24(2) and (3) and Article 26(2) are taken lawfully and are lawfully transmitted to Eurodac;
(b)
data are accurate and up to date when they are transmitted to Eurodac;
(c)
without prejudice to the responsibilities of eu-LISA, data in Eurodac are lawfully recorded, stored, rectified and erased;
(d)
the results of biometric data comparisons transmitted by Eurodac are lawfully processed.
2. The Member State of origin shall ensure the security of the data referred to in paragraph 1 of this Article before and during transmission to Eurodac, as provided for in Article 48, and the security of the data it receives from Eurodac.
3. The Member State of origin shall be responsible for the final identification of the data pursuant to Article 38(4).
4. eu-LISA shall ensure that Eurodac is operated, including for testing purposes, in accordance with this Regulation and relevant Union data protection rules. In particular, eu-LISA shall:
(a)
adopt measures ensuring that all persons, including contractors, working with Eurodac process the data recorded therein only in accordance with the purposes of Eurodac laid down in Article 1;
(b)
take the necessary measures to ensure the security of Eurodac in accordance with Article 48;
(c)
ensure that only persons authorised to work with Eurodac have access thereto, without prejudice to the competences of the European Data Protection Supervisor.
eu-LISA shall inform the European Parliament, the Council and the European Data Protection Supervisor of the measures it takes pursuant to the first subparagraph of this paragraph.
Transmission
1. Biometric data and other personal data shall be digitally processed and transmitted in the data format as set out in the agreed Interface Control Document. As far as necessary for the efficient operation of Eurodac, eu-LISA shall establish the technical requirements concerning the data format to be used for the transmission of data by Member States to Eurodac and vice versa. eu-LISA shall ensure that the biometric data transmitted by the Member States can be compared by the computerised fingerprint and facial recognition system.
2. Member States shall transmit the data referred to in Article 17(1) and (2), Article 19(1), Article 21(1), Article 22(2) and (3), Article 23(2) and (3), Article 24(2) and (3) and Article 26(2) electronically. The data referred to in Article 17(1) and (2), Article 19(1), Article 21(1), Article 22(2) and (3), Article 23(2) and (3), Article 24(2) and (3) and Article 26(2) shall be automatically recorded in Eurodac. As far as necessary for the efficient operation of Eurodac, eu-LISA shall establish the technical requirements to ensure that data can be properly electronically transmitted from the Member States to Eurodac and vice versa.
3. Member States shall ensure that the reference number referred to in Article 17(1), point (k), Article 19(1), point (k), Article 21(1), point (k), Article 22(2), point (k), Article 23(2), point (k), Article 24(2), point (k), Article 26(2), point (k), and Article 32(1) makes it possible to relate data unambiguously to a particular person and to the Member State which is transmitting the data and also makes it possible to indicate whether such data relate to a person as referred to in Article 15(1), Article 18(2), Article 20(1), Article 22(1), Article 23(1), Article 24(1) or Article 26(1).
4. The reference number referred to in paragraph 3 of this Article shall begin with the identification letter or letters by which the Member State transmitting the data is identified. The identification letter or letters shall be followed by the identification of the category of person or request. ‘1’ refers to persons as referred to in Article 15(1), ‘2’ to persons as referred to in Article 22(1), ‘3’ to persons as referred to in Article 23(1), ‘4’ to requests as referred to in Article 33, ‘5’ to requests as referred to in Article 34, ‘6’ to requests as referred to in Article 43, ‘7’ to requests as referred to in Article 18, ‘8’ to persons as referred to in Article 20, ‘9’ to persons as referred to in Article 24(1) and ‘0’ to persons as referred to in Article 26(1).
5. eu-LISA shall establish the technical procedures necessary for Member States to ensure receipt of unambiguous data by Eurodac.
6. Eurodac shall confirm receipt of the transmitted data as soon as possible. To that end, eu-LISA shall establish the necessary technical requirements to ensure that Member States receive the confirmation receipt if requested.
Carrying out comparisons and transmitting results
1. Member States shall ensure the transmission of biometric data of an appropriate quality for the purposes of comparison by means of the computerised fingerprint and facial recognition system. As far as is necessary to ensure that the results of the comparison by Eurodac reach a very high level of accuracy, eu-LISA shall establish the appropriate quality of transmitted biometric data. Eurodac shall, as soon as possible, check the quality of the biometric data transmitted. If the biometric data do not lend themselves to comparison using the computerised fingerprint and facial recognition system, Eurodac shall inform the Member State concerned. That Member State shall then transmit biometric data of the appropriate quality using the same reference number as the previous set of biometric data.
2. Eurodac shall carry out comparisons in the order of arrival of requests. Each request shall be handled within 24 hours of its arrival. A Member State may, for reasons connected with national law, require particularly urgent comparisons to be carried out within one hour. Where such time limits cannot be respected due to circumstances which are outside the eu-LISA’s responsibility, Eurodac shall process the request as a matter of priority as soon as those circumstances no longer prevail. In such cases, as far as is necessary for the efficient operation of Eurodac, eu-LISA shall establish criteria to ensure the priority handling of requests.
3. As far as is necessary for the efficient operation of Eurodac, eu-LISA shall establish the operational procedures for the processing of the data received and for transmitting the result of the comparison.
4. Where necessary, a fingerprint expert in the receiving Member State, as defined in accordance with its national rules and specifically trained in the types of fingerprint comparisons provided for in this Regulation, shall immediately check the result of the comparison of fingerprint data carried out pursuant to Article 27.
Where, following a comparison of both fingerprint and facial image data with data recorded in the computerised central database, Eurodac returns a fingerprint hit and a facial image hit, Member States may check the result of the comparison of the facial image data.
For the purposes laid down in Article 1(1), points (a), (b), (c) and (j), of this Regulation, final identification shall be made by the Member State of origin in cooperation with the other Member States concerned.
5. The result of the comparison of facial image data carried out pursuant to Article 27, where a hit based only on a facial image is received, and Article 28 shall be immediately checked and verified in the receiving Member State by an expert trained in accordance with national practice.
For the purposes laid down in Article 1(1), points (a), (b), (c) and (j), of this Regulation, final identification shall be made by the Member State of origin in cooperation with the other Member States concerned.
Information received from Eurodac relating to other data found to be unreliable shall be erased as soon as the unreliability of the data is established.
6. Where final identification in accordance with paragraphs 4 and 5 reveals that the result of the comparison received from Eurodac does not correspond to the biometric data sent for comparison, Member States shall immediately erase the result of the comparison and communicate that fact as soon as possible, and no later than three working days after the receipt of the result, to eu-LISA and inform it of the reference number of the Member State of origin and the reference number of the Member State that received the result.
Communication between Member States and Eurodac
Data transmitted from the Member States to Eurodac and vice versa shall use the Communication Infrastructure. As far as is necessary for the efficient operation of Eurodac, eu-LISA shall establish the technical procedures necessary for the use of the Communication Infrastructure.
Access to, and rectification or erasure of, data recorded in Eurodac
1. The Member State of origin shall have access to data which it has transmitted and which are recorded in Eurodac in accordance with this Regulation.
Member States shall not conduct searches of the data transmitted by another Member State or receive such data with the exception of data resulting from the comparison referred to in Articles 27 and 28.
2. The authorities of Member States which, pursuant to paragraph 1 of this Article, have access to data recorded in Eurodac shall be those designated by each Member State for the purposes laid down in Article 1(1), points (a), (b), (c) and (j). That designation shall specify the exact unit responsible for carrying out tasks related to the application of this Regulation. Each Member State shall without delay communicate to the Commission and eu-LISA a list of those units and any amendments thereto. eu-LISA shall publish the consolidated list in the Official Journal of the European Union . Where there are amendments to that list, eu-LISA shall publish once a year an updated consolidated list online.
3. Only the Member State of origin shall have the right to amend the data which it has transmitted to Eurodac by rectifying or supplementing such data, or to erase them, without prejudice to erasure carried out pursuant to Article 29.
4. Access for the purpose of consulting the Eurodac data stored in the CIR shall be granted to the duly authorised staff of the national authorities of each Member State and to the duly authorised staff of the Union bodies competent for the purposes laid down in Articles 20 and 21 of Regulation (EU) 2019/818. That access shall be limited to the extent necessary for the performance of the tasks of those national authorities and Union bodies and for the achievement of those purposes and shall be proportionate to the objectives pursued.
5. If a Member State or eu-LISA has evidence to suggest that data recorded in Eurodac are factually inaccurate, it shall, without prejudice to the notification of a personal data breach pursuant to Article 33 of Regulation (EU) 2016/679, inform the Member State of origin thereof as soon as possible.
If a Member State has evidence to suggest that data were recorded in Eurodac in breach of this Regulation, it shall inform eu-LISA, the Commission and the Member State of origin thereof as soon as possible. The Member State of origin shall check the data concerned and, if necessary, amend or erase them without delay.
6. eu-LISA shall not transfer or make available data recorded in Eurodac to the authorities of any third country. That prohibition shall not apply to transfers of such data to third countries to which Regulation (EU) 2024/1351 applies.
Keeping of records
1. eu-LISA shall keep records of all data processing operations within Eurodac. Those records shall show the purpose, date and time of access, the data transmitted, the data used for querying and the name of both the unit entering or retrieving the data and the persons responsible.
2. For the purposes of Article 8 of this Regulation, eu-LISA shall keep records of each data processing operation carried out within Eurodac. Records of such type of operations shall include the elements provided for in paragraph 1 of this Article and the hits triggered while carrying out the automated processing laid down in Article 20 of Regulation (EU) 2018/1240.
3. For the purposes of Article 10 of this Regulation, Member States and eu-LISA shall keep records of each data processing operation carried out within Eurodac and the VIS in accordance with this Article and Article 34 of Regulation (EC) No 767/2008.
4. The records referred to in paragraph 1 of this Article may be used only for the data protection monitoring of the admissibility of data processing and to ensure data security pursuant to Article 46. Those records shall be protected by appropriate measures against unauthorised access and erased after a period of one year after the storage period referred to in Article 29 has expired, unless they are required for monitoring procedures which have already begun.
5. For the purposes laid down in Article 1(1), points (a), (b), (c), (g), (h) and (j), each Member State shall take the necessary measures in order to achieve the objectives set out in paragraphs 1 to 4 of this Article in relation to its national system. In addition, each Member State shall keep a record of the staff duly authorised to enter or retrieve the data.
Rights of information
1. The Member State of origin shall inform a person covered by Article 15(1), Article 18(1) and (2), Article 20(1), Article 22(1), Article 23(1), Article 24(1) or Article 26(1) of this Regulation, in writing, and where necessary, orally, in a language that he or she understands or is reasonably supposed to understand, in a concise, transparent, intelligible and easily accessible form, using clear and plain language, of the following:
(a)
the identity and contact details of the controller within the meaning of Article 4, point (7), of Regulation (EU) 2016/679 and of his or her representative, if any, and the contact details of the data protection officer;
(b)
the data to be processed in Eurodac and the legal basis for processing, including a description of the aims of Regulation (EU) 2024/1351, in accordance with Article 19 of that Regulation and, where applicable, of the aims of Regulation (EU) 2024/1350, and an explanation in an intelligible form of the fact that Eurodac may be accessed by the Member States and Europol for law enforcement purposes;
(c)
in relation to a person covered by Article 15(1), Article 22(1), Article 23(1) or Article 24(1), the fact that, if a security check as referred to in Articles 17(2), point (i), 22(3), point (d), Article 23(3), point (e), and Article 24(3), point (f), shows that he or she could pose a threat to internal security, the Member State of origin is obliged to register that fact in Eurodac;
(d)
the recipients or categories of recipients of the data, if any;
(e)
in relation to a person covered by Article 15(1), Article 18(1) and (2), Article 20(1), Article 22(1), Article 23(1), Article 24(1) or Article 26(1), the obligation to have his or her biometric data taken and the relevant procedure, including the possible implications of non-compliance with such an obligation;
(f)
the period for which the data will be stored pursuant to Article 29;
(g)
the existence of the right to request from the controller access to data relating to him or her, and the right to request the rectification of inaccurate personal data, the completion of incomplete personal data or the erasure or restriction of the processing of unlawfully processed personal data concerning the data subject, as well as the right to receive information on the procedures for exercising those rights including the contact details of the controller and the supervisory authorities referred to in Article 44(1);
(h)
the right to lodge a complaint with the supervisory authority.
2. In relation to a person covered by Article 15(1), Article 18(1) and (2), Article 20(1), Article 22(1), Article 23(1), Article 24(1) and Article 26(1), the information referred to in paragraph 1 of this Article shall be provided at the time when his or her biometric data are taken.
Where a person covered by Article 15(1), Article 18(1) and (2), Article 20(1), Article 22(1), Article 23(1), Article 24(1) and Article 26(1), is a minor, the information shall be provided by Member States in an age-appropriate manner.
The procedure to capture biometric data shall be explained to minors by using leaflets, infographics or demonstrations, or a combination of any of the three, as appropriate, specifically designed in such a way as to ensure that minors understand it.
3. A common leaflet, containing at least the information referred to in paragraph 1 of this Article and the information referred to in Article 19(1) of Regulation (EU) 2024/1351, shall be drawn up in accordance with the procedure referred to in Article 77(2) of that Regulation.
The leaflet shall be clear and simple, drafted in a concise, transparent, intelligible and easily accessible form and in a language that the person concerned understands or is reasonably supposed to understand.
The leaflet shall be drawn up in such a manner as to enable Member States to complete it with additional Member State-specific information. That Member State-specific information shall include at least the administrative measures for ensuring compliance with the obligation to provide biometric data, the rights of the data subject, the possibility of information and assistance by the national supervisory authorities, the contact details of the office of the controller and of the data protection officer, and the contact details of the national supervisory authorities.
Right of access to, rectification, completion, erasure and restriction of the processing of personal data
1. For the purposes laid down in Article 1(1), points (a), (b), (c) and (j), of this Regulation, the data subject’s rights of access to, rectification, completion, erasure and restriction of the processing of personal data shall be exercised in accordance with Chapter III of Regulation (EU) 2016/679 and applied as set out in this Article.
2. The right of access of the data subject in each Member State shall include the right to have communicated to him or her the personal data relating to him or her recorded in Eurodac, including any record indicating that the person could pose a threat to internal security, and the Member State which transmitted them to Eurodac under the conditions set out in Regulation (EU) 2016/679 and in national law adopted pursuant thereto. Such access to personal data may be granted only by a Member State.
When the rights of rectification and erasure of personal data are exercised in a Member State other than that, or those, which transmitted the data, the authorities of that Member State shall contact the authorities of the Member State or Member States which transmitted the data so that they can check the accuracy of the data and the lawfulness of their transmission to and recording in Eurodac.
3. With regard to a record indicating that the person could pose a threat to internal security, Member States may restrict the data subject’s rights referred to in this Article in accordance with Article 23 of Regulation (EU) 2016/679.
4. If it emerges that data recorded in Eurodac are factually inaccurate or have been recorded unlawfully, the Member State which transmitted them shall rectify or erase the data in accordance with Article 40(3). That Member State shall confirm in writing to the data subject that it has taken action to rectify, complete, erase or restrict the processing of personal data relating to that data subject.
5. If the Member State which has transmitted the data does not agree that the data recorded in Eurodac are factually inaccurate or have been recorded unlawfully, it shall explain in writing to the data subject why it does not intend to rectify or erase the data.
That Member State shall also provide the data subject with information explaining the steps which can be taken if he or she does not accept the explanation provided. That shall include information on how to bring an action or, if appropriate, a complaint before the competent authorities or courts of that Member State and on any financial or other assistance that is available in accordance with the laws, regulations and procedures of that Member State.
6. Any request under paragraphs 1 and 2 for access to, rectification, completion, erasure or restriction of the processing of personal data shall contain all the necessary particulars to identify the data subject, including biometric data. Such data shall be used exclusively to permit the exercise of the data subject’s rights as referred to in paragraphs 1 and 2 and shall be erased immediately afterwards.
7. The competent authorities of the Member States shall cooperate actively to enforce promptly the data subject’s rights to access, rectification, completion, erasure and restriction of the processing of personal data.
8. Whenever a person requests access to data relating to him or her, the competent authority shall keep a record in the form of a written document that such a request was made and how it was addressed, and shall make that document available to the national supervisory authorities without delay.
9. The national supervisory authority of the Member State which has transmitted the data and the national supervisory authority of the Member State in which the data subject is present shall, where requested, provide information to the data subject concerning the exercise of his or her right to request from the data controller access to, rectification, completion, erasure or the restriction of the processing of personal data concerning him or her. The supervisory authorities shall cooperate in accordance with Chapter VII of Regulation (EU) 2016/679.
Supervision by the national supervisory authorities
1. Each Member State shall provide that its supervisory authority or authorities, as referred to in Article 51(1) of Regulation (EU) 2016/679, are to monitor the lawfulness of the processing of personal data by the Member State in question for the purposes laid down in Article 1(1), points (a), (b), (c) and (j), of this Regulation, including their transmission to Eurodac.
2. Each Member State shall ensure that its supervisory authority has access to advice from persons with sufficient knowledge of biometric data.
Supervision by the European Data Protection Supervisor
1. The European Data Protection Supervisor shall ensure that all the personal data processing activities concerning Eurodac, in particular by eu-LISA, are carried out in accordance with Regulations (EU) 2018/1725 and with this Regulation.
2. The European Data Protection Supervisor shall ensure that an audit of eu-LISA’s personal data processing activities is carried out in accordance with international auditing standards at least every three years. A report of such audits shall be sent to the European Parliament, to the Council, to the Commission, to eu-LISA, and to the national supervisory authorities. eu-LISA shall be given an opportunity to make comments before the report is adopted.
Cooperation between national supervisory authorities and the European Data Protection Supervisor
1. In accordance with Article 62 of Regulation (EU) 2018/1725, the national supervisory authorities and the European Data Protection Supervisor shall, each acting within the scope of their respective competences, cooperate actively in the framework of their responsibilities and ensure the coordinated supervision of Eurodac.
2. Member States shall ensure that every year an audit of the processing of personal data for law enforcement purposes is carried out by an independent body, in accordance with Article 47(1), including an analysis of a sample of reasoned electronic requests.
The audit shall be attached to the annual report by the Member States referred to in Article 57(8).
3. The national supervisory authorities and the European Data Protection Supervisor shall, each acting within the scope of their respective competences, exchange relevant information, assist each other in carrying out audits and inspections, examine difficulties in the interpretation or application of this Regulation, study problems with regard to the exercise of independent supervision or in the exercise of the rights of data subjects, draw up harmonised proposals for joint solutions to any problems and promote awareness of data protection rights, as necessary.
4. For the purposes of paragraph 3, the national supervisory authorities and the European Data Protection Supervisor shall meet at least twice a year within the framework of the European Data Protection Board. The costs and servicing of the meetings shall be covered by the European Data Protection Board. The rules of procedure for the meetings shall be adopted at the first such meeting. Further working methods shall be developed jointly as necessary. The European Data Protection Board shall send a joint report of activities to the European Parliament, to the Council and to the Commission every two years. That report shall include a chapter with regard to each Member State prepared by the national supervisory authority of that Member State.
Protection of personal data for law enforcement purposes
1. The supervisory authority or authorities of each Member State, as referred to in Article 41(1) of Directive (EU) 2016/680, shall monitor the lawfulness of the processing of personal data under this Regulation by the Member States for law enforcement purposes, including their transmission to and from Eurodac.
2. The processing of personal data by Europol pursuant to this Regulation shall be in accordance with Regulation (EU) 2016/794 and shall be supervised by the European Data Protection Supervisor.
3. Personal data obtained pursuant to this Regulation from Eurodac for law enforcement purposes shall only be processed for the purposes of the prevention, detection or investigation of the specific case for which the data have been requested by a Member State or by Europol.
4. Without prejudice to Article 24 of Directive (EU) 2016/680, Eurodac, the designated and verifying authorities and Europol shall keep records of searches for the purpose of permitting the national supervisory authorities and the European Data Protection Supervisor to monitor the compliance of data processing with Union data protection rules, including for the purpose of maintaining records in order to prepare the annual reports referred to in Article 57(8) of this Regulation. Other than for such purposes, personal data, as well as the records of the searches, shall be erased in all national and Europol files after a period of one month, unless the data are required for the purposes of the specific ongoing criminal investigation for which they were requested by a Member State or by Europol.
Data security
1. The Member State of origin shall ensure the security of data before and during transmission to Eurodac.
2. Each Member State shall, in relation to all data processed by its competent authorities pursuant to this Regulation, adopt the necessary measures, including a data security plan, in order to:
(a)
physically protect the data, including by making contingency plans for the protection of critical infrastructure;
(b)
deny unauthorised persons access to data-processing equipment and national installations in which the Member State carries out operations in accordance with the purposes of Eurodac (equipment, access control and checks at entrance to the installation);
(c)
prevent the unauthorised reading, copying, modification or removal of data media (data media control);
(d)
prevent the unauthorised input of data and the unauthorised inspection, modification or erasure of stored personal data (storage control);
(e)
prevent the use of automated data-processing systems by unauthorised persons using data communication equipment (user control);
(f)
prevent the unauthorised processing of data in Eurodac and any unauthorised modification or erasure of data processed in Eurodac (control of data entry);
(g)
ensure that persons authorised to access Eurodac have access only to the data covered by their access authorisation, by means of individual and unique user IDs and confidential access modes only (data access control);
(h)
ensure that all authorities with a right of access to Eurodac create profiles describing the functions and responsibilities of persons who are authorised to access, enter, update, erase and search the data, and make those profiles and any other relevant information which those authorities might require for supervisory purposes available to the supervisory authorities referred to in Article 51 of Regulation (EU) 2016/679 and in Article 41 of Directive (EU) 2016/680, without delay, at their request (personnel profiles);
(i)
ensure that it is possible to verify and establish to which bodies personal data may be transmitted using data communication equipment (communication control);
(j)
ensure that it is possible to verify and establish what data have been processed in Eurodac, when, by whom and for what purpose (control of data recording);
(k)
prevent the unauthorised reading, copying, modification or deletion of personal data during the transmission of personal data to or from Eurodac or during the transport of data media, in particular by means of appropriate encryption techniques (transport control);
(l)
ensure that installed systems may, in the event of interruption, be restored (recovery);
(m)
ensure that Eurodac performs its functions, that the appearance of faults in the functions is reported (reliability) and that stored personal data cannot be corrupted by means of the system malfunctioning (integrity); and
(n)
monitor the effectiveness of the security measures referred to in this paragraph and take the necessary organisational measures related to internal monitoring in order to ensure compliance with this Regulation (self-auditing) and to automatically detect within 24 hours any relevant events arising from the application of measures listed in points (b) to (k) that might indicate the occurrence of a security incident.
3. Member States and Europol shall inform eu-LISA of security incidents related to Eurodac detected on their systems without prejudice to the notification and communication of a personal data breach, pursuant to Articles 33 and 34 of Regulation (EU) 2016/679 and Articles 30 and 31 of Directive (EU) 2016/680, as well as Articles 34 and 35 of Regulation (EU) 2016/794, respectively. eu-LISA shall inform the Member States, Europol and the European Data Protection Supervisor, without undue delay, of security incidents related to Eurodac detected on their systems without prejudice to Articles 34 and 35 of Regulation (EU) 2018/1725. The Member States concerned, eu-LISA and Europol shall collaborate during a security incident.
4. eu-LISA shall take the necessary measures in order to achieve the objectives set out in paragraph 2 of this Article as regards the operation of Eurodac, including the adoption of a data security plan.
Prior to the start of the operational use of Eurodac, the security framework for Eurodac’s business and technical environment shall be updated, in accordance with Article 33 of Regulation (EU) 2018/1725.
5. The European Union Agency for Asylum shall take necessary measures in order to implement Article 18(4), including the adoption of a data security plan as referred to in paragraph 2 of this Article.
Prohibition of transfers of data to third countries, international organisations or private entities
1. Personal data obtained by a Member State or by Europol from Eurodac pursuant to this Regulation shall not be transferred or made available to any third country, international organisation or private entity established in or outside the Union. That prohibition shall also apply if those data are further processed within the meaning of Article 4, point (2), of Regulation (EU) 2016/679 and Article 3, point (2), of Directive (EU) 2016/680, at national level or between Member States.
2. Personal data which originate in a Member State and are exchanged between Member States following a hit obtained for law enforcement purposes shall not be transferred to third countries if there is a real risk that, as a result of such a transfer, the data subject might be subjected to torture, inhuman and degrading treatment or punishment or any other violation of his or her fundamental rights.
3. Personal data which originate in a Member State and are exchanged between a Member State and Europol following a hit obtained for law enforcement purposes shall not be transferred to third countries if there is a real risk that, as a result of such a transfer, the data subject might be subjected to torture, inhuman and degrading treatment or punishment or any other violation of his or her fundamental rights. In addition, any transfers shall only be carried out when they are necessary and proportionate in cases falling within Europol’s mandate, in accordance with Chapter V of Regulation (EU) 2016/794 and subject to the consent of the Member State of origin.
4. No information regarding the fact that an application for international protection has been made or that a person has been subject to an admission procedure in a Member State shall be disclosed to any third country with regard to persons as referred to in Article 15(1), Article 18(1) and (2) or Article 20(1).
5. The prohibitions set out in paragraphs 1 and 2 of this Article shall be without prejudice to the right of Member States to transfer such data in accordance with Chapter V of Regulation (EU) 2016/679 or with the national rules adopted pursuant to Chapter V of Directive (EU) 2016/680, as appropriate, to third countries to which Regulation (EU) 2024/1351 applies.
Transfer of data to third countries for the purpose of return
1. By way of derogation from Article 49, the personal data relating to persons as referred to in Article 15(1), Article 18(2)(a), Article 20(1), Article 22(2), Article 23(1), Article 24(1) and Article 26(1) obtained by a Member State following a hit for the purposes laid down in Article 1(1), point (a), (b), (c) or (j), may be transferred or made available to a third country with the agreement of the Member State of origin.
2. Transfers of data to a third country pursuant to paragraph 1 of this Article shall be carried out in accordance with the relevant provisions of Union law, in particular provisions on data protection, including Chapter V of Regulation (EU) 2016/679, and, where applicable, readmission agreements, and the national law of the Member State transferring the data.
3. Transfers of data to a third country pursuant to paragraph 1 shall take place only where the following conditions have been met:
(a)
the data are transferred or made available solely for the purpose of identifying, and issuing an identification or travel document to, an illegally staying third-country national for the purposes of return; and
(b)
the third-country national concerned has been informed that his or her personal data may be shared with the authorities of a third country.
4. The implementation of Regulation (EU) 2016/679, including with regard to the transfer of personal data to third countries pursuant to this Article, and, in particular, the use, proportionality and necessity of transfers based on Article 49(1), point (d), of that Regulation, shall be subject to monitoring by the independent supervisory authority set up pursuant to Chapter VI of Regulation (EU) 2016/679.
5. Transfers of personal data to third countries pursuant to this Article shall not prejudice the rights of persons as referred to in Article 15(1), Article 18(2)(a), Article 20(1), Article 22(2), Article 23(1), Article 24(1) and Article 26(1) of this Regulation, in particular as regards non-refoulement, or the prohibition to disclose or obtain information in accordance with Article 7 of Regulation (EU) 2024/1348.
6. A third country shall not have direct access to Eurodac to compare or transmit biometric data or any other personal data of a third-country national or stateless person and shall not be granted access to Eurodac via a Member State’s National Access Point.
Logging and documentation
1. Member States and Europol shall ensure that all data processing operations resulting from requests for comparison with Eurodac data for law enforcement purposes are logged or documented for the purpose of checking the admissibility of the request and monitoring the lawfulness of the data processing and data integrity and security and for the purposes of self-monitoring.
2. The log or documentation shall show in all cases:
(a)
the exact purpose of the request for comparison, including the type of terrorist offence or other serious criminal offence concerned and, for Europol, the exact purpose of the request for comparison;
(b)
the reasonable grounds given in accordance with Article 33(1), point (a), of this Regulation for not conducting comparisons with other Member States under Decision 2008/615/JHA;
(c)
the national file number;
(d)
the date and exact time of the request for comparison by the National Access Point to Eurodac;
(e)
the name of the authority that requested access for comparison and the person responsible who made the request and processed the data;
(f)
where applicable, the use of the urgent procedure referred to in Article 32(4) and the decision taken with regard to the ex post verification;
(g)
the data used for comparison;
(h)
in accordance with national rules or with Regulation (EU) 2016/794, the identifying mark of the official who carried out the search and of the official who ordered the search or supply;
(i)
where applicable, a reference to the use of the European search portal to query Eurodac as referred to in Article 7(2) of Regulation (EU) 2019/818.
3. Logs and documentation shall be used only for monitoring the lawfulness of data processing and for ensuring data integrity and security. Logs which contain personal data shall not be used for the monitoring and evaluation referred to in Article 57.
The national supervisory authorities responsible for checking the admissibility of the request and monitoring the lawfulness of the data processing and data integrity and security shall have access to those logs at their request for the purpose of fulfilling their tasks.
Liability
1. Any person who, or Member State which, has suffered material or non-material damage as a result of an unlawful processing operation or any other act incompatible with this Regulation shall be entitled to receive compensation from the Member State responsible for the damage suffered, or from eu-LISA if it is responsible for the damage suffered and in so far as it has not complied with obligations on it pursuant to this Regulation specifically directed to it or where it has acted outside or contrary to lawful instructions of that Member State. The Member State responsible or eu-LISA shall be exempt from its liability, in whole or in part, if it proves that it is not in any way responsible for the event giving rise to the damage.
2. If any failure of a Member State to comply with its obligations under this Regulation causes damage to Eurodac, that Member State shall be held liable for such damage, unless and in so far as eu-LISA or another Member State failed to take reasonable steps to prevent the damage from occurring or to minimise its impact..
3. Claims for compensation against a Member State for the damage referred to in paragraphs 1 and 2 of this Article shall be governed by the provisions of national law of the defendant Member State in accordance with Articles 79 and 80 of Regulation (EU) 2016/679 and Articles 54 and 55 of Directive (EU) 2016/680. Claims for compensation against eu-LISA for the damage referred to in paragraphs 1 and 2 of this Article shall be subject to the conditions provided for in the Treaties.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.