Definitions
For the purpose of this Regulation, the following definitions shall apply:
(1)
‘eFTI exchange environment’ means the ensemble of ICT components used for the exchange of data in accordance with Regulation (EU) 2020/1056 and the implementing and delegated acts adopted pursuant to that Regulation;
(2)
‘ICT component’ means a material (hardware) or immaterial (software) unit or set of such units used to perform specific functionalities to enable electronic data communication;
(3)
‘competent authority officer’ means a physical person entitled to access and process regulatory information requirements referred to in Article 2(1) of Regulation (EU) 2020/1056, on behalf of a competent authority in a Member State;
(4)
‘eFTI data’ means data corresponding to regulatory information, when made available by economic operators on an eFTI platform in accordance with Regulation (EU) 2020/1056;
(5)
‘request for access to eFTI data’ means a request on behalf of a competent authority to receive the eFTI data made available by economic operators on an eFTI platform;
(6)
‘follow-up communication’ means communication between competent authorities and the economic operators concerned on the information made available by the economic operators on an eFTI platform, following a compliance check by a competent authority officer of that information as provided in response to a request for access to eFTI data. This follow-up communication may consist of a request for missing eFTI data, or information in relation to follow-up action taken by the competent authority in accordance with applicable national provisions;
(7)
‘access rights’ means the permissions granted to a competent authority officer to perform operations in relation to one or more eFTI data subsets;
(8)
‘processing rights’ means the operations or sets of operations that a competent authority officer is allowed to perform on a specific eFTI data subset received in response to a request for access to eFTI data;
(9)
‘electronic identification means’ means a material or immaterial unit, containing person identification data and which is used for authentication for an online service;
(10)
‘identification references’ means a personal identification number or coded reference that allows the unique identification of a competent authority officer;
(11)
‘Authority Access Point (AAP)’ means an ICT component or a set of ICT components performing the functionalities set out in Article 4;
(12)
‘eFTI Gate’ means an ICT component or a set of ICT components performing the functionalities set out in Article 6;
(13)
‘requesting Gate’ means an eFTI Gate that processes a request for access to eFTI data lodged via an AAP connected to or integrated into that eFTI Gate;
(14)
‘receiving Gate’ means an eFTI Gate that processes a request for access to eFTI data received from a requesting Gate;
(15)
‘eDelivery’ means a set of technical specifications and standards for electronic message exchange developed by the Commission under the Connecting Europe Facility programme ( 7 ) and continued under the Digital Europe programme ( 8 ) ;
(16)
‘eDelivery Access Point’ means a communication component that is part of the eDelivery electronic delivery service based on technical specifications and standards;
(17)
‘static discovery’ means a mechanism for an eDelivery Access Point to obtain the connection details of another eDelivery Access Point without resorting to third party systems;
(18)
‘dynamic discovery’ means a mechanism for an eDelivery Access Point to obtain the connection details of another eDelivery Access Point by looking up these details in a third-party system;
(19)
‘security keys’ means pairs of public and private cryptographic keys, generated by cryptographic algorithms in the form of very large numbers that have a unique relationship to each other;
(20)
‘security certificate’ means a digital document issued by a certificate authority that is used to establish a secure electronic communication channel between two parties; it includes the public security key and information about the subject of the certificate;
(21)
‘certificate authority’ means an entity that manages the life cycle of digital certificates, which may include enrolment processes and processes for the issuance, delivery, activation, suspension, revocation, renewal or reactivation of the security certificates;
(22)
‘user application’ means an ICT component performing the functionalities set out in Article 7;
(23)
‘technical guidance documents’ means a set of detailed and non-binding technical documents, drawn up by the Commission in cooperation with Member States in the framework of the working group referred to in Article 13.
Common measures
1. Member States shall ensure that their competent authorities have access to ICT systems that can process the unique electronic identifying links (UIL) communicated by the economic operators pursuant to Article 4(3) of Regulation (EU) 2020/1056, and that allow their competent authorities’ officers to access and process eFTI data in either of the following procedures:
(a)
by directly processing the UIL, when communicated by the economic operator in machine readable format, by displaying it on the screen of an electronic device or printed on a physical support such as paper or, when the competent authority chooses to allow such communication, also by sending it by email or other electronic messaging application;
(b)
by retrieving first the UIL, as communicated by the economic operators through publication on a dedicated registry, by means of a unique identifier associated with a transport operation.
2. Member States shall ensure that the ICT systems referred to in paragraph 1 provide at least the following functionalities:
(a)
duly authenticated identification and due authorisation of the competent authorities’ officers, each time an officer lodges a request for access to eFTI data;
(b)
mediation of the requests for access to eFTI data lodged by the competent authorities’ officers, including retrieval of the information requested from the appropriate eFTI platform or platforms, by means of secure connections to those platforms.
3. To implement the functionalities listed in paragraph 2, those ICT systems shall comprise at least the following components:
(a)
authority access points (AAP);
(b)
an authorisation registry;
(c)
eFTI Gates;
(d)
a search mechanism;
(e)
a user application.
4. Member States shall ensure that the components listed in paragraph 3 comply with the requirements laid down in Chapter II. Member States shall be responsible for the setting up, hosting, development, availability, monitoring, updating and maintenance of those components and for the security of the information processed within those components. Where two or more Member States set up or develop one or more of those components jointly, they shall be jointly responsible for their setting up, hosting, development, availability, monitoring, updating, maintenance and security.
5. Member States remain responsible for ensuring that the access and processing by competent authorities of eFTI data is done only for the purposes of checking compliance with the applicable EU and national legal provisions, and in accordance with applicable EU and national provisions laying down the conditions for performing those compliance checks, and rules on respect of personal data privacy and confidentiality of commercial data.
Requests for access to eFTI data, responses and follow-up communication
1. Competent authority officers shall lodge all requests for access to eFTI data via the AAP component described in Article 4, by means of the user application described in Article 7.
2. A request for access to eFTI data shall contain the following information:
(a)
the UIL of the eFTI data to which access is requested, or one or more identifiers that allow the retrieval of that UIL from the registry of identifiers described in Article 11. This information shall be provided by the competent authority officer responsible for the request;
(b)
the references to the access rights of the competent authority officer responsible for lodging the request, as recorded in the authorisation registry described in Article 5. This information shall be automatically added by the user application;
(c)
the unique identification number of the request, as issued by the AAP. This information shall be automatically added by the user application.
3. Responses to a request for access to eFTI data may take one of the following forms:
(a)
eFTI data, as transmitted by an eFTI platform based on the information contained in a request, and associated message exchange metadata or identifiers, necessary to enable the receiving eFTI Gates or authority access points to map the eFTI data to the respective request;
(b)
error messages, containing coded or brief textual specification of the type of error when an eFTI Gate or an eFTI platform cannot provide the requested eFTI data for technical or business process reasons;
(c)
message indicating that no data is available, to be issued by a receiving eFTI Gate when it processes a request that contains identifiers and the search mechanism of the Gate detects no active UIL linked to those identifiers in its registry of identifiers;
(d)
‘no response’ message, transmitted by an eFTI Gate or eFTI platform when that eFTI Gate or platform confirmed receipt of request but did not send a message containing the requested eFTI data within 60 seconds from confirmation of receipt.
4. Where the competent authority officer establishes that the information made available by an economic operator on an eFTI platform, and as retrieved in response to a request for access to eFTI data, is incomplete or fails in other ways to comply with the regulatory information requirements on the basis of which the request was made, the officer may communicate those findings to the economic operator by lodging a specific follow-up communication for that information. Any such follow-up communication shall comply with applicable national legal requirements on follow-up actions to regulatory compliance checks.
5. Where a specific follow-up communication referred to in paragraph 4 is lodged, the competent authority shall also transmit it via the AAP component, by means of the user application. It shall contain:
(a)
the information to be communicated by the competent authority to the economic operator, in free text format, or as an attached document;
(b)
the UIL of the eFTI data and the unique identification number of the request for access to that data for which the follow-up communication is lodged.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.