My bookmarksSign up free

Commission Implementing Regulation (EU) 2024/2145 CHAPTER II — DATA PROTECTION

Article 12–Article 19 · 8 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Personal data processing within the scope of joint controllership

Article 12

1.   The following processing activities performed by EU CSW-CERTEX shall fall within the scope of joint controllership between the Commission, customs authorities and partner competent authorities within the meaning of Article 28(1) of Regulation (EU) 2018/1725 and Article 26(1) of Regulation (EU) 2016/679: (a) the receipt of personal data from national single window environments for customs and Union non-customs systems; (b) the business and technical transformation of personal data in accordance with Articles 1, 2 and 3; (c) the transmission of transformed personal data to national single window environments for customs or Union non-customs systems. 2.   When processing personal data, the joint controllers shall comply with Regulations (EU) 2016/679 and (EU) 2018/1725.

Personal data processing outside the scope of joint controllership

Article 13

1.   The Commission shall be considered controller for the processing of personal data in the context of the following activities: (a) system maintenance and urgent servicing; (b) the business and technical transformation of personal data in accordance with customs legislation and Union legislation other than customs legislation, without prejudice to the transformation taking place pursuant to Article 12(1), point (b). 2.   Customs authorities shall each be considered controller for the processing of personal data required to take decisions on customs formalities in accordance with customs legislation. 3.   Partner competent authorities shall each be considered controller for the processing of personal data required to fulfil Union non-customs formalities in accordance with Union legislation other than customs legislation applicable to the specific Union non-customs formality.

Specific responsibilities of the Commission, customs authorities and partner competent authorities

Article 14

1.   The Commission shall be responsible for: (a) ensuring privacy by design and privacy by default when developing EU CSW-CERTEX in accordance with Article 5(1) of Regulation (EU) 2022/2399; (b) establishing and keeping up to date the list of all recipients of personal data; (c) ensuring that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (d) nominating a contact point for data protection matters; (e) assisting customs authorities and partner competent authorities in responding to data subject requests, where needed. 2.   Customs authorities shall be responsible for: (a) ensuring privacy by design and privacy by default in developing the interconnection between their national single window environment for customs and EU CSW-CERTEX, in accordance with Article 5(4) and (5) of Regulation (EU) 2022/2399; (b) establishing and keeping up to date the list of all recipients of personal data (in the Member States, third countries and international organisations); (c) ensuring that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (d) cooperating with the national supervisory authority in the performance of their tasks; (e) nominating a contact point for data protection matters; (f) responding to data subject requests when those requests are addressed to them and cooperating with partner competent authorities and the Commission as necessary in accordance with Article 16(5) of this Regulation. 3.   Each partner competent authority shall be responsible for: (a) establishing and keeping up to date the list of all recipients of personal data (in the Member States, third countries and international organisations); (b) ensuring that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (c) nominating a contact point for data protection matters; (d) responding to data subject requests when those requests are addressed to them and cooperating with customs authorities and the Commission as necessary in accordance with Article 16(5) of this Regulation.

Security of processing

Article 15

1.   The Commission shall, following consultations with customs authorities and partner competent authorities, implement appropriate technical and organisational measures to ensure security of processing in accordance with Article 32 of Regulation (EU) 2016/679 and Article 33 of Regulation (EU) 2018/1725. 2.   Customs authorities and partner competent authorities shall implement appropriate organisational measures to ensure the security of processing. 3.   The technical measures and organisational measures referred to in paragraphs 1 and 2 shall be designed to: (a) ensure the security, integrity, confidentiality, availability and continuity of the personal data processed, in accordance with the relevant legislation; (b) protect against any unauthorised or unlawful processing, loss, use, disclosure of, or access to any personal data in their possession; (c) restrict disclosure of or access to personal data to the intended recipients in accordance with this Regulation, Regulation (EU) No 952/2013 and Union legislation other than customs legislation relevant for the specific Union non-customs formalities. 4.   The joint controllers shall notify each other and provide assistance in case of security incidents, including personal data breaches. Such notification shall take place no later than 48 hours from the moment one of the joint controllers becomes aware of the security incident. 5.   In the case of a personal data breach, the Commission shall notify the European Data Protection Supervisor in accordance with Article 34 of Regulation (EU) 2018/1725. 6.   The joint controllers shall in any case notify each other of the following: (a) any potential or actual risk to the availability, confidentiality and integrity of the personal data processed in EU CSW-CERTEX; (b) any security incidents that are linked to the processing operation.

Responsibility of the joint controllers towards data subjects

Article 16

1.   In accordance with Articles 13 and 14 of Regulation (EU) 2016/679 and Articles 15 and 16 of Regulation (EU) 2018/1725, the Commission, partner competent authorities and customs authorities shall ensure that data subjects are duly informed of the processing operations carried out within the framework of this Regulation and shall update the data protection statement of their systems accordingly. 2.   Customs authorities and partner competent authorities shall ensure that any information and communication to data subjects regarding their rights is provided in a transparent manner. The Commission shall ensure that customs authorities and partner competent authorities have the required information to subsequently provide such information and communication to data subjects. 3.   The Commission, customs authorities and partner competent authorities shall facilitate the exercise of the rights of data subjects. 4.   The Commission, customs authorities and partner competent authorities shall handle requests from data subjects and shall cooperate without undue delay to handle those requests and provide each other with swift and efficient assistance. 5.   Where a joint controller receives a data subject request that does not fall under its responsibility in accordance with Article 12, it shall forward that request to the joint controller responsible promptly and at the latest within 3 calendar days from the receipt of the request. The Commission shall assist in identifying the joint controller responsible. 6.   Where a data subject requests access to personal data and that personal data is processed by EU CSW-CERTEX, the joint controller to which the request is addressed shall consult the other joint controllers before dealing with the request. 7.   Where a joint controller decides to restrict the rights of data subjects for processing activities falling outside of the scope of the joint controllership and concerning personal data that may be exchanged pursuant to this Regulation, it shall inform the other joint controllers without undue delay. 8.   In accordance with Article 34 of Regulation (EU) 2016/679 and Article 35 of Regulation (EU) 2018/1725, the controller responsible for a personal data breach shall notify affected data subjects if the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. The controller responsible shall inform the other controllers of such notification.

Access to personal data by the Commission, customs authorities and partner competent authorities

Article 17

Without prejudice to the specific rules for accessing personal data or determining its recipients in accordance with customs legislation or Union legislation other than customs legislation, access to personal data processed in EU CSW-CERTEX shall only be allowed to authorised staff of the Commission, customs authorities and partner competent authorities for the purposes of managing and operating EU CSW-CERTEX.

Engagement of data processors

Article 18

1.   A joint controller shall notify the other joint controllers before it engages one or more data processors to carry out processing operations on its behalf. 2.   The notification referred to in paragraph 1 shall take place at the latest 5 working days before the conclusion of the processing agreement with a processor.

Role of national coordinators in data protection matters

Article 19

1.   National coordinators as referred to in Article 17 of Regulation (EU) 2022/2399 and the Commission shall ensure that the contact information of the joint controllers along with any other relevant information referred to in this Chapter is kept up to date and shared between the joint controllers. 2.   The Commission shall make available to the joint controllers the information referred to in paragraph 1.

Back to Commission Implementing Regulation (EU) 2024/2145 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next