Personal data protection
The personal data registered in the CBAM registry, and the components of electronic systems developed at national level, shall be processed by the competent authorities and the Commission for the following purposes:
(a)
authentication purposes and access management;
(b)
application processing and management;
(c)
submission and management of CBAM declarations;
(d)
monitoring, checks and review of CBAM declarations;
(e)
operator and verifier management;
(f)
CBAM certificates management;
(g)
communication and notifications;
(h)
for ensuring compliance;
(i)
functioning of the IT infrastructure, including interoperability with national systems and trans-European decentralised systems under this Regulation;
(j)
statistics and review of the functioning of Regulation (EU) 2023/956;
(k)
risk analysis and circumvention monitoring;
(l)
verification that the importation of goods and the re-export of goods, in the cases provided for in Article 2(2) of Regulation (EU) 2023/956 is performed by an authorised CBAM declarant.
Specific role of the Commission and the competent authorities
1. The Commission shall be the controller for:
(a)
the processing of personal data for the access management for the Commission Portal in accordance with Article 12 of this Regulation;
(b)
the processing of personal data registered in the CBAM Operators Portal;
(c)
the use, validation and retrieving of EORI or other data for the purpose of the risk analysis and circumvention monitoring as provided for in Articles 15, and 27 of Regulation (EU) 2023/956.
2. The competent authority shall be the controller for:
(a)
the personal data processing to take decisions on the granting and revocation of authorisations of CBAM declarants in accordance with Regulation (EU) 2023/956;
(b)
the personal data processing to take decisions regarding penalties in accordance with Article 26 of Regulation (EU) 2023/956;
(c)
the processing of personal data for the access management of declarants established within their Member State in accordance with Articles 8, 11 and 13 of this Regulation;
(d)
the processing of personal data of accredited verifiers.
3. The competent authority and the Commission shall be joint controllers for:
(a)
management of the CBAM registry;
(b)
the personal data processing for the management of CBAM declarations in accordance with Regulation (EU) 2023/956;
(c)
the personal data processing for the CBAM certificates management in accordance with Regulation (EU) 2023/956.
Responsibility of the controllers towards data subjects
Where a controller receives a data subject request that does not fall under its responsibility in accordance with Article 19, it shall forward that request promptly and at the latest within 3 working days from the receipt to the responsible controller.
Limitation of data access, data processing and confidentiality
1. All information held in the CBAM registry shall be considered confidential.
The authorised CBAM declarants and applicants may access their personal data registered in the CBAM registry after their registration in the registry.
2. The operators may access their personal data registered in the CBAM registry after their registration in the CBAM registry. In accordance with Article 10 of Regulation (EU) 2023/956, authorised CBAM declarants may access personal data registered by operators in the CBAM registry or otherwise process those data, where authorisation in that respect was granted by the operators.
3. The Commission and the competent authorities may access and otherwise process the personal data and other data from Customs Import Declarations for goods not listed in Annex I to Regulation (EU) 2023/956 in accordance with Articles 15, 19 and 27 of Regulation (EU) 2023/956.
The Commission and the competent authorities may access and otherwise process the data from the EORI system, in accordance with Articles 15, 19 and 27 of Regulation (EU) 2023/956.
System security
1. The Commission shall implement appropriate technical and organisational measures for the system security following consultations with competent authorities.
2. The competent authorities shall implement appropriate organisational measures for the system security.
3. The technical measures and organisational measures referred to in paragraphs 1 and 2 of this Article shall be designed to:
(a)
ensure the security, integrity, confidentiality, availability and continuity of the personal data processed;
(b)
protect against any unauthorised or unlawful processing, alteration, loss, use, disclosure of, or access to any personal data in their possession;
(c)
restrict disclosure or access to personal data to anyone other than the intended recipients in accordance with this Regulation and Regulation (EU) 2023/956.
4. The Commission and the competent authorities shall notify each other and provide assistance in case of critical security incidents activating the CBAM business continuity plan when such incidents imply a personal data breach in the meaning of Article 4(12) of Regulation (EU) 2016/679 and Article 3(16) of the Regulation (EU) 2018/1725.
5. The Commission shall conduct regular assessments of the components of the CBAM registry and shall analyse the security and integrity of those components and the confidentiality of the data processed within those components.
Data retention period
1. When processing personal data for the purposes listed in Article 18, the competent authorities and the Commission shall retain the data only for the time necessary to achieve the purpose, and for a maximum of 7 years from the registering of the personal data in the CBAM registry.
2. Notwithstanding paragraph 1, where an appeal has been lodged or where court proceedings have begun involving data stored in the CBAM registry, those data shall be retained until the appeal procedure or court proceedings are terminated and shall only be used for the purpose of the appeal procedure or court proceedings.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.