Keeping of logs
1. Air carriers shall create logs of all processing operations related to API data under this Regulation undertaken by using the automated means referred to in Article 5(2). Those logs shall cover the date, time and place of transfer of the API data. Those logs shall not contain any personal data, other than the information necessary to identify the relevant member of the staff of the air carrier.
2. eu-LISA shall keep logs of all processing operations relating to the transfer and transmission of API data through the router under this Regulation. Those logs shall cover:
(a)
the air carrier that transferred the API data to the router;
(b)
the competent border authorities to which the API data were transmitted through the router;
(c)
the date and time of the transfer or transmission referred to in points (a) and (b), and the place of that transfer or transmission;
(d)
any access by the staff of eu-LISA necessary for the maintenance of the router, as referred to in Article 26(3);
(e)
any other information relating to those processing operations necessary to monitor the security and integrity of the API data and the lawfulness of those processing operations.
Those logs shall not include any personal data, other than the information necessary to identify the relevant member of the staff of eu-LISA, referred to in point (d) of the first subparagraph.
3. The logs referred to in paragraphs 1 and 2 of this Article shall be used only for ensuring the security and integrity of the API data and the lawfulness of the processing, in particular as regards compliance with the requirements set out in this Regulation, including proceedings for penalties for infringements of those requirements in accordance with Articles 36 and 37.
4. Air carriers and eu-LISA shall take appropriate measures to protect the logs that they created pursuant to paragraphs 1 and 2, respectively, against unauthorised access and other security risks.
5. The national API supervision authority referred to in Article 36 and competent border authorities shall have access to the relevant logs referred to in paragraph 1 of this Article where necessary for the purposes referred to in paragraph 3 of this Article.
6. Air carriers and eu-LISA shall keep the logs that they created pursuant to paragraphs 1 and 2, respectively, for a period of one year from the moment of the creation of those logs. They shall immediately and permanently delete those logs upon the expiry of that period.
However, if those logs are needed for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations, as referred to in paragraph 3, and those procedures have already begun at the moment of the expiry of the period referred to in the first subparagraph of this paragraph, eu-LISA and air carriers shall keep those logs for as long as necessary for those procedures. In that case, they shall immediately delete those logs when they are no longer necessary for those procedures.
Data protection responsibilities
1. Air carriers shall be controllers, within the meaning of Article 4, point (7), of Regulation (EU) 2016/679, for the processing of API data constituting personal data in relation to the collection of such data and the transfer thereof to the router under this Regulation.
2. Each Member State shall designate a competent authority as controller in accordance with this Article. Member States shall notify the Commission, eu-LISA and the other Member States of those authorities.
All the competent authorities designated by Member States shall be joint controllers in accordance with Article 26 of Regulation (EU) 2016/679 for the purpose of processing of personal data in the router.
3. eu-LISA shall be a processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the purposes of the processing of API data constituting personal data under this Regulation through the router, including transmission of the data from the router to the competent border authorities and storage for technical reasons of those data on the router. eu-LISA shall ensure that the router is operated in accordance with this Regulation.
4. The Commission shall adopt implementing acts establishing the respective responsibilities of the joint controllers, and the respective obligations between the joint controllers and the processor. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 43(2).
Information for passengers
In accordance with Article 13 of Regulation (EU) 2016/679, air carriers shall provide passengers, on flights covered by this Regulation, with information on the purpose of the collection of their personal data, the type of personal data collected, the recipients of the personal data and the means to exercise their rights as data subjects.
That information shall be communicated to passengers in writing and in an easily accessible format at the moment of booking and at the moment of check-in, irrespective of the means used to collect the personal data at the moment of check-in in accordance with Article 5.
Security
1. eu-LISA shall ensure the security and encryption of the API data, in particular API data constituting personal data, that it processes pursuant to this Regulation. The competent border authorities and the air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation. eu-LISA, the competent border authorities and the air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other to ensure such security.
2. eu-LISA shall take the measures necessary to ensure the security of the router and the API data, in particular API data constituting personal data, transmitted through the router, including by establishing, implementing and regularly updating a security plan, a business continuity plan and a disaster recovery plan, in order to:
(a)
physically protect the router, including by making contingency plans for the protection of critical components thereof;
(b)
prevent any unauthorised processing of the API data, including any unauthorised access thereto and the copying, modification or deletion thereof, both during the transfer of the API data to and from the router and during any storage of the API data on the router where necessary to complete the transmission, in particular by means of appropriate encryption techniques;
(c)
ensure that the persons authorised to access the router have access only to the data covered by their access authorisation;
(d)
ensure that it is possible to verify and establish to which competent border authorities the API data are transmitted through the router;
(e)
properly report to its Management Board any faults in the functioning of the router;
(f)
monitor the effectiveness of the security measures required under this Article and under Regulation (EU) 2018/1725, and assess and update those security measures where necessary in the light of technological or operational developments.
The measures referred to in the first subparagraph of this paragraph shall not affect Article 32 of Regulation (EU) 2016/679 or Article 33 of Regulation (EU) 2018/1725.
Self-monitoring
Air carriers and competent border authorities shall monitor their compliance with their respective obligations under this Regulation, in particular as regards their processing of API data constituting personal data. For air carriers, the monitoring shall include frequent verification of the logs referred to in Article 17(1).
Personal data protection audits
1. The independent supervisory authorities referred to in Article 51 of Regulation (EU) 2016/679 shall carry out an audit of processing operations of API data constituting personal data performed by the competent border authorities for the purposes of this Regulation at least once every four years. Member States shall ensure that their independent supervisory authorities have sufficient resources and expertise to fulfil the tasks entrusted to them under this Regulation.
2. The European Data Protection Supervisor shall carry out an audit of processing operations of API data constituting personal data performed by eu-LISA for the purposes of this Regulation, in accordance with relevant international auditing standards at least once every year. A report of that audit shall be sent to the European Parliament, to the Council, to the Commission, to the Member States and to eu-LISA. eu-LISA shall be given an opportunity to make comments before the reports are adopted.
3. In relation to the processing operations referred to in paragraph 2 of this Article, upon request, eu-LISA shall supply information requested by the European Data Protection Supervisor, shall grant the European Data Protection Supervisor access to all the documents it requests and to the logs referred to in Article 17(2), and shall allow the European Data Protection Supervisor access to all eu-LISA’s premises at any time.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.