Personal data protection
1. The personal data registered in the electronic systems shall be processed for the purposes of implementing the customs legislation and other legislation referred to in the Code, having regard to the specific objectives of each of the electronic systems set out in Article 4, Articles 7(1), 16(1), and 21(1), Article 30, Articles 35(1), 42(1), 50(1), 57(1), 65(1), 70(1), 74(1), 80(1), 87(1), 93(1), 100(1) and 104(1) of this Regulation.
2. The Member States’ national supervisory authorities in the field of personal data protection and the European Data Protection Supervisor shall cooperate, in accordance with Article 62 of Regulation (EU) 2018/1725, to ensure the coordinated supervision of the processing of personal data registered in the electronic systems.
3. Any request by a data subject registered in the REX system to exercise his or her rights under Chapter III of Regulations (EU) 2016/679 and (EU) 2018/1725 shall first be submitted to the competent authorities in the third country or to the customs authorities in the Member State which registered the personal data.
Where a data subject has submitted such a request to the Commission without having tried to obtain his or her rights from the competent authorities in the third country or from the customs authorities in the Member State which registered the personal data, the Commission shall forward that request to the competent authorities in the third country or to the customs authorities in the Member State respectively which registered those data.
Where the registered exporter fails to obtain his or her rights from the competent authorities in the third country or from the customs authorities in the Member State which registered the personal data, the registered exporter shall submit such request to the Commission acting as controller as defined in Article 4, point (7), of Regulation (EU) 2016/679 and in Article 3, point (8), of Regulation (EU) 2018/1725.
Updating of data in the electronic systems
1. Member States shall ensure that the data registered at national level correspond to the data registered in the common components and are kept up to date.
2. By way of derogation from paragraph 1, in respect of the ICS2, Member States shall ensure that the following data are kept up to date and correspond to the data in the ICS2 common repository:
(a)
data registered at national level and communicated from the national entry system to the ICS2 common repository;
(b)
data received by the national entry system from the ICS2 common repository.
Limitation of data access and data processing
1. The data registered in the common components of the electronic systems by a Member State may be accessed or processed by that Member State. Another Member State that is involved in the processing of an application or the management of a decision to which the data relate may also access and process those data.
2. The data registered in the common components of the electronic systems by an economic operator or other person may be accessed or processed by that economic operator or that other person. A Member State involved in the processing of an application or the management of a decision to which the data relate may also access and process those data.
3. The data in the ICS2 common component that are communicated to or registered in the shared trader interface by an economic operator or other person may be accessed or processed by that economic operator or that other person.
4. The data registered in the central EBTI system by a Member State may be processed by that Member State. Another Member State which is involved in the processing of an application to which the data relate may also process those data, including by way of a consultation between the customs authorities of the Member States in accordance with Article 26 of this Regulation. The customs authorities of the Member States may access those data for the purposes of Article 25(2) of this Regulation and the Commission may access those data for the purposes of Article 21(1) of this Regulation.
5. The data registered in the central EBTI system by an economic operator or other person may be accessed or processed by that economic operator or that person. The customs authorities of the Member States may access those data for the purposes of Article 25(2) of this Regulation and the Commission may access those data for the purposes of Article 21(1) of this Regulation.
6. The data registered in the common component of the EORI system may be accessed and processed by the Commission. The Member State that registered those data may also access and process those data.
7. The data in the ICS2 common components:
(a)
communicated to a Member State by an economic operator or other person through the shared trader interface into the ICS2 common repository may be accessed and processed by that Member State in the ICS2 common repository, and, where needed, that Member State may also access those data that are registered in the shared trader interface;
(b)
communicated to or registered in the ICS2 common repository by a Member State may be accessed or processed by that Member State;
(c)
referred to in points (a) and (b) may also be accessed and processed by another Member State where that other Member State, in accordance with Article 186(2), points (a), (b) and (d), Article 186(5), (7) and (7a), and Article 189(3) and (4) of Implementing Regulation (EU) 2015/2447, is involved in the risk analysis or control process, or both, to which the data relate, with the exception of data recorded in the system by customs authorities of other Member States in relation to information on security and safety risks as referred to in Article 186(2), point (a), of Implementing Regulation (EU) 2015/2447;
(d)
may be processed by the Commission in cooperation with the Member States for the purposes referred to in Article 43(2) of this Regulation and in Article 182(1), point (c), of Implementing Regulation (EU) 2015/2447, and the results of such processing may be accessed by the Commission and the Member States;
(e)
may be accessed and processed by the Member States and the Commission for the purposes referred to in Article 43(3) of this Regulation, under the conditions referred to in Article 119 of this Regulation and in accordance with the specific project agreements detailing processing operations between the Member States and the Commission.
8. The data in the ICS2 common component that are registered in the ICS2 common repository by the Commission may be accessed and processed by the Commission and Member States.
9. The data in the Surveillance system may be accessed and processed by the Commission and Member States.
10. The data registered in the central REX system for Member States may be accessed for the purpose of implementing and monitoring Union’s preferential trade arrangements by the customs authorities of Member States and the Commission.
11. The data registered in the central REX system for third countries with which the Union has a preferential trade arrangement may be accessed by the following:
(a)
the competent authorities of the third country in which the data have been registered;
(b)
the customs authorities of Member States for the purpose of carrying out verifications of customs declarations under Article 188 of the Code or post-release control under Article 48 of the Code;
(c)
the Commission for the purpose of implementing and monitoring the Union’s preferential trade arrangements.
12. Where Member States report incidents and problems in the operational processes for the provision of the services of the systems where the Commission acts as a processor, the Commission may have access to the data only to resolve a registered incident or problem. The Commission shall ensure the confidentiality of such data in accordance with Article 12 of the Code.
13. The data registered in the common components of the CRMS by a Member State, Switzerland, Norway or by the Commission may be accessed or processed by that Member State, Switzerland, Norway, another Member State or by the Commission to ensure the implementation of the common risk management framework in line with Article 46(5) of the Code and Article 36 of Implementing Regulation (EU) 2015/2447.
14. The data registered in the central PoUS system may be accessed or processed by:
(a)
the customs authorities of Member States in accordance with Article 93 of this Regulation;
(b)
the Commission for statistical purposes.
15. In the context of the Windsor Framework, the Union representatives may access the ICS2-data in respect of Northern Ireland.
System ownership
1. The Commission shall be the system owner of the common components.
2. The Member States shall be the system owners of the respective national components.
System security
1. The Commission shall ensure the security of the common components. The Member States shall ensure the security of the national components.
For those purposes, the Commission and the Member States shall take the necessary measures to:
(a)
prevent any unauthorised person from having access to installations used for the processing of data;
(b)
prevent the entry of data and any consultation, modification, or deletion of data by unauthorised persons;
(c)
detect any of the activities referred to in points (a) and (b).
2. The Commission and the Member States shall inform each other of any activities that might result in a breach or a suspected breach of the security of the electronic systems.
3. The Commission and the Member States shall establish security plans concerning all electronic systems.
Controller and Processor for the systems
For the systems referred to in Article 1 of this Regulation and in relation to the processing of personal data:
(a)
the Member States shall act as controllers as defined in Article 4, point (7), of Regulation (EU) 2016/679 and shall comply with the obligations set out in that Regulation;
(b)
the Commission shall act as processor as defined in Article 3, point (12), of Regulation (EU) 2018/1725 and shall comply with the obligations set out in that Regulation;
(c)
by way of derogation from point (b), the Commission shall act as a joint controller together with the Member States in the ICS2 when processing the data for monitoring and evaluating the implementation of the common security and safety risk criteria and standards and of the control measures and priority control in accordance with Article 116(7), point (d) of this Regulation;
(d)
by way of derogation from point (b), the Commission shall act as a joint controller together with the Member States in the ICS2 when processing the data to collect, store, process, or analyse additional elements of information in conjunction with entry summary declarations and to provide support to risk management processes as referred to in Article 43(3) of this Regulation, under the conditions set out by Article 116(7), point (e), of this Regulation;
(e)
by way of derogation from point (b), the Commission shall also act as a joint controller together with the Member States in the CRMS;
(f)
by way of derogation from point (b), the Commission shall act as joint controller together with the Member States in the REX system in the following cases:
(i)
when processing the data for synchronisation with a national system;
(ii)
when processing the data to access the data to verify customs declarations under Article 188 of the Code or post-release control under Article 48 of the Code;
(iii)
when processing data for statistics and monitoring purposes on the use of the REX system for Member States;
(iv)
when processing data for statistics and monitoring purposes on the use of the REX system for third countries.
(g)
by way of derogation from point (b), the Commission shall act as a joint controller together with the Member States in the Surveillance system.
Data retention periods
1. The data retention periods for the systems for which the Member States are controllers, as set out in Article 119 of this Regulation, shall be determined by those Member States, taking into account the requirements of the customs legislation. The Member States shall inform the Commission of those retention periods.
2. The following data retention periods shall apply to the following systems for which the Commission and Member States are joint controllers:
(a)
for the ICS2, to monitor and evaluate the implementation of the common security and safety risk criteria and standards, of the control measures and priority control areas referred to in Article 43(2), and to support the risk management processes referred in Article 43(3) of this Regulation, a retention period of 10 years starting from the moment the data are processed in the central system for the first time;
(b)
for the REX system, to allow for the notification of the customs debt for a maximum period of 10 years in accordance with Article 103(2) of the Code, a revoked registration shall be retained in the REX system for a maximum period of 10 years starting from 1 January of the year after the year in which the revocation took place, and, after the expiry of that period, the competent authority of a third country or the customs authorities of the Member State having revoked the registration shall delete the registration data. However, if all registrations in a beneficiary country of the Generalized System of Preference were revoked in accordance with Article 90(1) of Implementing Regulation (EU) 2015/2447, and if the beneficiary country has not been a beneficiary country of the Generalized System of Preferences of Norway, Switzerland or Türkiye for more than 10 years, the Commission shall delete the registration data;
(c)
for the CRMS, to ensure the protection of the security and safety of citizens and the protection of the financial interests of the Union and its Member States, a retention period of 10 years starting from the moment the data are processed in the central system for the first time;
(d)
for the Surveillance system, to ensure the protection of the financial interests of the Union and its Member States and the trade and all other Union policies that are based on the data retrieved by means of surveillance, a retention period of 10 years starting from the moment the data are processed in the central system for the first time.
However, where court proceedings or an appeal involving data stored in the electronic systems referred to in points (a) to (d) have begun, those data shall be retained until the appeal procedure or court proceedings are terminated.
3. The data retention period shall be applicable to all data covered by the electronic systems.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.