Access to eFTI platforms by competent authorities
1. eFTI platforms shall enable competent authorities to access eFTI data solely by means of machine-to-machine communication, via a secure connection between the eFTI platform and an eFTI Gate. An eFTI platform shall establish such a connection with at least one eFTI Gate.
2. To enable the communication referred to in paragraph 1, an eFTI platform shall provide the following functionalities:
(a)
validate the request for access to eFTI data or the follow-up communication received from the eFTI Gate, by verifying the security key of the eFTI Gate;
(b)
process the request for access to eFTI data, by identifying:
(i)
the UUID of the eFTI CMDS;
(ii)
the references to the access rights of the competent authority officer responsible for the request, expressed as the list of identifiers of eFTI data subsets;
(c)
keep an audit trail of the request for access to eFTI data, by recording at least the following information:
(i)
the unique identification number of the request for access to eFTI data, as contained in the request transmitted by the eFTI Gate;
(ii)
the UUID of the eFTI CMDS to which access was requested;
(iii)
the date and time of the request;
(d)
prepare and transmit to the eFTI Gate the response to the request for access to eFTI data, as appropriate:
(i)
the requested eFTI data, as a subset of the eFTI CMDS, consisting of all the data elements that correspond to the applicable regulatory information requirements and which are identified by the eFTI platform based on the references to the access rights of the competent authority officer included in the request;
(ii)
an error message, containing a coded or brief textual specification of the type of error when the platform cannot provide the requested eFTI data for technical or business process reasons;
(e)
keep an audit trail of the response, which allows at least the following information to be retrieved:
(i)
unique identification number of the response, and the unique identification number of the request to which the response was provided;
(ii)
the type of response provided, whether eFTI CMDS or error message;
(iii)
the date and time of the response;
(iv)
where the response contains the eFTI CMDS, the data elements and their respective values as included in the response;
(f)
process the follow-up communication, by:
(i)
retrieving the UUID of the eFTI CMDS and the unique identification number of the request for access to eFTI data for which the follow-up communication was lodged;
(ii)
recording the information contained in the follow-up communication, as transmitted by the competent authority in accordance with the specifications laid down in Article 3(5), point (a), of Implementing Regulation (EU) 2024/1942;
(iii)
notifying the business users concerned, when their authorisation includes appropriate corresponding processing rights, and transmitting to the eFTI Gate a confirmation message of receipt of the follow-up communication;
(g)
keep an audit trail of the follow-up communication, which allows at least the following information to be retrieved:
(i)
the unique identification number of the request for access to eFTI data for which the follow-up communication was lodged;
(ii)
the date and time of receipt of the follow-up communication.
Access to eFTI platforms by business users
1. eFTI platforms shall allow business users to access and process eFTI data by means of one or both of the following modalities:
(a)
human-to-machine user interfaces;
(b)
machine-to-machine communication via secure connections to other ICT systems that act as tributary ICT systems.
2. For access and processing of eFTI data by means of human-to-machine interfaces, eFTI platforms shall provide functionalities that ensure:
(a)
for each onboarded user:
(i)
user identification and authentication by electronic identification means issued under an electronic identification scheme complying with the requirements laid down in paragraph 3;
(ii)
user authorisation, by means of an authorisation registry referred to in Article 5(1), point (a);
(b)
for non-onboarded users, user identification, authentication and authorisation by means of the authorisation mechanism referred to in Article 5(1), point (b).
3. The electronic identification scheme referred to in paragraph 2, point (a)(i), shall comply, as a minimum, with the requirements laid down in Article 8(2), point (b), of Regulation (EU) No 910/2014.
For users accessing and processing eFTI data that corresponds to the information requirements referred to in Article 2(1), point (a)(iv), of Regulation (EU) 2020/1056, the electronic identification means referred to in paragraph 2, point (a)(i), of this Article shall include reference to the identification number of the waste shipments operator referred to in Article 9 of Implementing Regulation (EU) 2025/1290.
4. For access and processing of eFTI data by means of machine-to machine communication, eFTI platforms shall provide functionalities that ensure for each tributary ICT system:
(a)
the identification and authentication of the business user under whose legal responsibility the tributary ICT system operates, by means of a registry where at least the following information is recorded and kept updated:
(i)
identification reference of the business user;
(ii)
details of the security key of the tributary ICT system;
(b)
the authorisation of the business user under whose legal responsibility the tributary ICT system operates, by means of the authorisation registry referred to in Article 5(1), point (a).
5. eFTI platform operators shall establish and implement measures for the appropriate onboarding of tributary ICT systems that include, as a minimum:
(a)
verifying that the tributary ICT system identifies and authenticates the users that are allowed to act as business users of the eFTI platform, by electronic identification means issued under an electronic identification scheme that complies with the requirements laid down in paragraph 3;
(b)
verifying that the tributary ICT system controls the access of users that are allowed to act as business users of the eFTI platform, by means of an authorisation registry referred to in Article 5(1), point (a).
6. For each login session, the eFTI platform shall ensure the identification, authentication and authorisation of the business user, before allowing the business user to process eFTI data.
Authorisation mechanism
1. eFTI platforms shall use one or both of the following types of authorisation mechanisms:
(a)
verification of the processing rights of the user, by means of authorisation registries where the processing rights of onboarded users are recorded, kept updated and remain available for auditing purposes, and which shall constitute the principal mechanism for authorisation;
(b)
issuing and verification of temporary processing rights, by means of authorisation registries where temporary access credentials of occasional, non-onboarded users, are recorded.
2. The authorisation registries referred to in paragraph 1 shall be established and maintained as a separate ICT component. This separate ICT component shall be either internal to the eFTI platform or part of an ICT system external to the eFTI platform with which the eFTI platform establishes secure communications, in accordance with Article 12(4).
3. The authorisation registries referred to in paragraph 1, point (a), shall maintain a uniquely identified ‘user profile’ for each onboarded business user, by recording at least the following information:
(a)
unique identification of the business user, expressed as a coded reference;
(b)
processing rights, expressed as references, where those references include:
(i)
references to the processing operations referred to in Article 8;
(ii)
period of time for which each of the processing rights referred to in point (b) is granted;
(iii)
the coded references of the eFTI data elements or groups of eFTI data elements, as specified in Section 2 of the Annex to Delegated Regulation (EU) 2024/2024, on which each of the processing operations referred to in Article 8 may be performed;
(c)
an indication of whether the business user may act as primary or temporary authoriser;
(d)
for business users designated as primary authoriser, the unique identification numbers of the existing onboarded user profiles that they are allowed to modify;
(e)
for business users designated as temporary authoriser, the temporary processing rights they are entitled to issue to non-onboarded users, expressed as references to the processing operations referred to in Article 8;
(f)
an indication of whether the business user may request notifications related to requests for access to eFTI data by competent authorities and related follow-up communications, when related to the eFTI CMDS for which the business user has processing rights.
4. The eFTI platform operator or, where the authorisation registry is established as a component of an ICT system external to the eFTI platform, the operator of the external ICT system, shall take measures to ensure the appropriate onboarding of the business users that may act as ‘primary authoriser’. Those measures shall, as a minimum, consist of:
(a)
identification and authentication, in accordance with the requirements laid down in Article 4(2), point (a);
(b)
verification of credentials stating that the business user is a data holder or constitutes the legal representative of a data holder, or that the business user is empowered to authorise, on behalf of a data holder, the processing of data in relation to which that data holder has rights or obligations as referred to in Article 1, point (23);
(c)
keeping a record of those credentials for auditing purposes.
5. The authorisation mechanism referred to in paragraph 1, point (b), shall include functionalities that comply, as a minimum, with the following specifications:
(a)
allow onboarded users with temporary authoriser designation to issue temporary processing rights to non-onboarded users, by recording in a dedicated registry the temporary access credentials of non-onboarded users, containing as a minimum:
(i)
contact details that identify the non-onboarded user and where electronic messages can be sent;
(ii)
the UUID of the eFTI CMDS to which the non-onboarded user is given temporary processing rights;
(iii)
the processing rights given to the non-onboarded user, expressed as references to the processing operations referred to in Article 8;
(iv)
the precise period of time within which those processing rights are valid;
(b)
allow the onboarded users with temporary authoriser designation to give temporary access to eFTI data to the non-onboarded users for whom they recorded temporary access credentials by sending, using the recorded contact details of the non-onboarded user, a message containing:
(i)
an access link to the eFTI platform;
(ii)
the UUID of each eFTI CMDS to which the non-onboarded user is given temporary processing rights;
(c)
when access to the eFTI platform is requested by a non-onboarded user, give the non-onboarded user access to the eFTI platform based on two-factor authentication, and allow them to perform processing operations based on their processing rights recorded in accordance with point (a);
(d)
terminate the login session of a non-onboarded user as soon as one of the following events occur:
(i)
the user acknowledges completion of the data processing session;
(ii)
the period of time referred to in point (a)(iv) expires.
6. The information recorded in the authorisation registries in accordance with paragraphs 1 to 5 shall be retained for auditing purposes, as a minimum, for the same period of time for which the eFTI CMDS, on which the respective users performed processing operations, is required to be kept available, in accordance with the applicable national or Union law, pursuant to Article 9(1), point (i), of Regulation (EU) 2020/1056.
7. eFTI platforms shall delete all information that constitute personal data in accordance with Regulation (EU) 2016/679 within a reasonable time after the expiration of the period referred to in paragraph 6.
Communication with DIWASS
1. To allow economic operators concerned to make available to competent authorities the regulatory information referred to in Article 2(1), point (a)(iv), of Regulation (EU) 2020/1056, eFTI platforms shall establish secure connections with the central system referred to in Article 27(3) of Regulation (EU) 2024/1157, through an application programming interface as referred to in Article 5(2) of Implementing Regulation (EU) 2025/1290, or where made available by a Member State, through connection to the local system operated by a competent authority in that Member State in accordance with Article 27(4) of Regulation (EU) 2024/1157 and that connects to the that central system in accordance with the requirements of Implementing Regulation (EU) 2025/1290.
2. Where eFTI platforms establish either of the connections referred to in paragraph 1, they shall also provide corresponding additional functionalities in accordance with Article 9(2) of this Regulation.
Transparency
1. eFTI platforms shall provide functionalities that allow business users to request and receive notifications, including in the form of periodical reports, based on appropriate authorisations. Those notifications and reports shall cover requests for access to eFTI data by competent authorities and related follow-up communications. They shall also cover processing operations by business users, when the business user requesting those notifications or reports constitutes a data holder or has processing rights for that data assigned in the authorisation registry referred to in Article 5(1), point (a) in relation to that data.
2. Where the notifications or reports referred to in paragraph 1 concern requests for access to eFTI data by competent authorities and related follow-up communications, those notifications shall contain at least the following information:
(a)
date and time of receipt of the request for access to eFTI data and, where lodged, of the follow-up communication;
(b)
the Member State of the competent authority that lodged the request for access to eFTI data;
(c)
the UUID of the eFTI CMDS for which the request for access to eFTI data was made;
(d)
where lodged, the information in the follow-up communication.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.