My bookmarksSign up free

Commission Implementing Regulation (EU) 2025/2243 CHAPTER III — DATA PROCESSING ON eFTI PLATFORMS

Article 8–Article 10 · 3 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

The eFTI CMDS

Article 8

1.   eFTI platforms shall manage the processing of eFTI data based on uniquely identified data sets, each constituting an eFTI CMDS. 2.   eFTI CMDS shall be generated by selecting all the data elements that constitute the eFTI data subsets corresponding to the applicable regulatory information requirements for a specific consignment movement, where all the data elements common to two or more eFTI data subsets shall be included only once. 3.   All eFTI data processed on an eFTI platform shall comply with the definitions and technical characteristics, including structure, code lists and business rules, established by Delegated Regulation (EU) 2024/2024.

Processing operations

Article 9

1.   eFTI platforms shall provide functionalities that enable business users, following validation of their processing rights by means of an authorisation mechanism referred to in Article 5, to perform the following processing operations on eFTI data: (a) create eFTI CMDS; (b) edit eFTI CMDS; (c) read eFTI CMDS data; (d) download a copy of eFTI CMDS data; (e) consignor signature; (f) carrier signature; (g) consignee signature; (h) combined transport ‘stamp’ by competent authority in sea port, inland waterway port or railway station; (i) archive eFTI CMDS. 2.   The eFTI platform functionalities referred to in Article 6 shall enable business users, following validation of their processing rights by means of an authorisation mechanism referred to in Article 5, to perform the following processing operations on eFTI data: (a) download a copy of waste shipments documents; (b) submit waste shipment carrier transfer confirmations, in accordance with Annex II, Part B, point 3 and Part C point 3 of Implementing Regulation (EU) 2025/1290; (c) edit submitted waste shipments carrier transfer confirmations, in accordance with Annex II, Part B, point 4 and Part C point 4 of Implementing Regulation (EU) 2025/1290. 3.   The processing operations referred to in paragraphs 1 and 2 shall be as specified in the Annex, together with the actions to be performed by eFTI platforms to enable business users to perform those operations. 4.   Before allowing a business user to perform processing operations on eFTI data, the platform shall inform the user through clearly worded messages that, by processing the data on the eFTI platform, the user consents that: (a) the data processed by the business user may automatically be made available to the competent authorities, specifically whenever the eFTI platform receives a request for access to eFTI data, from a competent authority, for the specific eFTI CMDS of which that data is part; (b) an audit trail of the data processing operations made by the business user is recorded, in accordance with the provisions in paragraph 6, and may be made available to the competent authorities for consultation in accordance with applicable Union law or national law. 5.   eFTI platforms shall log each processing operation performed by a business user on an eFTI CMDS, by recording in relation to each data element processed, the following information: (a) the UUID of the eFTI CMDS; (b) for onboarded users, a coded identification linked to their user account; (c) for non-onboarded users, identification information provided by the user in the context of the two-factor authentication referred to in Article 5(5), point (c); (d) date and time; (e) type of operation performed, identified in accordance with paragraphs 1 and 2; when the processing operation involves modifying or deleting the value of a data element, the original value of the data element shall also be maintained. 6.   eFTI platforms shall record and keep the eFTI CMDS data readily available for access by both business users and competent authorities on an online data storage system, for at least the period in which the eFTI CMDS has the status ‘active’ and, where applicable, ‘inactive’, as assigned by the eFTI platform in accordance with the specifications laid down in the Annex to this Regulation. 7.   eFTI platforms shall maintain the eFTI CMDS that have the status ‘ready to archive’ or ‘archived’ and the corresponding processing operation logs accessible for access by competent authorities for the periods of time referred to in Article 9(1), point (i), of Regulation (EU) 2020/1056. 8.   eFTI platforms shall delete all information that constitute personal data in accordance with Regulation (EU) 2016/679 within a reasonable time after the expiration of the periods referred to in paragraph 8.

Human-to-machine user interfaces

Article 10

1.   The human-to-machine interfaces referred to in Article 4(1), point (a) shall provide the following web or application-based functionalities: (a) allow business users to interact with the eFTI platform for purposes of identification, authentication and authorisation by the eFTI platform in accordance with Articles 4 and 5 and, respectively, for processing eFTI data on the eFTI platform in accordance with Articles 5 and 9; (b) allow authorised users to download the unique electronic identifying link (UIL) of the eFTI CMDS, and enable them to communicate it in machine-readable format to the competent authorities; (c) allow authorised users to download a human-readable copy of the eFTI CMDS and, where applicable, of the waste shipment documents, and to display these copies for inspection by competent authorities’ officers, when required by those officers in accordance with Article 4(2) of Regulation (EU) 2020/1056. 2.   The human-readable copies referred to in paragraph 1, point (d), shall include a machine-readable coded reference of the eFTI platform certification mark and an indication of the date and time of the download in the form of a time stamp. 3.   eFTI platforms’ human-to-machine interfaces shall include access protection features to prevent unauthorised access to eFTI data and eFTI platform functionalities when the device by the means of which the business user accesses the eFTI platform is not under the control of the user.

Back to Commission Implementing Regulation (EU) 2025/2243 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next