Availability
An eFTI platform shall remain available for access by competent authorities, as specified in Article 3, for at least the period of time for which the eFTI CMDSs recorded on that platform have the status ‘active’ and, where applicable, ‘inactive’, as assigned by the eFTI platform in accordance with the specifications laid down in the Annex to this Regulation.
Security of data exchanges
1. For communication with an eFTI Gate, eFTI platforms shall:
(a)
maintain an eDelivery Access Point, in compliance with the eDelivery message exchange specifications, or an access point compliant with the equivalent message exchange specifications supported by the eFTI Gate, where such message exchange specifications are established by a Member State in accordance with Article 9(4) of Implementing Regulation (EU) 2024/1942;
(b)
use secure procedures and protocols for receiving, recording, retrieving and validating the security keys or security certificates of the eFTI Gate.
2. The access points referred to in paragraph 1, point (a), shall use security certificates issued, through a certificate authority, by the Member State where the eFTI platform received the compliance certificate referred to in Article 12(1) of Regulation (EU) 2020/1056.
3. All communication between the eFTI platform and the eFTI Gate shall take place by means of message exchanges that comply with the specifications laid down in Article 9(3) and (4) of Implementing Regulation (EU) 2024/1942.
4. For communication with tributary ICT systems or other external ICT systems hosting components that perform certain eFTI platform functionalities, eFTI platforms shall, as a minimum:
(a)
maintain access points with valid security keys or security certificates;
(b)
use secure procedures and protocols for receiving, recording, retrieving and validating the security keys or security certificates of those other ICT systems.
5. For communication with DIWASS, eFTI platforms shall:
(a)
maintain access points that comply with the specifications referred to in Article 12 of Implementing Regulation (EU) 2025/1290;
(b)
use secure procedures and protocols for receiving, recording, retrieving and validating the security key of DIWASS;
(c)
maintain an application programming interface that allows it to receive from DIWASS data related to the consignee signature, when the consignee is a waste treatment facility as referred to in Regulation (EU) 2024/1157.
Security of stored data
eFTI platform operators shall define and implement measures that ensure the security and preservation of the data stored on eFTI platforms, and in particular:
(a)
where eFTI data is stored on physical storage devices managed by the platform operator:
(i)
measures to ensure sufficient data storage, including for back-up;
(ii)
measures to ensure protection against physical damage to physical storage units, both intentional or accidental, human-made or as a result of natural calamities;
(iii)
measures to ensure data recovery in case of damage;
(iv)
measures implementing appropriate information security risk management policies, including regular security vulnerability assessments and their follow-up;
(b)
where eFTI data is stored by means of cloud storage, measures to ensure that cloud storage space is purchased from service providers that comply with main international standards and best practices for cloud security and protection of personal data;
(c)
measures to ensure that eFTI data is stored within the Union or under Union or Member State jurisdiction.