Rules on privacy, security and the re-use of information
Article 9
1. Member States shall ensure that processing of personal data necessary for the operation of RIS is carried out in accordance with the Community rules protecting the freedoms and fundamental rights of individuals, including Directives 95/46/EC and 2002/58/EC. 2. Member States shall implement and maintain security measures to protect RIS messages and records against untoward events or misuse, including improper access, alteration or loss. 3. Directive 2003/98/EC of the European Parliament and of the Council of 17 November 2003 on the re-use of public sector information ( 8 ) shall apply.