My bookmarksSign up free

Council Decision 2008/633/JHA of 23 June 2008 concerning… Article 9

Council Decision 2008/633/JHA of 23 June 2008 concerning… Article 9

Data security

Article 9

1.   The Member State responsible shall ensure the security of the data during transmission to the designated authorities and when received by them. 2.   Each Member State shall adopt the necessary security measures with respect to data to be retrieved from the VIS pursuant to this Decision and to be subsequently stored, in particular in order to: (a) physically protect data, including by making contingency plans for the protection of critical infrastructure; (b) deny unauthorised persons access to national installations in which the Member State stores data (checks at entrance to the installation); (c) prevent the unauthorised reading, copying, modification or removal of data media (data media control); (d) prevent the unauthorised inspection, modification or deletion of stored personal data (storage control); (e) prevent the unauthorised processing of data from the VIS (control of data processing); (f) ensure that persons authorised to access the VIS have access only to the data covered by their access authorisation, by means of individual and unique user identities and confidential access modes only (data access control); (g) ensure that all authorities with a right of access to the VIS create profiles describing the functions and responsibilities of persons who are authorised to access and search the data and make these profiles available to the national supervisory authorities referred to in Article 8(5) without delay upon their request (personnel profiles); (h) ensure that it is possible to verify and establish to which bodies personal data may be transmitted using data communication equipment (communication control); (i) ensure that it is possible to verify and establish what data has been retrieved from the VIS, when, by whom and for what purpose (control of data recording); (j) prevent the unauthorised reading and copying of personal data during their transmission from the VIS, in particular by means of appropriate encryption techniques (transport control); (k) monitor the effectiveness of the security measures referred to in this paragraph and take the necessary organisational measures related to internal monitoring to ensure compliance with this Decision (self-auditing).

Read the full instrument →

Other provisions in Council Decision 2008/633/JHA of 23 June 2008 concerning…

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 9 of Council Decision 2008/633/JHA of 23 June 2008 concerning… (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next