Responsibility for the use of data
Article 29
1. Each Member State shall ensure that the data are processed lawfully, and in particular that only duly authorised staff have access to data processed in the VIS for the performance of their tasks in accordance with this Regulation. The Member State responsible shall ensure in particular that: (a) the data are collected lawfully; (b) the data are transmitted lawfully to the VIS; (c) the data are accurate and up-to-date when they are transmitted to the VIS. 2. The management authority shall ensure that the VIS is operated in accordance with this Regulation and its implementing rules referred to in Article 45(2). In particular, the management authority shall: (a) take the necessary measures to ensure the security of the central VIS and the communication infrastructure between the central VIS and the national interfaces, without prejudice to the responsibilities of each Member State; (b) ensure that only duly authorised staff have access to data processed in the VIS for the performance of the tasks of the management authority in accordance with this Regulation. 3. The management authority shall inform the European Parliament, the Council and the Commission of the measures which it takes pursuant to paragraph 2.