Obligations of legal entities establishing and managing a repository which is part of the repositories system
Article 37
Any legal entity establishing and managing a repository which is part of the repositories system shall perform the following actions: (a) inform the relevant national competent authorities of its intention to physically locate the repository or part of it in their territory and notify them once the repository becomes operational; (b) put in place security procedures ensuring that only users whose identity, role and legitimacy has been verified can access the repository or upload the information referred to in Article 33(2); (c) continuously monitor the repository for events alerting to potential incidents of falsification in accordance to Article 36(b); (d) provide for the immediate investigation of all potential incidents of falsification flagged in the system in accordance with Article 36(b) and for the alerting of national competent authorities, the European Medicines Agency and the Commission should the falsification be confirmed; (e) carry out regular audits of the repository to verify compliance with the requirements of this Regulation. Audits shall take place at least annually for the first five years after this Regulation becomes applicable in the Member State where the repository is physically located, and at least every three years thereafter. The outcome of those audits shall be provided to competent authorities upon request; (f) make the audit trail referred to in Article 35(1)(g) immediately available to competent authorities upon their request; (g) make the reports referred to in Article 36(j) available to competent authorities upon their request.