My bookmarksSign up free

Commission Decision (EU, Euratom) 2017/46 of 10 January… Article 10

Commission Decision (EU, Euratom) 2017/46 of 10 January… Article 10

Data owners

Article 10

1.   The data owner is responsible for the IT security of a specific data set to the Head of the Commission department and is accountable for the confidentiality, integrity and availability of the data set. 2.   In relation to this data set, the data owner shall: (a) ensure that all data sets under his or her responsibility are appropriately classified in accordance with Decision (EU, Euratom) 2015/443 and (EU, Euratom) 2015/444; (b) define the information security needs and inform the relevant system owners of these needs; (c) participate in the CIS risk assessment; (d) report any unresolvable disagreements between the data owner and the system owner to the head of the Commission department; (e) communicate IT security incidents as provided for in Article 15. 3.   Data owners may formally delegate some or all of their IT security tasks but they maintain their responsibilities as defined in this Article. The processes related to these responsibilities and activities shall be further detailed in implementing rules.

Read the full instrument → · Read this in context: CHAPTER 2 — ORGANISATION AND RESPONSIBILITIES →

Other provisions in CHAPTER 2 — ORGANISATION AND RESPONSIBILITIES

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 10 of Commission Decision (EU, Euratom) 2017/46 of 10 January… (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next