My bookmarksSign up free

Regulation (EU) 2017/2226 Article 43

Regulation (EU) 2017/2226 Article 43

Data security

Article 43

1.   The Member State responsible shall ensure the security of the data before and during the transmission to the NUI. Each Member State shall ensure the security of the data it receives from the EES. 2.   Each Member State shall, in relation to its national border infrastructure, adopt the necessary measures, including a security plan and a business continuity and disaster recovery plan, in order to: (a) physically protect data, including by making contingency plans for the protection of critical infrastructure; (b) deny unauthorised persons access to data-processing equipment and national installations in which the Member State carries out operations in accordance with the purposes of the EES; (c) prevent the unauthorised reading, copying, modification or removal of data media; (d) prevent the unauthorised entering of data and the unauthorised inspection, modification or erasure of stored personal data; (e) prevent the use of automated data-processing systems by unauthorised persons using data communication equipment; (f) prevent the unauthorised processing of data in the EES and any unauthorised modification or erasure of data processed in the EES; (g) ensure that persons authorised to access the EES have access only to the data covered by their access authorisation, by means of individual and unique user identities and confidential access modes only; (h) ensure that all authorities with a right of access to the EES create profiles describing the functions and responsibilities of persons who are authorised to enter, amend, erase, consult and search the data and make their profiles available to the supervisory authorities; (i) ensure that it is possible to verify and establish to which bodies personal data may be transmitted using data communication equipment; (j) ensure that it is possible to verify and establish which data have been processed in the EES, as well as when, by whom and for what purpose they have been processed; (k) prevent the unauthorised reading, copying, modification or erasure of personal data during the transmission of personal data to or from the EES or during the transport of data media, in particular by means of appropriate encryption techniques; (l) ensure that, in the event of an interruption, installed systems can be restored to normal operation; (m) ensure reliability by making sure that any faults in the functioning of the EES are properly reported; (n) monitor the effectiveness of the security measures referred to in this paragraph and take the necessary organisational measures related to internal monitoring to ensure compliance with this Regulation. 3.   As regards the operation of the EES, eu-LISA shall take the necessary measures in order to achieve the objectives set out in paragraph 2, including the adoption of a security plan and a business continuity and disaster recovery plan. eu-LISA shall also ensure reliability by making sure that necessary technical measures are put in place to ensure that personal data can be restored in the event of corruption due to a malfunctioning of the EES. 4.   eu-LISA and the Member States shall cooperate in order to ensure a harmonised data security approach based on a security risk management process encompassing the entire EES.

Read the full instrument → · Read this in context: CHAPTER VI — DEVELOPMENT, OPERATION AND RESPONSIBILITIES →

Other provisions in CHAPTER VI — DEVELOPMENT, OPERATION AND RESPONSIBILITIES

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 43 of Regulation (EU) 2017/2226 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next