Security incidents
Article 44
1. Any event that has or may have an impact on the security of the EES and may cause damage or loss to data stored in the EES shall be considered to be a security incident, in particular where unauthorised access to data may have occurred or where the availability, integrity and confidentiality of data has or may have been compromised. 2. Security incidents shall be managed so as to ensure a quick, effective and proper response. 3. Without prejudice to the notification and communication of a personal data breach pursuant to Article 33 of Regulation (EU) 2016/679, Article 30 of Directive (EU) 2016/680, or both, Member States shall notify the Commission, eu-LISA and the European Data Protection Supervisor of security incidents. In the event of a security incident in relation to the EES Central System, eu-LISA shall notify the Commission and the European Data Protection Supervisor. 4. Information regarding a security incident that has or may have an impact on the operation of the EES or on the availability, integrity and confidentiality of the data shall be provided to the Member States and reported in compliance with the incident management plan to be provided by eu-LISA. 5. The Member States concerned and eu-LISA shall cooperate in the event of a security incident.