Specific security considerations
Article 8
1. The consent tool shall be designed and implemented to ensure the confidentiality, integrity and availability of processed data and to ensure non-repudiation of transactions. The technical and organisational implementation of it shall meet the requirements of the ETIAS security plan referred in Article 59(3) of Regulation (EU) 2018/1240 and of the rules on data protection and security applicable to the public website and the app for mobile devices referred to in Article 16(10) of Regulation (EU) 2018/1240. 2. The consent tool shall be designed and implemented in a way that precludes unlawful access to it. For this purpose, the consent tool shall limit the number of attempts to access the tool with the same travel document number, the same application number or the same unique code. The tool shall also include measures to protect against non-human behaviour. 3. The consent tool shall include time-out measures after some minutes of inactivity. 4. Additional details concerning the confidentiality, integrity and availability of processed data shall be subject of the technical specifications referred to in Article 73(3) of Regulation (EU) 2018/1240.