My bookmarksSign up free

Commission Decision (EU) 2021/2243 Article 2

Commission Decision (EU) 2021/2243 Article 2

Applicable exceptions and restrictions

Article 2

1.   Where the Commission exercises its duties with respect to data subjects’ rights under Regulation (EU) 2018/1725, it shall consider whether any of the exceptions laid down in that Regulation apply. 2.   Subject to Articles 3 to 7 of this Decision, where the exercise of the rights and obligations provided for in Articles 14 to 17, 19, 20 and 35 of Regulation (EU) 2018/1725 in relation to personal data processed by the Commission which would undermine the purpose of providing IT security operations and services, inter alia, by revealing the Commission’s investigative tools, vulnerabilities and methods, or would adversely affect the rights and freedoms and the security of other data subjects, in particular for the processing of personal data in order to: — communicate alerts and warnings relating to IT security events and incidents; — respond to and contain IT security events and incidents; — facilitate tools and operations through security audits, security assessments and vulnerability management; — increase the awareness of Commission staff in the field of cybersecurity; — monitor, detect and prevent the occurrence of IT security events and incidents; — review privileged user accounts. the Commission may restrict the application of: (a) Articles 14 to 17, 19, 20 and 35 of Regulation (EU) 2018/1725; (b) the principle of transparency laid down in Article 4(1)(a), of Regulation (EU) 2018/1725, in so far as its provisions correspond to the rights and obligations provided for in Articles 14 to 17, 19 and 20 of Regulation (EU) 2018/1725. The Commission may do so in line with Article 25(1)(c), (d) and (h) of Regulation (EU) 2018/1725. 3.   Subject to Articles 3 to 7, the Commission may restrict the rights and obligations referred to in paragraph 2 of this Article: (a) where the exercise of those rights and obligations in respect of the personal data obtained from another EU institution, body, agency or office could be restricted by that other EU institution, body, agency or office on the basis of legal acts provided for in Article 25 of Regulation (EU) 2018/1725, or pursuant to Chapter IX of that Regulation, in accordance with Regulation (EU) 2016/794 of the European Parliament and of the Council  ( 4 ) or in accordance with Council Regulation (EU) 2017/1939  ( 5 ) ; (b) where the exercise of those rights and obligations in respect of the personal data obtained from the competent authority of a Member State could be restricted by competent authorities of that Member State on the basis of legislative measures referred to in Article 23 of Regulation (EU) 2016/679 of the European Parliament and of the Council  ( 6 ) , or under national measures transposing Article 13(3), Article 15(3) or Article 16(3) of Directive (EU) 2016/680 of the European Parliament and of the Council  ( 7 ) ; (c) where the exercise of those rights and obligations would undermine the Commission’s cooperation with non-EU countries or international organisations on common cybersecurity threats. Before applying restrictions in the circumstances referred to in the first subparagraph, (a) and (b), the Commission shall consult the relevant EU institutions, bodies, agencies, offices or Member State authorities concerning the potential grounds for imposing restrictions and the necessity and proportionality of the restrictions concerned, unless this would undermine the activities of the Commission and unless it is clear to the Commission that the application of a restriction is provided for by one of the acts referred to in those points or that consultation would undermine the purpose of its activities under Decision (EU, Euratom) 2017/46. The first subparagraph, (c), shall not apply where the interests or fundamental rights and freedoms of the data subject override the interest of the Commission to cooperate with non-EU countries or international organisations. 4.   Paragraphs 1, 2 and 3 shall be without prejudice to the application of other Commission Decisions laying down internal rules governing the provision of information to data subjects and the restriction of application of certain rights under Article 25 of Regulation (EU) 2018/1725. 5.   Any restriction of the rights and obligations, referred to in paragraph 2 shall be necessary and proportionate to the risks to the rights and freedoms of data subjects. 6.   A necessity and proportionality test shall be carried out on a case-by-case basis before restrictions are applied and restrictions shall be limited to what is strictly necessary to achieve the intended purpose.

Read the full instrument →

Other provisions in Commission Decision (EU) 2021/2243

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 2 of Commission Decision (EU) 2021/2243 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next