My bookmarksSign up free

Decision (EU) 2022/2359 Article 3

Decision (EU) 2022/2359 Article 3

Application of restrictions

Article 3

1.   For personal data processing activities set out in Article 1(1) the controller may restrict the rights referred to in Article 1(2) to safeguard the interests and objectives referred to in Article 25(1) of Regulation (EU) 2018/1725, where the exercise of those rights would endanger any of the following: (a) the assessment and reporting of potential breaches of professional duties and, where necessary, their subsequent investigation and follow-up, including suspension from duties, the safeguarding of which is in accordance with points (b), (c), (f) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (b) the informal and/or formal dignity at work procedures, including the consideration of cases that may result in such a procedure as set out in Part 0.5 of the ECB Staff Rules, the safeguarding of which is in accordance with points (b), (c), (f) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (c) the proper performance of DG/HR’s functions under the employment law framework at the ECB relating to performance management, promotion procedures or the direct appointment of ECB personnel, selection procedures and professional development, the safeguarding of which is in accordance with points (c) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (d) the examination of internal appeals brought by ECB personnel (including through administrative review or grievance procedures, special appeal procedures or medical committees) and their follow up, the safeguarding of which is in accordance with points (b), (c) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (e) the reporting of any illegal activity or breach of professional duties via the ECB’s whistleblowing tool or the assessment of requests by the Compliance and Governance Office (CGO) for protection of whistle-blowers or witnesses from retaliation, the safeguarding of which is in accordance with points (b), (c), (f) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (f) the activities of the CGO under the Ethics Framework of the ECB set out in Part 0 of the ECB Staff Rules and the rules on selection and appointment set out in Part 1A of the ECB Staff Rules, and the monitoring for compliance purposes of private financial activities including both the functions exercised by the external service provider appointed pursuant to Article 0.4.3.3 of the ECB Staff Rules and the assessment and follow-up of potential breaches resulting from such monitoring by the CGO, the safeguarding of which is in accordance with points (b), (c), (f) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (g) audits undertaken by the Directorate Internal Audit, investigative activities and internal administrative inquiries, the safeguarding of which is in accordance with points (b), (c) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (h) the performance of the ECB’s functions pursuant to Decision (EU) 2016/456 (ECB/2016/3), in particular the duty of the ECB to report any information about illegal activity, the safeguarding of which is in accordance with points (b), (c), (g) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (i) investigations conducted by the DPO on processing activities carried out at the ECB pursuant to point (b) of Article 4 of Decision (EU) 2020/655 (ECB/2020/28), the safeguarding of which is in accordance with points (b) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (j) investigations for the purposes of ensuring physical security at the ECB of persons, premises and property, whether handled internally or with external support, the gathering of threat intelligence and security incidents analysis, the safeguarding of which is in accordance with points (b), (c), (d) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (k) judicial proceedings, the safeguarding of which is in accordance with points (b), (c) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (l) the cooperation between the ECB and national criminal investigation authorities, in particular the provision of confidential information held by the ECB for disclosure to a national criminal investigation authority at the request of the latter, the safeguarding of which is in accordance with points (b), (c), (d) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (m) the cooperation between the ECB and the EPPO pursuant to Regulation (EU) 2017/1939, in particular the duty of the ECB to provide information about offences, the safeguarding of which is in accordance with points (b), (c), (d) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (n) the cooperation with EU bodies exercising a supervisory, oversight or auditing function to which the ECB is subject, the safeguarding of which is in accordance with points (c), (d), (g) and/or (h) of Article 25(1) of Regulation (EU) 2018/1725; (o) the performance of a mediator’s tasks pursuant to the internal dispute resolution framework at the ECB, in particular giving support to help resolve or prevent a work-related dispute, the safeguarding of which is in accordance with point (h) of Article 25(1) of Regulation (EU) 2018/1725; (p) the provision of the counselling services by the social counsellor to support ECB personnel, the safeguarding of which is in accordance with point (h) of Article 25(1) of Regulation (EU) 2018/1725. The categories of personal data in relation to which restrictions referred to in paragraph 1 may be applied are specified in Annexes I to XIV to this Decision. 2.   The controller may only apply a restriction where on a case-by-case assessment it concludes that the restriction: (a) is necessary and proportionate taking into account the risks to the rights and freedoms of the data subject; and (b) respects the essence of the fundamental rights and freedoms in a democratic society. 3.   The controller shall document its assessment in an internal assessment note which shall include the legal basis, the reasons for the restriction, the rights of the data subjects that are restricted, the data subjects affected, the necessity and proportionality of the restriction and the likely duration of the restriction. 4.   A decision to restrict the rights of a data subject pursuant to paragraph 1 to be taken by the controller shall be made at the level of the relevant business area head or deputy head in whose business area the main processing operation involving the personal data is carried out.

Read the full instrument →

Other provisions in Decision (EU) 2022/2359

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 3 of Decision (EU) 2022/2359 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next