Safeguards and storage periods
Article 8
1. The Commission shall implement safeguards to prevent abuse and unlawful access to or transfer of personal data in respect of which restrictions apply or could be applied. Such safeguards shall include technical and organisational measures and be detailed as necessary in the Commission’s internal procedures. The safeguards shall include: (a) a clear definition of roles, responsibilities, access rights and procedural steps; (b) a secure electronic environment which prevents unlawful and accidental access or transfer of electronic data to unauthorised persons; (c) a secure storage and processing of paper-based documents; and (d) due monitoring of restrictions and a periodic review of their application. 2. The personal data shall be retained in accordance with Article 6(11) of Decision C (2024)1420. At the end of the retention period, the Commission shall delete the personal data.