Common measures
Article 2
1. Member States shall ensure that their competent authorities have access to ICT systems that can process the unique electronic identifying links (UIL) communicated by the economic operators pursuant to Article 4(3) of Regulation (EU) 2020/1056, and that allow their competent authorities’ officers to access and process eFTI data in either of the following procedures: (a) by directly processing the UIL, when communicated by the economic operator in machine readable format, by displaying it on the screen of an electronic device or printed on a physical support such as paper or, when the competent authority chooses to allow such communication, also by sending it by email or other electronic messaging application; (b) by retrieving first the UIL, as communicated by the economic operators through publication on a dedicated registry, by means of a unique identifier associated with a transport operation. 2. Member States shall ensure that the ICT systems referred to in paragraph 1 provide at least the following functionalities: (a) duly authenticated identification and due authorisation of the competent authorities’ officers, each time an officer lodges a request for access to eFTI data; (b) mediation of the requests for access to eFTI data lodged by the competent authorities’ officers, including retrieval of the information requested from the appropriate eFTI platform or platforms, by means of secure connections to those platforms. 3. To implement the functionalities listed in paragraph 2, those ICT systems shall comprise at least the following components: (a) authority access points (AAP); (b) an authorisation registry; (c) eFTI Gates; (d) a search mechanism; (e) a user application. 4. Member States shall ensure that the components listed in paragraph 3 comply with the requirements laid down in Chapter II. Member States shall be responsible for the setting up, hosting, development, availability, monitoring, updating and maintenance of those components and for the security of the information processed within those components. Where two or more Member States set up or develop one or more of those components jointly, they shall be jointly responsible for their setting up, hosting, development, availability, monitoring, updating, maintenance and security. 5. Member States remain responsible for ensuring that the access and processing by competent authorities of eFTI data is done only for the purposes of checking compliance with the applicable EU and national legal provisions, and in accordance with applicable EU and national provisions laying down the conditions for performing those compliance checks, and rules on respect of personal data privacy and confidentiality of commercial data.