Security of processing
Article 15
1. The Commission shall, following consultations with customs authorities and partner competent authorities, implement appropriate technical and organisational measures to ensure security of processing in accordance with Article 32 of Regulation (EU) 2016/679 and Article 33 of Regulation (EU) 2018/1725. 2. Customs authorities and partner competent authorities shall implement appropriate organisational measures to ensure the security of processing. 3. The technical measures and organisational measures referred to in paragraphs 1 and 2 shall be designed to: (a) ensure the security, integrity, confidentiality, availability and continuity of the personal data processed, in accordance with the relevant legislation; (b) protect against any unauthorised or unlawful processing, loss, use, disclosure of, or access to any personal data in their possession; (c) restrict disclosure of or access to personal data to the intended recipients in accordance with this Regulation, Regulation (EU) No 952/2013 and Union legislation other than customs legislation relevant for the specific Union non-customs formalities. 4. The joint controllers shall notify each other and provide assistance in case of security incidents, including personal data breaches. Such notification shall take place no later than 48 hours from the moment one of the joint controllers becomes aware of the security incident. 5. In the case of a personal data breach, the Commission shall notify the European Data Protection Supervisor in accordance with Article 34 of Regulation (EU) 2018/1725. 6. The joint controllers shall in any case notify each other of the following: (a) any potential or actual risk to the availability, confidentiality and integrity of the personal data processed in EU CSW-CERTEX; (b) any security incidents that are linked to the processing operation.