My bookmarksSign up free

Commission Decision (EU) 2025/628 Article 9

Commission Decision (EU) 2025/628 Article 9

Safeguards and retention

Article 9

1.   The Commission shall implement safeguards to prevent abuse and unlawful access to or transfer of personal data in respect of which restrictions or exceptions apply or could be applied. Such safeguards shall include technical and organisational measures such as: (a) a clear definition of roles, responsibilities, procedural steps and access rights; (b) a secure electronic environment which prevents unlawful or accidental access to or transfer of electronic data to unauthorised persons; (c) a secure storage and processing of paper documents limited to what is strictly necessary to achieve the purpose of processing; (d) due monitoring of restrictions and a periodic review of their application. The reviews shall be conducted at least every six months and at the closure of the file. 2.   The personal data shall be retained in accordance with the applicable Commission retention rules to be defined in the records of processing kept under Article 31 of Regulation (EU) 2018/1725. At the end of the retention period, the personal data shall be deleted, anonymised or transferred to the archives in accordance with Article 13 of Regulation (EU) 2018/1725.

Read the full instrument →

Other provisions in Commission Decision (EU) 2025/628

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 9 of Commission Decision (EU) 2025/628 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next