Safeguards and retention
Article 9
1. The Commission shall implement safeguards to prevent abuse and unlawful access to or transfer of personal data in respect of which restrictions or exceptions apply or could be applied. Such safeguards shall include technical and organisational measures such as: (a) a clear definition of roles, responsibilities, procedural steps and access rights; (b) a secure electronic environment which prevents unlawful or accidental access to or transfer of electronic data to unauthorised persons; (c) a secure storage and processing of paper documents limited to what is strictly necessary to achieve the purpose of processing; (d) due monitoring of restrictions and a periodic review of their application. The reviews shall be conducted at least every six months and at the closure of the file. 2. The personal data shall be retained in accordance with the applicable Commission retention rules to be defined in the records of processing kept under Article 31 of Regulation (EU) 2018/1725. At the end of the retention period, the personal data shall be deleted, anonymised or transferred to the archives in accordance with Article 13 of Regulation (EU) 2018/1725.