Security
Article 20
1. eu-LISA shall ensure the security and encryption of the API data and other PNR data, in particular data constituting personal data, that it processes pursuant to this Regulation. PIUs and air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation.eu-LISA, PIUs and air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other to ensure such security. 2. eu-LISA shall ensure the security and the confidentiality of the data related to flights and routes selected by the Member States in accordance with Article 12(4). The PIUs and the air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation. eu-LISA, PIUs and air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other to ensure such security. 3. eu-LISA shall take the measures necessary to ensure the security of the router and the API data and other PNR data, in particular data constituting personal data, transmitted through the router, including by establishing, implementing and regularly updating a security plan, a business continuity plan and a disaster recovery plan, in order to: (a) physically protect the router, including by making contingency plans for the protection of critical components thereof; (b) prevent any unauthorised processing of the API data or other PNR data, including any unauthorised access thereto and the copying, modification or deletion thereof, both during the transfer of the API data or other PNR data to and from the router and during any storage of the API data or other PNR data on the router where necessary to complete the transmission, in particular by means of appropriate encryption techniques; (c) ensure that the persons authorised to access the router have access only to the data covered by their access authorisation; (d) ensure that it is possible to verify and establish to which PIUs the API data or other PNR data are transmitted through the router; (e) properly report to its Management Board any faults in the functioning of the router; (f) monitor the effectiveness of the security measures required under this Article and under Regulation (EU) 2018/1725, and assess and update those security measures where necessary in the light of technological or operational developments. The measures referred to in the first subparagraph of this paragraph shall not affect Article 32 of Regulation (EU) 2016/679, Article 33 of Regulation (EU) 2018/1725 or Article 29 of Directive (EU) 2016/680.