What changed, Commission Implementing Regulation (EU) 2015/1501 of 8 September 2015 on the interoperability framework pursua…
2015-09-08 → 2015-09-09 · no interpretation, just the text delta
| on 2015-09-08 | eu-eurlex:32015r1501:2015-09-08 (2015-09-08 → 2015-09-08) · official source ↗ |
| on 2015-09-09 | eu-eurlex:32015r1501:2015-09-09 (2015-09-09 → open) · official source ↗ |
Open the structured article comparison → matched by provision anchor, with changed, added, removed and unchanged articles separated
151 line(s) in the old middle, 103 in the new; 1 unchanged leading and 1 trailing lines trimmed.
+ ### Article 1 — Subject matter − ### art_1 − − Article 1 + (a) minimum technical requirements related to the assurance levels and the mapping of national assurance levels of notified electronic identification means issued under notified electronic identification schemes under Article 8 of Regulation (EU) No 910/2014 as set out in Articles 3 and 4; − | (a) | minimum technical requirements related to the assurance levels and the mapping of national assurance levels of notified electronic identification means issued under notified electronic identification schemes under Article 8 of Regulation (EU) No 910/2014 as set out in Articles 3 and 4; | − | --- | --- | + (b) minimum technical requirements for interoperability, as set out in Articles 5 and 8; − | (b) | minimum technical requirements for interoperability, as set out in Articles 5 and 8; | − | --- | --- | + (c) the minimum set of person identification data uniquely representing a natural or legal person as set out in Article 11 and in the Annex; − | (c) | the minimum set of person identification data uniquely representing a natural or legal person as set out in Article 11 and in the Annex; | − | --- | --- | + (d) common operational security standards as set out in Articles 6, 7, 9 and 10; − | (d) | common operational security standards as set out in Articles 6, 7, 9 and 10; | − | --- | --- | + (e) arrangements for dispute resolution as set out in Article 13. − | (e) | arrangements for dispute resolution as set out in Article 13. | − | --- | --- | + ### Article 2 — Definitions − ### art_2 − − Article 2 + (1) ‘node’ means a connection point which is part of the electronic identification interoperability architecture and is involved in cross-border authentication of persons and which has the capability to recognise and process or forward transmissions to other nodes by enabling the national electronic… − | (1) | ‘node’ means a connection point which is part of the electronic identification interoperability architecture and is involved in cross-border authentication of persons and which has the capability to recognise and process or forward transmissions to other nodes by enabling the national electr… − | --- | --- | + (2) ‘node operator’ means the entity responsible for ensuring that the node performs correctly and reliably its functions as a connection point. − | (2) | ‘node operator’ means the entity responsible for ensuring that the node performs correctly and reliably its functions as a connection point. | − | --- | --- | + ### Article 3 — Minimum technical requirements related to the assurance levels − ### art_3 − − Article 3 + ### Article 4 — Mapping of national assurance levels − ### art_4 − − Article 4 + The mapping of national assurance levels of the notified electronic identification schemes shall follow the requirements laid down in Implementing Regulation (EU) 2015/1502. ►C1 The results of the mapping shall be notified to the Commission using the notification template laid down in Commission Imp… − The mapping of national assurance levels of the notified electronic identification schemes shall follow the requirements laid down in Implementing Regulation (EU) 2015/1502. The results of the mapping shall be notified to the Commission using the notification template laid down in Commission Impleme… + ### Article 5 — Nodes − ### art_5 + **1.** A node in one Member State shall be able to connect with nodes of other Member States. − Article 5 + **2.** The nodes shall be able to distinguish between public sector bodies and other relying parties through technical means. − 1. A node in one Member State shall be able to connect with nodes of other Member States. + **3.** A Member State implementation of the technical requirements set out in this Regulation shall not impose disproportionate technical requirements and costs on other Member States in order for them to interoperate with the implementation adopted by the first Member State. − 2. The nodes shall be able to distinguish between public sector bodies and other relying parties through technical means. + ### Article 6 — Data privacy and confidentiality − 3. A Member State implementation of the technical requirements set out in this Regulation shall not impose disproportionate technical requirements and costs on other Member States in order for them to interoperate with the implementation adopted by the first Member State. + **1.** Protection of privacy and confidentiality of the data exchanged and the maintenance of data integrity between the nodes shall be ensured by using best available technical solutions and protection practices. − ### art_6 + **2.** The nodes shall not store any personal data, except for the purpose set out in Article 9(3). − Article 6 − − 1. Protection of privacy and confidentiality of the data exchanged and the maintenance of data integrity between the nodes shall be ensured by using best available technical solutions and protection practices. + ### Article 7 — Data integrity and authenticity for the communication − 2. The nodes shall not store any personal data, except for the purpose set out in Article 9(3). − − ### art_7 − Article 7 − + ### Article 8 — Message format for the communication − ### art_8 − Article 8 − + (a) proper processing of the minimum set of person identification data uniquely representing a natural or legal person; − | (a) | proper processing of the minimum set of person identification data uniquely representing a natural or legal person; | − | --- | --- | + (b) proper processing of the assurance level of the electronic identification means; − | (b) | proper processing of the assurance level of the electronic identification means; | − | --- | --- | + (c) distinction between public sector bodies and other relying parties; − | (c) | distinction between public sector bodies and other relying parties; | − | --- | --- | + (d) flexibility to meet the needs of additional attributes relating to identification. − | (d) | flexibility to meet the needs of additional attributes relating to identification. | − | --- | --- | + ### Article 9 — Management of security information and metadata − ### art_9 + **1.** The node operator shall communicate the metadata of the node management in a standardised machine processable manner and in a secure and trustworthy way. − Article 9 + **2.** At least the parameters relevant to security shall be retrieved automatically. − 1. The node operator shall communicate the metadata of the node management in a standardised machine processable manner and in a secure and trustworthy way. + **3.** The node operator shall store data which, in the event of an incident, enable reconstruction of the sequence of the message exchange for establishing the place and the nature of the incident. The data shall be stored for a period of time in accordance with national requirements and, as a mini… − 2. At least the parameters relevant to security shall be retrieved automatically. + ### Article 10 — Information assurance and security standards − 3. The node operator shall store data which, in the event of an incident, enable reconstruction of the sequence of the message exchange for establishing the place and the nature of the incident. The data shall be stored for a period of time in accordance with national requirements and, as a minimum,… + **1.** Node operators of nodes providing authentication shall prove that, in respect of the nodes participating in the interoperability framework, the node fulfils the requirements of standard ISO/IEC 27001 by certification, or by equivalent methods of assessment, or by complying with national legis… − | (a) | node's identification; | − | --- | --- | + **2.** Node operators shall deploy security critical updates without undue delay. − | (b) | message identification. | − | --- | --- | + ### Article 11 — Person identification data − | (c) | message date and time. | − | --- | --- | + **1.** A minimum set of person identification data uniquely representing a natural or a legal person shall meet the requirements set out in the Annex when used in a cross-border context. − ### art_10 + **2.** A minimum data set for a natural person representing a legal person shall contain the combination of the attributes listed in the Annex for natural persons and legal persons when used in a cross-border context. − Article 10 + **3.** Data shall be transmitted based on original characters and, where appropriate, also transliterated into Latin characters. − 1. Node operators of nodes providing authentication shall prove that, in respect of the nodes participating in the interoperability framework, the node fulfils the requirements of standard ISO/IEC 27001 by certification, or by equivalent methods of assessment, or by complying with national legislati… + ### Article 12 — Technical specifications − 2. Node operators shall deploy security critical updates without undue delay. + **1.** Where it is justified by the process of implementation of the interoperability framework, the Cooperation Network established by Implementing Decision (EU) 2015/296 may adopt opinions pursuant to Article 14(d) thereof on the need to develop technical specifications. Such technical specificati… − ### art_11 + **2.** Pursuant to the opinion referred to in paragraph 1 the Commission in cooperation with Member States shall develop the technical specifications as part of the digital service infrastructures of Regulation (EU) No 1316/2013. − Article 11 + **3.** The Cooperation Network shall adopt an opinion pursuant to Article 14(d) of Implementing Decision (EU) 2015/296 in which it evaluates whether and to what extent the technical specifications developed under paragraph 2 correspond to the need identified in the opinion referred to in paragraph 1… − 1. A minimum set of person identification data uniquely representing a natural or a legal person shall meet the requirements set out in the Annex when used in a cross-border context. + **4.** The Commission shall provide a reference implementation as an example interpretation of the technical specifications. Member States may apply this reference implementation or use it as a sample when testing other implementations of the technical specifications. − 2. A minimum data set for a natural person representing a legal person shall contain the combination of the attributes listed in the Annex for natural persons and legal persons when used in a cross-border context. + ### Article 13 — Dispute resolution − 3. Data shall be transmitted based on original characters and, where appropriate, also transliterated into Latin characters. + **1.** Where possible, any dispute concerning the interoperability framework shall be resolved by the concerned Member States through negotiation. − ### art_12 + **2.** If no solution is reached in accordance with paragraph 1, the Cooperation Network established in accordance with Article 12 of Implementing Decision (EU) 2015/296 shall have competence in the dispute in accordance with its rules of procedure. − Article 12 + ### Article 14 — Entry into force − 1. Where it is justified by the process of implementation of the interoperability framework, the Cooperation Network established by Implementing Decision (EU) 2015/296 may adopt opinions pursuant to Article 14(d) thereof on the need to develop technical specifications. Such technical specifications … + This Regulation shall enter into force on the twentieth day following that of its publication in the *Official Journal of the European Union*. − 2. Pursuant to the opinion referred to in paragraph 1 the Commission in cooperation with Member States shall develop the technical specifications as part of the digital service infrastructures of Regulation (EU) No 1316/2013. − − 3. The Cooperation Network shall adopt an opinion pursuant to Article 14(d) of Implementing Decision (EU) 2015/296 in which it evaluates whether and to what extent the technical specifications developed under paragraph 2 correspond to the need identified in the opinion referred to in paragraph 1 or … − − 4. The Commission shall provide a reference implementation as an example interpretation of the technical specifications. Member States may apply this reference implementation or use it as a sample when testing other implementations of the technical specifications. − − ### art_13 − − Article 13 − − 1. Where possible, any dispute concerning the interoperability framework shall be resolved by the concerned Member States through negotiation. − − 2. If no solution is reached in accordance with paragraph 1, the Cooperation Network established in accordance with Article 12 of Implementing Decision (EU) 2015/296 shall have competence in the dispute in accordance with its rules of procedure. − − ### art_14 − − Article 14 − − This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |