Commission Implementing Regulation (EU) 2024/3084 of 4 December 2024 on the functioning of the information system pursuant to Regulation (EU) 2023/1115
as it stood on 2026-07-17, permalink: /eu-eurlex/32024r3084/2026-07-17
2 versions · click any mark to read the law as it stood that day · ▌ the one you are reading
Outline, 22 provisions
Article 1 Article 2 Article 3 Article 4 Article 4a Article 5 Article 6 Article 7 Article 8 Article 8a Article 9 Article 10 Article 11 Article 12 Article 13 Article 14 Article 15 Article 15a Article 16 Article 17 Article 18 Article 19
CHAPTER I — GENERAL PROVISIONS
This Regulation lays down the rules for the functioning of the Information System, including rules for the protection of personal data, exchange of data with other IT systems and contingency arrangements in the event of unavailability of the functionalities of the Information System.
1. The Commission shall:▼M1(a) develop the Information System;▼B(b) ensure the functioning, maintenance, support and any necessary update or development of the Information System.
2. The Information System shall be used by operators, and where applicable, their authorised representatives, for submitting and managing Due Diligence Statements and Simplified Declarations, by Member States to make information available pursuant to Article 4a(4) of Regulation (EU) 2023/1115, and by downstream operators and by traders to comply with their obligations in accordance with Regulation (EU) 2023/1115. It shall also be used by competent authorities, customs authorities and the Commission for accessing, processing and acting on Due Diligence Statements and Simplified Declarations, including the exchange of information containing personal data between competent authorities, customs authorities and the Commission in relation to implementation and enforcement of Regulation (EU) 2023/1115. Any such exchange of information shall comply with the rules on the protection of personal data laid down in Regulations (EU) 2016/679 and (EU) 2018/1725.
3. The Due Diligence Statements are attributed in the Information System to the competent authorities in the following order:(a) if the Information System user provides information indicating the Member State where the relevant product enters or leaves the Union market, or in the absence of that, where the relevant product is placed or made available on the market, the Due Diligence Statements shall be attributed to the competent authorities of that Member State;(b) in the absence of the information required by subparagraph a), the Due Diligence Statements shall be attributed to the competent authorities of the Member State in which the Information System user is established. In case the Information System user is established outside the Union, then the Due Diligence Statements shall be attributed to the competent authorities of the Member State with which the Information System user is associated according to their identifier provided upon registration in the Information System.
4. The Simplified Declarations shall be attributed in the Information System to the competent authorities of the Member State in which the micro or small primary operator is established. If the micro or small primary operator is established outside the Union, the Simplified Declaration shall be attributed to the competent authorities of the Member State with which the micro or small primary operator is associated according to the micro or small primary operator’s unique identifier provided in the Information System. If the information about the Simplified Declaration is made available in the Information System by a Member State in accordance with Article 4a(4) of Regulation (EU) 2023/1115, the Simplified Declaration shall be attributed to the competent authorities of that Member State.
For the purposes of this Regulation, in addition to the definitions set out in Article 2 of Regulation (EU) 2023/1115, Article 4 of Regulation (EU) 2016/679, and Article 3 of Regulation (EU) 2018/1725, the following definitions shall apply:
(a) ‘Information System’ means the information system established and maintained by the Commission pursuant to Article 33 of Regulation (EU) 2023/1115;
(b) ‘Information System actor’ means the competent authorities and customs authorities pursuant to Regulation (EU) 2023/1115, and the Commission, which carry out the tasks conferred on them in accordance with Regulation (EU) 2023/1115;
(c) ‘Information System user’ means operators, including micro or small primary operators, and their authorised representatives, where applicable, downstream operators and traders, pursuant to Regulation (EU) 2023/1115, as well as Member States acting pursuant to Article 4a(4) of that Regulation, and which are identified by individual registration within EU Login, the user authentication service of the Commission and by provision of a unique identifier;
(d) ‘Due Diligence Statement’ means Due Diligence Statement submitted by the Information System user pursuant to Regulation (EU) 2023/1115;
(da) ‘Simplified Declaration’ means a simplified declaration submitted by the Information System user pursuant to Article 4a(2) of Regulation (EU) 2023/1115;
(e) ‘Reference number’ means the reference number assigned by the Information System to the Due Diligence Statement;
(ea) ‘Declaration identifier’ means the identifier assigned by the Information System to the Simplified Declaration;
(f) ‘Verification number’ means a security number assigned by the Information System to the Due Diligence Statement or Simplified Declaration to ensure additional security of data contained therein;
(g) ‘Risk profiling’ means the identification of the risks of non-compliance of a relevant product within the scope of Regulation (EU) 2023/1115 within the Information System, based on risk criteria, for the purpose of assigning to each Due Diligence Statement and Simplified Declaration submitted in the Information System, including after any amendment or update thereof, a risk status reflecting those risks.
CHAPTER II — FUNCTIONING OF THE INFORMATION SYSTEM
1. Except where the Due Diligence Statement is made available through the electronic interface referred to in Article 28(2) of Regulation (EU) 2023/1115, the Information System users shall submit and manage the Due Diligence Statements of relevant products in the Information System.
2. Where a relevant product contains or has been made using wood, Information System users shall enter in the Due Diligence Statement the full scientific names of the wood species which the relevant products contain or have been made with.
1. The Information System user shall submit the Simplified Declaration in the Information System except where information is made available in accordance with paragraph 2.
2. Where all information listed in Annex III to Regulation (EU) 2023/1115 is available in a system or database that exists under Union or Member State law, the Information System shall enable Member States to make that information and, where relevant, any updates thereto, available in the Information System per micro or small primary operator as referred to in Article 4a(4) of Regulation (EU) 2023/1115. The Information System shall assign a declaration identifier for the information made available per individual micro or small primary operator. The declaration identifier shall be communicated by the Member State concerned to the respective micro or small primary operator and used by that micro or small primary operator for the purposes of Regulation (EU) 2023/1115 and this Regulation.
3. An update to the Simplified Declaration shall be submitted to and made available in the Information System in accordance with paragraphs 1 and 2. The declaration identifier associated to the Simplified Declaration shall be maintained in case of an update.
4. The Information System shall keep record of the Simplified Declarations and any updates thereto.
5. An update to the Simplified Declaration shall trigger a new risk profiling of the entire updated Simplified Declaration in accordance with Article 6.
6. The Information System shall enable Information System users to withdraw Simplified Declarations.
7. Simplified Declarations shall not be withdrawn after the Simplified Declaration was used as a reference by the same Information System user in accordance with Article 8a.
1. The Information System shall enable Information System users to amend or withdraw Due Diligence Statements within 72 hours after the reference number for the Due Diligence Statement was made available in the Information System.
2. Due Diligence Statements shall not be amended or withdrawn after the Due Diligence Statement was used as a reference in a Due Diligence Statement submitted by the same Information System user for grouping pursuant to Article 8a.
3. The Due Diligence Statement shall not be amended or withdrawn by an Information System user after:(a) the Information System user was notified about the intention to carry out a check on the Due Diligence Statement or on the relevant product associated with the Due Diligence Statement, for the period of the check;▼M1(b) a relevant product covered by a Due Diligence Statement was placed on the Union market or exported pursuant to Regulation (EU) 2023/1115;▼B(c) the reference number of the Due Diligence Statement was provided or made available to customs authorities before the release for free circulation or export of a relevant product entering or leaving the market as part of the procedures laid down in Chapter 4 of Regulation (EU) 2023/1115.
4. Without prejudice to paragraphs 2 and 3, upon individual and reasoned request of an Information System user, the competent authorities may extend the period referred to in paragraph 1 only when such period referred to in paragraph 1 has expired. Such extension shall not be longer than 8 calendar days. The request shall be based on reasons beyond the control of the Information System user, who shall, as part of their reasoned request, state that paragraph 3 of this Article is not applicable. Such extension shall also be possible retroactively after the period referred to in paragraph 1 has passed.
5. The amended Due Diligence Statement shall be subject to risk profiling as set out in Article 6. The risk profiling shall apply to the whole amended Due Diligence Statement.
1. The Information System shall enable competent authorities to identify situations within the Information System where relevant products present such a high risk of non-compliance that they require immediate action before those relevant products are placed or made available on the market or exported, pursuant to Article 17 of Regulation (EU) 2023/1115, and to inform the competent authorities to identify the checks to be carried out and fulfil tasks conferred on them pursuant to Chapter 3 of Regulation (EU) 2023/1115.
2. For the purposes of paragraph 1, the Information System shall enable competent authorities to set up risk profiles in the Information System to support informed decision for selecting operators, including micro or small primary operators, downstream operators, traders or relevant products associated to the Due Diligence Statements and Simplified Declarations on which to carry out checks. Those risk profiles shall be based, inter alia, on the risk criteria set out in annual plan of checks of the competent authorities pursuant to Article 16(5) of Regulation (EU) 2023/1115.
3. Upon its submission in the Information System, each Due Diligence Statement and Simplified Declaration shall be subjected to an automated electronic risk profiling and the Information System shall assign a risk status to each Due Diligence Statement and Simplified Declaration, which shall not be disclosed to the Information System user.
4. At any stage after submission of a Due Diligence Statement or a Simplified Declaration, including after a grouping thereof pursuant to Article 8a, competent authorities may review the Due Diligence Statement or the Simplified Declaration to determine whether a relevant product complies with Article 3 of Regulation (EU) 2023/1115. In such case, the competent authorities may assign to the Due Diligence Statement or Simplified Declaration, or the grouping thereof, where applicable, a new risk status as a result of the review. If the competent authority assigns a new risk status to a Due Diligence Statement or to a Simplified Declaration, or to a grouping thereof, such new risk status shall take precedence over a risk status assigned pursuant to paragraph 3 of this Article. The information system shall keep record of any changes made to the risk status of a Simplified Declaration or groupings thereof.
5. The risk status assigned to the Due Diligence Statement or the Simplified Declaration shall only be visible to the Information System actors.
1. The Information System shall, without undue delay after concluding the risk profiling referred to in Article 6, assign a reference number to the Due Diligence Statement and a declaration identifier to the Simplified Declaration submitted by the Information System user. At the same time, it shall assign a verification number associated with the Due Diligence Statement or Simplified Declaration.
2. The reference number or declaration identifier and the associated verification number shall be made available to the Information System user upon concluding the risk profiling referred to in Article 6.
3. The Information System shall enable competent authorities to delay making available the reference number or declaration identifier and the associated verification number to establish whether the relevant products comply with Article 3 of Regulation (EU) 2023/1115 and, in particular, to verify that the identified situation referred to in Article 6(1) of this Regulation is not applicable to that relevant product. Such delay shall be as short as possible and shall not exceed the period set out in Article 17(3) of Regulation (EU) 2023/1115. This period may be extended at the discretion of the competent authority for as long as necessary, by additional periods as set out in Article 17(3) of Regulation (EU) 2023/1115, to carry out their checks and fulfil their obligations under Regulation (EU) 2023/1115 and this Regulation.
1. The competent authorities may reject a Due Diligence Statement or a Simplified Declaration during the period laid down in Article 17(3) of Regulation (EU) 2023/1115 starting from the moment when a high risk of non-compliance is identified in the Information System pursuant to Article 6. The rejection of a Due Diligence Statement shall no longer be possible once the reference number of a Due Diligence Statement has become available to the Information System user.
2. The relevant product declared in a rejected Due Diligence Statement or a rejected Simplified Declaration shall be deemed not covered by a Due Diligence Statement or Simplified Declaration as required in Article 3, point (c), of Regulation (EU) 2023/1115 from the moment of rejection.
3. The rejection shall be reflected in the Information System by the assignment of a specific status to the concerned Due Diligence Statement or Simplified Declaration.
1. Information System users may group individual Due Diligence Statements or Simplified Declarations by submitting a new Due Diligence Statement or Simplified Declaration that references individual Due Diligence Statements or Simplified Declarations previously submitted by the same Information System user, or for the same operator or micro or small primary operator by an authorised representative, if applicable, via the previously submitted reference numbers or declaration identifiers (‘grouped Due Diligence Statement or Simplified Declaration’).
2. The Information System shall assign a specific status to the individual Due Diligence Statements or Simplified Declarations once they are referenced in the grouped Due Diligence Statement or Simplified Declaration to identify that they are grouped and replaced by the grouped Due Diligence Statement or Simplified Declaration.
3. The grouped Due Diligence Statement or Simplified Declaration shall represent the individual Due Diligence Statement or Simplified Declaration for the purposes of compliance with Regulation (EU) 2023/1115. The grouped Due Diligence Statement or Simplified Declaration shall therefore cover the placing on the market or export of the relevant products included in the individual Due Diligence Statements or Simplified Declarations referenced therein. For the purposes of compliance with Articles 4(7) and 26(4) of Regulation (EU) 2023/1115, instead of the individual reference numbers or declaration identifiers which were assigned a specific status in accordance with paragraph 2, Information System users shall communicate or make available the reference number or declaration identifier of the grouped Due Diligence Statement or Simplified Declaration.
CHAPTER III — FUNCTIONS AND RESPONSIBILITIES IN RELATION TO THE INFORMATION SYSTEM
In addition to the tasks listed in Article 2(1), the Commission shall be responsible for carrying out the following tasks in relation to the Information System:
(a) providing knowledge, training, and support, including technical assistance, to Information System users and Information System actors in relation to the use of the Information System and, where national expertise is required, requesting assistance from competent authorities in cases requiring national expertise;
(b) granting access to Information System actors designated by each Member State;
(c) granting access to Information System users, who are under the supervision of the competent authorities and cooperating with competent authorities, where necessary, to verify identification information provided by Information System users and other information whose validity can be assessed only by the Member States;
(ca) developing a feature in the Information System that allows competent authorities to manage Information System users, including activities listed in point (h), and to extract data related to Information System users;
(d) processing personal data in the Information System, where required in this Regulation, or for the implementation and enforcement under Regulation (EU) 2023/1115;
(e) providing webservices for Information System users supported by common technical specifications to submit and manage Due Diligence Statements and Simplified Declarations, including grouping thereof, in the Information System in an automated manner, and establishing conditions for the connection and use of these webservices, where necessary;
(f) providing webservices for Member States competent authorities supported by common technical specifications to perform tasks on submitted Due Diligence Statements or Simplified Declarations, including groupings thereof, in the Information System in an automated manner, and establishing conditions for the connection and use of these webservices, where necessary;
(g) providing the electronic interface pursuant to Article 28 of Regulation (EU) 2023/1115;
(h) suspending and revoking access of Information System users, including to address cases of non-compliance with obligations set out in Regulation (EU) 2023/1115 or this Regulation upon request of the competent authorities of the Member State in which the Information System user is established, or, in case the user is established outside the Union, the competent authorities of the Member State with which the Information System user is associated according to its unique identifier provided upon registration in the Information System.
1. Only registered Information System users shall have access to the Information System. Information System users shall create one single account in the Information System. The Information System shall provide for the possibility for Information System users to create different roles under the same account.
2. Authentication to the Information System shall take place via EU Login, the European Commission Authentication Service.
3. Information System users shall have access to the information in the Information System which they have submitted, or to which they have been given access by another Information System user through reference numbers and verification numbers of associated Due Diligence Statements and declaration identifiers and verification numbers of associated Simplified Declarations, including grouped Due Diligence Statements or Simplified Declarations.
4. The Information System shall enable Information System users to keep their registration information up to date.
1. The Commission shall have access to all data, information and documents in the Information System for the purpose of processing them in accordance with Articles 21 and 27(1) of Regulation (EU) 2023/1115, producing reports and for the development, functioning and maintenance of the Information System.
2. The Commission shall grant and may revoke access rights to the Information System actors in case of change in competencies pursuant to Article 14(2) of Regulation (EU) 2023/1115.
3. Authentication to the Information System shall take place via EU Login, the European Commission Authentication Service.
4. Information System actors shall put in place appropriate means to ensure that individual users representing Information System actors in the Information System are allowed to access personal data processed in the Information system only where strictly necessary for the implementation and enforcement under Regulation (EU) 2023/1115.
5. Information System actors shall have access to all relevant information in the Information System which is necessary for the purpose of fulfilling their obligations and tasks under Regulation (EU) 2023/1115.
CHAPTER IV — PROCESSING OF PERSONAL DATA AND SECURITY
1. The transmission, storage and other processing of personal data in the Information System may take place only as necessary and proportionate and only for the following purposes:(a) supporting communications between Information System actors in connection with the implementation and enforcement under Regulation (EU) 2023/1115;(b) case-handling by Information System actors when carrying out their own activities in connection with the implementation and enforcement under Regulation (EU) 2023/1115;(c) performing the business and technical transformations of data listed in this Regulation, where this is necessary to enable the exchange and use of information referred to in points (a) and (b).
2. The processing of personal data may take place in the Information System only in respect of the following categories of personal data:(a) identification data: first name and surname, unique identifier including the Economic Operators Registration and Identification number (‘EORI’), in accordance with Article 9 of Regulation (EU) No 952/2013 of the European Parliament and of the Council (1), if applicable;(b) professional contact details: email and postal address, country of residence or country of registered office, phone number and fax number, if applicable;(c) role of the Information System user;(d) data on geolocation pursuant to Article 2(28) of Regulation (EU) 2023/1115, where natural persons can be identified;(e) user authentication and access data to access the Information System: IP address and user name.
3. The Information System shall store the categories of personal data listed in paragraph 2 which has been processed for the implementation and enforcement under Regulation (EU) 2023/1115.
4. The storage of data referred to in paragraph 2 shall be performed using information technology infrastructure located in the European Economic Area.
5. ►M1 The Information System shall store the personal data contained in Due Diligence Statements not longer than five years from the date when the Due Diligence Statement is submitted in the Information System, or, in case of grouping pursuant to Article 8a, from the date of the grouping; the Information System shall store the personal data contained in Simplified Declarations not longer than five years from the date when the Simplified Declaration is withdrawn from the Information System.** ◄ ** The storage period may be further extended by the Commission upon individual request of Information System users or Information System actors where it is necessary to comply with their responsibilities and obligations under Regulation (EU) 2023/1115.
6. Without prejudice to the data processing activities set out in Article 14, each Information System actor shall be a separate controller within the meaning of Regulations (EU) 2016/679 and (EU) 2018/1725 with respect to the data processing activities which the Information System actor performs.
7. The national Supervisory Authorities and the European Data Protection Supervisor, each acting within the scope of their respective competence, shall ensure coordinated supervision of the Information System and its use by Information System actors and Information System users in accordance with Article 62 of Regulation (EU) 2018/1725.
1. The Commission shall be a controller within the meaning of Article 3, point (8), of Regulation (EU) 2018/1725 with respect to the processing of personal data of the Information System users, including the processing of personal data when registering Information System users in the Information System.
2. Where the Commission processes personal data in the operation of the Information System on behalf of other Information System actors for the purpose of exchanging information under Article 27 of Regulation (EU) 2023/1115, it shall be considered a processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725.
3. The Commission shall be a processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the processing of personal data carried out for joint investigations pursuant to Article 21 of Regulation (EU) 2023/1115 carried out in the context of the implementation and enforcement under Regulation (EU) 2023/1115.
When competent authorities and customs authorities pursuant to Regulation (EU) 2023/1115 carry out implementation and enforcement in cooperation pursuant to Article 21 of Regulation (EU) 2023/1115, the concerned competent authorities and customs authorities shall be joint controllers, within the meaning of Article 26(1) of Regulation (EU) 2016/679, for the transmission, storage, and other processing of personal data in the Information System in the context of such particular cooperation. Where required according to Article 26(1) of Regulation (EU) 2016/679, the controllers shall determine their respective responsibilities for compliance with the obligations under Regulation (EU) 2016/679 by means of an arrangement between them.
1. The Commission shall put in place the necessary, state-of-the-art measures to ensure security of personal data processed in the Information System, including appropriate data access control and a security plan, which shall be kept up-to-date.
2. The Commission shall put in place the necessary, state-of-the-art measures in the event of a security incident, take remedial action, and ensure that it shall be possible to verify what personal data have been processed in the Information System, when, by whom, and for what purpose.
3. The Commission shall inform the competent authorities about the measures regarding paragraph 1 and 2 of this Article.
4. The Commission may put in place the following measures:(a) measures to ensure the continued availability of the Information System by specifying conditions for individual interactions, including specifying technical limits for file size and regulating the frequency of interactions;(b) measures to prevent the submission of incorrect, superfluous or duplicated data.
The Commission shall inform competent authorities and Information System users about the measures taken pursuant to this paragraph without delay.
1. By 30 December 2026, the Commission shall provide the following on a publicly accessible website:(a) information about the availability and functioning of the Information System;(b) information about contingency measures that are to be taken in case of unplanned unavailability of the functionalities of the Information System exceeding the duration of 60 minutes.
2. The contingency measures referred to in paragraph 1, point (b), shall contain at least the following:(a) notification of the Information System actors in the event of unplanned unavailability of the Information System via digital means;(b) provision of a contingency reference number and a contingency declaration identifier to cover the products for which a Due Diligence Statement or Simplified Declaration cannot be submitted pursuant to Regulation (EU) 2023/1115 and reference numbers or declaration identifiers cannot be assigned due to the unavailability of the Information System.
1. Each Member State and the Commission shall apply their own rules on professional secrecy or other equivalent duties of confidentiality in relation to the Information System in accordance with national or Union law.
2. Each Information System actor shall ensure that demands from other Information System actors for confidential treatment of information exchanged in the Information System are complied with by individuals working under their authority.
CHAPTER V — FINAL PROVISIONS
1. The Commission shall make the Information System available in all official languages of the Union.
2. An Information System actor may produce and use, in relation to the performance of any of the tasks conferred on it in accordance with Regulation (EU) 2023/1115, any information, document, finding, statement, or certified true copy which it has received in the Information System, on the same basis as similar information obtained in its own country, for purposes compatible with those for which the data were originally collected and in accordance with relevant Union and national law.
1. The costs incurred for the set-up, maintenance and operation of the Information System shall be borne by the Commission.
2. The costs associated to the Information System at Member State level, including the human resources needed for training, promotion, technical assistance activities, as well as for the use of the Information System at national level and any adaptations required to national networks and information systems shall be borne by the Member State which incurs them.
This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2026-07-17 → this version applied |
| valid | 2026-07-17 → open publisher-asserted |
| type | REG_IMPL Commission Implementing Regulation (EU) 2024/3084 of 4 December 2024 on the functioning of the information system pursuant to Regulation (EU) 2023/1115 of the European Parliament and of the Council on the making available on the Union market and the export from the Union of certain commodities and products associated with deforestation and forest degradation |
| language | en |
| published | 2026-07-17 |
| lex_id | eu-eurlex:32024r3084:2026-07-17 |
| record sha256 | 5f13cfd7590c745debaf2c0171a3cf7de79a3293cb7eb0ba3fed728aa5993f19 |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
← previous version (2024-12-04) what changed? timeline next version (2026-07-17) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |