What changed, Commission Implementing Regulation (EU) 2024/3084 of 4 December 2024 on the functioning of the information sys…
2024-12-04 → 2026-07-17 · no interpretation, just the text delta
| on 2024-12-04 | eu-eurlex:32024r3084:2024-12-04 (2024-12-04 → 2026-07-16) · official source ↗ |
| on 2026-07-17 | eu-eurlex:32024r3084:2026-07-17 (2026-07-17 → open) · official source ↗ |
Open the structured article comparison → matched by provision anchor when continuity is sufficient; otherwise Lex refuses rather than inventing changes
269 line(s) in the old middle, 227 in the new; 1 unchanged leading and 1 trailing lines trimmed.
+ ## CHAPTER I — GENERAL PROVISIONS − ### art_1 + ### Article 1 — Subject matter − Article 1 + This Regulation lays down the rules for the functioning of the Information System, including rules for the protection of personal data, exchange of data with other IT systems and contingency arrangements in the event of unavailability of the functionalities of the Information System. − This Regulation lays down the rules for the functioning of the Information System, including rules for the protection of personal data and exchange of data with other IT systems. + ### Article 2 — Deployment and Use of the Information System − ### art_2 + **1.** The Commission shall:▼M1(a) develop the Information System;▼B(b) ensure the functioning, maintenance, support and any necessary update or development of the Information System. − Article 2 + **2.** The Information System shall be used by operators, and where applicable, their authorised representatives, for submitting and managing Due Diligence Statements and Simplified Declarations, by Member States to make information available pursuant to Article 4a(4) of Regulation (EU) 2023/1115, a… − 1. The Commission shall: + **3.** The Due Diligence Statements are attributed in the Information System to the competent authorities in the following order:(a) if the Information System user provides information indicating the Member State where the relevant product enters or leaves the Union market, or in the absence of that… − | (a) | develop the Information System as an independent module of TRACES platform; | − | --- | --- | + **4.** The Simplified Declarations shall be attributed in the Information System to the competent authorities of the Member State in which the micro or small primary operator is established. If the micro or small primary operator is established outside the Union, the Simplified Declaration shall be … − | (b) | ensure the functioning, maintenance, support and any necessary update or development of the Information System. | − | --- | --- | + ### Article 3 — Definitions − 2. The Information System shall be used by operators and traders, and if applicable, their authorised representatives, for submitting and managing Due Diligence Statements and verifying the validity of reference numbers, and by competent authorities, customs authorities and the Commission for access… − − 3. The Due Diligence Statements are attributed in the Information System to the competent authorities in the following order: − − | (a) | if the Information System user provides information indicating the Member State where the relevant product enters or leaves the Union market, or in the absence of that, where the relevant product is placed or made available on the market, the Due Diligence Statements shall be attributed to t… − | --- | --- | − − | (b) | in the absence of the information required by subparagraph a), the Due Diligence Statements shall be attributed to the competent authorities of the Member State in which the Information System user is established. In case the Information System user is established outside the Union, then the… − | --- | --- | − ### art_3 − − Article 3 − + (a) ‘Information System’ means the information system established and maintained by the Commission pursuant to Article 33 of Regulation (EU) 2023/1115; − | (a) | ‘Information System’ means the information system established and maintained by the Commission pursuant to Article 33 of Regulation (EU) 2023/1115; | − | --- | --- | + (b) ‘Information System actor’ means the competent authorities and customs authorities pursuant to Regulation (EU) 2023/1115, and the Commission, which carry out the tasks conferred on them in accordance with Regulation (EU) 2023/1115; − | (b) | ‘Information System actor’ means the competent authorities and customs authorities pursuant to Regulation (EU) 2023/1115, and the Commission, to carry out the tasks conferred on them in accordance with Regulation (EU) 2023/1115; | − | --- | --- | + (c) ‘Information System user’ means operators, including micro or small primary operators, and their authorised representatives, where applicable, downstream operators and traders, pursuant to Regulation (EU) 2023/1115, as well as Member States acting pursuant to Article 4a(4) of that Regulation, an… − | (c) | ‘Information System user’ means operators and traders, and their authorised representatives, where applicable, pursuant to Regulation (EU) 2023/1115 which are identified by individual registration within EU Login, the user authentication service of the European Commission; | − | --- | --- | + (d) ‘Due Diligence Statement’ means Due Diligence Statement submitted by the Information System user pursuant to Regulation (EU) 2023/1115; − | (d) | ‘Due Diligence Statement’ means Due Diligence Statement submitted by the Information System user pursuant to Regulation (EU) 2023/1115; | − | --- | --- | + (da) ‘Simplified Declaration’ means a simplified declaration submitted by the Information System user pursuant to Article 4a(2) of Regulation (EU) 2023/1115; − | (e) | ‘Reference number’ means the reference number assigned by the Information System to the Due Diligence Statement submitted by the Information System user pursuant to Regulation (EU) 2023/1115; | − | --- | --- | + (e) ‘Reference number’ means the reference number assigned by the Information System to the Due Diligence Statement; − | (f) | ‘Verification number’ means a security number assigned by the Information System to the Due Diligence Statement submitted by the Information System user to ensure additional security of data contained in the Due Diligence Statement; | − | --- | --- | + (ea) ‘Declaration identifier’ means the identifier assigned by the Information System to the Simplified Declaration; − | (g) | ‘Risk profiling’ means the identification of the risks of non-compliance of a relevant product within the scope of Regulation (EU) 2023/1115 within the Information System, based on risk criteria, for the purpose of assigning to each Due Diligence Statement submitted in the Information System… − | --- | --- | + (f) ‘Verification number’ means a security number assigned by the Information System to the Due Diligence Statement or Simplified Declaration to ensure additional security of data contained therein; − ### art_4 + (g) ‘Risk profiling’ means the identification of the risks of non-compliance of a relevant product within the scope of Regulation (EU) 2023/1115 within the Information System, based on risk criteria, for the purpose of assigning to each Due Diligence Statement and Simplified Declaration submitted in… − Article 4 + ## CHAPTER II — FUNCTIONING OF THE INFORMATION SYSTEM − 1. Except where the Due Diligence Statement is made available through the electronic interface referred to in Article 28(2) of Regulation (EU) 2023/1115, the Information System users shall submit and manage the Due Diligence Statements of relevant products in the Information System. + ### Article 4 — Submission of the Due Diligence Statements − 2. Where a relevant product contains or has been made using wood, Information System users shall enter in the Due Diligence Statement the common names and full scientific names of the wood species which the relevant products contain or have been made with. + **1.** Except where the Due Diligence Statement is made available through the electronic interface referred to in Article 28(2) of Regulation (EU) 2023/1115, the Information System users shall submit and manage the Due Diligence Statements of relevant products in the Information System. − ### art_5 + **2.** Where a relevant product contains or has been made using wood, Information System users shall enter in the Due Diligence Statement the full scientific names of the wood species which the relevant products contain or have been made with. − Article 5 + ### Article 4a — Submission, update and withdrawal of Simplified Declarations − 1. The Information System shall enable Information System users to amend or withdraw Due Diligence Statements within 72 hours after the reference number for the Due Diligence Statement was made available in the Information System. + **1.** The Information System user shall submit the Simplified Declaration in the Information System except where information is made available in accordance with paragraph 2. − 2. Due Diligence Statements cannot be amended or withdrawn within the duration set out in paragraph 1 after the Due Diligence Statement was used as a reference in a Due Diligence Statement submitted by the same or another Information System user. + **2.** Where all information listed in Annex III to Regulation (EU) 2023/1115 is available in a system or database that exists under Union or Member State law, the Information System shall enable Member States to make that information and, where relevant, any updates thereto, available in the Inform… − 3. The Due Diligence Statement shall not be amended or withdrawn by an Information System user after: + **3.** An update to the Simplified Declaration shall be submitted to and made available in the Information System in accordance with paragraphs 1 and 2. The declaration identifier associated to the Simplified Declaration shall be maintained in case of an update. − | (a) | the Information System user was notified about the intention to carry out a check on the Due Diligence Statement or on the relevant product associated with the Due Diligence Statement, for the period of the check; | − | --- | --- | + **4.** The Information System shall keep record of the Simplified Declarations and any updates thereto. − | (b) | the relevant product was placed on or made available on the Union market pursuant to Regulation (EU) 2023/1115; | − | --- | --- | + **5.** An update to the Simplified Declaration shall trigger a new risk profiling of the entire updated Simplified Declaration in accordance with Article 6. − | (c) | the reference number of the Due Diligence Statement was provided or made available to customs authorities before the release for free circulation or export of a relevant product entering or leaving the market as part of the procedures laid down in Chapter 4 of Regulation (EU) 2023/1115. | − | --- | --- | + **6.** The Information System shall enable Information System users to withdraw Simplified Declarations. − 4. Without prejudice to paragraphs 2 and 3, upon individual and reasoned request of an Information System user, the competent authorities may extend the period referred to in paragraph 1 only when such period referred to in paragraph 1 has expired. Such extension shall not be longer than 8 calendar … + **7.** Simplified Declarations shall not be withdrawn after the Simplified Declaration was used as a reference by the same Information System user in accordance with Article 8a. − 5. The amended Due Diligence Statement shall be subject to risk profiling as set out in Article 6. The risk profiling shall apply to the whole amended Due Diligence Statement. + ### Article 5 — Amendment and withdrawal of Due Diligence Statements − ### art_6 + **1.** The Information System shall enable Information System users to amend or withdraw Due Diligence Statements within 72 hours after the reference number for the Due Diligence Statement was made available in the Information System. − Article 6 + **2.** Due Diligence Statements shall not be amended or withdrawn after the Due Diligence Statement was used as a reference in a Due Diligence Statement submitted by the same Information System user for grouping pursuant to Article 8a. − 1. The Information System shall enable competent authorities to identify situations within the Information System where relevant products present such a high risk of non-compliance that they require immediate action before those relevant products are placed or made available on the market or exporte… + **3.** The Due Diligence Statement shall not be amended or withdrawn by an Information System user after:(a) the Information System user was notified about the intention to carry out a check on the Due Diligence Statement or on the relevant product associated with the Due Diligence Statement, for th… − 2. For the purposes of paragraph 1, the Information System shall enable competent authorities to set up risk profiles in the Information System to support informed decision for selecting operators or traders or relevant products associated to the Due Diligence Statements on which to carry out checks… + **4.** Without prejudice to paragraphs 2 and 3, upon individual and reasoned request of an Information System user, the competent authorities may extend the period referred to in paragraph 1 only when such period referred to in paragraph 1 has expired. Such extension shall not be longer than 8 calen… − 3. Upon its submission in the Information System, each Due Diligence Statement shall be subjected to an automated electronic risk profiling and the Information System shall assign a risk status to each Due Diligence Statement. + **5.** The amended Due Diligence Statement shall be subject to risk profiling as set out in Article 6. The risk profiling shall apply to the whole amended Due Diligence Statement. − 4. At any stage after submission of a Due Diligence Statement, competent authorities may review a Due Diligence Statement to determine whether a relevant product complies with Article 3 of Regulation (EU) 2023/1115. In such case, they may assign to the Due Diligence Statement a new risk status as a … + ### Article 6 — Risk profiling − ### art_7 + **1.** The Information System shall enable competent authorities to identify situations within the Information System where relevant products present such a high risk of non-compliance that they require immediate action before those relevant products are placed or made available on the market or exp… − Article 7 + **2.** For the purposes of paragraph 1, the Information System shall enable competent authorities to set up risk profiles in the Information System to support informed decision for selecting operators, including micro or small primary operators, downstream operators, traders or relevant products ass… − 1. The Information System shall, without undue delay, assign a reference number and verification number to the Due Diligence Statement submitted by the Information System user after concluding the risk profiling referred to in Article 6. + **3.** Upon its submission in the Information System, each Due Diligence Statement and Simplified Declaration shall be subjected to an automated electronic risk profiling and the Information System shall assign a risk status to each Due Diligence Statement and Simplified Declaration, which shall not… − 2. The reference number and verification number shall be made available to the Information System user upon concluding the risk profiling referred to in Article 6. + **4.** At any stage after submission of a Due Diligence Statement or a Simplified Declaration, including after a grouping thereof pursuant to Article 8a, competent authorities may review the Due Diligence Statement or the Simplified Declaration to determine whether a relevant product complies with A… − 3. The Information System shall enable competent authorities to delay the making available of the reference number to establish whether the relevant products comply with Article 3 of Regulation (EU) 2023/1115 and, in particular, to verify that the identified situation referred to in Article 6(1) of … + **5.** The risk status assigned to the Due Diligence Statement or the Simplified Declaration shall only be visible to the Information System actors. − ### art_8 + ### Article 7 — Assigning and making available reference numbers, declaration identifiers and verification numbers − Article 8 + **1.** The Information System shall, without undue delay after concluding the risk profiling referred to in Article 6, assign a reference number to the Due Diligence Statement and a declaration identifier to the Simplified Declaration submitted by the Information System user. At the same time, it sh… − 1. In order to prevent a relevant product not complying with Regulation (EU) 2023/1115 from being placed or made available on the market or exported pursuant to Article 17 of Regulation (EU) 2023/1115, the competent authorities may reject a Due Diligence Statement, unless the reference number of a D… + **2.** The reference number or declaration identifier and the associated verification number shall be made available to the Information System user upon concluding the risk profiling referred to in Article 6. − 2. The relevant product declared in a rejected Due Diligence Statement shall be deemed not covered by a Due Diligence Statement as required in Article 3, point (c) of Regulation (EU) 2023/1115. + **3.** The Information System shall enable competent authorities to delay making available the reference number or declaration identifier and the associated verification number to establish whether the relevant products comply with Article 3 of Regulation (EU) 2023/1115 and, in particular, to verify… − 3. The rejection shall be reflected in the Information System by the assignment of a specific status to the concerned Due Diligence Statement. + ### Article 8 — Rejecting Due Diligence Statements and Simplified Declarations − ### art_9 + **1.** The competent authorities may reject a Due Diligence Statement or a Simplified Declaration during the period laid down in Article 17(3) of Regulation (EU) 2023/1115 starting from the moment when a high risk of non-compliance is identified in the Information System pursuant to Article 6. The r… − Article 9 + **2.** The relevant product declared in a rejected Due Diligence Statement or a rejected Simplified Declaration shall be deemed not covered by a Due Diligence Statement or Simplified Declaration as required in Article 3, point (c), of Regulation (EU) 2023/1115 from the moment of rejection. − In addition to the tasks listed in Article 2(1), the Commission shall be responsible for carrying out the following tasks in relation to the Information System: + **3.** The rejection shall be reflected in the Information System by the assignment of a specific status to the concerned Due Diligence Statement or Simplified Declaration. − | (a) | providing knowledge, training, and support, including technical assistance, to Information System users and Information System actors in relation to the use of the Information System; | − | --- | --- | + ### Article 8a — Grouping of Due Diligence Statements and Simplified Declarations within the Information System − | (b) | granting access to Information System actors designated by each Member State; | − | --- | --- | + **1.** Information System users may group individual Due Diligence Statements or Simplified Declarations by submitting a new Due Diligence Statement or Simplified Declaration that references individual Due Diligence Statements or Simplified Declarations previously submitted by the same Information S… − | (c) | granting access to Information System users, who are under the supervision of the competent authorities; | − | --- | --- | + **2.** The Information System shall assign a specific status to the individual Due Diligence Statements or Simplified Declarations once they are referenced in the grouped Due Diligence Statement or Simplified Declaration to identify that they are grouped and replaced by the grouped Due Diligence Sta… − | (d) | processing personal data in the Information System, where required in this Regulation, or for the implementation and enforcement under Regulation (EU) 2023/1115; | − | --- | --- | − − | (e) | providing webservices for Information System users to submit and manage Due Diligence Statements in the Information System in an automated manner; | − | --- | --- | + **3.** The grouped Due Diligence Statement or Simplified Declaration shall represent the individual Due Diligence Statement or Simplified Declaration for the purposes of compliance with Regulation (EU) 2023/1115. The grouped Due Diligence Statement or Simplified Declaration shall therefore cover the… − | (f) | providing webservices for Member States competent authorities to perform tasks on submitted Due Diligence Statements in the Information System in an automated manner. | − | --- | --- | + ## CHAPTER III — FUNCTIONS AND RESPONSIBILITIES IN RELATION TO THE INFORMATION SYSTEM − | (g) | providing the electronic interface pursuant to Article 28 of Regulation (EU) 2023/1115; | − | --- | --- | + ### Article 9 — Functions and responsibilities of the Commission − | (h) | suspending and revoking access of Information System users upon request of the competent authorities of the Member State in which the Information System user is established, or, in case the user is established outside the Union, the competent authorities of the Member State with which the In… − | --- | --- | + In addition to the tasks listed in Article 2(1), the Commission shall be responsible for carrying out the following tasks in relation to the Information System: − ### art_10 + (a) providing knowledge, training, and support, including technical assistance, to Information System users and Information System actors in relation to the use of the Information System and, where national expertise is required, requesting assistance from competent authorities in cases requiring na… − Article 10 + (b) granting access to Information System actors designated by each Member State; − 1. Only registered Information System users shall have access to the Information System. + (c) granting access to Information System users, who are under the supervision of the competent authorities and cooperating with competent authorities, where necessary, to verify identification information provided by Information System users and other information whose validity can be assessed only… − 2. Authentication to the Information System shall take place via EU Login, the European Commission Authentication Service. + (ca) developing a feature in the Information System that allows competent authorities to manage Information System users, including activities listed in point (h), and to extract data related to Information System users; − 3. Information System users shall have access to the information in the Information System which they have submitted, or to which they have been given access by another Information System user through reference numbers and verification numbers of associated Due Diligence Statements. + (d) processing personal data in the Information System, where required in this Regulation, or for the implementation and enforcement under Regulation (EU) 2023/1115; − ### art_11 + (e) providing webservices for Information System users supported by common technical specifications to submit and manage Due Diligence Statements and Simplified Declarations, including grouping thereof, in the Information System in an automated manner, and establishing conditions for the connection … − Article 11 + (f) providing webservices for Member States competent authorities supported by common technical specifications to perform tasks on submitted Due Diligence Statements or Simplified Declarations, including groupings thereof, in the Information System in an automated manner, and establishing conditions… − 1. The Commission shall have access to all data, information and documents in the Information System for the purpose of producing reports and for the development, functioning and maintenance of the system. + (g) providing the electronic interface pursuant to Article 28 of Regulation (EU) 2023/1115; − 2. The Commission shall grant and may revoke access rights to the Information System actors in case of change in competencies pursuant to Article 14(2) of Regulation (EU) 2023/1115. + (h) suspending and revoking access of Information System users, including to address cases of non-compliance with obligations set out in Regulation (EU) 2023/1115 or this Regulation upon request of the competent authorities of the Member State in which the Information System user is established, or,… − 3. Authentication to the Information System shall take place via EU Login, the European Commission Authentication Service. + ### Article 10 — Access rights of Information System users − 4. Information System actors shall put in place appropriate means to ensure that individual users representing Information System actors in the Information System are allowed to access personal data processed in the Information system only where strictly necessary for the implementation and enforcem… + **1.** Only registered Information System users shall have access to the Information System. Information System users shall create one single account in the Information System. The Information System shall provide for the possibility for Information System users to create different roles under the s… − 5. Information System actors shall have access to all relevant information in the Information System which is necessary for the purpose of fulfilling their obligations and tasks under Regulation (EU) 2023/1115. + **2.** Authentication to the Information System shall take place via EU Login, the European Commission Authentication Service. − ### art_12 + **3.** Information System users shall have access to the information in the Information System which they have submitted, or to which they have been given access by another Information System user through reference numbers and verification numbers of associated Due Diligence Statements and declarati… − Article 12 + **4.** The Information System shall enable Information System users to keep their registration information up to date. − 1. The transmission, storage and other processing of personal data in the Information System may take place only as necessary and proportionate and only for the following purposes: + ### Article 11 — Access rights of Information System actors − | (a) | supporting communications between Information System actors in connection with the implementation and enforcement under Regulation (EU) 2023/1115; | − | --- | --- | + **1.** The Commission shall have access to all data, information and documents in the Information System for the purpose of processing them in accordance with Articles 21 and 27(1) of Regulation (EU) 2023/1115, producing reports and for the development, functioning and maintenance of the Information… − | (b) | case-handling by Information System actors when carrying out their own activities in connection with the implementation and enforcement under Regulation (EU) 2023/1115; | − | --- | --- | + **2.** The Commission shall grant and may revoke access rights to the Information System actors in case of change in competencies pursuant to Article 14(2) of Regulation (EU) 2023/1115. − | (c) | performing the business and technical transformations of data listed in this Regulation, where this is necessary to enable the exchange and use of information referred to in points (a) and (b). | − | --- | --- | + **3.** Authentication to the Information System shall take place via EU Login, the European Commission Authentication Service. − 2. The processing of personal data may take place in the Information System only in respect of the following categories of personal data: + **4.** Information System actors shall put in place appropriate means to ensure that individual users representing Information System actors in the Information System are allowed to access personal data processed in the Information system only where strictly necessary for the implementation and enfo… − | (a) | identification data: first name and surname, unique identifier including the Economic Operators Registration and Identification number (‘EORI’), in accordance with Article 9 of Regulation (EU) No 952/2013 of the European Parliament and of the Council (5), if applicable; | − | --- | --- | + **5.** Information System actors shall have access to all relevant information in the Information System which is necessary for the purpose of fulfilling their obligations and tasks under Regulation (EU) 2023/1115. − | (b) | professional contact details: email and postal address, country of residence or country of registered office, phone number and fax number, if applicable; | − | --- | --- | + ## CHAPTER IV — PROCESSING OF PERSONAL DATA AND SECURITY − | (c) | role of the Information System user; | − | --- | --- | + ### Article 12 — Processing of personal data in the Information System − | (d) | data on geolocation pursuant to Article 2(28) of Regulation (EU) 2023/1115, where natural persons can be identified; | − | --- | --- | + **1.** The transmission, storage and other processing of personal data in the Information System may take place only as necessary and proportionate and only for the following purposes:(a) supporting communications between Information System actors in connection with the implementation and enforcemen… − | (e) | user authentication and access data to access the Information System: IP address and user name. | − | --- | --- | + **2.** The processing of personal data may take place in the Information System only in respect of the following categories of personal data:(a) identification data: first name and surname, unique identifier including the Economic Operators Registration and Identification number (‘EORI’), in accorda… − 3. The Information System shall store the categories of personal data listed in paragraph 2 which has been processed for the implementation and enforcement under Regulation (EU) 2023/1115. + **3.** The Information System shall store the categories of personal data listed in paragraph 2 which has been processed for the implementation and enforcement under Regulation (EU) 2023/1115. − 4. The storage of data referred to in paragraph 2 shall be performed using information technology infrastructure located in the European Economic Area. + **4.** The storage of data referred to in paragraph 2 shall be performed using information technology infrastructure located in the European Economic Area. − 5. The Information System shall store the personal data contained in Due Diligence Statements not longer than 10 years from the date when the Due Diligence Statement is submitted in the Information System. The storage period may be further extended by the Commission upon individual request of Inform… + **5.** ►M1 The Information System shall store the personal data contained in Due Diligence Statements not longer than five years from the date when the Due Diligence Statement is submitted in the Information System, or, in case of grouping pursuant to Article 8a, from the date of the grouping; the I… − 6. Without prejudice to the data processing activities set out in Article 14, each Information System actor shall be a separate controller within the meaning of Regulations (EU) 2016/679 and (EU) 2018/1725 with respect to the data processing activities which the Information System actor performs. + **6.** Without prejudice to the data processing activities set out in Article 14, each Information System actor shall be a separate controller within the meaning of Regulations (EU) 2016/679 and (EU) 2018/1725 with respect to the data processing activities which the Information System actor performs… − 7. The national Supervisory Authorities and the European Data Protection Supervisor, each acting within the scope of their respective competence, shall ensure coordinated supervision of the Information System and its use by Information System actors and Information System users in accordance with Ar… + **7.** The national Supervisory Authorities and the European Data Protection Supervisor, each acting within the scope of their respective competence, shall ensure coordinated supervision of the Information System and its use by Information System actors and Information System users in accordance wit… − ### art_13 + ### Article 13 — Processing of personal data by the Commission − Article 13 + **1.** The Commission shall be a controller within the meaning of Article 3, point (8), of Regulation (EU) 2018/1725 with respect to the processing of personal data of the Information System users, including the processing of personal data when registering Information System users in the Information… − 1. The Commission shall be a controller within the meaning of Article 3, point (8), of Regulation (EU) 2018/1725 with respect to the processing of personal data of the Information System users, including the processing of personal data when registering Information System users in the Information Sys… + **2.** Where the Commission processes personal data in the operation of the Information System on behalf of other Information System actors for the purpose of exchanging information under Article 27 of Regulation (EU) 2023/1115, it shall be considered a processor within the meaning of Article 3, poi… − 2. Where the Commission processes personal data in the operation of the Information System on behalf of other Information System actors for the purpose of exchanging information under Article 27 of Regulation (EU) 2023/1115, it shall be considered a processor within the meaning of Article 3, point (… + **3.** The Commission shall be a processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the processing of personal data carried out for joint investigations pursuant to Article 21 of Regulation (EU) 2023/1115 carried out in the context of the implementation and enfor… − 3. The Commission shall be a processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the processing of personal data carried out for joint investigations pursuant to Article 21 of Regulation (EU) 2023/1115 carried out in the context of the implementation and enforceme… + ### Article 14 — Joint controllership in the Information System − ### art_14 + When competent authorities and customs authorities pursuant to Regulation (EU) 2023/1115 carry out implementation and enforcement in cooperation pursuant to Article 21 of Regulation (EU) 2023/1115, the concerned competent authorities and customs authorities shall be joint controllers, within the mea… − Article 14 + ### Article 15 — Security − When competent authorities and customs authorities pursuant to Regulation (EU) 2023/1115 carry out implementation and enforcement in cooperation pursuant to Article 21 of Regulation (EU) 2023/1115, the concerned competent authorities and customs authorities shall be joint controllers, within the mea… + **1.** The Commission shall put in place the necessary, state-of-the-art measures to ensure security of personal data processed in the Information System, including appropriate data access control and a security plan, which shall be kept up-to-date. − ### art_15 + **2.** The Commission shall put in place the necessary, state-of-the-art measures in the event of a security incident, take remedial action, and ensure that it shall be possible to verify what personal data have been processed in the Information System, when, by whom, and for what purpose. − Article 15 + **3.** The Commission shall inform the competent authorities about the measures regarding paragraph 1 and 2 of this Article. − 1. The Commission shall put in place the necessary, state-of-the-art measures to ensure security of personal data processed in the Information System, including appropriate data access control and a security plan, which shall be kept up-to-date. + **4.** The Commission may put in place the following measures:(a) measures to ensure the continued availability of the Information System by specifying conditions for individual interactions, including specifying technical limits for file size and regulating the frequency of interactions;(b) measure… − 2. The Commission shall put in place the necessary, state-of-the-art measures in the event of a security incident, take remedial action, and ensure that it shall be possible to verify what personal data have been processed in the Information System, when, by whom, and for what purpose. + The Commission shall inform competent authorities and Information System users about the measures taken pursuant to this paragraph without delay. − 3. The Commission shall inform the competent authorities about the measures regarding paragraph 1 and 2 of this Article. + ### Article 15a — Contingency arrangements − ### art_16 + **1.** By 30 December 2026, the Commission shall provide the following on a publicly accessible website:(a) information about the availability and functioning of the Information System;(b) information about contingency measures that are to be taken in case of unplanned unavailability of the function… − Article 16 + **2.** The contingency measures referred to in paragraph 1, point (b), shall contain at least the following:(a) notification of the Information System actors in the event of unplanned unavailability of the Information System via digital means;(b) provision of a contingency reference number and a con… − 1. Each Member State and the Commission shall apply their own rules on professional secrecy or other equivalent duties of confidentiality in relation to the Information System in accordance with national or Union law. + ### Article 16 — Confidentiality − 2. Each Information System actor shall ensure that demands from other Information System actors for confidential treatment of information exchanged in the Information System are complied with by individuals working under their authority. + **1.** Each Member State and the Commission shall apply their own rules on professional secrecy or other equivalent duties of confidentiality in relation to the Information System in accordance with national or Union law. − ### art_17 + **2.** Each Information System actor shall ensure that demands from other Information System actors for confidential treatment of information exchanged in the Information System are complied with by individuals working under their authority. − Article 17 + ## CHAPTER V — FINAL PROVISIONS − 1. The Commission shall make the Information System available in all official languages of the Union. + ### Article 17 — Translation − 2. An Information System actor may produce and use, in relation to the performance of any of the tasks conferred on it in accordance with Regulation (EU) 2023/1115, any information, document, finding, statement, or certified true copy which it has received in the Information System, on the same basi… + **1.** The Commission shall make the Information System available in all official languages of the Union. − ### art_18 + **2.** An Information System actor may produce and use, in relation to the performance of any of the tasks conferred on it in accordance with Regulation (EU) 2023/1115, any information, document, finding, statement, or certified true copy which it has received in the Information System, on the same … − Article 18 + ### Article 18 — Costs − 1. The costs incurred for the set-up, maintenance and operation of the Information System shall be borne by the Commission. + **1.** The costs incurred for the set-up, maintenance and operation of the Information System shall be borne by the Commission. − 2. The costs associated to the Information System at Member State level, including the human resources needed for training, promotion, technical assistance activities, as well as for the use of the Information System at national level and any adaptations required to national networks and information… + **2.** The costs associated to the Information System at Member State level, including the human resources needed for training, promotion, technical assistance activities, as well as for the use of the Information System at national level and any adaptations required to national networks and informa… − ### art_19 + ### Article 19 — Entry into force − Article 19 + This Regulation shall enter into force on the third day following that of its publication in the *Official Journal of the European Union*. − This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union.
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |