Regulation (EU) 2021/1134 of the European Parliament and of the Council of 7 July 2021 amending Regulations (EC) No 767/2008, (EC) No 810/2009, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1860, (EU) 2018/1861, (EU) 2019/817 and (EU) 2019/1896 of the European Parliament and of the Council and repealing Council Decisions 2004/512/EC and 2008/633/JHA, for the purpose of reforming the Visa Information System
For follow-up action with regard to hits in the SIS pursuant to point (a)(iv) to (vii) of paragraph 3 of this Article by the SIRENE Bureaux, Article 9f shall apply accordingly.
For follow-up action with regard to hits pursuant to point (a)(iv) or point (e) or (f) or point (g)(ii) of paragraph 3 of this Article by the VIS designated authorities, Article 9g shall apply accordingly. The reference to the central visa authority shall be understood as referring to the visa or immigration authority competent for long-stay visas or residence permits.
For the purpose of implementing this Article, eu-LISA shall, in cooperation with the Member States and Europol, establish appropriate channels for the notifications and exchange of information referred to in this Article.
The Commission shall adopt a delegated act in accordance with Article 48a to lay down in a manual the procedures and rules necessary for queries, verifications and assessments.
Article 22c
Data to be added for a long-stay visa or residence permit issued Where a competent authority decides to issue a long-stay visa or residence permit, it shall add the following data to the application file where the data is collected in accordance with the relevant Union and national law: (a) status information indicating that a long-stay visa or residence permit has been issued; (b) the authority that took the decision; (c) place and date of the decision to issue the long-stay visa or residence permit; (d) the type of document issued (long-stay visa or residence permit); (e) the number of the issued long-stay visa or residence permit; (f) the commencement and the expiry dates of the validity of the long-stay visa or residence permit; (g) data listed in Article 22a(1), if available and not entered in the application file upon application for a long-stay visa or residence permit.
Article 22d
Data to be added in certain cases of a long-stay visa or residence permit refused
Where a competent authority decides to refuse a long-stay visa or a residence permit because the applicant is considered to pose a threat to public policy, internal security or public health or the applicant has presented documents which were fraudulently acquired, or falsified, or tampered with, it shall add the following data to the application file where the data is collected in accordance with the relevant Union and national law:
(a) status information indicating that the long-stay visa or residence permit has been refused because the applicant is considered to pose a threat to public policy, internal security or public health, or because the applicant presented documents which were fraudulently acquired, or falsified, or tampered with; (b) the authority that took the decision; (c) place and date of the decision.
Where a final decision to refuse a long-stay visa or a residence permit has been taken on the basis of reasons other than those referred to in paragraph 1, the application file shall be deleted without delay from the VIS.
Article 22e
Data to be added for a long-stay visa or residence permit withdrawn, revoked or annulled Where a competent authority decides to withdraw, revoke or annul a long-stay visa or residence permit, it shall add the following data to the application file where the data is collected in accordance with the relevant Union and national law: (a) status information indicating that the long-stay visa or residence permit has been withdrawn, revoked or annulled; (b) the authority that took the decision; (c) place and date of the decision; (d) where applicable, the grounds for withdrawal, revocation or annulment of the long-stay visa or residence permit, in accordance with Article 22d.
Article 22f
Data to be added for a long-stay visa extended or residence permit renewed
Where a competent authority decides to extend a long-stay visa, it shall add the following data to the application file, where the data is collected in accordance with the relevant Union and national law:
(a) status information indicating that the long-stay visa has been extended; (b) the authority that took the decision; (c) place and date of the decision; (d) the number of the visa sticker; (e) the commencement and the expiry dates of the validity of the long-stay visa.
Where a competent authority decides to renew a residence permit, Article 22c applies.
Article 22g
Access to VIS data for verification of long-stay visas and residence permits at external border crossing points
For the sole purpose of verifying the identity of the holder of the long-stay visa or residence permit, or the authenticity and the validity of the long-stay visa or residence permit or whether the conditions for entry to the territory of the Member States in accordance with Article 6 of Regulation (EU) 2016/399 are fulfilled, the competent authorities for carrying out checks at external border crossing points in accordance with that Regulation shall have access to search the VIS using the following data:
(a) surname (family name), first name or names (given names); date of birth; nationality or nationalities; sex; type and number of the travel document or documents; three letter code of the issuing country of the travel document or documents; and the date of expiry of the validity of the travel document or documents; or (b) the number of the long-stay visa or residence permit.
If the search with the data listed in paragraph 1 of this Article indicates that data on the holder of the long-stay visa or residence permit are recorded in the VIS, the competent border control authority shall have access to the VIS to consult the following data of the application file and of linked application files pursuant to Article 22a(4), solely for the purposes referred to in paragraph 1 of this Article:
(a) the status information of the long-stay visa or residence permit indicating if it has been issued, withdrawn, revoked, annulled, extended or renewed; (b) the data referred to in points (d), (e), and (f) of Article 22c; (c) where applicable, the data referred to in points (d) and (e) of Article 22f(1); (d) facial images as referred to in point (j) of Article 22a(1).
For the purposes referred to in paragraph 1, the competent authorities for carrying out checks at external border crossing points shall also have access to the VIS to verify the fingerprints or the facial image of the holder of the long-stay visa or residence permit against the fingerprints or the facial image taken live recorded in the VIS.
Where verification of the holder of the long-stay visa or residence permit fails or where there are doubts as to the identity of the holder or the authenticity of the long-stay visa or residence permit or the travel document, the duly authorised staff of the competent authorities for carrying out checks at external border crossing points shall have access to VIS data in accordance with Article 22i(1) and (2).
Article 22h
Access to VIS data for verification within the territory of the Member States
For the sole purpose of verifying the identity of the holder of the long-stay visa or residence permit, or the authenticity and the validity of the long-stay visa or residence permit or whether the conditions for entry to, stay or residence on the territory of the Member States are fulfilled, the authorities competent for carrying out checks within the territory of the Member States as to whether the conditions for entry to, stay or residence on the territory of the Member States are fulfilled shall have access to the VIS to search with the number of the long-stay visa or residence permit in combination with verification of fingerprints of the holder of the long-stay visa or residence permit, or the number of the long-stay visa or residence permit.
Where the identity of the holder of the long-stay visa or residence permit cannot be verified with fingerprints, the competent authorities may also carry out verification by means of a facial image.
If the search with the data listed in paragraph 1 of this Article indicates that data on the holder of the long-stay visa or residence permit are recorded in the VIS, the competent authority shall have access to the VIS to consult the following data of the application file and of linked application files pursuant to Article 22a(4), solely for the purposes referred to in paragraph 1 of this Article:
(a) the status information of the long-stay visa or residence permit indicating if it has been issued, withdrawn, revoked, annulled, extended or renewed; (b) the data referred to in points (d), (e) and (f) of Article 22c; (c) where applicable, the data referred to in points (d) and (e) of Article 22f(1); (d) facial images as referred to in point (j) of Article 22a(1).
Where verification of the holder of the long-stay visa or residence permit fails or where there are doubts as to the identity of the holder or the authenticity of the long-stay visa or residence permit or the travel document, the duly authorised staff of the competent authorities shall have access to VIS data in accordance with Article 22i(1) and (2).
Article 22i
Access to VIS data for identification
For the sole purpose of the identification of any person who may have been registered previously in the VIS or who does not or no longer fulfils the conditions for the entry to, stay or residence on the territory of the Member States, the authorities competent for carrying out checks at external border crossing points in accordance with Regulation (EU) 2016/399 or within the territory of the Member States as to whether the conditions for entry to, stay or residence on the territory of the Member States are fulfilled, shall have access to the VIS to search with the fingerprints of that person.
Where the fingerprints of that person cannot be used or the search with the fingerprints fails, the search shall be carried out with the data referred to in points (d) to (g) or point (j) of Article 22a(1). However, the facial image shall not be the only search criterion.
If the search with the data listed in paragraph 1 of this Article indicates that data on the applicant are recorded in the VIS, the competent authority shall have access to the VIS to consult the following data of the application file and of linked application files pursuant to Article 22a(4), solely for the purposes referred to in paragraph 1 of this Article:
(a) the application number, the status information and the authority with which the application was lodged; (b) the data referred to in points (d) to (g) and (i) of Article 22a(1); (c) facial images as referred to in point (j) of Article 22a(1); (d) the data entered in respect of any long-stay visa or residence permit issued, refused, withdrawn, revoked, annulled, extended or renewed referred to in Articles 22c to 22f.
Where the person holds a long-stay visa or residence permit, the competent authorities shall access the VIS first in accordance with Article 22g or 22h.
Article 22j
Access to VIS data for determining the responsibility for applications for international protection
For the sole purpose of determining the Member State responsible for examining an application for international protection in accordance with Articles 12 and 34 of Regulation (EU) No 604/2013, the competent asylum authorities shall have access to the VIS to search with the fingerprints of the applicant for international protection.
Where the fingerprints of the applicant for international protection cannot be used or the search with the fingerprints fails, the search shall be carried out with the data referred to in points (d) to (g) or point (j) of Article 22a(1). However, the facial image shall not be the only search criterion.
If the search with the data listed in paragraph 1 of this Article indicates that a long-stay visa or residence permit is recorded in the VIS, the competent asylum authority shall have access to the VIS to consult the following data of the application file and, as regards the data listed in point (e) of this paragraph, of linked application files relating to the spouse and children pursuant to Article 22a(4), solely for the purpose referred to in paragraph 1 of this Article:
(a) the application number and the authority that issued, revoked, annulled, extended or renewed the long-stay visa or residence permit; (b) the data referred to in points (d) to (g) and (i) of Article 22a(1); (c) the data entered in respect of any long-stay visa or residence permit issued, withdrawn, revoked, annulled, extended or renewed referred to in Articles 22c, 22e and 22f; (d) facial images as referred to in point (j) of Article 22a(1); (e) the data referred to in points (d) to (g) of Article 22a(1) of the linked application files relating to the spouse and children.
The consultation of the VIS pursuant to paragraphs 1 and 2 of this Article shall be carried out only by the designated national authorities referred to in Article 34(6) of Regulation (EU) No 604/2013.
Article 22k
Access to VIS data for examining the application for international protection
For the sole purpose of examining an application for international protection, the competent asylum authorities shall have access to the VIS in accordance with Article 34 of Regulation (EU) No 604/2013 to search with the fingerprints of the applicant for international protection.
Where the fingerprints of the applicant for international protection cannot be used or the search with the fingerprints fails, the search shall be carried out with the data referred to in points (d) to (g) or point (j) of Article 22a(1). However, the facial image shall not be the only search criterion.
If the search with the data listed in paragraph 1 of this Article indicates that data on the applicant for international protection is recorded in the VIS, the competent asylum authority shall have access to the VIS to consult the following data of the application file and, as regards the data listed in point (f) of this paragraph, of the linked application files relating to the spouse and children pursuant to Article 22a(4), solely for the purpose referred to in paragraph 1 of this Article:
(a) the application number; (b) the data referred to in points (d) to (g) and (i) of Article 22a(1); (c) facial images as referred to in point (j) of Article 22a(1); (d) scans of the biographic data page of the travel document as referred to in point (h) of Article 22a(1); (e) the data entered in respect of any long-stay visa or residence permit issued, withdrawn, revoked, annulled, extended or renewed referred to in Articles 22c, 22e and 22f; (f) the data referred to in points (d) to (g) of Article 22a(1) of the linked application files relating to the spouse and children.
The consultation of the VIS pursuant to paragraphs 1 and 2 of this Article shall be carried out only by the designated national authorities referred to in Article 34(6) of Regulation (EU) No 604/2013.
CHAPTER IIIb
PROCEDURE AND CONDITIONS FOR ACCESS TO THE VIS FOR LAW ENFORCEMENT PURPOSES
Article 22l
Member States’ designated authorities
Each Member State shall designate the authorities which are entitled to consult the VIS data in order to prevent, detect and investigate terrorist offences or other serious criminal offences.
The data accessed by those authorities shall only be processed for the purposes of the specific case for which the data have been consulted.
Each Member State shall keep a list of its designated authorities and shall communicate that list to the Commission and eu-LISA. Each Member State may at any time amend or replace the list which it communicated and shall inform the Commission and eu-LISA accordingly.
Each Member State shall designate a central access point which shall have access to the VIS. The central access point shall verify that the conditions for access to VIS data laid down in Article 22o are fulfilled.
The designated authorities and the central access point may be part of the same organisation if permitted under national law, but the central access point shall act fully independently of the designated authorities when performing its tasks under this Regulation. The central access point shall be separate from the designated authorities and shall not receive instructions from them as regards the outcome of the verification which it shall perform independently. Member States may designate more than one central access point to reflect their organisational and administrative structure in the fulfilment of their constitutional or legal requirements.
Each Member State shall communicate to the Commission and eu-LISA its central access point and may at any time amend or replace its communication.
At national level, each Member State shall keep a list of the operating units within the designated authorities that are authorised to request access to VIS data through the central access point.
Only duly empowered staff of the central access point shall be authorised to access VIS data in accordance with Articles 22n and 22o.
Article 22m
Europol
Europol shall designate one of its operating units as ‘Europol designated authority’ and shall authorise it to request access to VIS data through the VIS designated central access point referred to in paragraph 2 in order to support and strengthen action by Member States in preventing, detecting and investigating terrorist offences or other serious criminal offences.
The data accessed by Europol shall only be processed for the purposes of the specific case for which the data have been consulted.
Europol shall designate a specialised unit with duly empowered Europol officials as the central access point. The central access point shall verify that the conditions for access to VIS data laid down in Article 22r are fulfilled.
The central access point shall act independently when performing its tasks under this Regulation and shall not receive instructions from the Europol designated authority as regards the outcome of the verification.
Article 22n
Procedure for access to VIS data for law enforcement purposes
The operating units referred to in Article 22l(5) shall submit a reasoned electronic or written request to the central access points referred to in paragraph 3 of that Article for access to VIS data. Upon receipt of a request for access the central access point shall verify whether the conditions referred to in Article 22o are fulfilled. If the conditions are fulfilled, the central access point shall process the request. The VIS data accessed shall be transmitted to the operating units referred to in Article 22l(5) in such a way as not to compromise the security of the data.
In a case of exceptional urgency, where there is a need to prevent an imminent danger to the life of a person associated with a terrorist offence or other serious criminal offence, the central access point shall process the request immediately and shall only verify ex post whether all the conditions of Article 22o are fulfilled, including whether a case of urgency actually existed. The ex post verification shall take place without undue delay and in any event no later than seven working days after the processing of the request.
Where an ex post verification reveals that the access to VIS data was not justified, all the authorities that accessed such data shall without delay erase the data accessed from the VIS and shall inform the central access point of the erasure.
Article 22o
Conditions for access to VIS data by designated authorities of Member States
Without prejudice to Article 22 of Regulation (EU) 2019/817 designated authorities shall have access to the VIS for the purposes of consultation where all of the following conditions are met:
(a) consultation is necessary and proportionate for the purposes of the prevention, detection or investigation of a terrorist offence or other serious criminal offence; (b) consultation is necessary and proportionate in a specific case; (c) reasonable grounds exist to consider that consultation of VIS data will substantially contribute to the prevention, detection or investigation of any of the criminal offences in question, in particular where there is a substantiated suspicion that the suspect, perpetrator or victim of a terrorist offence or other serious criminal offence falls under a category covered by this Regulation; (d) a query of the CIR was launched in accordance with Article 22 of Regulation (EU) 2019/817 and the reply received as referred to in paragraph 2 of that Article indicates that data is stored in the VIS.
The fulfilment of the condition provided for in point (d) of paragraph 1 shall not be required where access to the VIS is needed as a tool to consult the visa history or the periods of authorised stay on the territory of the Member States of a known suspect, perpetrator or suspected victim of a terrorist offence or other serious criminal offence, or the data category with which the search is conducted is not stored in the CIR.
Consultation of the VIS shall be limited to searching with any of the following data in the application file:
(a) surname(s) (family name(s)), first name(s) (given name(s)), date of birth, nationality or nationalities and/or sex; (b) type and number of travel document or documents, the country which issued the travel document and date of expiry of the validity of the travel document; (c) visa sticker number or number of the long-stay visa or residence permit and the date of expiry of the validity of the visa, long-stay visa or residence permit, as applicable; (d) fingerprints, including latent fingerprints; (e) facial image.
The facial image referred to in point (e) of paragraph 3 shall not be the only search criterion.
Consultation of the VIS shall, in the event of a hit, give access to the data listed in paragraph 3 of this Article as well as to any other data taken from the application file, including data entered in respect of any document issued, refused, annulled, revoked, withdrawn, renewed or extended. Access to the data referred to in point (4)(l) of Article 9 as recorded in the application file shall only be given if consultation of that data was explicitly requested in a reasoned request and approved by independent verification.
By way of derogation from paragraphs 3 and 5 the data referred to in points (d) and (e) of paragraph 3 of children below the age of 14 shall only be used to search the VIS and, in the case of a hit, shall only be accessed where:
(a) necessary for the purposes of the prevention, detection or investigation of a serious criminal offence of which those children are the victim of and to protect missing children; (b) necessary in a specific case; and (c) the use of the data is in the best interest of the child.
Article 22p
Access to VIS data for identification of persons in specific circumstances
By way of derogation from Article 22o(1), designated authorities shall not be required to fulfil the conditions laid down in that paragraph to access the VIS for the purposes of the identification of persons who have gone missing, were abducted or were identified as victims of trafficking in human beings, and in respect of whom there are reasonable grounds to consider that consultation of VIS data will support their identification or contribute in investigating specific cases of human trafficking. In such circumstances, the designated authorities may search in the VIS with the fingerprints of those persons.
Where the fingerprints of the persons referred to in paragraph 1 cannot be used or the search with the fingerprints fails, the search shall be carried out with the data referred to in point (4)(a) to (ca) of Article 9 or points (d) to (g) of Article 22a(1).
Consultation of the VIS shall, in the event of a hit, give access to any of the data in Article 9 and Article 22a, as well as to the data in linked application files in accordance with Article 8(3) and (4) or Article 22a(4).
Article 22q
Use of VIS data for the purpose of entering in the SIS alerts on missing persons or vulnerable persons who need to be prevented from travelling and access to those data
VIS data may be used for the purpose of entering in the SIS an alert on missing persons or vulnerable persons who need to be prevented from travelling in accordance with Article 32 of Regulation (EU) 2018/1862. In those cases, the central access point referred to in Article 22l(3) shall ensure the transmission of data through secured means.
In the case of a hit against a SIS alert through the use of VIS data as referred to in paragraph 1, child protection authorities and national judicial authorities may request an authority with access to the VIS to grant them access to those data for the purposes of their tasks. Such national judicial authorities shall include those responsible for the initiation of public prosecutions in criminal proceedings and for judicial inquiries prior to charging a person, and their coordinating authorities, as referred to in Article 44(3) of Regulation (EU) 2018/1862. The conditions provided for in Union and national law shall apply. Member States shall ensure that the data are transmitted in a secure manner.
Article 22r
Procedure and conditions for access to VIS data by Europol
Europol shall have access to the VIS for the purposes of consultation where all of the following conditions are met:
(a) consultation is necessary and proportionate for the purpose of supporting and strengthening action by Member States in preventing, detecting or investigating terrorist offences or other serious criminal offences falling under Europol’s mandate; (b) consultation is necessary and proportionate in a specific case; (c) reasonable grounds exist to consider that consultation of VIS data will substantially contribute to the prevention, detection or investigation of any of the criminal offences in question, in particular where there is a substantiated suspicion that the suspect, perpetrator or victim of a terrorist offence or other serious criminal offence falls under a category covered by this Regulation; (d) a query of the CIR was launched in accordance with Article 22 of Regulation (EU) 2019/817 and the reply received as referred to in paragraph 2 of that Article indicates that data is stored in the VIS.
Fulfilment of the condition provided for in point (d) of paragraph 1 shall not be required where access to the VIS is needed as a tool to consult the visa history or the periods of authorised stay on the territory of the Member States of a known suspect, perpetrator or suspected victim of a terrorist offence or other serious criminal offence, or the data category with which the search is conducted is not stored in the CIR.
Consultation of the VIS shall be limited to searching with any of the following data in the application file:
(a) surname(s) (family name(s)), first name(s) (given name(s)), date of birth, nationality or nationalities and/or sex; (b) type and number of travel document or documents, the country which issued the travel document and date of expiry of the validity of the travel document; (c) visa sticker number or number of the long-stay visa or residence permit and the date of expiry of the validity of the visa, long-stay visa or residence permit, as applicable; (d) fingerprints, including latent fingerprints; (e) facial image.
The facial image referred to in point (e) of paragraph 3 shall not be the only search criterion.
Consultation of the VIS shall, in the event of a hit, give access to the data listed in paragraph 3 of this Article as well as to any other data taken from the application file, including data entered in respect of any document issued, refused, annulled, revoked, withdrawn, renewed or extended. Access to the data referred to in point (4)(l) of Article 9 as recorded in the application file shall only be given if consultation of that data was explicitly requested in a reasoned request and approved by independent verification.
By way of derogation from paragraphs 3 and 5 the data referred to in points (d) and (e) of paragraph 3 of children below the age of 14 shall only be used to search the VIS and, in the case of a hit, shall only be accessed where:
(a) necessary for the purposes of the prevention, detection or investigation of a serious criminal offence of which those children are the victim of and to protect missing children; (b) necessary in a specific case; and (c) the use of the data is in the best interest of the child.
Europol’s designated authority may submit a reasoned electronic request for the consultation of all VIS data or a specific set of VIS data to the Europol central access point. Upon receipt of a request for access the Europol central access point shall verify whether the conditions referred to in paragraphs 1 and 2 are fulfilled. If all conditions are fulfilled, the duly authorised staff of the central access point shall process the request. The VIS data accessed shall be transmitted to the Europol designated authority in such a way as not to compromise the security of the data.
The processing of data obtained by Europol by consulting VIS data shall be subject to the authorisation of the Member State of origin of the data. That authorisation shall be obtained via the Europol national unit of that Member State.
Article 22s
Keeping of logs of requests to consult VIS data for the purposes of the prevention, detection and investigation of terrorist offences or other serious criminal offences
eu-LISA shall keep logs of all data processing operations within the VIS involving access by the central access points referred to in Article 22l(3) for the purposes of Chapter IIIb. Those logs shall show the date and time of each operation, the data used for launching the search, the data transmitted by the VIS and the name of the authorised staff of the central access points entering and retrieving the data.
In addition, each Member State and Europol shall keep logs of all data processing operations within the VIS resulting from requests to consult VIS data or from access to VIS data for the purposes of Chapter IIIb.
The logs referred to in paragraph 2 shall show:
(a) the exact purpose of the request for consultation of or access to VIS data, including the terrorist offence or other serious criminal offence concerned and, for Europol, the exact purpose of the request for consultation; (b) the decision taken with regard to the admissibility of the request; (c) the national file reference; (d) the date and exact time of the request for access made by the central access point to the VIS; (e) where applicable, the use of the urgency procedure referred to in Article 22n(2) and the outcome of the ex post verification; (f) which of the data or set of data referred to in Article 22o(3) have been used for consultation; and (g) in accordance with national rules or with Regulation (EU) 2016/794, the identifying mark of the official who carried out the search and of the official who ordered the search or transmission of data.
The logs referred to in paragraphs 1 and 2 of this Article shall be used only to check the admissibility of the request, monitor the lawfulness of data processing and to ensure data integrity and security. The logs shall be protected by appropriate measures against unauthorised access. They shall be deleted one year after the retention period referred to in Article 23 has expired, if they are not required for monitoring procedures which have already begun. The European Data Protection Supervisor and the competent supervisory authorities shall have access to the logs at their request for the purpose of fulfilling their duties. The authority responsible for checking the admissibility of the request shall also have access to the logs for that purpose. Other than for such purposes, personal data shall be erased in all national and Europol files after a period of one month, unless those data are required for the purposes of the specific ongoing criminal investigation for which they were requested by a Member State or by Europol. Only logs containing non-personal data may be used for the monitoring and evaluation referred to in Article 50.
Article 22t
Conditions for access to VIS data by designated authorities of a Member State in respect of which this Regulation has not yet been put into effect
Access to the VIS for consultation by designated authorities of a Member State in respect of which this Regulation has not yet been put into effect shall take place where such access is:
(a) within the scope of the powers of those designated authorities; (b) subject to the same conditions as referred to in Article 22o(1); (c) preceded by a duly reasoned written or electronic request to a designated authority of a Member State to which this Regulation applies; that authority shall then request the national central access point to consult the VIS.
A Member State in respect of which this Regulation has not yet been put into effect shall make its data on visas available to Member States to which this Regulation applies, on the basis of a duly reasoned written or electronic request, subject to compliance with the conditions laid down in Article 22o(1).”;
(27) Article 23 is replaced by the following: “Article 23 Retention period for data storage
Each application file shall be stored in the VIS for a maximum of five years, without prejudice to the erasure referred to in Articles 24 and 25 and to the keeping of the logs referred to in Article 34.
That period shall start: (a) on the expiry date of the visa, the long-stay visa or the residence permit, if a visa, a long-stay visa or a residence permit has been issued; (b) on the new expiry date of the visa, the long-stay visa or the residence permit, if a visa, a long-stay visa or a residence permit has been extended or renewed; (c) on the date of the creation of the application file in the VIS, if the application has been withdrawn and closed; (d) on the date of the decision of the responsible authority if a visa, a long-stay visa or a residence permit has been refused, withdrawn, revoked or annulled, as applicable.
Upon expiry of the period referred to in paragraph 1 of this Article, the VIS shall automatically erase the application file and the links to that file as referred to in Article 8(3) and (4) and Article 22a(4).
By way of derogation from paragraph 1, fingerprints and facial images pertaining to children below the age of 12 shall be erased upon the visa, long-stay visa or residence permit having expired and, in the event of a visa, the child having exited the external borders.
For the purposes of that erasure, the EES shall automatically notify the VIS when the exit of the child is entered in the entry/exit record in accordance with Article 16(3) of Regulation (EU) 2017/2226.”;
(28) Article 24 is replaced by the following: “Article 24 Amendment of data
Only the Member State responsible shall have the right to amend data which it has transmitted to the VIS, by rectifying or erasing such data.
If a Member State has evidence to suggest that data processed in the VIS are inaccurate or that data were processed in the VIS contrary to this Regulation, it shall inform the Member State responsible immediately. That message shall be transmitted by VISMail in accordance with the procedure in Article 16(3).
Where the inaccurate data refers to links created pursuant to Article 8(3) or (4) or Article 22a(4) or where a link is missing, the Member State responsible shall check the data concerned and provide an answer within three working days, and shall rectify the link if necessary. If no answer is provided within that timeframe, the requesting Member State shall rectify the link and notify, by VISMail, the Member State responsible of the rectification made.
The Member State responsible shall, as soon as possible, check the data concerned and, if necessary, rectify or erase them immediately.”;
(29) Article 25 is amended as follows: (a) the title is replaced by the following: “Advance erasure of data”; (b) paragraphs 1 and 2 are replaced by the following: “1. Where, before expiry of the period referred to in Article 23(1), an applicant has acquired the nationality of a Member State, the application files and the links created pursuant to Article 8(3) and (4) or Article 22a(4) relating to the applicant shall be erased without delay from the VIS by the Member State which created the respective application files and links.
Each Member State shall inform the Member States responsible without delay if an applicant has acquired its nationality. That message shall be transmitted by the VISMail in accordance with the procedure in Article 16(3).”;
(30) Article 26 is replaced by the following: “Article 26 Operational management
eu-LISA shall be responsible for the technical and operational management of the VIS and its components as set out in Article 2a. It shall ensure, in cooperation with the Member States, that at all times the best available technology, subject to a cost-benefit analysis, is used for those components.
eu-LISA shall be responsible for the following tasks relating to the communication infrastructure between the VIS Central System and the NUIs:
(a) supervision; (b) security; (c) the coordination of relations between the Member States and the provider; (d) tasks relating to implementation of the budget; (e) acquisition and renewal; (f) contractual matters.
Operational management of the VIS shall consist of all the tasks necessary to keep the VIS functioning 24 hours a day, seven days a week in accordance with this Regulation. It shall include, in particular, the maintenance work and technical developments necessary to ensure that the VIS functions at a satisfactory level of operational quality, in particular as regards the response time for consultation of the VIS by visa authorities, the authorities competent to decide on an application for a long-stay visa or residence permit and border authorities. Such response times shall be as short as possible.
8a. eu-LISA may use anonymised real personal data in the VIS for testing purposes in the following circumstances: (a) for diagnostics and repair when faults are discovered in the VIS Central System; (b) for testing new technologies and techniques relevant to enhance the performance of the VIS Central System or transmission of data to it. In the cases referred to in point (b) of the first subparagraph, the security measures, access control and logging activities at the testing environment shall be equal to those for the VIS. Real personal data adopted for testing shall be rendered anonymous in such a way that the data-subject is no longer identifiable.
Without prejudice to Article 17 of the Staff Regulations of officials of the European Communities, laid down in Council Regulation (EEC, Euratom, ECSC) No 259/68 (13), eu-LISA shall apply appropriate rules of professional secrecy or other equivalent duties of confidentiality to all its staff required to work with VIS data. This obligation shall also apply after such staff leave office or employment or after the termination of their activities.
Where eu-LISA cooperates with external contractors in any VIS-related tasks, it shall closely monitor the activities of the contractor to ensure compliance with this Regulation, in particular on security, confidentiality and data protection.
(31) Article 27 is deleted;
(32) the following article is inserted: “Article 27a Interoperability with other EU information systems and Europol data Interoperability between the VIS and the SIS, the EES, the ETIAS, Eurodac, the ECRIS-TCN and Europol data shall be established to enable the automated processing of the queries of other systems pursuant to Articles 9a to 9g and Article 22b. Interoperability shall rely on the ESP.”;
(33) Article 28 is amended as follows: (a) paragraphs 1 and 2 are replaced by the following: “1. The VIS shall be connected to the national system of each Member State via the NUI in the Member State concerned.
Each Member State shall designate a national authority which shall provide the access of the competent authorities referred to in Article 6(1) and (2) to the VIS, and connect that national authority to the NUI.”;
(b) paragraph 4 is amended, as follows: (i) point (a) is replaced by the following: “(a) the development of the national system and its adaptation to the VIS;”; (ii) point (d) is replaced by the following: “(d) bearing the costs incurred by the national system and the costs of its connection to the NUI, including the investment and operational costs of the communication infrastructure between the NUI and the national system.”;
(34) Article 29 is replaced by the following: “Article 29 Responsibility for the use and quality of data
Each Member State shall ensure that the data are processed lawfully, and in particular that only duly authorised staff have access to data processed in the VIS for the performance of their tasks in accordance with this Regulation. The Member State responsible shall ensure in particular that:
(a) the data are collected lawfully: (b) the data are transmitted lawfully to the VIS; (c) the data are accurate, up-to-date and of an adequate level of quality and completeness when they are transmitted to the VIS.
eu-LISA shall ensure that the VIS is operated in accordance with this Regulation and its implementing rules referred to in Article 45. In particular, eu-LISA shall:
(a) take the necessary measures to ensure the security of the VIS Central System and the communication infrastructure between the VIS Central System and the NUIs, without prejudice to the responsibilities of each Member State; (b) ensure that only duly authorised staff have access to data processed in the VIS for the performance of the tasks of eu-LISA in accordance with this Regulation. 2a. eu-LISA shall develop and maintain a mechanism and procedures for carrying out quality checks on the data in the VIS and shall provide regular reports to the Member States. eu-LISA shall provide a regular report to the European Parliament, the Council and the Commission covering the issues encountered. The Commission shall adopt implementing acts to lay down and develop the mechanism and the procedures for carrying out quality checks and appropriate requirements for data quality compliance. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 49(2).
eu-LISA shall inform the European Parliament, the Council and the Commission of the measures which it takes pursuant to paragraph 2.
In relation to the processing of personal data in the VIS, each Member State shall designate the authority which is to be considered as controller in accordance with point (7) of Article 4 of Regulation (EU) 2016/679 and which shall have central responsibility for the processing of data by that Member State. Each Member State shall notify the Commission of the designation.
Article 29a
Specific rules for entering data
The data referred to in Article 6(4), Articles 9 to 14, Article 22a and Articles 22c to 22f shall be entered in the VIS only following a quality check performed by the responsible national authorities and shall be processed by the VIS following a quality check performed by the VIS in accordance with paragraph 2 of this Article.
Quality checks on the data referred to in Articles 9 to 14, Article 22a and Articles 22c to 22f shall be performed by the VIS in accordance with this paragraph.
The quality checks shall be initiated when creating or updating application files in the VIS. Where the quality checks fail to meet the established quality standards, the responsible authority or authorities shall be automatically notified by the VIS. The automated queries pursuant to Article 9a(3) and Article 22b(2) shall be triggered by the VIS only following a positive quality check. Quality checks on facial images and fingerprints shall be performed when creating or updating application files in the VIS, to ascertain the fulfilment of minimum data quality standards allowing for biometric matching. Quality checks on the data referred to Article 6(4) shall be performed when storing information about the national competent authorities in the VIS.
Quality standards shall be established for the storage of the data referred to in paragraphs 1 and 2 of this Article.
The Commission shall adopt implementing acts to lay down the specification of those quality standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 49(2).”;
(35) Article 31 is replaced by the following: “Article 31 Communication of data to third countries or international organisations
Data processed in the VIS pursuant to this Regulation shall not be transferred or made available to a third country or to an international organisation with the exception of transfers to Interpol for the purpose of carrying out the queries referred to in point (g) of Article 9a(4) and in point (g) of Article 22b(3) of this Regulation. Transfers of personal data to Interpol are subject to the provisions of Chapter V of Regulation (EU) 2018/1725 and Chapter V of Regulation (EU) 2016/679.
By way of derogation from paragraph 1 of this Article, the data referred to in points (4)(a), (b), (ca), (k) and (m) and points (6) and (7) of Article 9 or in points (d) to (i) and (k) of Article 22a(1) of this Regulation may be accessed by the competent authorities and transferred or made available to a third country or to an international organisation listed in the Annex, provided that it is necessary in individual cases in order to prove the identity of third-country nationals for the purposes of return in accordance with Directive 2008/115/EC, or, as regards transfers to an international organisation listed in the Annex to this Regulation, for the purposes of resettlement in accordance with European or national resettlement schemes, and provided that one of the following conditions is satisfied:
(a) the Commission has adopted a decision on the adequate level of protection of personal data in that third country or international organisation in accordance with Article 45(3) of Regulation (EU) 2016/679; (b) appropriate safeguards have been provided as referred to in Article 46 of Regulation (EU) 2016/679, such as through a readmission agreement which is in force between the Union or a Member State and the third country in question; (c) point (d) of Article 49(1) of Regulation (EU) 2016/679 applies. Moreover, the data referred to in the first subparagraph shall be transferred only where all of the following conditions are satisfied: (a) the transfer of the data is carried out in accordance with the relevant provisions of Union law, in particular provisions on data protection, readmission agreements, and the national law of the Member State transferring the data; (b) the Member State which entered the data in the VIS has given its approval; (c) the third country or international organisation has agreed to process the data only for the purposes for which they were provided. Subject to the first and second subparagraphs of this paragraph, where a return decision adopted pursuant to Directive 2008/115/EC has been issued in relation to a third-country national, the data referred to in the first subparagraph shall be transferred only where the enforcement of such a return decision is not suspended and provided that no appeal has been lodged which may lead to the suspension of its enforcement.
Transfers of personal data to third countries or to international organisations pursuant to paragraph 2 shall not prejudice the rights of applicants for and beneficiaries of international protection, in particular as regards non-refoulement.
Personal data obtained from the VIS by a Member State or by Europol for law enforcement purposes shall not be transferred or made available to any third country, international organisation or private entity established in or outside the Union. The prohibition shall also apply where those data are further processed at national level or between Member States pursuant to Directive (EU) 2016/680.
By way of derogation from paragraph 4 of this Article, the data referred to in point (4)(a) to (ca) of Article 9 and in points (d) to (g) of Article 22a(1) may be transferred by the designated authority to a third country in individual cases, only where all of the following conditions are met:
(a) there is an exceptional case of urgency where there is: (i) an imminent danger associated with a terrorist offence; or (ii) an imminent danger to the life of a person and that danger is associated with a serious criminal offence; (b) the transfer of data is necessary for the prevention, detection or investigation in the territory of the Member States or in the third country concerned of a terrorist offence or other serious criminal offence; (c) the designated authority has access to such data in accordance with the procedure and the conditions set out in Articles 22n and 22o; (d) the transfer is carried out in accordance with the applicable conditions set out in Directive (EU) 2016/680, in particular Chapter V thereof; (e) a duly motivated written or electronic request from the third country has been submitted; (f) the reciprocal provision of any information in visa information systems held by the requesting country to the Member States operating the VIS is ensured. Where a transfer is made pursuant to the first subparagraph of this paragraph, such a transfer shall be documented and the documentation shall, on request, be made available to the supervisory authority referred to in Article 41(1) of Directive (EU) 2016/680, including the date and time of the transfer, information about the receiving competent authority, the justification for the transfer and the personal data transferred.”;
(36) Article 32 is amended, as follows: (a) paragraph 2 is amended as follows: (i) the following point is inserted: “(ea) prevent the use of automated data-processing systems by unauthorised persons using data communication equipment;”; (ii) the following points are inserted: “(ja) ensure that, in the event of an interruption, installed systems can be restored to normal operation; (jb) ensure reliability by making sure that any faults in the functioning of the systems are properly reported and that the necessary technical measures are put in place to ensure that personal data can be restored in the event of corruption due to a malfunctioning of the systems;”; (b) paragraph 3 is replaced by the following: “3. eu-LISA shall take the necessary measures in order to achieve the objectives set out in paragraph 2 as regards the operation of the VIS, including the adoption of a security plan.”;
(37) the following Article is inserted: “Article 32a Security incidents
Any event that has or may have an impact on the security of the VIS and may cause damage to or loss of VIS data shall be considered to be a security incident, in particular where unauthorised access to data may have occurred or where the availability, integrity and confidentiality of data has or may have been compromised.
Security incidents shall be managed so as to ensure a quick, effective and proper response.
Without prejudice to the notification and communication of a personal data breach pursuant to Article 33 of Regulation (EU) 2016/679, Article 30 of Directive (EU) 2016/680, or both, Member States shall notify the Commission, eu-LISA and the European Data Protection Supervisor of security incidents. In the event of a security incident in relation to the VIS Central System, eu-LISA shall notify the Commission and the European Data Protection Supervisor. Europol and the European Border and Coast Guard Agency shall notify the Commission and the European Data Protection Supervisor in the case of a VIS-related security incident.
Information regarding a security incident that has or may have an impact on the operation of the VIS or on the availability, integrity and confidentiality of the VIS data shall be provided to the Commission and, if affected, to Member States, to Europol and to the European Border and Coast Guard Agency. Such incidents shall also be reported in compliance with the incident management plan to be provided by eu-LISA.
Member States, the European Border and Coast Guard Agency, eu-LISA and Europol shall cooperate in the event of a security incident.
The Commission shall inform the European Parliament and the Council without delay of serious incidents and the measures taken to address them. This information shall be classified, where appropriate, as EU RESTRICTED/ RESTREINT UE in accordance with applicable security rules.”;
(38) Articles 33 and 34 are replaced by the following: “Article 33 Liability
Without prejudice to the liability of and the right to compensation from the controller or processor under Regulation (EU) 2016/679, Directive (EU) 2016/680 and Regulation (EU) 2018/1725:
(a) any person or Member State that has suffered material or non-material damage as a result of an unlawful personal data processing operation or any other act incompatible with this Regulation by a Member State shall be entitled to receive compensation from that Member State; (b) any person or Member State that has suffered material or non-material damage as a result of an act of a Union institution, body, office or agency incompatible with this Regulation shall be entitled to receive compensation from that Union institution, body, office or agency. The Member State or Union institution, body, office or agency shall be exempt from its liability under the first subparagraph, in whole or in part, if it proves that it is not responsible for the event which gave rise to the damage.
If any failure of a Member State to comply with its obligations under this Regulation causes damage to the VIS, that Member State shall be held liable for such damage, unless and insofar as eu-LISA or another Member State participating in the VIS failed to take reasonable measures to prevent the damage from occurring or to minimise its impact.
Claims for compensation against a Member State for the damage referred to in paragraphs 1 and 2 shall be governed by the national law of that Member State. Claims for compensation against a Union institution, body, office or agency for the damage referred to in paragraphs 1 and 2 shall be subject to the conditions provided for in the Treaties.”;
Article 34
Keeping of logs
Each Member State, the European Border and Coast Guard Agency and eu-LISA shall keep logs of all their data processing operations within the VIS. Those logs shall show:
(a) the purpose of access; (b) the date and time; (c) the type of data entered; (d) the type of data used for search; and (e) the name of the authority entering or retrieving the data. In addition, each Member State shall keep logs of the staff duly authorised to enter data in or retrieve data from the VIS.
For the queries and consultations referred to in Articles 9a to 9g and 22b, a log for each data processing operation carried out within the VIS and, respectively, the EES, the ETIAS, the SIS, the ECRIS-TCN and Eurodac shall be kept in accordance with this Article and, respectively, Article 28a of Regulation (EU) No 603/2013, Article 46(2) of Regulation (EU) 2017/2226, Article 69 of Regulation (EU) 2018/1240, Article 18a of Regulation (EU) 2018/1861, Article 18a of Regulation (EU) 2018/1862 and Article 31a of Regulation (EU) 2019/816.
For the operations listed in Article 45c of this Regulation a log of each data processing operation carried out within the VIS and the EES shall be kept in accordance with that Article and Article 46 of Regulation (EU) 2017/2226. For the operations listed in Article 17a of this Regulation, a log of each data processing operation carried out in the VIS and the EES shall be kept in accordance with this Article and Article 46 of Regulation (EU) 2017/2226.
Logs kept pursuant to this Article shall be used only for the data-protection monitoring of the admissibility of data processing as well as to ensure data security. The logs shall be protected by appropriate measures against unauthorised access and modification and shall be deleted after a period of one year after the retention period referred to in Article 23 has expired, if they are not required for monitoring procedures which have already begun.”;
(39) Article 36 is replaced by the following: “Article 36 Penalties Without prejudice to Regulation (EU) 2016/679 and Directive (EU) 2016/680, Member States shall lay down the rules on penalties applicable to infringements of this Regulation, including for processing of personal data carried out in breach of this Regulation, and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive.”;
(40) in Chapter VI, the following Article is inserted: “Article 36a Data protection
Regulation (EU) 2018/1725 shall apply to the processing of personal data by the European Border and Coast Guard Agency and eu-LISA under this Regulation.
Regulation (EU) 2016/679 shall apply to the processing of personal data by the visa, border, asylum and immigration authorities when performing tasks under this Regulation.
Directive (EU) 2016/680 shall apply to the processing of personal data stored in the VIS, including access to those data, for the purposes referred to in Chapter IIIb of this Regulation by Member States’ designated authorities under that Chapter.
Regulation (EU) 2016/794 shall apply to the processing of personal data by Europol pursuant to this Regulation.”;
(41) Article 37 is amended as follows: (a) paragraph 1 is amended as follows: (i) the introductory sentence is replaced by the following: “1. Without prejudice to the right to information referred to in Articles 15 and 16 of Regulation (EU) 2018/1725, Articles 13 and 14 of Regulation (EU) 2016/679 and Article 13 of Directive (EU) 2016/680, applicants and the persons referred to in point (4)(f) of Article 9 of this Regulation shall be informed of the following by the Member State responsible:”; (ii) point (a) is replaced by the following: “(a) the identity of the controller referred to in Article 29(4), including the controller’s contact details;”; (iii) point (c) is replaced by the following: “(c) the categories of recipients of the data, including the authorities referred to in Article 22l and Europol; (ca) the fact that the VIS may be accessed by the Member States and Europol for law enforcement purposes;”; (iv) the following point is inserted: “(ea) the fact that personal data stored in the VIS may be transferred to a third country or an international organisation in accordance with Article 31 of this Regulation and to Member States in accordance with Council Decision (EU) 2017/1908 (14); (v) point (f) is replaced by the following: “(f) the existence of the right to request access to data relating to them, the right to request that inaccurate data relating to them be rectified, that incomplete personal data relating to them be completed, that unlawfully processed personal data concerning them be erased or that the processing thereof be restricted, as well as the right to receive information on the procedures for exercising those rights, including the contact details of the supervisory authorities, or of the European Data Protection Supervisor if applicable, which shall hear complaints concerning the protection of personal data;”; (b) paragraph 2 is replaced by the following: “2. The information referred to in paragraph 1 of this Article shall be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language in writing to the applicant when the data, the facial image and the fingerprint data as referred to in Article 9 and Article 22a are collected. Children shall be informed in an age-appropriate manner, including by using visual tools to explain the fingerprinting procedure.”; (c) in paragraph 3, the second subparagraph is replaced by the following: “In the absence of such a form signed by those persons this information shall be provided in accordance with Article 14 of Regulation (EU) 2016/679.”;
(42) Articles 38 to 43 are replaced by the following: “Article 38 Right of access to, rectification, completion, erasure of personal data and restriction of processing
In order to exercise their rights under Articles 15 to 18 of Regulation (EU) 2016/679, any person shall have the right to obtain communication of the data relating to him or her recorded in the VIS and of the Member State which entered them in the VIS. The Member State that receives the request shall examine and reply to it as soon as possible, and at the latest within one month of receipt of the request.
Any person may request that data relating to him or her which are inaccurate be rectified and that data recorded unlawfully be erased.
Where the request is addressed to the Member State responsible and where it is found that VIS data are factually inaccurate or have been recorded unlawfully, the Member State responsible shall, in accordance with Article 24(3), rectify or erase those data in the VIS without delay and at the latest within one month of receipt of the request. The Member State responsible shall confirm in writing to the person concerned without delay that it has taken action to rectify or erase data relating to him or her. Where the request is addressed to a Member State other than the Member State responsible, the authorities of the Member State to which the request was addressed shall contact the authorities of the Member State responsible within a period of seven days. The Member State responsible shall proceed in accordance with the second subparagraph of this paragraph. The Member State which contacted the authority of the Member State responsible shall inform the person concerned that his or her request was forwarded, to which Member State and about the further procedure.
Where the Member State responsible does not agree with the claim that data recorded in the VIS are factually inaccurate or have been recorded unlawfully, it shall without delay adopt an administrative decision explaining in writing to the person concerned why it does not intend to rectify or erase data relating to him or her.
The administrative decision referred to in paragraph 3 shall also provide the person concerned with information explaining the possibility to challenge that decision and, where relevant, information on how to bring an action or a complaint before the competent authorities or courts and information on any assistance available to the person, including from the competent supervisory authorities.
Any request made pursuant to paragraph 1 or 2 shall contain the necessary information to identify the person concerned. That information shall be used exclusively to enable the exercise of the rights referred to in paragraph 1 or 2.
The Member State responsible shall keep a record in the form of a written document that a request as referred to in paragraph 1 or 2 was made and how it was addressed. It shall make that document available to the competent supervisory authorities without delay and not later than seven days following the decision to rectify or erase the data referred to in the second subparagraph of paragraph 2 or following the administrative decision referred to in paragraph 3.
By way of derogation from paragraphs 1 to 6 of this Article, and only as regards data contained in the reasoned opinions that are recorded in the VIS in accordance with Article 9e(6), Article 9g(6) and Article 22b(14) and (16) as a result of the queries pursuant to Articles 9a and 22b, a Member State shall take a decision not to provide information to the person concerned, in whole or in part, in accordance with national or Union law, to the extent that, and for as long as such a partial or complete restriction constitutes a necessary and proportionate measure in a democratic society with due regard for the fundamental rights and legitimate interests of the person concerned, in order to:
(a) avoid obstructing official or legal inquiries, investigations or procedures; (b) avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties; (c) protect public security; (d) protect national security; or (e) protect the rights and freedoms of others. In the cases referred to in the first subparagraph, the Member State shall inform the person concerned in writing, without undue delay, of any refusal or restriction of access and of the reasons for the refusal or restriction. Such information may be omitted where its provision would undermine any of the reasons set out in points (a) to (e) of the first subparagraph. The Member State shall inform the person concerned of the possibility of lodging a complaint with a supervisory authority or of seeking a judicial remedy. The Member State shall document the factual or legal reasons on which the decision not to provide information to the person concerned is based. That information shall be made available to the supervisory authorities. For such cases, the person concerned shall also be able to exercise his or her rights through the competent supervisory authorities.
Article 39
Cooperation to ensure the rights on data protection
The competent authorities of the Member States shall cooperate actively to enforce the rights laid down in Article 38.
In each Member State, the supervisory authority referred to in Article 51(1) of Regulation (EU) 2016/679 shall, upon request, assist and advise the data subject in exercising his or her right to rectification, completion or erasure of personal data relating to him or her or to restriction of the processing of such data, in accordance with Regulation (EU) 2016/679.
In order to achieve the aims referred to in the first subparagraph, the supervisory authority of the Member State responsible and the supervisory authority of the Member State to which the request has been made shall cooperate with each other.
Article 40
Remedies
Without prejudice to Articles 77 and 79 of Regulation (EU) 2016/679, any person shall have the right to bring an action or a complaint before the competent authorities or courts of the Member State which refused the right of access to, rectification, completion or erasure of data relating to him or her provided for in Article 38 and Article 39(2) of this Regulation. The right to bring such an action or complaint shall also apply where requests for access to, rectification, completion or erasure were not responded to within the deadlines provided for in Article 38 or were never dealt with by the data controller.
The assistance of the supervisory authority referred to in Article 51(1) of Regulation (EU) 2016/679 shall remain available throughout the proceedings.
Article 41
Supervision by the supervisory authorities
Each Member State shall ensure that the supervisory authority referred to in Article 51(1) of Regulation (EU) 2016/679 independently monitors the lawfulness of the processing of personal data pursuant to this Regulation by the Member State concerned.
The supervisory authority referred to in Article 41(1) of Directive (EU) 2016/680 shall monitor the lawfulness of the processing of personal data by the Member States in accordance with Chapter IIIb, including the access to personal data by the Member States and their transmission to and from the VIS.
The supervisory authority referred to in Article 51(1) of Regulation (EU) 2016/679 shall ensure that an audit of the data processing operations by the responsible national authorities is carried out in accordance with relevant international auditing standards at least every four years. The results of the audit may be taken into account in the evaluations conducted under the mechanism established by Council Regulation (EU) No 1053/2013 (15). The supervisory authority referred to in Article 51(1) of Regulation (EU) 2016/679 shall publish annually the number of requests for rectification, completion or erasure, or restriction of processing of data, the action subsequently taken and the number of rectifications, completions, erasures and restrictions of processing made in response to requests by the persons concerned.
Member States shall ensure that their supervisory authorities have sufficient resources to fulfil the tasks entrusted to them under this Regulation and have access to advice from persons with sufficient knowledge of biometric data.
Member States shall supply any information requested by the supervisory authorities and shall, in particular, provide them with information on the activities carried out in accordance with their responsibilities under this Regulation. Member States shall grant the supervisory authorities access to their logs and allow them access at all times to all their VIS-related premises.
Article 42
Supervision by the European Data Protection Supervisor
The European Data Protection Supervisor shall be responsible for monitoring the personal data processing activities of eu-LISA, Europol and the European Border and Coast Guard Agency under this Regulation and for ensuring that such activities are carried out in accordance with this Regulation and Regulation (EU) 2018/1725 or, as regards Europol, with Regulation (EU) 2016/794.
The European Data Protection Supervisor shall ensure that an audit of eu-LISA’s personal data processing activities is carried out in accordance with relevant international auditing standards at least every four years. A report of that audit shall be sent to the European Parliament, the Council, eu-LISA, the Commission and the supervisory authorities. eu-LISA shall be given an opportunity to make comments before the reports are adopted.
eu-LISA shall supply information requested by the European Data Protection Supervisor, give the European Data Protection Supervisor access to all documents and to its logs as referred to in Articles 22s, 34 and 45c and allow the European Data Protection Supervisor access to all its premises at any time.
Article 43
Cooperation between supervisory authorities and the European Data Protection Supervisor
The supervisory authorities and the European Data Protection Supervisor shall, each acting within the scope of their respective competences, cooperate actively within the framework of their respective responsibilities to ensure the coordinated supervision of the VIS and the national systems.
The European Data Protection Supervisor and the supervisory authorities shall exchange relevant information, assist each other in carrying out audits and inspections, examine any difficulties concerning the interpretation or application of this Regulation, assess problems in the exercise of independent supervision or in the exercise of the rights of the data subject, draw up harmonised proposals for joint solutions to any problems and promote awareness of data protection rights, as necessary.
For the purposes of paragraph 2, the supervisory authorities and the European Data Protection Supervisor shall meet at least twice a year within the framework of the European Data Protection Board. The European Data Protection Board shall organise and bear the costs of those meetings. Rules of procedure shall be adopted at the first meeting. Further working methods shall be developed jointly as necessary.
A joint report of activities undertaken pursuant to this Article shall be sent by the European Data Protection Board to the European Parliament, to the Council, to the Commission, to Europol, to the European Border and Coast Guard Agency and to eu-LISA every two years. That report shall include a chapter on each Member State prepared by the supervisory authority of that Member State.
(43) Article 44 is deleted;
(44) Article 45 is replaced by the following: “Article 45 Implementation by the Commission
The Commission shall adopt implementing acts to lay down the measures necessary for the development of the VIS Central System, the NUIs in each Member State and the communication infrastructure between the VIS Central System and the NUIs concerning the following:
(a) the design of the physical architecture of the VIS Central System including its communication network; (b) technical aspects which have a bearing on the protection of personal data; (c) technical aspects which have serious financial implications for the budgets of the Member States or which have serious technical implications for the national systems; (d) the development of security requirements, including biometric aspects.
The Commission shall adopt implementing acts to lay down measures necessary for the technical implementation of the functionalities of the VIS Central System, in particular:
(a) for entering the data and linking applications in accordance with Article 8, Articles 10 to 14, Article 22a and Articles 22c to 22f; (b) for accessing the data in accordance with Article 15, Articles 18 to 22, Articles 22g to 22k, Articles 22n to 22r and Articles 45e and 45f; (c) for rectification, erasure and advance erasure of data in accordance with Articles 23, 24 and 25; (d) for keeping and accessing the logs in accordance with Article 34; (e) for the consultation mechanism and the procedures referred to in Article 16; (f) for accessing the data for the purposes of reporting and statistics in accordance with Article 45a.
The Commission shall adopt implementing acts to lay down the technical specifications for the quality, resolution and use of fingerprints and of the facial image for biometric verification and identification in the VIS.
The implementing acts referred to in paragraphs 1, 2 and 3 of this Article shall be adopted in accordance with the examination procedure referred to in Article 49(2).
Article 45a
Use of VIS data for reporting and statistics
The duly authorised staff of the competent authorities of Member States, the Commission, eu-LISA, the European Asylum Support Office and the European Border and Coast Guard Agency, including the ETIAS Central Unit in accordance with Article 9j, shall have access to the VIS to consult the following data, solely for the purposes of reporting and statistics without allowing for individual identification and in accordance with the safeguards related to non-discrimination referred to in Article 7(2):
(a) status information; (b) the authority with which the application has been lodged, including its location; (c) sex, age and nationality or nationalities of the applicant; (d) country and city of residence of the applicant, only as regards visas; (e) current occupation (job group) of the applicant, only as regards visas; (f) the Member States of first entry and destination, only as regards visas; (g) date and place of the application and the decision concerning the application (issued, withdrawn, refused, annulled, revoked, renewed or extended); (h) the type of document applied for or issued, i.e. whether airport transit visa, uniform or limited territorial validity visa, long-stay visa or residence permit; (i) the type of the travel document and the country which issued the travel document, only as regards visas; (j) the decision concerning the application and, in the case of refusal, withdrawal, annulment or revocation, the grounds indicated for that decision; (k) hits resulting from queries of EU information systems, Europol data or Interpol databases pursuant to Article 9a or 22b, differentiated by system or database, or hits against the specific risk indicators pursuant to Article 9j, and hits where, after manual verification pursuant to Article 9c, 9d, 9e or 22b the applicant’s personal data was confirmed as corresponding to the data present in one of the information systems or databases queried; (l) decisions to refuse a visa, long-stay visa or residence permit which are correlated to a manually verified and confirmed hit in one of the information systems or databases queried or to a hit against the specific risk indicators; (m) the competent authority, including its location, which decided on the application and the date of the decision, only as regards visas; (n) the cases in which the same applicant applied for a visa from more than one visa authority, indicating those visa authorities, their location and the dates of the decisions; (o) the main purposes of the journey, only as regards visas; (p) visa applications processed in representation pursuant to Article 8 of Regulation (EC) No 810/2009; (q) the data entered in respect of any document withdrawn, annulled, revoked, renewed or extended, as applicable; (r) the expiry date of the long-stay visa or residence permit; (s) the number of persons exempt from the requirement to give fingerprints pursuant to Article 13(7) of Regulation (EC) No 810/2009; (t) the cases in which the data referred to in point (6) of Article 9 could not be provided, in accordance with Article 8(5); (u) the cases in which the data referred to in point (6) of Article 9 was not required to be provided for legal reasons, in accordance with Article 8(5); (v) the cases in which a person who could not provide the data referred to in point (6) of Article 9 was refused a visa, in accordance with Article 8(5); (w) links to the previous application file on that applicant as well as links of the application files of the persons travelling together, only as regards visas. The duly authorised staff of the European Border and Coast Guard Agency shall have access to the VIS to consult the data referred to in the first subparagraph of this paragraph for the purpose of carrying out risk analyses and vulnerability assessments as referred to in Articles 29 and 32 of Regulation (EU) 2019/1896.
For the purposes of paragraph 1 of this Article, eu-LISA shall store the data referred to in that paragraph in the central repository for reporting and statistics referred to in Article 39 of Regulation (EU) 2019/817. In accordance with Article 39(1) of that Regulation, cross-system statistical data and analytical reporting shall allow the authorities listed in paragraph 1 of this Article to obtain customisable reports and statistics, to support the implementation of the specific risk indicators referred to in Article 9j of this Regulation, to improve the assessment of the security, illegal immigration and high epidemic risks, to enhance the efficiency of border checks and to help the visa authorities to process visa applications.
The procedures put in place by eu-LISA to monitor the functioning of the VIS referred to in Article 50(1) shall include the possibility to produce regular statistics for ensuring that monitoring.
Every quarter, eu-LISA shall compile statistics based on the VIS data on visas showing, for each location where a visa application was lodged and for each Member State, in particular:
(a) the number of airport transit (A) visas applied for; the number of A visas issued, disaggregated by single airport transit and multiple airport transits; the number of A visas refused; (b) the number of short-stay (C) visas applied for (and disaggregated by the main purposes of the journey); the number of C visas issued, disaggregated by issued for single entry, two entries or multiple entry and the latter divided by length of validity (six months or below, one year, two years, three years, four years, five years); the number of visas with limited territorial validity issued (LTV); the number of C visas refused. The daily statistics shall be stored in the central repository for reporting and statistics in accordance with Article 39 of Regulation (EU) 2019/817.
Every quarter, eu-LISA shall compile statistics based on the VIS data on long-stay visas and residence permits showing, for each location, in particular:
(a) total of long-stay visas applied for, issued, refused, withdrawn, revoked, annulled and extended; (b) total of residence permits applied for, issued, refused, withdrawn, revoked, annulled and renewed.
At the end of each year, statistical data shall be compiled in an annual report for that year. The statistics shall contain a breakdown of data for each location and each Member State. The report shall be published and transmitted to the European Parliament, to the Council, to the Commission, to the European Border and Coast Guard Agency, to the European Data Protection Supervisor and to the supervisory authorities.
At the request of the Commission, eu-LISA shall provide it with statistics on specific aspects related to the implementation of the common visa policy or of the migration and asylum policy, including on aspects pursuant to the application of Regulation (EU) No 1053/2013.
Article 45b
Notifications
Member States shall notify the Commission of the authority which is to be considered as controller as referred to in Article 29(4).
Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.
This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence.
EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.