Source: OJ L, 2024/607, 16.2.2024Current language: EN
- Digital services act
Implementing acts
- Information sharing system
Annex I
Responsibilities of the Digital Services Coordinators as joint controllers for data processing activities conducted in the context of AGORA for joint investigations and for the activities of the Board
SECTION 1
Subsection 1 Scope of the joint controllership arrangement
The following joint controllership arrangement shall apply to the concerned Digital Services Coordinators when conducting joint investigations pursuant to Article 60 of Regulation (EU) 2022/2065.
The following joint controllership arrangement shall apply to the Digital Services Coordinators as members of the Board for the processing of personal data activities of the Board pursuant to Regulation (EU) 2022/2065, carried out in the context of the supervision, investigation, enforcement and monitoring of services in scope of Regulation (EU) 2022/2065.
Subsection 2 Allocation of responsibilities
The joint controllers shall process personal data through AGORA.
The Digital Services Coordinators shall remain the sole controllers for the collection, use, disclosure and any other processing of personal data carried out outside AGORA. The Digital Services Coordinators shall also remain the sole controllers for the personal data processing activities they carry out within AGORA for the supervision, investigation, enforcement and monitoring of services in scope of Regulation (EU) 2022/2065.
Each joint controller shall be responsible for the processing of personal data in AGORA in accordance with Articles 5, 24 and 26 of Regulation (EU) 2016/679.
Each joint controller shall set up a contact point with a functional mailbox for the communication between the joint controllers themselves and between the joint controllers and the processor.
Each joint controller, when so requested, shall provide a swift and efficient assistance to the other joint controllers in execution of this arrangement, while complying with all applicable requirements of Regulation (EU) 2016/679 and other applicable data protection rules, including obligations towards its own respective supervisory authority.
The joint controllers shall define the working modalities through which processing of personal data through AGORA shall take place, and shall provide agreed upon instructions to the Commission as a processor.
Instructions to the processor shall be sent by any of the joint controllers’ contact points in agreement with the other joint controllers. The joint controller who provides the instruction shall provide them to the processor in writing and inform all other joint controllers of this. If the matter at hand is sufficiently time-critical that it does not allow for a meeting of the joint controllers, an instruction may be provided nonetheless, but may be rescinded by the joint controllers. This instruction shall be given in writing, and all other joint controllers shall be informed of this at the time of giving the instruction.
The working modalities between joint controllers shall not preclude any of the joint controllers’ individual competence to inform their competent Supervisory Authority in accordance with Articles 24 and 33 of Regulation (EU) 2016/679. Such notification shall not require the consent of any of the other joint controllers.
The working modalities between joint controllers shall not preclude any of the joint controllers to cooperate with its respective competent Supervisory Authority established under Regulation (EU) 2016/679 and Regulation (EU) 2018/1725.
Only persons authorised by each joint controller shall access the personal data exchanged.
Each joint controller shall maintain a record of the processing activities under its responsibility. The joint controllership shall be indicated in such a record.
Subsection 3 Responsibilities and roles for handling requests of and informing data subjects
Each controller shall provide information to natural persons whose data is being processed for joint investigations and activities of the Board carried out in the context of supervision, investigation, enforcement and monitoring of services in scope of Regulation (EU) 2022/2065, in accordance with Article 14 of Regulation (EU) 2016/679, unless this would prove impossible or would involve a disproportionate effort.
Each controller shall act as the contact point for natural persons whose personal data it has processed and shall handle the requests submitted by data subjects or their representatives in the exercise of their rights in accordance with Regulation (EU) 2016/679. If a joint controller receives a request from a data subject that relates to the processing by another joint controller, it shall inform the data subject of the identity and contact details of the responsible joint controller. If requested by another joint controller, the joint controllers shall assist each other in handling data subjects’ requests and shall reply to each other without undue delay and at the latest within one month from receiving a request for assistance.
Each controller shall make available the content of this Annex to data subjects.
SECTION 2 MANAGEMENT OF SECURITY INCIDENTS, INCLUDING PERSONAL DATA BREACHES
The joint controllers shall assist each other in the identification and handling of any security incidents, including personal data breaches, linked to the processing in AGORA.
In particular, the joint controllers shall notify each other of:
any potential or actual risks to the availability, confidentiality and/or integrity of the personal data undergoing processing in AGORA;
any personal data breach, the likely consequences of the personal data breach and the assessment of the risk to the rights and freedoms of natural persons, and any measures taken to address the personal data breach and to mitigate the risk to the rights and freedoms of natural persons; and
any breach of the technical and/or organisational safeguards of the processing operation in AGORA.
The joint controllers shall communicate any personal data breaches related to the processing operation in AGORA to the Commission, to the competent data protection supervisory authorities and, where required, to data subjects, in accordance with Articles 33 and 34 of Regulation (EU) 2016/679, or following notification by the Commission.
Each controller shall implement appropriate technical and organisational measures, designed to:
ensure and protect the availability, integrity and confidentiality of the personal data jointly processed;
protect against any unauthorised or unlawful processing, loss, use, disclosure or acquisition of or access to any personal data in its possession; and
ensure that access to the personal data is not disclosed or granted to anyone else other than the recipients or processor.
SECTION 3 DATA PROTECTION IMPACT ASSESSMENT
If a controller, in order to comply with its obligations under Articles 35 and 36 of Regulation (EU) 2016/679 needs information from another controller or from the processor, it shall send a specific request to the functional mailbox referred to in Subsection 2(4) of Section 1. The latter shall use its best efforts to provide any such information.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.