Source: OJ L, 2024/607, 16.2.2024Current language: EN
- Digital services act
Implementing acts
- Information sharing system
Annex II
Responsibilities of the commission as processor for data processing activities conducted in the context of AGORA by Digital Services Coordinators, other national authorities and the Board
The Commission shall:
set up and ensure a secure and reliable communication infrastructure, the AGORA, on behalf of the Digital Services Coordinators, other national authorities and the Board that supports the exchange of information for coordinated investigations, consistency mechanisms and activities of the Board, and
process personal data only based on documented instructions from the controllers and joint controllers, unless required to do so under Union or Member State laws; in such a case, the Commission shall inform the controllers and joint controllers of that legal requirement before carrying on the processing activity, unless that law prohibits submitting such information on important grounds of public interest.
To fulfil its obligations as processor for the Digital Services Coordinators, other national authorities and the Board, the Commission may use third parties as sub-processors. If it is the case, the controllers and joint controllers shall authorise the Commission to use sub-processors or replace sub-processors where necessary. The Commission shall inform the controllers and joint controllers of said use or replacement of sub-processors, thereby giving the controllers and joint controllers the opportunity to object to any such changes. The Commission shall ensure that the same data protection obligations as set out in this Regulation apply to these sub-processors.
The processing by the Commission shall entail:
authentication and access control with regard to all AGORA administrators and AGORA users;
authorisation of AGORA administrators and AGORA users to create, update and delete any records and information contained in AGORA;
reception of the personal data referred to in Article 12(3) of this Regulation uploaded by national AGORA users and AGORA administrators by providing an application programming interface that allows national AGORA users and AGORA administrators to upload the relevant data;
storage of the personal data in AGORA;
making the personal data available for access and download by AGORA administrators and AGORA users and any other necessary data processing activity;
deletion of the personal data at their expiration date or upon instruction of the controller that submitted them;
after the end of the provision of service, deletion of any remaining personal data unless Union or Member State laws require storage of such personal data.
The Commission shall take all state of the art organisational, physical, and logical security measures to ensure AGORA functioning. To this end, the Commission shall:
designate a responsible entity for the security management of AGORA, communicate to the joint controllers its contact information and ensure its availability to react to security threats;
assume the responsibility for the security of AGORA, including regularly carrying out tests, evaluations and assessments of the security measures;
ensure that AGORA administrators and AGORA users that are granted access to AGORA are subject to a contractual, professional or statutory obligation of confidentiality.
The Commission shall take all necessary security measures to avoid compromising the smooth operational functioning of AGORA. This shall include:
risk assessment procedures to identify and estimate potential threats to AGORA;
audit and review procedure to:
check the correspondence between the implemented security measures and the applicable security policy;
control on a regular basis the integrity of AGORA files, security parameters and granted authorisations;
detect security breaches and intrusions into AGORA;
implement changes to mitigate existing security weaknesses in AGORA;
define the conditions under which to authorise, including at the request of controllers, and contribute to, the performance of independent audits, including inspections, and reviews on security measures subject to conditions that respect Protocol (No 7) to the Treaty on the Functioning of the European Union on the Privileges and Immunities of the European Union;
changing the control procedure to document, measure the impact of a change before its implementation, and keep the controllers and joint controllers informed of any changes that can affect the communication with and/or the security of AGORA;
laying down a maintenance and repair procedure to specify the rules and conditions to be respected when maintenance and/or repair of AGORA equipment is to be performed;
laying down a security incident procedure to define the reporting and escalation scheme, inform without delay the controllers affected, inform without delay the controllers for them to notify the national data protection supervisory authorities of any personal data breach and define a disciplinary process to deal with security breaches in AGORA.
The Commission shall take state of the art physical and logical security measures for the facilities hosting AGORA and for the controls of data and security access thereto. To this end, the Commission shall:
enforce physical security to establish distinct security perimeters and allowing detection of breaches in AGORA;
control access to AGORA facilities and maintain a AGORA visitor register for tracing purposes;
ensure that external individuals granted access to the premises are escorted by duly authorised staff;
ensure that equipment cannot be added, replaced or removed without prior authorisation from the designated responsible bodies;
control access from and to the AGORA;
ensure that AGORA administrators and AGORA users who access AGORA are identified and authenticated;
review the authorisation rights related to the access to AGORA in case of a security breach affecting AGORA;
keep the integrity of the information transmitted through AGORA;
implement technical and organisational security measures to prevent unauthorised access to personal data in AGORA;
implement, whenever necessary, measures to block unauthorised access to AGORA (i.e., block a location/IP address).
The Commission shall:
take steps to protect its domain, including the severing of connections, in the event of substantial deviation from the principles and concepts for quality and security;
maintain a risk management plan related to its area of responsibility;
monitor, in real time, the performance of all the service components of AGORA, produce regular statistics and keep records;
provide support for AGORA in English to AGORA administrators and AGORA users;
assist the controllers and joint controllers by appropriate technical and organisational measures for the fulfilment of the controller’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III of Regulation (EU) 2016/679;
support the controllers and joint controllers by providing information concerning AGORA to implement the obligations pursuant to Articles 32, 33, 34, 35 and 36 of Regulation (EU) 2016/679;
ensure that data processed within AGORA is unintelligible to any person who is not authorised to access it;
take all relevant measures to prevent unauthorised access to transmitted personal data via AGORA;
take measures in order to facilitate communication between the controllers and joint controllers;
maintain a record of processing activities carried out on behalf of the controllers and joint controllers in accordance with Article 31(2) of Regulation (EU) 2018/1725.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.