1. eu-LISA, the ETIAS Central Unit and the ETIAS National Units shall ensure the security of processing of personal data pursuant to this Regulation. eu-LISA, the ETIAS Central Unit and the ETIAS National Units shall cooperate on data security related tasks.
2. Without prejudice to Article 22 of Regulation (EC) No 45/2001, eu-LISA shall take the necessary measures to ensure the security of the ETIAS Information System.
3.
Without prejudice to Article 22 of Regulation (EC) No 45/2001 and Articles 32 and 34 of Regulation (EU) 2016/679, eu-LISA, the ETIAS Central Unit and the ETIAS National Units shall adopt the necessary measures, including a security plan and a business continuity and disaster recovery plan, in order to:
(a)
physically protect data, including by making contingency plans for the protection of critical infrastructure;
(b)
deny unauthorised persons access to the secure web service, the email service, the secure account service, the carrier gateway, the verification tool for applicants and the consent tool for applicants;
(c)
deny unauthorised persons access to data processing equipment and national installations in accordance with the purposes of ETIAS;
(d)
prevent the unauthorised reading, copying, modification or removal of data media;
(e)
prevent the unauthorised input of data and the unauthorised inspection, modification or deletion of recorded personal data;
(f)
prevent the use of automated data processing systems by unauthorised persons using data communication equipment;
(g)
prevent the unauthorised processing of data in the ETIAS Central System and any unauthorised modification or deletion of data processed in the ETIAS Central System;
(h)
ensure that persons authorised to access the ETIAS Information System have access only to the data covered by their access authorisation, by means of individual and unique user identities and confidential access modes only;
(i)
ensure that all authorities with a right of access to the ETIAS Information System create profiles describing the functions and responsibilities of persons who are authorised to access the data and make their profiles available to the supervisory authorities;
(j)
ensure that it is possible to verify and establish to which bodies personal data may be transmitted using data communication equipment;
(k)
ensure that it is possible to verify and establish what data has been processed in the ETIAS Information System, when, by whom and for what purpose;
(l)
prevent the unauthorised reading, copying, modification or deletion of personal data during the transmission of personal data to or from the ETIAS Central System or during the transport of data media, in particular by means of appropriate encryption techniques;
(m)
ensure that, in the event of an interruption, installed systems can be restored to normal operation;
(n)
ensure reliability by making sure that any faults in the functioning of ETIAS are properly reported and that necessary technical measures are put in place to ensure that personal data can be restored in the event of corruption due to a malfunctioning of ETIAS;
(o)
monitor the effectiveness of the security measures referred to in this paragraph and take the necessary organisational measures related to internal monitoring to ensure compliance with this Regulation.
4. The Commission shall, by means of implementing acts, adopt a model security plan and a model business continuity and disaster recovery plan. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 90(2). eu-LISA’s Management Board, the European Border and Coast Guard Agency’s Management Board and the Member States shall adopt the security, business continuity and disaster recovery plans for eu-LISA, for the ETIAS Central Unit and for the ETIAS National Units respectively. They shall use the model plans adopted by the Commission as a basis, adjusted as necessary.
5. eu-LISA shall inform the European Parliament, the Council and the Commission and the European Data Protection Supervisor of the measures it takes pursuant to this Article.