1. Any event that has or may have an impact on the security of ETIAS and may cause damage or loss to the data stored in ETIAS shall be considered to be a security incident, in particular where unauthorised access to data may have occurred or where the availability, integrity and confidentiality of data has or may have been compromised.
2. Security incidents shall be managed so as to ensure a quick, effective and proper response.
3. Without prejudice to the notification and communication of a personal data breach pursuant to Article 33 of Regulation (EU) 2016/679, Article 30 of Directive (EU) 2016/680, or both, Member States shall notify the Commission, eu-LISA and the European Data Protection Supervisor of security incidents. In the event of a security incident in relation to the ETIAS Information System, eu-LISA shall notify the Commission and the European Data Protection Supervisor. Europol shall notify the Commission and the European Data Protection Supervisor in the case of an ETIAS-related security incident.
4. Information regarding a security incident that has or may have an impact on the operation of ETIAS or on the availability, integrity and confidentiality of the data stored in ETIAS shall be provided to the Commission and, if affected, to the ETIAS Central Unit, to the ETIAS National Units and to Europol. Such incidents shall also be reported in compliance with the incident management plan to be provided by eu-LISA.
5. Member States, the European Border and Coast Guard Agency, eu-LISA and Europol shall cooperate in the event of a security incident.
Home› Justice & Home Affairs› ETIAS Regulation
Chapter XII · DATA PROTECTION › Article 60
Security incidents
←→ also move between articles