[eu]cite

Home› Justice & Home Affairs› SIS Borders Regulation

Chapter VIII · GENERAL DATA PROCESSING RULES › Article 41

Processing of SIS data

1.   The Member States shall only process the data referred to in Article 20 for the purposes of refusing entry into and stay on their territories.

2.   Data shall only be copied for technical purposes, where such copying is necessary in order for the competent authorities referred to in Article 34 to carry out a direct search. This Regulation shall apply to those copies. A Member State shall not copy alert data or additional data entered by another Member State from its N.SIS or from the CS-SIS into other national data files.

3.   Technical copies referred to in paragraph 2 which result in offline databases may be retained for a period not exceeding 48 hours.

Notwithstanding the first subparagraph, technical copies which result in offline databases to be used by visa-issuing authorities shall not be permitted, except for copies made to be used only in an emergency following the unavailability of the network for more than 24 hours.

Member States shall keep an up-to-date inventory of those copies, make that inventory available to their supervisory authorities, and ensure that this Regulation, in particular Article 10, is applied in respect of those copies.

4.   Access to data in SIS by national competent authorities referred to in Article 34 shall only be authorised within the limits of their competence and only to duly authorised staff.

5.   Any processing of SIS data by Member States for purposes other than those for which it was entered into SIS has to be linked with a specific case and justified by the need to prevent an imminent and serious threat to public policy and to public security, on serious grounds of national security or for the purposes of preventing a serious crime. Prior authorisation from the issuing Member State shall be obtained for this purpose.

6.   Data concerning documents related to persons that are entered into SIS under points (k) and (l) of Article 38(2) of Regulation (EU) 2018/1862 may be used by the competent authorities referred to in point (f) of Article 34(1) in accordance with the laws of each Member State.

7.   Any use of SIS data which does not comply with paragraphs 1 to 6 of this Article shall be considered as misuse under the national law of each Member State and subject to penalties in accordance with Article 59.

8.   Each Member State shall send to eu-LISA a list of its competent authorities which are authorised to search the data in SIS directly pursuant to this Regulation, as well as any changes to the list. The list shall specify, for each authority, which data it may search and for what purposes. eu-LISA shall ensure that the list is published in the Official Journal of the European Union annually. eu-LISA shall maintain a continuously updated list on its website containing changes sent by Member States between the annual publications.

9.   Insofar as Union law does not lay down specific provisions, the law of each Member State shall apply to data in its N.SIS.

←→ also move between articles