1. eu-LISA shall ensure that procedures are in place to monitor the functioning of SIS against objectives relating to output, cost-effectiveness, security and quality of service.
2. For the purposes of technical maintenance, reporting, data quality reporting and statistics, eu-LISA shall have access to the necessary information relating to the processing operations performed in Central SIS.
3. eu-LISA shall produce daily, monthly and annual statistics showing the number of records per category of alerts, both for each Member State and in aggregate. eu-LISA shall also provide annual reports on the number of hits per category of alert, how many times SIS was searched and how many times SIS was accessed for the purpose of entering, updating or deleting an alert, both for each Member State and in aggregate. Such statistics shall include statistics on the exchanges of information under Article 27 to Article 31. The statistics produced shall not contain any personal data. The annual statistical report shall be published.
4. Member States, Europol and the European Border and Coast Guard Agency shall provide eu-LISA and the Commission with the information necessary to draft the reports referred to in paragraphs 3, 5, 7 and 8.
5. eu-LISA shall provide the European Parliament, the Council, the Member States, the Commission, Europol, the European Border and Coast Guard Agency and the European Data Protection Supervisor with any statistical reports that it produces.
In order to monitor the implementation of Union legal acts, including for the purposes of Regulation (EU) No 1053/2013, the Commission may request that eu-LISA provide additional specific statistical reports, either on a regular or ad hoc basis, on the performance of SIS, the use of SIS and on the exchange of supplementary information.
The European Border and Coast Guard Agency may request that eu-LISA provide additional specific statistical reports for the purpose of carrying out risk analyses and vulnerability assessments as referred to in Articles 11 and 13 of Regulation (EU) 2016/1624, either on a regular or ad hoc basis.
6. For the purpose of Article 15(4) and of paragraphs 3, 4 and 5 of this Article, eu-LISA shall establish, implement and host a central repository in its technical sites containing the data referred to in Article 15(4) and in paragraph 3 of this Article which shall not allow for the identification of individuals and which shall allow the Commission and the agencies referred to in paragraph 5 of this Article to obtain bespoke reports and statistics. Upon request, eu-LISA shall give access to Member States, the Commission, Europol, and the European Border and Coast Guard Agency, to the extent required for the performance of their tasks, to the central repository by means of secured access through the Communication Infrastructure. eu-LISA shall implement access controls and specific user profiles to ensure that the central repository is accessed solely for the purpose of reporting and statistics.
7. Two years after the date of application of this Regulation pursuant to the first subparagraph of Article 66(5) and every two years thereafter, eu-LISA shall submit to the European Parliament and to the Council a report on the technical functioning of Central SIS and of the Communication Infrastructure, including their security, on the AFIS and on the bilateral and multilateral exchange of supplementary information between Member States. This report shall also contain, once the technology is in use, an evaluation of the use of facial images to identify persons.
8. Three years after the date of application of this Regulation pursuant to the first subparagraph of Article 66(5) and every four years thereafter, the Commission shall carry out an overall evaluation of Central SIS and the bilateral and multilateral exchange of supplementary information between Member States. That overall evaluation shall include an examination of results achieved against objectives, and an assessment of the continuing validity of the underlying rationale, the application of this Regulation in respect of Central SIS, the security of Central SIS and any implications for future operations. The evaluation report shall also include an assessment of the AFIS and the SIS information campaigns carried out by the Commission in accordance with Article 19.
The evaluation report shall also contain statistics on the number of alerts entered in accordance with point
(a) of Article 24(1)and statistics on the number of alerts entered in accordance with point
(b) of that paragraph. As regards alerts falling under point
(a) of Article 24(1), it shall detail how many alerts were entered following the situations referred to in point (a),
(b) or
(c) of Article 24(2). The evaluation report shall also contain an assessment of the application of Article 24 by Member States.
The Commission shall transmit the evaluation report to the European Parliament and to the Council.
9. The Commission shall adopt implementing acts to lay down detailed rules on the operation of the central repository referred to in paragraph 6 of this Article and the data protection and security rules applicable to that repository. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2).