[eu]cite

Home› Justice & Home Affairs› ECRIS-TCN Regulation

Chapter V · Data protection rights and supervision › Article 31

Keeping of logs

1.   eu-LISA and the competent authorities shall ensure, in accordance with their respective responsibilities, that all data processing operations in ECRIS-TCN are logged in accordance with paragraph 2 for the purposes of checking the admissibility of requests, monitoring data integrity and security and the lawfulness of the data processing as well as for the purposes of self-monitoring.

2.   The log shall show:

(a)

the purpose of the request for access to ECRIS-TCN data;

(b)

the data transmitted as referred to in Article 5;

(c)

the national file reference;

(d)

the date and exact time of the operation;

(e)

the data used for a query;

(f)

the identifying mark of the official who carried out the search.

3.   The log of consultations and disclosures shall make it possible to establish the justification of such operations.

4.   Logs shall be used only for monitoring the lawfulness of data processing and for ensuring data integrity and security. Only logs containing non-personal data may be used for the monitoring and evaluation referred to in Article 36. Those logs shall be protected by appropriate measures against unauthorised access and erased after three years, if they are no longer required for monitoring procedures which have already begun.

5.   On request, eu-LISA shall make the logs of its processing operations available to the central authorities without undue delay.

6.   The competent national supervisory authorities responsible for checking the admissibility of the requests and monitoring the lawfulness of the data processing and data integrity and security shall have access to logs at their request for the purpose of fulfilling their duties. On request, the central authorities shall make the logs of their processing operations available to the competent national supervisory authorities without undue delay.

←→ also move between articles