Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 19 Sept 2022
on the proposal for a regulation of the European Parliament and of the Council on automated data exchange for police cooperation (“Prüm II”), amending Council Decisions 2008/615/JHA and 2008/616/JHA and Regulations (EU) 2018/1726, 2019/817 and 2019/818 of the European Parliament and of the Council
To · plenary report· 26 May 2023
on the proposal for a regulation of the European Parliament and of the Council on automated data exchange for police cooperation (“Prüm II”), amending Council Decisions 2008/615/JHA and 2008/616/JHA and Regulations (EU) 2018/1726, 2019/817 and 2019/818 of the European Parliament and of the Council
+115 added · −64 removed · 128 changed paragraphs, packaging included.
Part 5 of 7: Paragraphs 241–300
Change 103
Changed:Article 49 – paragraph 1: 1. Without prejudice to any restrictions indicated by the provider of the information to Europol in accordance with Article 19(2) of Regulation (EU) 2016/794, Member States shall, in accordance with Regulation (EU) 2016/794, have access to, and be able to search via the router, biometric data which has been provided to Europol by third-countrythird authoritiescountries for the purposes of Article 18(2), points(a),points (a), (b) and (c), of Regulation (EU) 2016/794.
Change 104
Changed:Article 49 – paragraph 2: 2. Where the search referred to in paragraph 1 results in a match between the data used for the search and third-country-sourced data held by Europol, the follow-up shall take place in accordance with Regulation (EU) 2016/794.
Change 105
Changed:Article 50 – paragraph 1: 1. Where necessary to achieve itsthe objectives and carryset out its tasks, Europol shall, in accordanceArticle with3 of Regulation (EU) 2016/794, have access, for the purposes of Article 18(2), pointsEuropol (a)shall, andin (c),accordance ofwith Regulation (EU) 2016/794, have access to data which are stored by Member States in their national databases and police records indexes in accordance with this Regulation.
Change 106
Changed:Article 50 – paragraph 3:4: 3.4. Europol queries performed with vehicle registrationbiographical data as referred to in Article 1825 as a search criterion shall be carried out using Eucaris.EPRIS.
Change 107
Changed:Article 50 – paragraph 4:5: 4.5. Europol queriesshall performedcarry without the biographicalsearches datain ofaccordance suspectswith andparagraph convicted1 personsof asthis referredArticle toonly infor Articlesthe 25purpose andof 26Article as18(2), apoint search(a), criterionof shallRegulation be(EU) carried2016/794, when carrying out usingits EPRIS.tasks referred to in Regulation (EU) 2016/794.
Change 108
Removed:Article 50 – paragraph 5: deleted
Added:Article 50 – paragraph 6 – introductory part: 6. Where the procedures referred to in Article 6, 7, 13 or 22 show a match between the data used for the search or comparison and data held in the national database of the requested Member State(s), and upon human review of that match by qualified staff of Europol in accordance with this Regulation and the transmission of the name of the third country which provided the data, the requested Member State shall decide whether to return a set of core data via the router within 24 hours. Where a judicial authorisation is required under national law, the core data shall be returned within 72 hours. That set of core data, if available, shall contain the following data:
Change 109
Changed:Article 50 – paragraph 67: –7. introductoryEuropol's part:use 6.of Whereinformation theobtained proceduresfrom referreda tosearch made in Articleaccordance 6,with 7,paragraphs 131 orand 225, showand afrom matchthe betweenexchange theof datacore useddata forin theaccordance searchwith orparagraph comparison6, andshall databe heldsubject into the national databaseconsent of the requested Member State(s), and uponState manualin confirmationwhose ofdatabase thatthe match byoccurred. Europol,If the requested Member State shall decide whether to return a set of core data viaallows the router within 24 hours. Where a judicial authorisation isuse requiredof undersuch nationalinformation, law,its thehandling coreby dataEuropol shall be returned within 72 hours. That set of core data, if available, shallgoverned containby theRegulation following(EU) data:2016/794.
Change 110
Removed:Article 50 – paragraph 7: 7. Europol's use of information obtained from a search made in accordance with paragraph 1 and from the exchange of core data in accordance with paragraph 6 shall be subject to the consent of the Member State in whose database the match occurred. If the Member State allows the use of such information, its handling by Europol shall be governed by Regulation (EU) 2016/794.
Article 51 – title: Purpose of the data processing
Change 111
Changed:Article 51 – paragraph 1: 1. Processing of personal data received by the requesting Member State or Europol shall be permitted solely for the purposes for which the data have been supplied by the requested Member State.State Processingin accordance with this Regulation. Without prejudice to Directive (EU) 2016/680 or Regulation (EU) 2018/1725, as applicable, processing for other purposes shall be permitted solely with the prior authorisation of the requested Member State or Europol, as relevant.
Article 51 – paragraph 2 – introductory part: 2. Processing of data supplied pursuant to Article 6, 7, 13, 18, 22 or 26 by the requesting Member State or Europol shall be permitted solely where necessary in order to:
Change 112
Changed:Article 51 – paragraph 2 – point a a (new): (aa) exchange a set of core data in accordancepursuant withto Article 47;
Article 51 – paragraph 2 – point b: (b) prepare and submit a police or judicial request for legal assistance if those data match;
Article 51 – paragraph 2 – point c: (c) logging within the meaning of Articles 20, 40 and 45.
Change 113
Changed:Article 51 – paragraph 3: 3. The personal data received by the requesting Member State or Europol shall be deleted immediately following data comparison or automated replies to searches unless further processing is necessary by the requesting Member State is strictly necessary and proportionate for the purposes of the prevention, detection and investigation of criminal offences.
Change 114
Changed:Article 5251 – paragraph 1: 1. Member States and Europol shall ensure the accuracy and current4: relevance4. ofData personalsupplied datain whichaccordance arewith processedArticle pursuant18 tomay thisbe Regulation.used Shouldby athe requestedrequesting Member State or Europol become aware that incorrect data or data which should not have been supplied have beensolely supplied,where this shallis bestrictly notifiednecessary withoutand delayproportionate to anyachieve requestingthe Memberpurposes State.of Allthis requestingRegulation. MemberThe Statesdata concernedsupplied shall be obliged to correct or delete the data accordinglydeleted withoutimmediately unduefollowing delay.automated Moreover,replies personalto datasearches suppliedunless shallfurther beprocessing correctedis ifnecessary theyfor arerecording foundpursuant to be incorrect.Article If20. theThe requesting Member State or Europol has reason to believeshall thatuse the supplied data arereceived incorrectin ora shouldreply besolely deletedfor the requestedprocedure Memberfor Statewhich shallthe besearch informed.was made.
Change 115
Added:Article 51 – paragraph 4 a (new): 4a. Prior to connecting their national databases to the router, EPRIS or Eucaris, Member States shall conduct a data protection impact assessment as referred to in Article 27 of Directive (EU) 2016/680 and consult the supervisory authority as referred to in Article 28 of that Directive. The supervisory authority may use any of its powers referred to in Article 47 of Directive (EU) 2016/680, in accordance with paragraph 5 of Article 28 of that Directive.
Added:Article 51 – paragraph 4 b (new): 4b. Member States shall ensure that data subjects are provided with information pursuant to Article 13 of Directive (EU) 2016/680 to allow them to exercise their rights.
Added:Article 51 – paragraph 4 c (new): 4c. The European Data Protection Board shall issue guidelines on the implementation of Directive (EU) 2016/680 concerning the criminal databases and cross-border exchanges of personal data, in particular concerning accuracy, strict necessity and how to ensure respect for the right to data protection.
Added:Article 52 – paragraph 1: 1. Member States and Europol shall ensure the accuracy and current relevance of personal data which are processed pursuant to this Regulation. Should a requested Member State or Europol become aware that data that are incorrect or no longer up to date or data which should not have been supplied have been supplied, this shall be notified without delay to any requesting Member State. All requesting Member States concerned shall be obliged to correct or delete the data accordingly without delay. Moreover, personal data supplied shall be corrected if they are found to be incorrect. If the requesting Member State or Europol has reason to believe that the supplied data are incorrect or should be deleted the requested Member State shall be informed without delay.
Added:Article 52 – paragraph 1 – subparagraph 1 a (new): Member States and Europol shall put in place appropriate measures for updating their databases, including as regards acquittals of persons whose personal data are in the databases.
Article 52 – paragraph 2: 2. Where a data subject contested the accuracy of data in possession of a Member State or Europol, where the accuracy cannot be reliably established by the Member State concerned or Europol and where it is requested by the data subject, the data concerned shall be marked with a flag. Where such a flag exists, Member States or Europol may remove it only with the permission of the data subject or based on a decision of the competent court or national supervisory authority or the European Data Protection Supervisor, as relevant.
Change 116
Changed:Article 52 – paragraph 3 – subparagraph 1 – point b: (b) following the expiry of the maximum period for keeping data laid down under the national law of the requested Member State where the requested Member State or Europol informed the requesting Member State of that maximum period at the time of supplying the data;
Change 117
Changed:Article 52 – paragraph 3 – subparagraph 1 – point b a (new): (ba) following the expiry of the maximum period for keeping data laid down in Regulation (EU) 2016/794.
Change 118
Changed:Article 52 – paragraph 3 – subparagraph 1:2: Where there is reason to believe that the deletion of data would prejudice the interests of the data subject, the data shall be restricted instead of being deleted. Restricted data shall be processed solely for the purpose which prevented their deletion.
Article 53 – paragraph 2 a (new): 2a. Member States shall be the processors for the processing of personal data via Eucaris.
Article 54 – paragraph 1: 1. Europol, eu-LISA and Member States’ competent law enforcement authorities shall ensure the security of the processing of personal data that takes place pursuant to this Regulation. Europol, eu-LISA and Member States’ competent law enforcement authorities shall cooperate on security-related tasks.
Article 54 – paragraph 2: 2. Without prejudice to Article 91 of Regulation (EU) 2018/1725 and Article 32 of Regulation (EU) 2016/794, eu-LISA and Europol shall take the necessary measures to ensure the security of the router and EPRIS respectively as well as their related communication infrastructure.
Change 119
Removed:Article 55 – paragraph 3 – subparagraph 1: Without prejudice to Article 34 of Regulation (EU) 2016/794 and Article 92 of Regulation (EU) 2018/1725, Europol shall notify CERT-EU of significant cyber threats, significant vulnerabilities and significant incidents without undue delay and in any event no later than 24 hours after becoming aware of them. Actionable and appropriate technical details of cyber threats, vulnerabilities and incidents that enable proactive detection, incident response or mitigating measures shall be disclosed to CERT-EU without undue delay.
Added:Article 55 – paragraph 2: 2. Security incidents shall be managed in close cooperation between the Member States concerned or Europol and eu-LISA, as relevant, so as to ensure a quick, effective and proper response.
Change 120
Changed:Article 55 – paragraph 3 – subparagraph 2: In the event of a security incident inWithout relationprejudice to the centralArticle infrastructure34 of the router and without prejudice toRegulation Articles(EU) 342016/794 and Article 92 of Regulation (EU) 2018/1725, eu-LISAEuropol shall notify CERT-EU of significant cyber threats, significant vulnerabilities and significant incidents without undue delay and in any event no later than 24 hours after becoming aware of them. Actionable and appropriate technical details of cyber threats, vulnerabilities and incidents that enable proactive detection, incident response or mitigating measures shall be disclosed to CERT-EU without undue delay.
Change 121
Removed:Article 56 – paragraph 1: 1. Member States shall ensure that each authority entitled to use Prüm II takes the measures necessary to monitor its compliance with this Regulation and cooperates, where necessary, with the supervisory authority.
Added:Article 55 – paragraph 3 – subparagraph 3: In the event of a security incident in relation to the central infrastructure of the router and without prejudice to Article 92 of Regulation (EU) 2018/1725, eu-LISA shall notify CERT-EU of significant cyber threats, significant vulnerabilities and significant incidents without undue delay and in any event no later than 24 hours after becoming aware of them. Actionable and appropriate technical details of cyber threats, vulnerabilities and incidents that enable proactive detection, incident response or mitigating measures shall be disclosed to CERT-EU without undue delay.
Change 122
Changed:Article 5655 – paragraph 15 –a subparagraph(new): 15a. (new):This EuropolArticle shallis takewithout prejudice to the measuresreporting necessaryobligations pursuant to monitorArticles its92 complianceand with93 thisof Regulation and(EU) shall2018/1725 cooperate,and whereArticles necessary,30 withand the31 Europeanof DataDirective Protection(EU) Supervisor.2016/680.
Change 123
Changed:Article 56 – paragraph 2: 2.1: The1. dataMember controllersStates shall takeensure thethat necessaryeach measuresauthority entitled to monitoruse thePrüm complianceII oftakes datathe processingmeasures pursuantnecessary to thismonitor Regulation,includingits throughcompliance frequentwith verificationthis ofRegulation theand logscooperates, referredwhere tonecessary, inwith Articlesthe 20,supervisory 40authority. andEuropol 45,shall andtake cooperate,the wheremeasures necessary andto asmonitor appropriate,its withcompliance thewith supervisorythis authoritiesRegulation and shall cooperate, where necessary, with the European Data Protection Supervisor.
Change 124
Changed:Article 6156 – paragraph 1:2: 1.2. The supervisorydata authoritiescontrollers andshall implement the Europeannecessary Datatechnical Protectionand Supervisororganisational shall,measures eachto actingensure withineffective supervision and monitor the scopecompliance of theirdata respectiveprocessing competences,pursuant cooperateto activelythis withinRegulation, theincluding frameworkthrough offrequent theirverification respectiveof responsibilitiesthe tologs ensurereferred theto coordinatedin supervisionArticles of20, the40 applicationand of45 thisconcerning Regulation,the inadmissibility particularof ifqueries, the Europeanlawfulness Dataof Protectiondata Supervisorprocessing orand adata supervisorysecurity authorityand findsintegrity, majorand discrepanciescooperate, betweenwhere practicesnecessary ofand Memberas Statesappropriate, orwith findsthe potentiallysupervisory unlawfulauthorities transfersand usingwith the PrümEuropean IIData communicationProtection channels.Supervisor.
Change 125
Removed:Article 62 – title: Transfer of personal data to third countries and international organisations
Added:Article 56 – paragraph 2 a (new): 2a. The data controllers and Europol shall be provided with adequate human, financial and technical resources to fulfil their tasks pursuant to this Article.
Change 126
Changed:Article 6258 – paragraph 1: 1.If Aany requestingfailure of a Member State shallto transfercomply anywith dataits itobligations hasunder obtainedthis inRegulation accordancecauses withdamage thisto Regulationthe torouter aor thirdEPRIS, countrythat orMember anState internationalshall organisationbe onlyliable infor accordancesuch withdamage, Chapterunless Vand ofin Directiveso (EU)far 2016/680as andeu-LISA, whereEuropol theor requestedanother Member State hasbound grantedby itsthis authorisationRegulation priorfailed to take reasonable measures to prevent the transfer.damage from occurring or to minimise the impact.
Change 127
Changed:Article 6259 – paragraph 12: a2. (new):Without 1a.prejudice Europolto shallArticle transfer43(3) anyof dataRegulation it(EU) has2016/794, obtainedeu-LISA inand accordanceEuropol withshall thissupply Regulationinformation requested by the European Data Protection Supervisor to ait, thirdgrant countrythe orEuropean anData internationalProtection organisationSupervisor onlyaccess whereto all the conditionsdocuments laidit downrequests inand Articleto 25their oflogs Regulationreferred (EU)to 2016/794in areArticles fulfilled40 and 45 and allow the requestedEuropean MemberData StateProtection hasSupervisor grantedaccess itsto authorisationall priortheir premises at any time. This paragraph is without prejudice to the transfer.powers of the European Data Protection Supervisor pursuant to Article 58 of Regulation (EU) 2018/1725.
Change 128
Removed:Article 63 – paragraph 1 – point g: (g) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to the router in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;
Added:Article 59 – paragraph 2 a (new): 2a. The European Data Protection Supervisor shall be provided with the staff and financial resources necessary to carry out the audits referred to in paragraph 1.
Removed:Article 63 – paragraph 1 – point h: (h) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to EPRIS in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;
Added:Article 60 – paragraph 1: 1. The supervisory authorities and the European Data Protection Supervisor shall, each acting within the scope of their respective competences, cooperate actively within the framework of their respective responsibilities to ensure the coordinated supervision of the application of this Regulation, in particular if the European Data Protection Supervisor or a supervisory authority finds major discrepancies between practices of Member States or finds potentially unlawful transfers using the Prüm II communication channels.
Removed:Article 63 – paragraph 1 – point i: (i) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to Eucaris in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;
Added:Article 60 – paragraph 3: 3. The European Data Protection Supervisor and the European Data Protection Board shall send a joint report of its activities under this Article to the European Parliament, to the Council, to the Commission, to Europol and to eu-LISA by 2 years after entry into operation of the router and EPRIS and every two years thereafter. That report shall include a chapter on each Member State prepared by the supervisory authority of the Member State concerned.
Removed:Article 63 – paragraph 1 – point m: (m) correcting or deleting any data received from a requested Member State within 48 hours following the notification from the requested Member State that the personal data submitted was incorrect, no longer up-to-date or was unlawfully transmitted.
Added:Article 61 – title: Transfer of personal data to third countries and international organisations
Removed:Article 63 – paragraph 2: 2. Each Member State shall be responsible for connecting its competent national law enforcement authorities to the router, EPRIS and Eucaris.
Added:Article 61 – paragraph 1: A requesting Member State shall transfer personal data it has obtained in accordance with this Regulation to a third country or an international organisation only in accordance with Chapter V of Directive (EU) 2016/680 and where the requested Member State has granted its authorisation prior to the transfer.
Change 129
Changed:Article 6461 – paragraph 3:1 3.a Without(new): prejudiceEuropol toshall Articletransfer 26(6c)personal ofany Regulationdata (EU)it 2016/794has andobtained Europol’sin searchesaccordance pursuantwith this Regulation to Articlea 50(4)third ofcountry thisor Regulation,an Europolinternational shallorganisation notonly havewhere accessthe toconditions anylaid down in Article 25 of Regulation (EU) 2016/794 are fulfilled and the personalrequested dataMember processedState throughhas EPRIS.granted its authorisation prior to the transfer.
Change 130
Removed:Article 66 – paragraph 1 – subparagraph 2: The router shall be developed and managed in such a way as to ensure fast, efficient and controlled access, full and uninterrupted availability of the router, and a response time in line with the operational needs of the competent law enforcement authorities of the Member States and Europol.
Added:Article 61 a (new): Article 61 a / Relation to other legal acts on data protection / Any processing of personal data for the purposes of this Regulation shall be carried out in compliance with this Chapter and with Directive (EU) 2016/680, Regulation (EU) 2018/1725 or Regulation (EU) 2016/794, as applicable.
Added:Article 62 – paragraph 1 – point g: (g) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to the router in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;
Added:Article 62 – paragraph 1 – point h: (h) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to EPRIS in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;
Added:Article 62 – paragraph 1 – point i: (i) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to Eucaris in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;
Added:Article 62 – paragraph 1 – point j: (j) the human confirmation by qualified staff of a match as referred to in Article 6(3), Article 7(3), Article 13(2) and Article 22(2);
Added:Article 62 – paragraph 1 – point m: (m) correcting, updating or deleting any data received from a requested Member State within 24 hours following the notification from the requested Member State that the personal data submitted was incorrect, is no longer up-to-date or was unlawfully transmitted.
Added:Article 62 – paragraph 2: 2. Each Member State shall be responsible for connecting their competent national law enforcement authorities to the router, EPRIS and Eucaris.