Regulation (EU) No 1077/2011 of the European Parliament and of the Council of 25 October 2011 establishing a European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice
Regulation (EU) No 1077/2011 of the European Parliament and of the Councilof 25 October 2011establishing a European Agency for the operational management of large-scale IT systems in the area of freedom, security and justiceTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,Having regard to the Treaty on the Functioning of the European Union and in particular Article 74, Article 77(2)(a) and (b), Article 78(2)(e), Article 79(2)(c), Article 82(1)(d), Article 85(1), Article 87(2)(a) and Article 88(2) thereof,Having regard to the proposal from the European Commission,After transmission of the draft legislative act to the national parliaments,Acting in accordance with the ordinary legislative procedurePosition of the European Parliament of 5 July 2011 (not yet published in the Official Journal) and Decision of the Council of 12 September 2011.,Whereas:(1)The second-generation Schengen Information System (SIS II) was established by Regulation (EC) No 1987/2006 of the European Parliament and of the Council of 20 December 2006 on the establishment, operation and use of the second generation Schengen Information System (SIS II)OJ L 381, 28.12.2006, p. 4. and by Council Decision 2007/533/JHA of 12 June 2007 on the establishment, operation and use of the second generation Schengen Information System (SIS II)OJ L 205, 7.8.2007, p. 63.. Regulation (EC) No 1987/2006 and Decision 2007/533/JHA provide that the Commission is to be responsible, during a transitional period, for the operational management of Central SIS II. After that transitional period, a Management Authority is to be responsible for the operational management of Central SIS II and certain aspects of the communication infrastructure.(2)The Visa Information System (VIS) was established by Council Decision 2004/512/EC of 8 June 2004 establishing the Visa Information System (VIS)OJ L 213, 15.6.2004, p. 5.. Regulation (EC) No 767/2008 of the European Parliament and of the Council of 9 July 2008 concerning the Visa Information System (VIS) and the exchange of data between Member States on short-stay visas (VIS Regulation)OJ L 218, 13.8.2008, p. 60. provides that the Commission is to be responsible, during a transitional period, for the operational management of the VIS. After that transitional period, a Management Authority is to be responsible for the operational management of the Central VIS and of the national interfaces and for certain aspects of the communication infrastructure.(3)Eurodac was established by Council Regulation (EC) No 2725/2000 of 11 December 2000 concerning the establishment of "Eurodac" for the comparison of fingerprints for the effective application of the Dublin ConventionOJ L 316, 15.12.2000, p. 1.. Council Regulation (EC) No 407/2002Council Regulation (EC) No 407/2002 of 28 February 2002 laying down certain rules to implement Regulation (EC) No 2725/2000 concerning the establishment of "Eurodac" for the comparison of fingerprints for the effective application of the Dublin Convention (OJ L 62, 5.3.2002, p. 1). lays down necessary implementing rules.(4)It is necessary to establish a Management Authority in order to ensure the operational management of SIS II, VIS and Eurodac and of certain aspects of the communication infrastructure after the transitional period, and potentially that of other large-scale information technology (IT) systems in the area of freedom, security and justice, subject to the adoption of separate legislative instruments.(5)With a view to achieving synergies, it is necessary to provide for the operational management of those large-scale IT systems in a single entity, benefiting from economies of scale, creating critical mass and ensuring the highest possible utilisation rate of capital and human resources.(6)In the joint statements accompanying the SIS II and VIS legislative instruments, the European Parliament and the Council invited the Commission to present, following an impact assessment, the necessary legislative proposals entrusting an agency with the long-term operational management of Central SIS II and of certain aspects of the communication infrastructure, and of the VIS.(7)Since the Management Authority should have legal, administrative and financial autonomy it should be established in the form of a regulatory agency (Agency) having legal personality. As was agreed, the seat of the Agency should be in Tallinn (Estonia). However, since the tasks relating to technical development and the preparation for the operational management of SIS II and VIS are carried out in Strasbourg (France) and a backup site for those IT systems has been installed in Sankt Johann im Pongau (Austria), this should continue to be the case. Those two sites should also be the locations, respectively, where the tasks relating to technical development and operational management of Eurodac should be carried out and where a backup site for Eurodac should be established. Those two sites should also be the locations, respectively, for the technical development and operational management of other large-scale IT systems in the area of freedom, security and justice, and, if so provided in the relevant legislative instrument, for a backup site capable of ensuring the operation of a large-scale IT system in the event of failure of that system.(8)Consequently, the tasks of the Management Authority set out in Regulations (EC) No 1987/2006 and (EC) No 767/2008 should be exercised by the Agency. Those tasks include further technical development.(9)In accordance with Regulations (EC) No 2725/2000 and (EC) No 407/2002, a central Unit has been established within the Commission which is responsible for the operation of the central database of Eurodac and other tasks relating to it. In order to exploit synergies, the Agency should take over the Commission’s tasks relating to the operational management of Eurodac including certain tasks relating to the communication infrastructure as from the date on which the Agency takes up its responsibilities.(10)The core function of the Agency should be to fulfil the operational management tasks for SIS II, VIS and Eurodac and, if so decided, other large-scale IT systems in the area of freedom, security and justice. The Agency should also be responsible for technical measures required by the tasks entrusted to it, which are not of a normative nature. Those responsibilities should be without prejudice to the normative tasks reserved to the Commission alone or to the Commission assisted by a Committee in the respective legislative instruments governing the systems operationally managed by the Agency.(11)In addition, the Agency should perfom tasks relating to training on the technical use of SIS II, VIS and Eurodac and other large-scale IT systems which might be entrusted to it in the future.(12)Furthermore, the Agency could also be made responsible for the preparation, development and operational management of additional large-scale IT systems in application of Articles 67 to 89 of the Treaty on the Functioning of the European Union (TFEU). The Agency should be entrusted with such tasks only by means of subsequent and separate legislative instruments, preceded by an impact assessment.(13)The Agency should be responsible for monitoring research and for carrying out pilot schemes, in accordance with Article 49(6)(a) of Council Regulation (EC, Euratom) No 1605/2002 of 25 June 2002 on the Financial Regulation applicable to the general budget of the European CommunitiesOJ L 248, 16.9.2002, p. 1., for large-scale IT systems in application of Articles 67 to 89 TFEU, at the specific and precise request of the Commission. When tasked with carrying out a pilot scheme, the Agency should pay particular attention to the European Union Information Management Strategy.(14)Entrusting the Agency with the operational management of large-scale IT systems in the area of freedom, security and justice should not affect the specific rules applicable to those systems. In particular, the specific rules governing the purpose, access rights, security measures and further data protection requirements for each large-scale IT system the operational management of which the Agency is entrusted with, are fully applicable.(15)The Member States and the Commission should be represented on a Management Board, in order to control the functions of the Agency effectively. The Management Board should be entrusted with the necessary functions, in particular to adopt the annual work programme, carry out its functions relating to the Agency’s budget, adopt the financial rules applicable to the Agency, appoint an Executive Director and establish procedures for taking decisions relating to the operational tasks of the Agency by the Executive Director.(16)As regards SIS II, the European Police Office (Europol) and the European Judicial Cooperation Unit (Eurojust), both having the right to access and search directly data entered into SIS II in application of Decision 2007/533/JHA, should have observer status at the meetings of the Management Board when a question in relation to the application of Decision 2007/533/JHA is on the agenda. Europol and Eurojust should each be able to appoint a representative to the SIS II Advisory Group established under this Regulation.(17)As regards VIS, Europol should have observer status at the meetings of the Management Board, when a question in relation to the application of Council Decision 2008/633/JHA of 23 June 2008 concerning access for consultation of the Visa Information System (VIS) by designated authorities of Member States and by Europol for the purposes of the prevention, detection and investigation of terrorist offences and of other serious criminal offencesOJ L 218, 13.8.2008, p. 129. is on the agenda. Europol should be able to appoint a representative to the VIS Advisory Group established under this Regulation.(18)Member States should have voting rights on the Management Board of the Agency concerning a large-scale IT system, if they are bound under Union law by any legislative instrument governing the development, establishment, operation and use of that particular system. Denmark should also have voting rights concerning a large-scale IT system, if it decides under Article 4 of the Protocol (No 22) on the position of Denmark, annexed to the Treaty on European Union (TEU) and the TFEU, (Protocol on the position of Denmark) to implement the legislative instrument governing the development, establishment, operation and use of that particular system in its national law.(19)Member States should appoint a Member to the Advisory Group concerning a large-scale IT system, if they are bound under Union law by any legislative instrument governing the development, establishment, operation and use of that particular system. Denmark should, in addition, appoint a Member to the Advisory Group concerning a large-scale IT system, if it decides under Article 4 of the Protocol on the position of Denmark to implement the legislative instrument governing the development, establishment, operation and use of that particular system in its national law.(20)In order to guarantee its full autonomy and independence, the Agency should be granted an autonomous budget with revenue from the general budget of the European Union. The financing of the Agency should be subject to an agreement by the budgetary authority as set out in point 47 of the Interinstitutional Agreement of 17 May 2006 between the European Parliament, the Council and the Commission on budgetary discipline and sound financial managementOJ C 139, 14.6.2006, p. 1.. The Union budgetary and discharge procedures should be applicable. The auditing of accounts and of the legality and regularity of the underlying transactions should be undertaken by the Court of Auditors.(21)Within the framework of their respective competences, the Agency should cooperate with other agencies of the Union, in particular those established in the area of freedom, security and justice, and, in particular, the European Union Agency for Fundamental Rights. It should also consult and follow up the recommendations of the European Network and Information Security Agency regarding network security, where appropriate.(22)When ensuring the development and the operational management of large-scale IT systems, the Agency should follow European and international standards taking into account the highest professional requirements, in particular the European Union Information Management Strategy.(23)Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such dataOJ L 8, 12.1.2001, p. 1. should apply to the processing of personal data by the Agency. The European Data Protection Supervisor should be able to obtain from the Agency access to all information necessary for his or her enquiries. In accordance with Article 28 of Regulation (EC) No 45/2001, the Commission consulted the European Data Protection Supervisor, who delivered his opinion on 7 December 2009.(24)In order to ensure the transparent operation of the Agency, Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documentsOJ L 145, 31.5.2001, p. 43. should apply to the Agency. The activities of the Agency should be subject to the scrutiny of the European Ombudsman in accordance with Article 228 TFEU.(25)Regulation (EC) No 1073/1999 of the European Parliament and of the Council of 25 May 1999 concerning investigations conducted by the European Anti-Fraud Office (OLAF)OJ L 136, 31.5.1999, p. 1. should apply to the Agency, which should accede to the Interinstitutional Agreement of 25 May 1999 between the European Parliament, the Council of the European Union and the Commission of the European Communities concerning internal investigations by the European Anti-Fraud Office (OLAF)OJ L 136, 31.5.1999, p. 15..(26)The Agency’s host Member States should provide the best possible conditions to ensure the proper functioning of the Agency, for example including multilingual, European-oriented schooling and appropriate transport connections.(27)In order to ensure open and transparent employment conditions and equal treatment of staff, the Staff Regulations of Officials of the European Union (Staff Regulations of Officials) and the Conditions of Employment of Other Servants of the European Union (Conditions of Employment), laid down in Regulation (EEC, Euratom, ECSC) No 259/68OJ L 56, 4.3.1968, p. 1. (together referred to as the "Staff Regulations"), should apply to the staff and to the Executive Director of the Agency, including the rules of professional secrecy or other equivalent duties of confidentiality.(28)The Agency is a body set up by the Union in the sense of Article 185(1) of Regulation (EC, Euratom) No 1605/2002 and should adopt its financial rules accordingly.(29)Commission Regulation (EC, Euratom) No 2343/2002OJ L 357, 31.12.2002, p. 72. on the framework Financial Regulation for the bodies referred to in Article 185 of Regulation (EC, Euratom) No 1605/2002 should apply to the Agency.(30)Since the objectives of this Regulation, namely the establishment of an Agency at Union level responsible for the operational management and where appropriate the development of large-scale IT systems in the area of freedom, security and justice cannot be sufficiently achieved by the Member States and can therefore, by reason of the scale and effects of the action, be better achieved at Union level, the Union may adopt measures in accordance with the principle of subsidiarity as set out in Article 5 TEU. In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary to achieve those objectives.(31)This Regulation respects fundamental rights and observes the principles recognised by the Charter of Fundamental Rights of the European Union in accordance with Article 6(1) TEU.(32)In accordance with Articles 1 and 2 of the Protocol on the Position of Denmark, Denmark is not taking part in the adoption of this Regulation and is not bound by it or subject to its application. Given that this Regulation, insofar as it relates to SIS II and VIS, builds upon the Schengen acquis, Denmark shall, in accordance with Article 4 of that Protocol, decide within a period of 6 months of the date of adoption of this Regulation whether it will implement it in its national law. In accordance with Article 3 of the Agreement between the European Community and the Kingdom of Denmark on the criteria and mechanisms for establishing the State responsible for examining a request for asylum lodged in Denmark or any other Member State of the European Union and "Eurodac" for the comparison of fingerprints for the effective application of the Dublin ConventionOJ L 66, 8.3.2006, p. 38., Denmark is to notify the Commission whether it will implement the contents of this Regulation, insofar as it relates to Eurodac.(33)Insofar as its provisions relate to SIS II as governed by Decision 2007/533/JHA, the United Kingdom is taking part in this Regulation, in accordance with Article 5(1) of Protocol (No 19) on the Schengen acquis integrated into the framework of the European Union, annexed to the TEU and to the TFEU (Protocol on the Schengen acquis), and Article 8(2) of Council Decision 2000/365/EC of 29 May 2000 concerning the request of the United Kingdom of Great Britain and Northern Ireland to take part in some of the provisions of the Schengen acquisOJ L 131, 1.6.2000, p. 43..Insofar as its provisions relate to SIS II as governed by Regulation (EC) No 1987/2006 and to VIS, which constitute developments of provisions of the Schengen acquis in which the United Kingdom does not take part in accordance with Decision 2000/365/EC, the United Kingdom requested, by letter of 5 October 2010 to the President of the Council, to be authorised to take part in the adoption of this Regulation, in accordance with Article 4 of the Protocol on the Schengen acquis. By virtue of Article 1 of Council Decision 2010/779/EU of 14 December 2010 concerning the request of the United Kingdom of Great Britain and Northern Ireland to take part in some of the provisions of the Schengen acquis relating to the establishment of a European Agency for the operational management of large-scale IT systems in the area of freedom, security and justiceOJ L 333, 17.12.2010, p. 58., the United Kingdom has been authorised to take part in this Regulation.Furthermore, insofar as its provisions relate to Eurodac, the United Kingdom has notified, by letter of 23 September 2009 to the President of the Council, its wish to take part in the adoption and application of this Regulation, in accordance with Article 3 of Protocol (No 21) on the position of the United Kingdom and Ireland in respect of the area of freedom, security and justice, annexed to the TEU and to the TFEU (Protocol on the position of the United Kingdom and Ireland). The United Kingdom therefore takes part in the adoption of this Regulation, is bound by it and subject to its application.(34)Insofar as its provisions relate to SIS II as governed by Regulation (EC) No 1987/2006 and to VIS, this Regulation constitutes a development of provisions of the Schengen acquis in which Ireland does not take part, in accordance with Council Decision 2002/192/EC of 28 February 2002 concerning Ireland’s request to take part in some of the provisions of the Schengen acquisOJ L 64, 7.3.2002, p. 20..Ireland has not requested to take part in the adoption of this Regulation, in accordance with Article 4 of the Protocol on the Schengen acquis. Ireland is therefore not taking part in the adoption of this Regulation and is not bound by it or subject to its application to the extent that its measures develop provisions of the Schengen acquis as they relate to SIS II as governed by Regulation (EC) No 1987/2006 and to VIS.Insofar as its provisions relate to Eurodac, in accordance with Articles 1 and 2 of the Protocol on the position of the United Kingdom and Ireland, Ireland is not taking part in the adoption of this Regulation and is not bound by it or subject to its application. Since it is not possible, under these circumstances, to ensure the applicability of this Regulation to Ireland in its entirety, as required by Article 288 TFEU, Ireland is not taking part in the adoption of this Regulation and is not bound by it or subject to its application, without prejudice to its rights under the aforementioned Protocols.(35)As regards Iceland and Norway, this Regulation constitutes, insofar as it relates to SIS II and VIS, a development of the provisions of the Schengen acquis within the meaning of the Agreement concluded by the Council of the European Union and the Republic of Iceland and the Kingdom of Norway concerning the latters’ association with the implementation, application and development of the Schengen acquisOJ L 176, 10.7.1999, p. 36. which fall within the area referred to in Article 1, points A, B and G of Council Decision 1999/437/EC of 17 May 1999 on certain arrangements for the application of that AgreementOJ L 176, 10.7.1999, p. 31.. As regards Eurodac, this Regulation constitutes a new measure related to Eurodac within the meaning of the Agreement between the European Community and the Republic of Iceland and the Kingdom of Norway concerning the criteria and mechanisms for establishing the State responsible for examining a request for asylum lodged in a Member State or in Iceland or NorwayOJ L 93, 3.4.2001, p. 40.. Consequently, subject to their decision to implement it in their internal legal order, delegations of the Republic of Iceland and the Kingdom of Norway should participate in the Management Board of the Agency. In order to determine further detailed rules, for example voting rights, allowing for the participation of the Republic of Iceland and the Kingdom of Norway in the activities of the Agency, a further arrangement should be concluded between the Union and these States.(36)As regards Switzerland, this Regulation constitutes, insofar as it relates to SIS II and VIS, a development of the provisions of the Schengen acquis within the meaning of the Agreement between the European Union, the European Community and the Swiss Confederation on the Swiss Confederation’s association with the implementation, application and development of the Schengen acquisOJ L 53, 27.2.2008, p. 52. which fall within the area referred to in Article 1, points A, B and G of Decision 1999/437/EC read in conjunction with Article 3 of Council Decision 2008/146/ECOJ L 53, 27.2.2008, p. 1.. As regards Eurodac, this Regulation constitutes a new measure related to Eurodac within the meaning of the Agreement between the European Community and the Swiss Confederation concerning the criteria and mechanisms for establishing the State responsible for examining a request for asylum lodged in a Member State or in SwitzerlandOJ L 53, 27.2.2008, p. 5.. Consequently, subject to its decision to implement it in their internal legal order, the delegation of the Swiss Confederation should participate in the Management Board of the Agency. In order to determine further detailed rules, for example voting rights, allowing for the participation of the Swiss Confederation in the activities of the Agency, a further arrangement should be concluded between the Union and the Swiss Confederation.(37)As regards Liechtenstein, this Regulation constitutes, insofar as it relates to SIS II and VIS, a development of the provisions of the Schengen acquis within the meaning of the Protocol between the European Union, the European Community, the Swiss Confederation and the Principality of Liechtenstein on the accession of the Principality of Liechtenstein to the Agreement between the European Union, the European Community and the Swiss Confederation on the Swiss Confederation’s association with the implementation, application and development of the Schengen acquisOJ L 160, 18.6.2011, p. 21. which fall within the area referred to in Article 1, points A, B and G of Decision 1999/437/EC read in conjunction with Article 3 of Council Decision 2011/350/EUOJ L 160, 18.6.2011, p. 19.. As regards Eurodac, this Regulation constitutes a new measure related to Eurodac within the meaning of the Protocol between the European Community, the Swiss Confederation and the Principality of Liechtenstein on the accession of the Principality of Liechtenstein to the Agreement between the European Community and the Swiss Confederation concerning the criteria and mechanisms for establishing the State responsible for examining a request for asylum lodged in a Member State or in SwitzerlandOJ L 160, 18.6.2011, p. 39.. Consequently, the delegation of the Principality of Liechtenstein should participate in the Management Board of the Agency. In order to determine further detailed rules, for example voting rights, allowing for the participation of the Principality of Liechtenstein in the activities of the Agency, a further arrangement should be concluded between the Union and the Principality of Liechtenstein,HAVE ADOPTED THIS REGULATION: