Commission Delegated Regulation (EU) 2020/473 of 20 January 2020 supplementing Directive (EU) 2017/2397 of the European Parliament and of the Council with regard to the standards for databases for the Union certificates of qualification, service record books and logbooks
(a) "Union database" means the database provided by the Commission pursuant to Article 25(2) of Directive (EU) 2017/2397 to record and exchange data on certificates of qualifications and service record books referred to in Article 25(1) of Directive (EU) 2017/2397 and on certificates of qualifications and service record books recognised pursuant to its Article 10(3); (b) "European hull database (EHDB)" means the database provided by the Commission pursuant to Article 25(2) of Directive (EU) 2017/2397 to record and exchange the data on the logbooks referred to in Article 25(1) of that Directive; (c) "National registers" means the registers of the Union certificates of qualification, service record books and logbooks and, where relevant, of documents recognised pursuant to Article 10(2) of Directive (EU) 2017/2397, which are established and kept by Member States pursuant to Article 25(1) of that Directive (d) "crew member identification number" (CID) means a number generated by the Union database that identifies a crew member registered in that database and that is unique to the holder; (e) "Status "active"" means that certificates of qualification and specific authorisations are valid; (f) "Status "expired"" means that certificates of qualification and specific authorisations are no longer valid because the validity period came to an end or because they have been replaced by a new certification of qualification or specific authorisation following a need for change of administrative data or the validity period coming to an end; (g) "Status "suspended"" means that certificates of qualification and specific authorisations are no longer valid because measures have been taken by competent authorities in accordance with Article 14(2) of Directive (EU) 2017/2397; (h) "Status "withdrawn"" means that certificates of qualification and specific authorisations are no longer valid because measures have been taken by competent authorities in accordance with Article 14(1) of Directive (EU) 2017/2397; (i) "Status "lost"" means that certificates of qualification and specific authorisations have been declared lost to the competent authority; (j) "Status "stolen"" means that certificates of qualification and specific authorisations have been declared stolen to the competent authority; (k) "Status "destroyed"" means that certificates of qualification and specific authorisations have been declared destroyed to the competent authority. (l) "metadata" means data processed in the Union database for the purposes of sending or exchanging electronic communications content; including data used to trace and identify the source and destination of a communication, data on the location of the electronic communications content, and the date, time, duration and type of communication.
User profiles | Definitions | Access rights |
---|---|---|
Certification authorities | Competent authorities designated to issue, renew or withdraw certificates of qualifications, specific authorisations and services record books referred to in Article 26 of Directive (EU) 2017/2397. | Read and write in relation to functionalities 3.1 to 3.5. |
Authorities in charge of suspension | Authorised users in competent authorities for the suspension of certificates of qualifications and specific authorisations referred to in Article 26 of Directive (EU) 2017/2397. | Read and write in relation to functionalities 3.3 and 3.4. |
Enforcement authorities | Authorised users in competent authorities detecting and combating fraud and other unlawful practices referred to in Article 26 of Directive (EU) 2017/2397. | Read-only in relation to functionalities 3.1, 3.2, 3.3 and 3.5. |
Registers’ keepers | Authorised users in competent authorities desigated to keep the registers referred to in Article 26 of Directive (EU) 2017/2397. | Read and write in relation to functionalities 3.1 to 3.5 if not exercised by certification authorities or authorities in charge of supensions |
Statistics offices | Authorised users in national or international offices in charge of collecting statistical data. | Read-only in relation to functionality 3.5. |
International organisations | Authorised users in international organisations that have been provided access to, in accordance with Article 25(4) of Directive (EU) 2017/2397 and Article 46 of Regulation (EU) 2018/1725. | Read-only access to be determined in relation to functionalities 3.2, 3.3 and 3.5 following the result of the assessment concerrning the level of protection of natural persons and compliance with this Regulation |
Authorities from third countries | Authorised users in designated competent authorities from third countries that have been provided access to, in accordance with Article 25(4) of Directive (EU) 2017/2397 and Article 46 of Regulation (EU) 2018/1725. | To be determined in relation to functionalities 3.1 to 3.5 following the result of the assessment concerrning the level of protection of natural persons and compliance with this Regulation |
Commission |
|
|
(a) routing metadata; (b) access right tables; (c) CIDs with: (i) the holder’s list of types of certificates and of specific authorisations with their respective issuing authority and status; (ii) the serial number of the holder’s active service record book, where relevant; (iii) the pointer to the national register that hosts the holder’s most recent personal identity-related data.
User profiles | Definitions | Access rights |
---|---|---|
Certification authorities | Authorised users in competent authorities for the issuing of logbooks in accordance with Article 26 of Directive (EU) 2017/2397. | Full-access |
Enforcement authorities | Authorised users in competent authorities detecting and combating fraud and other unlawful practices in accordance with Article 26 of Directive (EU) 2017/2397. | Read-only |
Statistics offices | Authorised users in national or international offices in charge of collecting statistical data. | Read-only |
International organisations | Authorised users in international organisations that have been provided access to EHDB in accordance with Article 25(4) of Directive (EU) 2017/2397 and Article 46 of Regulation (EU) 2018/1725. | Read-only access to be determined following the result of the assessment concerning the level of protection of natural persons |
Authorities from third countries | Authorised users in designated competent authorities from third countries that have been provided access to in accordance with Article 25(4) of Directive (EU) 2017/2397 and Article 46 of Regulation (EU) 2018/1725. | To be determined following the result of the assessment concerrning the level of protection of natural persons |
(a) ensuring that the Union database complies with the requirements applicable to Commission’s communication and information systems, including those concerning the protection of personal data and the application of data protection rules on security of the processing . The Commission shall carry out an information security risk assessment and ensure an appropriate level of security;Commission Decision (EU, Euratom) 2017/46 of 10 January 2017 on the security of communication and information systems in the European Commission (OJ L 6, 11.1.2017, p. 40 ) and Commission Decision of13 December 2017 laying down implementing rules for Articles 3, 5, 7, 8, 9, 10, 11, 12, 14, 15 of Decision 2017/46/EC on the security of communication and information systems in the Commission.(b) responding to the requests of data subjects addressed directly to it in relation to the Union database and publishing a data protection information notice to fulfil information requirements. Where appropriate and in particular when the request concerns rectification and erasure of personal data, the Commission shall foward the request of the data subject to the relevant single contact point(s) that shall address it. In cases where a request is addressed directly to the Commission, it shall inform the data subject on the follow-up given to the request; (c) communicating any personal data breaches within the Union database to the single contact points referred to in Section 8.1 of Annex I, to the European Data Protection Supervisor and to the relevant individuals where there is a high risk in accordance with Articles 34 and 35 of Regulation (EU) 2018/1725; (d) identifying the categories of staff and other individuals to whom access to the Union database may be granted and ensuring that access by all those concerned is compliant with applicable data protection rules; (e) ensuring that Commission staff who have access to crew members’ personal data within the Union database, are adequately trained to ensure that they perform their tasks in compliance with the rules applicable to the protection of personal data, and are subject to the obligation of professional secrecy under Union law.
(a) collecting and processing the personal data of applicants, and for processing the personal data they obtain from/exchange through the Union database. Collecting and processing personal data shall be done in accordance with Regulation (EU) 2016/679, in particular to ensure lawful collection of data, provide appropriate information, keep the data accurate (including erasing outdated data or profiles where relevant) and ensure appropriate security of the data in the national register(s). (b) acting as the contact point for the crew members, including when they exercise their rights, responding to the requests of crew members and ensuring that crew members whose data are processed through the Union database and national registers are enabled to exercise their rights in compliance with data protection legislation. In this context, they shall cooperate with other Member States’ competent authorities via the single contact points and with the Commission to address appropriately the requests of data subjects addressed to it, to other Member States or to the Commission. Member States competent authorities that have received the data subject request shall inform the data subject on the follow-up given to the request; (c) communicating any personal data breaches with regard to crew members data processed through the Union database to the Commission, to the single contact point referred to in section 8.1. of Annex I, to the competent supervisory authority at national level and, where so required, to relevant crew members, in accordance with Articles 33 and 34 of Regulation (EU) 2016/679 or if requested by the Commission; (d) identifying, in compliance with access rights to users corresponding to the user profiles laid down in the table 1 of Annex I, staff whom shall be granted access to crew members’ personal data within the Union database and communicating it to the Commission; (e) ensuring that their staff who have access to crew members’ personal data within the Union database, are adequately trained to ensure that they perform their tasks in compliance with the rules applicable to the protection of personal data, and are subject to the obligation of professional secrecy in accordance with national law or rules established by national competent authority.