Source: OJ L, 2024/607, 16.2.2024

Current language: EN

Article 11 Processing of personal data in AGORA


Summary What does Article 11 of the Information sharing system say?

This is the core data protection article governing how personal data may be processed within AGORA.

It sets strict boundaries on the purposes, categories of data subjects, and types of personal data that are permitted in the system, tying all permissible processing directly to supervisory, investigative, enforcement, and monitoring activities under Regulation (EU) 2022/2065.

Beyond defining these limits, the article also establishes key operational rules: data must be stored within the European Economic Area, AGORA actors are responsible for enabling data subjects to exercise their rights, and coordinated oversight of the system falls to national Supervisory Authorities and the European Data Protection Supervisor.

Important points:

  • Only process personal data in AGORA for the permitted purposes and within the defined categories of data subjects and personal data types — anything beyond this is not allowed.
  • All AGORA actors are responsible for ensuring data subjects can exercise their rights under Regulation (EU) 2016/679 and Regulation (EU) 2018/1725.
  • Data storage must use IT infrastructure located within the European Economic Area, and national Supervisory Authorities together with the European Data Protection Supervisor are responsible for coordinated supervision of AGORA.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. The transmission, storage and other processing of personal data in AGORA may take place only as necessary and proportionate and only for the following purposes:

      1. supporting communications between AGORA actors in connection with the supervision, investigation, enforcement and monitoring under Regulation (EU) 2022/2065;

      2. case-handling by AGORA actors when carrying out their own activities in connection with the supervision, investigation, enforcement and monitoring under Regulation (EU) 2022/2065;

      3. performing the business and technical transformations of data listed in this Regulation, where this is necessary to enable the exchange of information referred to in points (a) and (b).

    1. The processing of personal data may take place in AGORA only in respect of the following categories of data subjects:

      1. natural persons whose personal information is contained in documents obtained in connection with the supervision, investigation, enforcement and monitoring under Regulation (EU) 2022/2065;

      2. AGORA administrators and AGORA users that have been granted access to AGORA.

    1. The processing of personal data may take place in AGORA only in respect of the following categories of personal data:

      1. identification data, contact details, case involvement data, case related data, and any other information deemed necessary for the supervision, investigation, enforcement and monitoring under Regulation (EU) 2022/2065;

      2. name, address, contact information, contact number and user ID of the AGORA administrators and AGORA users referred to in paragraph 2, point (b).

    1. AGORA shall store the categories of personal data listed under Article 11(3) of this Regulation and the logs indicating information about the flow and movements of the exchanged data carried out for the supervision, investigation, enforcement and monitoring under Regulation (EU) 2022/2065.

    1. The storage of data referred to in paragraph 2 shall be performed using information technology infrastructure located in the European Economic Area.

    1. Each AGORA actor shall ensure that data subjects can exercise their rights in accordance with Regulation (EU) 2016/679 and Regulation (EU) 2018/1725, and shall be responsible for compliance with these regulations for the personal data processing activities carried out on its behalf.

    1. The national Supervisory Authorities and the European Data Protection Supervisor, each acting within the scope of their respective competence, shall ensure coordinated supervision of AGORA and its use by AGORA administrators and AGORA users.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod