Source: OJ L, 2024/607, 16.2.2024

Current language: EN

Article 13 Security


Summary What does Article 13 of the Information sharing system say?

This article places the responsibility for data security within AGORA squarely on the Commission.

It covers two dimensions: proactive security measures to protect personal data under normal operating conditions, and reactive measures to be taken when a security incident occurs.

The article connects directly to the Commission's broader role established in Article 4, where it is designated as the entity responsible for the reliability and security of AGORA's infrastructure.

Important points:

  • The Commission is required to implement state-of-the-art security measures for personal data in AGORA, including data access controls and an up-to-date security plan.
  • The Commission is required to have state-of-the-art measures in place for security incidents and must take remedial action when they occur.
  • The Commission must ensure full auditability of personal data processed in AGORA, meaning it must be verifiable what data was processed, when, by whom, and for what purpose.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. The Commission shall put in place the necessary, state-of-the-art measures to ensure security of personal data processed in AGORA, including appropriate data access control and a security plan, which shall be kept up-to-date.

    1. The Commission shall put in place the necessary, state-of-the-art measures in the event of a security incident, take remedial action, and ensure that it shall be possible to verify what personal data have been processed in AGORA, when, by whom, and for what purpose.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod