Source: OJ L, 2024/607, 16.2.2024Current language: EN
- Digital services act
Implementing acts
- Information sharing system
Article 13 Security
Summary What does Article 13 of the Information sharing system say?
This article places the responsibility for data security within AGORA squarely on the Commission.
It covers two dimensions: proactive security measures to protect personal data under normal operating conditions, and reactive measures to be taken when a security incident occurs.
The article connects directly to the Commission's broader role established in Article 4, where it is designated as the entity responsible for the reliability and security of AGORA's infrastructure.
Important points:
- The Commission is required to implement state-of-the-art security measures for personal data in AGORA, including data access controls and an up-to-date security plan.
- The Commission is required to have state-of-the-art measures in place for security incidents and must take remedial action when they occur.
- The Commission must ensure full auditability of personal data processed in AGORA, meaning it must be verifiable what data was processed, when, by whom, and for what purpose.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
The Commission shall put in place the necessary, state-of-the-art measures to ensure security of personal data processed in AGORA, including appropriate data access control and a security plan, which shall be kept up-to-date.
The Commission shall put in place the necessary, state-of-the-art measures in the event of a security incident, take remedial action, and ensure that it shall be possible to verify what personal data have been processed in AGORA, when, by whom, and for what purpose.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
AGORA
Definition
AGORA actor