Source: OJ L, 2024/607, 16.2.2024

Current language: EN

Article 5 Processing of personal data by the Commission


Summary What does Article 5 of the Information sharing system say?

This article defines the Commission's data protection roles under EU data protection law in the context of AGORA.

It is closely linked to Article 4, which outlines the Commission's operational responsibilities for running the system.

Here, the focus shifts to accountability: depending on the context of the processing activity, the Commission can occupy different legal positions — sometimes acting as a processor on behalf of others, and sometimes as a controller in its own right.

The distinction hinges on whether the Commission is processing data for its own purposes or on behalf of other AGORA actors.

Important points:

  • The Commission acts as a processor when registering AGORA administrators on behalf of other actors, but as a separate controller when managing data related to its own administrators and users.
  • The Commission is a separate controller when it processes personal data for its own operational purposes within AGORA, such as sharing or requesting information.
  • The Commission's responsibilities as a processor for data processing activities carried out by other AGORA actors are governed by Annex II of this Regulation.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. The Commission shall be a processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 with respect to the processing of personal data when registering AGORA administrators.

    1. The Commission shall be a separate controller within the meaning of Article 3, point (8), of Regulation (EU) 2018/1725 with respect to the processing of personal data of its own AGORA administrators and AGORA users.

    1. Where the Commission processes personal data in the operation of AGORA for the purpose of sharing, requesting and accessing information, requesting action and requesting support, it shall be considered a separate controller, within the meaning of Article 3, point (8), of Regulation (EU) 2018/1725, from the other AGORA actors for the personal data processing activities it carries out.

    1. Where the Commission processes personal data in the operation of AGORA on behalf of other AGORA actors for the purpose of sharing, requesting and accessing information, requesting action and requesting support, it shall be considered a processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725.

    1. For the purposes of this Regulation, the responsibilities of the Commission as processor for data processing activities conducted in AGORA by those other AGORA actors shall be defined in accordance with Annex II.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod