Source: OJ L, 2024/607, 16.2.2024

Current language: EN

Article 9 Access rights of AGORA actors


Summary What does Article 9 of the Information sharing system say?

Article 9 establishes the access control rules for AGORA, building directly on the roles defined in earlier articles for AGORA actors, administrators, and users.

The article sets out a clear framework of restricted access: only those who are authorised may enter the system, and even within that group, access to personal data is tightly limited to what is strictly necessary for their supervisory, investigatory, enforcement, or monitoring role.

The article goes a step further by requiring that where a specific procedure involves personal data, only those actually participating in that procedure may access it.

Important points:

  • AGORA actors are responsible for granting and revoking access rights to their administrators.
  • Implement appropriate means to ensure personal data in AGORA is accessible only where strictly necessary for the relevant regulatory tasks.
  • Where a specific procedure involves personal data, only AGORA administrators and users participating in that procedure may access it.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. AGORA actors shall grant and revoke access rights to AGORA administrators for which they are responsible.

    1. Only authorised AGORA administrators and authorised AGORA users shall have access to AGORA.

    1. AGORA actors shall put in place appropriate means to ensure that AGORA administrators and AGORA users are allowed to access personal data processed in AGORA only where strictly necessary for the supervision, investigation, enforcement and monitoring under Regulation (EU) 2022/2065.

    1. Where a procedure relating to the supervision, investigation, enforcement and monitoring under Regulation (EU) 2022/2065 involves the processing of personal data, only AGORA administrators and AGORA users participating in that procedure shall have access to such personal data.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod