CHAPTER VIDEVELOPMENT, OPERATION AND RESPONSIBILITIES

Article 39Responsibility for data processing

1.

In relation to the processing of personal data in the EES, each Member State shall designate the authority which is to be considered as controller in accordance with point (7) of Article 4 of Regulation (EU) 2016/679 and which shall have central responsibility for the processing of data by that Member State. Each Member State shall communicate the details of that authority to the Commission.

Each Member State shall ensure that the data collected and recorded in the EES is processed lawfully and, in particular, that only duly authorised staff have access to the data for the performance of their tasks. The Member State responsible shall ensure, in particular, that the data are:

(a)

collected lawfully and in full respect of the human dignity of the third-country national concerned;

(b)

registered lawfully in the EES;

(c)

accurate and up-to-date when they are transmitted to the EES.

2.

eu-LISA shall ensure that the EES is operated in accordance with this Regulation and the implementing acts referred to in Article 36. In particular, eu-LISA shall:

(a)

take the necessary measures to ensure the security of the EES Central System and the Communication Infrastructure between the EES Central System and the NUI, without prejudice to the responsibilities of the Member States;

(b)

ensure that only duly authorised staff have access to data processed in the EES.

3.

eu-LISA shall inform the European Parliament, the Council and the Commission, as well as the European Data Protection Supervisor, of the measures it takes pursuant to paragraph 2 in view of the start of operations of the EES.