dokumendiregister.ee
OtsingAsutusedMCP
Otsing›Tartu Maakohus
Sissetulev kiriAvalik

Üleskutse arvamuse avaldamiseks ühiste uurimisrühmade teabevahetusplatvormi loomise eelnõu osas

Tartu Maakohus · 6. jaanuar 2022
Viit
10-3/22/15-1
Registreeritud
6. jaanuar 2022
Dokumendi liik
Sissetulev kiri
Adressaat
Justiitsministeerium
Saabumis/saatmisviis
e-post
Funktsioon
10 Õigusemõistmise üldküsimused ja õigusteabe analüüs
Sari
10-3 Arvamused õigusaktide eelnõude kohta
Toimik
10-3/2022
Vastutaja
Pille Justus (Tartu Maakohus, Kohtudirektori juhtimisvaldkond, Kantselei)

Failid

  • 📎7-17885 06.01.2022 Väljaminev kiri.bdoc1695 KB
  • 📎Üleskutse arvamuse avaldamiseks ühiste uurimisrühmade teabevahetusplatvormi loomise eelnõu osas.msg1767 KB

Sisu (failidest)

EUROPEAN COMMISSION Brussels, 1.12.2021 COM(2021) 756 final 2021/0391 (COD) Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL establishing a collaboration platform to support the functioning of Joint Investigation Teams and amending Regulation (EU) 2018/1726 {SWD(2021) 390 final} EN EN EXPLANATORY MEMORANDUM 1. CONTEXT OF THE PROPOSAL • Reasons for and objectives of the proposal Introduction Joint Investigation Teams (JITs) are teams set up for specific criminal investigations and for a limited period of time. They are set up by the competent authorities of two or more Member States and possibly non-EU countries (third countries), to carry out together criminal investigations that cross borders. A JIT can be set up, in particular, when a Member State's investigations into criminal offences require difficult and demanding investigations having links with other Member States or third countries. It can also be set up when a number of Member States are conducting investigations into criminal offences in which the circumstances of the case necessitate coordinated, concerted action in the Member States involved. The legal basis for setting up a JIT are Article 13 of the European Union (EU) Convention on Mutual Assistance in Criminal Matters1 and Council Framework Decision 2002/465/JHA of 13 June 2002 on joint investigation teams2. Third countries can be parties in JITs if the legal basis allow for this. For example, Article 20 of the Second Additional Protocol of the 1959 Council of Europe Convention3 and Article 5 of the Agreement on Mutual Legal Assistance between the European Union and the United States of America4. JITs are one of the most successful tools for cross-border investigations and prosecutions in the EU. They enable direct cooperation and communication between judicial and law enforcement authorities of several States to organise their actions and investigations to efficiently investigate cross-border cases. Problems the proposal tackles However, practice shows that JITs have been facing several technical difficulties preventing them from being efficient in their daily work and from fostering their operations. The main difficulties concern secure electronic exchange of information and evidence (including large files), secure electronic communication with other JIT members and the competent Union bodies, offices and agencies such as Eurojust, Europol and the European Anti-Fraud Office (OLAF), as well as a joint daily management of a JIT. The second evaluation report on JITs5, prepared in 2018 by the Network of National Experts on Joint Investigation Teams (the JITs Network), a body established to support Member States and share best practices and experience in the area of JITs, already indicated that the JITs’ work could be improved and sped up if supported by a dedicated IT platform. The IT platform would enable its members to securely communicate among themselves, and share information and evidence. The Digital Criminal Justice study6 confirmed the findings of that 1 OJ C 197, 12.7.2000, p. 3–23. 2 OJ L 162, 20.6.2002, p. 1–3. 3 CET No 182. 4 OJ L 181, 19.7.2003, p. 34. 5 6 https://op.europa.eu/en/publication-detail/-/publication/e38795b5-f633-11ea-991b-01aa75ed71a1 EN 1 EN report and recommended creating an IT platform for JITs to ensure that JITs function more efficiently and more securely. Following these findings, the Commission announced plans7 to propose legislation establishing a dedicated ‘collaboration platform to support the functioning of Joint Investigation Teams’ (the platform). Objectives of the proposal The general objective of the proposal is to provide technological support to those involved in JITs to increase the efficiency and effectiveness of their cross-border investigations and prosecutions. The specific objectives of the proposal are to: (1) Ensure that the members and participants of JITs can more easily share information and evidence collected in the course of the JIT activities. (2) Ensure that the members and participants of JITs can more easily and more safely communicate with each other in the context of the JIT activities. (3) Facilitate the joint daily management of a JIT, including planning and coordination of parallel activities, enhanced traceability of shared evidence and coordination with third countries, especially where physical meetings are too expansive or time consuming. The proposed solution To meet those objectives and to tackle the underlying problems, a dedicated IT platform consisting of both centralised and decentralised components – the JITs collaboration platform – is proposed. The platform would be accessible to all actors involved in JIT proceedings, i.e. Member States’ representatives fulfilling the role of members of a given JIT, representatives of third countries invited to cooperate in the context of a given JIT, and the competent Union bodies, offices and agencies such as Eurojust, Europol, the European Public Prosecutor’s Office and OLAF. The key functions, described in detail below, will ease electronic communication, allow information and evidence to be shared, including large amounts of data, ensure traceability of evidence as well as planning and coordination of JIT operations. The design, development, technical management and maintenance of the platform would be entrusted to the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA), which is the Union agency in charge of large-scale IT systems in the in the Area of Freedom, Security and Justice. The platform would be of a voluntary nature, so the authorities involved in JITs would have full discretion in deciding whether they want to use the platform for a specific JIT. In addition, the JIT members and participants would be free to use other tools while making use of the platform. For instance, if they decide to pass on evidence in person at a working meeting or through the Secure Information Exchange Network Application (SIENA), managed by Europol. 7 Commission Communication on the Digitalisation of justice in the European Union - A toolbox of opportunities, COM (2020) 710 final, 2.12.2020. EN 2 EN The platform’s architecture would enable the creation of (non-interoperable) sessions in silo, the ‘JIT collaboration spaces,’ specific to each JIT and open only for the duration of the JIT. There would be no cross-cutting functions or any interactions between different JITs hosted by the platform. The platform would support the functioning of JITs throughout their operational and post- operational phases. In practical terms, an individual JIT collaboration space could be created on the platform as soon as all establishing parties sign the JIT agreement. The space would be closed following the end of the evaluation process. Access to the platform would be granted through regular computers (desktops, laptops, etc.) as well as through mobile devices. Its interface would be made available in all EU languages. From a technical perspective, the platform would be composed of two distinctive elements, (i) a centralised information system, which would allow for a temporary central storage of data, and (ii) a communication software, a mobile application, which would enable communication and local communication data storage. From a security perspective, while the platform will operate over the internet to offer flexible means of accessing it, the focus will be to guarantee confidentiality by design. This will be achieved by using robust end-to-end encryption algorithms to encrypt data in transit or at rest (i.e. stored on a physical storage). This feature is crucial for gaining the trust of JITs practitioners who deal with sensitive data and must be reassured regarding any risk of uncontrolled disclosure. In addition, appropriate multi-step identification and authentication mechanisms will be put in place to ensure that only authorised JIT members and participants have access to the platform. When designing the JITs collaboration platform, eu-LISA should ensure technical interoperability with SIENA. Key functions The platform will offer the following key functions: • secure, untraceable communication stored locally at the devices of the users, including a communication tool offering an instant messaging system, a chat feature, audio/video- conferencing and a function replacing standard emails; • exchange of information and evidence, including large files, through an upload/download system designed to store the data centrally only for the limited time needed to technically transfer the data. As soon as the data are downloaded by all addresses, it would be automatically deleted from the platform; • evidence traceability – an advanced logging mechanism logging a trail of who did what and when regarding all evidence shared through the platform, and supporting the need to ensure admissibility of evidence before a court. Other functions Apart from these key functions, the platform will also offer the following: • functions related to daily management of the JIT during its operational and post- operational (evaluation) phase; • support for the administrative and financial processes; EN 3 EN • various technical capabilities supporting operational and administrative processes, including the integration with the JITs-related electronic services already hosted at Eurojust and managed by the JIT Secretariat, i.e. JITs Funding, JITs Evaluation and JITs Restricted Area, allowing relevant information and documents to be obtained without needing to connect separately to the platform and the services offered by the JIT Secretariat. Access rights Particular attention will be given to the platform’s access rights. The platform’s starting principle will be that the management of access rights rests with the JIT space administrator(s) from the JITs participating Member States. They will be in charge of granting access, during the operational and post-operational phases of the JIT, to: • representatives of the other Member States participating in the JIT; • representatives of third countries which are also members of a given JIT; • representatives of Eurojust, Europol, the European Public Prosecutor’s Office, OLAF and other competent Union bodies, offices and agencies; and • representatives of the JIT Secretariat. In addition, the JIT space administrator(s) will have the option to limit access to parts of information and evidence only to those who are concerned by it, including case-by-case granular access permissions. This restriction would concern all users of the JITs collaboration platform, be it the Member States, third countries, the competent Union bodies, offices and agencies or the JIT Secretariat. It must be underlined that eu-LISA, as the hosting provider, will not have access to the data stored or exchanged through the platform. It will also not be involved in the access rights management, except for the initial process of granting access rights to JIT space administrator(s) based on the signed JIT agreement. The platform’s architecture must offer sufficient guarantees for this to happen. The access rights of the competent Union bodies, offices and agencies should be defined in view of the operational support they provide to JITs, covering all steps of the proceedings, from the moment of the signed JIT agreement until the end of the evaluation phase. On the latter, the platform must provide for access rights for the JIT Secretariat, which plays an important role in that process. The JIT Secretariat could also be in charge of the platform’s administrative support, including access rights management, as long as the JIT space administrator(s) of each individual JIT envisage such a role. Keeping in mind the increasing role of third countries in the successful prosecution of serious organised crime and terrorism, the platform will also be available to them, if they are part of a JIT agreement. However, specific access rights will depend on their role in a given JIT and should be set out by the JIT space administrator(s) for each respective JIT. To guarantee the respect for fundamental rights, including data protection, and in line with the currently applicable procedures, before granting access to a specific third country, the JIT space administrator(s) will need to thoroughly assess the data protection aspects against the applicable rules, notably Directive 2016/6808. 8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for EN 4 EN • Consistency with existing policy provisions in the policy area Strengthening cross-border criminal investigations and prosecutions carried out by JITs is a crucial part of creating an area of freedom, security and justice. This proposal has been announced in the Commission’s Communication on the digitalisation of justice in the EU9, as part of a broader initiative to enable the secure electronic communication and exchange of information and documents between courts, national authorities, and justice and home affairs agencies. It also constitutes part of the digitalisation of justice package contained in the Commission’s work programme for 2021 under the heading ‘A New Push for European Democracy’10. • Consistency with other Union policies The proposal is in line with the EU Security Union strategy11, the counter-terrorism agenda for the EU12 and the EU strategy to tackle organised crime13. Given the highly sensitive nature of the information exchanged, it is essential that the implementation of the toolbox approach on the digitalisation of justice, including through this proposal, takes place in a way that guarantees strong cybersecurity standards. This is consistent with the approach outlined in the EU's Cybersecurity Strategy and the Commission’s proposal for a Directive on measures for a high common level of cybersecurity across the Union (NIS2), aiming to improve further the cybersecurity capacities of public and private entities, competent authorities and the Union as a whole in the field of cybersecurity and critical infrastructure protection. While judiciary in Member States is not in the scope of NIS2 proposal it is of essence that Member States will put in place national measures that would ensure a comparable level of cybersecurity. 2. LEGAL BASIS, SUBSIDIARITY AND PROPORTIONALITY • Legal basis The legal basis for the proposal is Article 82(1)(d) of the Treaty on the Functioning of the European Union (TFEU). In line with that Article, the EU has the power to adopt measures to ease cooperation between judicial or equivalent authorities of the Member States in relation to proceedings in criminal matters. In line with Articles 1 and 2 of Protocol No 22 on the position of Denmark, annexed to the Treaty of the European Union (TEU) and to the TFEU, Denmark is not taking part in the adoption of this Regulation and is not bound by it or subject to its application. In line with Articles 1 to 3 of Protocol No 21 on the position of Ireland, annexed to the TEU and to the TFEU, Ireland may notify the President of the Council in writing that it wishes to the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data. 9 Commission Communication on the Digitalisation of justice in the European Union - A toolbox of opportunities, COM (2020) 710 final, 2.12.2020. 10 Commission Communication Commission Work Programme 2021, A Union of vitality in a world of fragility, COM(2020) 690 final. 11 Commission Communication on the EU Security Union strategy, COM(2020) 605 final. 12 Commission Communication on a counter-terrorism agenda for the EU, COM(2020) 795 final. 13 Commission Communication on the EU strategy to tackle organised crime 2021-2025, COM(2021) 170 final. EN 5 EN take part in the adoption and application of any such proposed measure, where it will be entitled to do so. The notice must be within three months after a proposal or initiative has been presented to the Council under Title V of Part Three of the Treaty on the Functioning of the European Union. • Subsidiarity (for non-exclusive competence) According to the principle of subsidiarity laid down in Article 5(3) of the TEU, action at EU level should be taken only when the aims envisaged cannot be achieved sufficiently by Member States alone and can therefore, by reason of the scale or effects of the proposed action, be better achieved by the EU. Furthermore, there is a need to match the nature and intensity of a given measure to the identified problem. The creation of a common Union wide IT platform to support JITs, allowing the Member States to make use of a technology solution that does not depend on the national IT infrastructure, can neither be achieved unilaterally at Member State level nor bilaterally between the Member States. It is by its nature a task to be undertaken at EU level. Therefore, it is also for the Union to establish a legally binding instrument to create such a system and to lay down the conditions under which that system will function. • Proportionality According to the principle of proportionality laid down in Article 5(4) of the TEU, there is a need to match the nature and intensity of a given measure to the identified problem. All problems described in this document require EU-level support to tackle them effectively. Addressing the problems individually, for instance by creating separate tools tackling the communication issue, the lack of data exchange mechanism, etc. would be much more costly and would create an administrative burden for the JITs. The Union wide IT platform is the only way to provide JITs with a common modern technical solution that will allow them to carry out their cross-border investigations more efficiently. Therefore, it can be concluded that the action at EU level to establish the platform to support functioning of JITs is proportionate to the identified problems that JITs encounter in their daily work. • Choice of the instrument The Commission is putting forward a proposal for a Regulation as the proposed legal instrument establishes a central system at EU level managed by the European agency eu- LISA. The proposal also amends Regulation (EU) No 2018/1726. A Regulation is directly applicable in all Member States and binding in its entirety. It therefore guarantees a common application of the rules across the Union and their entry into force at the same time. It ensures legal certainty by avoiding different interpretations in the Member States, thus preventing legal fragmentation. 3. RESULTS OF EX-POST EVALUATIONS, STAKEHOLDER CONSULTATIONS AND IMPACT ASSESSMENTS • Stakeholder consultations Whereas no public consultations were conducted due to a specific character of the proposal, the Commission has carried out an extensive targeted consultation campaign to ensure that all EN 6 EN stakeholders concerned have an opportunity to express their views. The campaign has involved: • prosecutors, judges and law enforcement representatives from the Member States; • Member States’ national authorities; • experts from the JITs network; • academics and practitioners in EU criminal law; • data protection experts; • representatives of Eurojust, Europol and OLAF. Stakeholders have had an opportunity to voice their opinion through bilateral contacts, expert meetings, online surveys and written contributions. The targeted consultations organised between March and July 2021, gathered views on the platform related elements of the Digital Criminal Justice study, functions that are to be covered by the future platform, as well as the applicable data protection regime(s). First and foremost, all stakeholders welcomed the initiative and provided a positive opinion about establishment of a platform as a much-needed step towards the digitalisation of JITs cooperation. As far as cross-cutting issues are concerned, most stakeholders focused on: • the simplicity of the platform so that it can be used by all practitioners concerned – a too cumbersome tool with complex workflows could create problems for the users and would be a main reason for not using it; • the prevention of an impact on the substantial or legal requirements of investigators’ work, so the proper functioning of a JIT is not jeopardised by the platform; • the security of the platform – the level of protection is of crucial importance so practitioners can be confident that outcomes of their national investigations that are shared through the platform would not be disclosed in an uncontrolled way. Some discussions have also taken place on the entity in charge of the platform’s future development and management. The following scenarios were considered: • creation of the platform by the Commission and making it available to the Member States to implement when needed within their own infrastructure; • creation of the platform and its establishment at the Commission; • creation of the platform and its establishment at one of the JHA agencies directly involved in supporting the Member State’s authorities in combating crime (e.g. Eurojust); • creation of the platform and its establishment at eu-LISA. All stakeholders consulted, including Eurojust and Europol, supported the option to entrust the platform’s development and maintenance to eu-LISA. They all recognised eu-LISA’s expertise in the area as well as its experience with large-scale IT systems meeting state-of-the- art security standards. Also, this option takes into account, that JITs can be conducted without the financial support or operational involvement of either Eurojust or Europol. EN 7 EN Undoubtedly, the two key functions of the platform debated the most during the targeted consultations were a possible coverage by the platform of a JIT set-up process and the central storage. Administrative process to set-up a JIT The starting point for this discussion was the final report of the Digital Criminal Justice study, which recommends that the JITs collaboration platform covers also the pre-operational phase of JITs, i.e. the administrative process to set up a JIT. There are many advantages of such a solution, including: • the possibility to securely and efficiently exchange documents cross-border, leading to the signature of a JIT agreement; • a machine translations function; • an inventory of the procedures to be followed during the JIT set-up process; • support for various electronic signatures. However, it has been established during the stakeholder consultations that in most Member States, actors participating in the JIT set-up process are completely different from those who are members of JITs once they are established. Moreover, the decision to join a JIT is very often taken by someone who will not necessarily be a member of the JIT itself, e.g. the Prosecutor General or even the Minister of Justice. Therefore, the inclusion of the administrative JIT set-up process in the platform would require a complete departure from the above-described model of isolated JIT spaces, as well as a separate access rights management workflow. Such a scenario would heavily complicate the envisaged easy-to-use concept of the platform and would require implementation of rather incomprehensible and time-consuming administrative workflows. Therefore, following the targeted consultations, the recommended scenario would be to cover the JIT set-up process within the e-Evidence Digital Exchange System (eEDES) that is currently being implemented by the Commission. This solution would on the one-hand cover administrative needs of the stakeholders and, on the other, not complicate the daily functioning of the future platform. Central storage One of the most crucial functions of the platform will be to exchange information and evidence among the JIT members and other participants. That function could be implemented in three different ways: (1) A plain upload/download function – data would be uploaded on the platform by one member/participant of the JIT and would be stored centrally only until the other JIT member(s)/participant(s) download(s) it. (2) A temporary flexible storage – in addition to the plain upload/download, data could be optionally stored at the platform for some period of time, e.g. one week, one month, etc. The member/participant uploading the data would define duration and access rights. (3) A permanent storage – all exchanged data would be stored throughout the JIT’s lifespan – precise access rights to the data would be defined by the EN 8 EN member/participant uploading the data. This option would constitute a ‘common JIT case-file.’ Though JITs allow for the direct communication, cooperation and coordinated action, the underlying national investigations remain separate and independent. The possibility to create a common case-file to supplement national investigations is not envisaged by the current legal framework. Therefore, almost all stakeholders rejected the permanent storage option (option 3). Indeed, the creation of such a common case-file would raise serious questions related to criminal procedures in certain Member States since not all JIT information is necessarily shared among all members of the JIT. Investigators from one country often do not need access to all relevant information from the investigation of the other country participating in the same JIT. Whereas the other two options had more or less the same degree of support among the practitioners, a preferred option is to equip the platform with the plain upload/download function (option 1). This function would prevent platform’s users to view the data before downloading it. It would also prevent any central storage of exchanged data, i.e. the data would be stored centrally until it is downloaded by the other party, but for not more than four weeks. The main reason for that has been a concern that any storage of operational data, going beyond a technical requirement to send it from one party to another, would lead to at least a temporary common file and to possible follow–up questions. For example, access requests to that file. However, this instrument should not change the separate investigations and separate national files, to which the respective national rules still apply. Although the lack of central storage would prevent including in the platform various additional technical functions, e.g. an interface with a crime analysis tool, a search tool, a text to speech converter, a speech to text converter, Optical Character Recognition, etc., stakeholders took the view that such functions would duplicate the tools already provided by other agencies (primarily by Europol). It also must be underlined that even in the absence of a central storage of information and evidence, some basic information would be stored centrally to allow the JIT members to trace the exchanged data. • Collection and use of expertise The proposal is based on the findings of the Digital Criminal Justice study14. The study reviewed the needs and options to create a ‘Cross-Border digital criminal justice project,’ a fast, reliable and secure IT ecosystem to enable national prosecution authorities in Member States to interact with their national counterparts, Justice and Home Affairs (JHA) agencies and EU bodies in the JHA area. • Impact assessment No impact assessment was conducted, as the proposal only aims at establishing a technical solution supporting the functioning of JITs, without changing the main principles that underpin the legal frameworks for setting up a JIT. The proposal is accompanied by a Commission staff working document15, which contains a detailed problem description and sets out the objectives of the proposal. It also analyses the 14 Cross-border Digital Criminal Justice, Final report, https://op.europa.eu/en/publication-detail/- /publication/e38795b5-f633-11ea-991b-01aa75ed71a1/language-en. 15 SWD(2021) 390 EN 9 EN proposed solution in the light of its efficacy, indicates the benefits of the initiative and also its potential impact on fundamental rights. The staff working document explains that the establishment of the platform is expected to render cooperation within JITs more efficient and effective. All future functionalities of the platform, starting with the communication tools, through exchange of data mechanism, to collaborative management of JITs, are intended to save time and cost of those involved in JITs. Although voluntary in nature, it is anticipated that practitioners will quickly realise the platform’s added value and systematically use it in cross-border cases. The platform would allow speeding up the flow of information among its users, increase security of the exchanged data as well as enhance transparency. In addition, impacts on simplification and administrative burdens are anticipated. Consequently, more efficient functioning of JITs would improve overall collaboration between Member States in investigating and prosecuting cross-border crime. • Fundamental rights No major impact on fundamental rights is expected, as the legal basis for the exchanges of information and evidence within a JIT would not be changed. However, as explained in more detail below, the proposed solution will comply with fundamental rights and freedoms enshrined, in particular, in the Charter of Fundamental Rights of the European Union16, including the right to protection of personal data. In this regard, it will also comply with the European Convention for the Protection of Human Rights and Fundamental Freedoms, the International Covenant on Civil and Political Rights, and other human rights obligations under international law. Since establishing the platform at EU level would imply the processing of personal data, appropriate data protection safeguards must be put in place. The platform would fully comply with Union data protection rules on the legality of exchanging information and evidence. Directive (EU) 2016/680 of the European Parliament and of the Council would apply to the processing of personal data by competent national authorities to prevent, investigate, detect or prosecute criminal offences or execute criminal penalties, including safeguarding against and preventing threats to public security. Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies would also apply. These legal safeguards would need to dovetail with the alignment of the data protection approach for JITs with the current data protection rules, as proposed by the Commission on 20 January 202117. On the centralised component of the platform, i.e. the upload/download mechanism allowing temporarily storing of the operational data until the moment it is downloaded, the impact on data protection is considered to be limited because: • the personal data would be exchanged by a very limited group of individuals who are part of an isolated JIT collaboration space; • the personal data would be stored centrally only for technical reasons and would be deleted as soon as it is downloaded by all addresses; 16 OJ C 326, 26.10.2012, p. 391–407. 17 COM (2021) 21 Final - Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Directive 2014/41/EU, as regards its alignment with EU rules on the protection of personal data. EN 10 EN • the retention period would be set at a maximum of four weeks and would be enforced automatically; • exchange of personal data would be limited to serve the purpose for which it was obtained; • eu-LISA would not have access to the data and would fulfil the role of data processor; • a separate data controller for each entity uploading the personal data, apart from third countries, would be warranted; • exchanges of personal data that qualify as international transfers to third countries that are part of a given JIT would always require a legal basis in union or Member State law applicable to such transfers; • personal data uploaded to JIT collaboration space by third countries would be under the responsibility of a JIT space administrator who would need to check such data before it can be downloaded by other users. 4. BUDGETARY IMPLICATIONS The proposal for a Regulation establishing the platform is envisaged to incur the following costs: • development of the platform – the one-off cost incurred for eu-LISA; • technical maintenance and operation of the platform – the recurring cost incurred for eu- LISA; • development of the necessary technical adaptations of the relevant IT systems hosted at Eurojust, i.e. JITs funding, JITs evaluation and JITs restricted area to partially integrate them with the platform – the one-off cost incurred for Eurojust; • technical maintenance and operations on the adaptations of the IT systems hosted at Eurojust – the recurring cost incurred for Eurojust; • administrative support to the platform’s users on behalf of the JIT space administrator(s) – the recurring cost incurred for Eurojust (the JIT Secretariat). As far as Member States’ access to the platform is concerned, no technical costs are envisaged because of the web-based nature of the centralised component of the platform. It would not require any adaptations of the national technical infrastructure. The same applies to the communication software, which would simply need to be downloaded on each device of the JIT platform’s users. Access to the platform for the competent Union bodies, offices and agencies would be driven by the same principles and would not incur any costs for them. The costs for eu-LISA and Eurojust are explained in detail in the accompanying legal financial statement. In total, eu-LISA would require the following financial and human resources to develop, maintain and operate the JITs collaboration platform: • one-off build cost – EUR 8.4 million; • annual maintenance and operation cost – EUR 1.7 million; • staff – 4 TA FTE as of 2024, 4 TA FTE as of 2025 and 2 CA FTE as of 2026 (10 in total). The costs for eu-LISA apply to hosting the platform in its operational site in Strasbourg/France and the back-up site in Sankt Johann/Austria. EN 11 EN In total, Eurojust (including the JIT Secretariat) would require the following financial and human resources: • for development maintenance and operations of the required technical adaptations of Eurojust IT systems, i.e. JITs funding, JITs evaluation and JITs restricted area, in order to partially integrate them with the platform: EUR 0.250 million in 2025 (one-off) and 1 FTE – a technical profile – as of 2025 onwards; • for administrative support of the JIT Secretariat to the platform’s users on behalf of JIT space administrator(s): 2 FTEs as of 2026 onwards. These costs would be borne by the Union general budget and would need to be reflected in the budget of both agencies. 5. OTHER ELEMENTS • Implementation plans and monitoring, evaluation and reporting arrangements Monitoring and evaluating the development and technical functioning of the JITs collaboration platform is vital and will be applied by following the principles outlined in the common approach on decentralised agencies18. Once the development of the JITs collaboration platform is finalised, eu-LISA will submit a report to the European Parliament and to the Council explaining how the objectives, in particular relating to planning and costs, were achieved. Two years after the start of operations of the JITs collaboration platform and every year after that, eu-LISA will submit, to the Commission, a report on the technical functioning of the JITs cooperation platform, including its security. Four years after the start of operations of the JITs collaboration platform and every four years after that, the Commission will conduct an overall evaluation of the JITs collaboration platform. The Commission will send the evaluation report to the European Parliament and the Council. • Detailed explanation of the specific provisions of the proposal Chapter I General provisions Article 1 sets out the subject matter of the Regulation. The ‘JITs collaboration platform’ is a centralised IT platform at EU level for those involved in JITs to collaborate, securely communicate among themselves, and share information and evidence. The Regulation also lays down rules on the division of responsibilities between the JITs collaboration platform users and eu-LISA, the organisation responsible for developing and maintaining the JITs collaboration platform. It sets out conditions, under which the JITs collaboration platform users may be granted access to a JIT collaboration space. It also lays down specific data protection provisions needed to supplement the existing data protection arrangements and to provide for an overall adequate level of data protection, data security and protection of the fundamental rights of the persons concerned. 18 https://europa.eu/european- union/sites/default/files/docs/body/joint_statement_and_common_approach_2012_en.pdf. EN 12 EN Article 2 defines the scope of the Regulation. The Regulation applies to the processing of information, including personal data, within the context of a JIT. This includes the exchange and storage of operational information and evidence as well as non-operational information. This Regulation covers the operational and post-operational phases of a JIT, starting from the moment the relevant JIT agreement has been signed by its members. Article 3 defines the terms used in the Regulation. Article 4 describes the technical architecture of the JITs collaboration platform. The JITs collaboration platform must be composed of a centralised information system, which allows for a temporary central data storage; a communication software, which allows for local storage of communication data; and a connection between the centralised information system and relevant IT tools, supporting functioning of JITs, hosted at Eurojust and managed by the JIT Secretariat and. Article 5 sets out the purpose of the JITs collaboration platform, which is to ease the daily coordination and management of a JIT; the exchange of operational information and evidence; secure communications; evidence traceability; and the evaluation of a JIT. The centralised information system is to be hosted by eu-LISA at its technical sites. Chapter II: Development and operational management Article 6 confers implementing powers on the Commission to establish conditions for the technical development and implementation of the JITs collaboration platform. Those powers should be exercised in line with Regulation (EU) No 182/2011. The comitology procedure chosen is the examination procedure. Article 25 supplements Article 6 on the establishment of this procedure. Article 7 grants eu-LISA the task of designing, developing and operating the JITs collaboration platform, given its experience with managing large-scale systems in the area of justice and home affairs. Its mandate should be amended to reflect those new tasks. eu-LISA should be equipped with the appropriate funding and staffing to meet its responsibilities under this Regulation. Article 8 requires Member States to put in place technical arrangements so that their competent authorities can access the JITs collaboration platform in line with this Regulation. Article 9 states that the competent Union bodies, offices and agencies must put in place technical arrangements so that they can access the JITs collaboration platform in line with this Regulation. In addition, Eurojust is responsible for the technical adaptation of its systems to establish a connection between the centralised information system and relevant IT tools, supporting functioning of JITs and managed by the JIT Secretariat, in line with Article 4(c). Article 10 defines the mandate, composition and organisational aspects of a Programme Management Board to be set up by the eu-LISA Management Board. This Programme Management Board must adequately manage the design and development phase of the JITs collaboration platform. Article 11 defines the mandate, composition and organisation aspects of an Advisory Group to be established by eu-LISA. The Advisory Group will provide expertise related to the JITs collaboration platform, in particular in the context of preparation of its annual work programme and its annual activity report. EN 13 EN Chapter III: Access to the JITs collaboration platform Article 12 governs access to the JIT collaboration spaces by Member States’ competent authorities. Following the signature of the JIT agreement, a JIT collaboration space must be created within the JITs collaboration platform for each JIT. The JIT collaboration space must be opened by the JIT space administrator(s), with the technical support of eu-LISA. Based on the JIT agreement, the JIT space administrator(s) must define the access rights to the JIT collaboration space. Article 13 states that the JIT space administrator(s) may decide to grant access to the JIT collaboration spaces to the competent Union bodies, offices and agencies for them to fulfil their statutory tasks. Article 14 states that for the purpose of Article 5, the JIT space administrator(s) may decide to grant access to the JIT collaboration spaces to third countries which have signed a particular JITs agreement. The JIT space administrator(s) must ensure that exchanges of operational information with third countries that have been granted access to a JIT collaboration space are limited to the purpose and subject to the conditions of the JIT agreement. Member States must ensure that transfers of personal data to third countries that have been granted access to a JIT collaboration space only take place when the conditions laid down in Chapter V of Directive 2016/680 are met. Chapter IV: Security and liability Article 15 requires eu-LISA to take the necessary technical and organisational measures to ensure the security of the JITs collaboration platform and security of the data within the JITs collaboration platform. Article 16 refers to liability of the Member States or the competent Union bodies, offices or agencies and claims for compensation against them. Chapter V: Data protection Article 17 governs the retention period for storing operational data, as defined in Article 3. Such operational data must be stored in the centralised information system for as long as needed so that all users complete the downloading process. The retention period must not exceed four weeks. Upon expiry of this retention period, the data record must be automatically erased from the centralised system. Article 18 governs the retention period for the storage of non-operational data, as defined in Article 3. Non-operational data must be stored in the centralised information system until the evaluation has been completed. The retention period must not exceed five years. Upon expiry of this retention period, the data record must be automatically erased from the centralised system. Article 19 governs the data controllers and the data processor. It clarifies that each Member State competent authority, and where appropriate, Eurojust, Europol, the European Public Prosecutor’s Office, OLAF or any other competent Union body, office or agency , are data controllers in line with applicable Union data protection rules for the processing of the personal data under this Regulation. eu-LISA must be considered as data processor in line with Regulation (EU) 2018/1725 on the personal data exchanged through – and stored in the JITs collaboration platform. Wherever a third country uploads operational information or EN 14 EN evidence to the JITs collaboration platform, that information or evidence must be scrutinised by a JIT space administrator before it can be downloaded by other platform users. Article 20 limits the purposes of the processing of personal data entered into the JITs collaboration platform. Those data must only be processed for exchanging operational information and evidence between the platform users and exchanging of non-operational data between collaboration platform users for managing the JIT. Access to the JITs collaboration platform must be limited to authorised staff of the Member States’ competent authorities and third country authorities, Eurojust, Europol the European Public Prosecutor’s Office, OLAF and other competent Union bodies, offices or agencies. The access must also be limited to the extent needed to perform the tasks in line with the purpose referred to in paragraph 1 of Article 20, and to what is necessary and proportionate to the objectives being pursued. Article 21 governs keeping logs. It states that eu-LISA must ensure that accessing the centralised information system and all data processing operations in the centralised information system are logged to check the admissibility of requests, to monitor data integrity and security and the lawfulness of the data processing and to self-monitor. Chapter VI: Final provisions Article 22 sets out eu-LISA's and the Commission's reporting and reviewing obligations. Four years after the start of the JITs collaboration platform’s operations and every four years after that, the Commission will conduct an overall evaluation of the JITs collaboration platform. Article 23 states that the costs incurred to establish and operate the JITs collaboration platform must be borne by the general budget of the Union. Article 24 sets out the conditions that need to be met before the Commission determines the date of the start of operations of the JITs collaboration platform. Article 25 governs the comitology procedure to be used, based on a standard provision. Article 26 governs the amendments to Regulation (EU) 2018/1726 for the new responsibilities and tasks of eu-LISA. Article 27 provides that the Regulation will enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. EN 15 EN 2021/0391 (COD) Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL establishing a collaboration platform to support the functioning of Joint Investigation Teams and amending Regulation (EU) 2018/1726 THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION, Having regard to the Treaty on the Functioning of the European Union, and in particular Article 82(1), point (d), thereof, Having regard to the proposal from the European Commission, After transmission of the draft legislative act to the national parliaments, Acting in accordance with the ordinary legislative procedure, Whereas: (1) The Union has set itself the objective of offering its citizens a common area of freedom, security and justice without internal frontiers, in which the free movement of persons is ensured. At the same time, the Union has to ensure that that common area remains a safe place. That objective can only be achieved by means of appropriate measures to prevent and combat crime, including organised crime and terrorism. (2) That is especially challenging where crime takes a cross-border dimension on the territory of several Member States and/or third countries. In such situations, Member States need to be able to join their forces and operations to allow for effective and efficient cross-border investigations and prosecutions for which the exchange of information and evidence is crucial. One of the most successful tools for such cross- border cooperation are Joint Investigation Teams (‘JITs’) that allow for direct cooperation and communication between the judicial and law enforcement authorities of several Member States and possibly third countries to organise their actions and investigations in the most efficient way. JITs are set up for a specific purpose and a limited time-period by the competent authorities of two or more Member States and possibly third countries, to carry out jointly criminal investigations with a cross-border impact. (3) The Union aquis provides for two legal frameworks to set up JITs with the participation of at least two Member States: Council Framework Decision 2002/465/JHA19 and Article 13 of the Convention established by the Council in accordance with Article 34 of the Treaty on European Union on Mutual Assistance in Criminal Matters between the Member States of the European Union20. Third countries can be involved in JITs as parties where there is a legal basis for such 19 Council Framework Decision 2002/465/JHA of 13 June 2002 on joint investigation teams (OJ L 162, 20.6.2002, p. 1). 20 OJ C 197, 12.7.2000, p. 3. EN 16 EN involvement, such as Article 20 of the Second Additional Protocol of the 1959 Council of Europe Convention21 and Article 5 of the Agreement on Mutual Legal Assistance between the European Union and the United States of America22. (4) The existing legal frameworks at Union level do not set out how the entities participating in JITs exchange information and communicate. Those entities reach an agreement on such exchange and communication on the basis of the needs and available means. However, there is a lack of dedicated secure and effective channel to which all participants could have recourse and through which they could promptly exchange large volumes of information and evidence or allow for secure and effective communication. Furthermore, there is no system that would support daily management of JITs, including the traceability of evidence exchanged among the participants. (5) In light of the increasing possibilities of crime infiltrating Information Technology (IT) systems, the current state of play could hamper the effectiveness and efficiency of cross-border investigations, as well as jeopardise and slow down such investigations and prosecutions, making them more costly. The judiciary and law enforcement in particular need to ensure that their systems are as safe as possible and that all JIT members can connect and interact easily, independently of their national systems. (6) The speed and efficiency of the exchanges between the entities participating in JITs could be considerably enhanced by creating a dedicated IT platform to support their functioning. Therefore it is necessary to lay down rules establishing a centralised IT platform (‘JITs collaboration platform’) at Union level to help JITs collaborate, securely communicate and share information and evidence. (7) The JITs collaboration platform should only be used where one of the Union legal bases is, among others, a legal basis for the JIT. For all JITs based solely on international legal bases, the platform, financed by the Union budget and developed on basis of Union legislation, should not be used. However, where a third country is part of a JIT agreement that lists one of the Union legal bases besides an international one, its competent authorities should be considered JIT members. (8) The use of the JITs collaboration platform should be on a voluntary basis. However, in view of its added value for cross-border investigations its use is strongly encouraged. The use or non-use of the JITs collaboration platform should not prejudice or affect the legality of other forms of communication or exchange of information and should not change the way the JITs are set up, organised or function. The establishment of the JITs collaboration platform should not impact the underlying legal bases for JITs nor the applicable national procedural legislation regarding the collection and use of the obtained evidence. The platform should only provide a secure IT tool to improve the cooperation and the effectiveness of the JITs. (9) The JITs collaboration platform should cover the operational and post-operational phases of a JIT, starting from the moment the relevant JIT agreement is signed by its members, and finishing once the JIT evaluation is over. Due to the fact that the actors participating in the JIT set-up process are different from the actors who are members of JIT once it is established, the process of setting up a JIT, especially the negotiation of the content and the signature of the JIT agreement, should not be managed by the JITs collaboration platform. However, following a need for an electronic tool to 21 CET No 182 22 OJ L 181, 19.7.2003, p. 34. EN 17 EN support the process of signing up a JIT, the Commission should consider covering that process by the e-Evidence Digital Exchange System (eEDES). (10) For each JIT making use of the JITs collaboration platform, the JIT members should be encouraged to conduct an evaluation of the JIT, either during the operational phase of the JIT or following its closure, using the tools provided for by the JITs collaboration platform. (11) The JIT agreement should be a prerequisite for the use of the JITs collaboration platform. The content of all future JIT agreements should be adapted to take into account the relevant provisions of this Regulation. (12) From an operational perspective, the JITs collaboration platform should be composed of isolated JIT collaboration spaces created for each individual JIT hosted by the platform. (13) From a technical perspective, the JITs collaboration platform should be accessible via a secure connection over the internet and should be composed of a centralised information system, accessible through a web portal, communication software for mobile and desktop devices, and a connection between the centralised information system and relevant IT tools, supporting the functioning of JITs and managed by the JIT Secretariat. (14) The purpose of the JITs collaboration platform should be to facilitate the daily coordination and management of a JIT, ensure the exchange and temporary storage of operational information and evidence, provide secure communication, provide for evidence traceability and support the process of the evaluation of a JIT. All entities participating in JITs should be encouraged to use all functionalities of the JITs collaboration platform and to replace as much as possible the communication and data exchange channels which are currently used. (15) The JITs collaboration platform complements existing tools allowing for secure exchange of data among judicial authorities and law enforcement, such as the Secure Information Exchange Network Application (SIENA). (16) Communication-related functionalities of the JITs collaboration platform should be provided by a software allowing for non-traceable communication stored locally at the devices of the users. (17) A proper functionality allowing to exchange operational information and evidence, including large files, should be ensured through an upload/download mechanism designed to store the data centrally only for the limited period of time necessary for the technical transfer of the data. As soon as the data is downloaded by all addresses, it should be automatically deleted from the JITs collaboration platform. (18) Given its experience with managing large-scale systems in the area of justice and home affairs, the European Union Agency for the Operational Management of Large- Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) established by Regulation (EU) 2018/1726 of the European Parliament and of the Council23 should be entrusted with the task of designing, developing and operating the JITs 23 Regulation (EU) 2018/1726 of the European Parliament and of the Council of 14 November 2018 on the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA), and amending Regulation (EC) No 1987/2006 and Council Decision 2007/533/JHA and repealing Regulation (EU) No 1077/2011 (OJ L 295, 21.11.2018, p. 99). EN 18 EN collaboration platform making use of the existing functionalities of SIENA and other functionalities at Europol to ensure complementarity and interoperability. Therefore, its mandate should be amended to reflect those new tasks and it should be provided with the appropriate funding and staffing to meet its responsibilities under this Regulation. In that regard, rules should be established on the responsibilities of eu- LISA, as the Agency entrusted with the development, technical operation and maintenance of the JITs collaboration platform. (19) When designing the JITs collaboration platform, eu-LISA should ensure technical interoperability with SIENA. (20) Since the establishment of the Network of National Experts on Joint Investigation Teams (the ‘JITs Network’) in accordance with Council Document 11037/0524, the JIT Secretariat supports the work of the JITs Network by organising annual meetings, trainings, collecting and analysing the JIT evaluation reports and managing the Eurojust’s JIT funding programme. Since 2011, the JIT Secretariat is hosted by Eurojust as a separate unit. To allow the JIT Secretariat to support users in the practical application of the JITs collaboration platform, as well as to provide technical and administrative support to JIT space administrators, Eurojust should be provided with appropriate staff allocated to the JIT Secretariat. (21) Given the currently existing IT tools supporting operations of JITs, which are hosted at Eurojust and managed by the JIT Secretariat, it is necessary to connect the JITs collaboration platform with those IT tools, in order to facilitate the management of JITs. To that end, Eurojust should ensure the necessary technical adaptation of its systems in order to establish such connection. Eurojust should be provided with the appropriate funding and staffing to meet its responsibilities in that regard. (22) In order to ensure a clear allocation of rights and tasks, rules should be established on the responsibilities of Member States, Eurojust, Europol, the European Public Prosecutor’s Office, the European Anti-Fraud Office (OLAF) and other competent Union bodies, offices and agencies, including the conditions, under which they may use the JITs collaboration platform for operative purposes. (23) This Regulation sets out the details about the mandate, composition and organisational aspects of a Programme Management Board which should be set up by the Management Board of eu-LISA. The Programme Management Board should ensure the adequate management of the design and development phase of the JITs collaboration platform. It is also necessary to set out the details of the mandate, composition and organisation aspects of an Advisory Group to be established by eu- LISA in order to obtain expertise related to the JITs collaboration platform, in particular in the context of preparation of its annual work programme and its annual activity report. (24) This Regulation establishes rules on access to the JITs collaboration platform and the necessary safeguards. The JIT space administrator or administrators should be entrusted with the management of the access rights to the individual JIT collaboration spaces. They should be in charge of granting access, during the operational and post- 24 Council of the European Union, Outcome of Proceedings of Article Art 36 Committee on 7 and 8 July 2005, Item 7 of the Agenda: Joint Investigation Teams - Proposal for designation of national experts, 11037/05. EN 19 EN operational phases of the JIT, to JITs collaboration platform users. JIT space administrators should be able to transfer their role to the JIT secretariat. (25) Bearing in mind the sensitivity of the operational data exchanged among the JITs collaboration platform users, the JITs collaboration platform should guarantee a high level of security. eu-LISA should take all necessary technical and organisational measures in order to ensure the security of the exchange of data by using strong end- to-end encryption algorithms to encrypt data in transit or at rest. (26) This Regulation establishes rules on the liability of Member States, eu-LISA, Eurojust, Europol, the European Public Prosecutor’s Office, OLAF and other competent Union bodies, offices and agencies, in respect of material or non-material damage occurring as a result of any act incompatible with this Regulation. Concerning third countries, liability clauses in respect of material or non-material damage should be contained in respective JIT agreements. (27) In addition, this Regulation provides specific data protection provisions, concerning both operational data and non-operational data, needed to supplement the existing data protection arrangements and to provide for an adequate overall level of data protection, data security and protection of the fundamental rights of the persons concerned. (28) Directive (EU) 2016/680 of the European Parliament and of the Council25 applies to the processing of personal data by competent national authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. As regards the processing by Union institutions, bodies, offices and agencies, Regulation (EU) 2018/1725 of the European Parliament and of the Council26 should apply in the context of this Regulation. (29) Where appropriate, it should be possible for JIT space administrators to grant access to a JIT collaboration space to third countries which are parties to a JIT agreement. Any transfer of personal data to third countries or international organisations in the context of a JIT agreement is subject to compliance with the provisions set out in Chapter V of Directive (EU) 2016/680. Exchanges of operational data with third countries should be limited to those required to fulfil the purposes of the JIT agreement. (30) Whenever a third country uploads operational information or evidence to a JIT collaboration space, the JIT space administrator should verify that such information or evidence is provided to fulfil the purposes of the JIT agreement, before it can be downloaded by other users of the platform. (31) Where a JIT has multiple JIT space administrators, those JIT space administrators should agree among themselves, as soon as the JIT collaboration space including third 25 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89). 26 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39). EN 20 EN countries is established, about one of them to be controller of the data uploaded by those third countries. (32) eu-LISA should ensure that accessing the centralised information system and all data processing operations in the centralised information system are logged for the purposes of monitoring data integrity and security, the lawfulness of the data processing as well as for the purposes of self-monitoring. (33) This Regulation imposes reporting obligations on eu-LISA regarding the development and functioning of the JITs collaboration platform in light of objectives relating to the planning, technical output, cost-effectiveness, security and quality of service. Furthermore, the Commission should conduct an overall evaluation of the JITs collaboration platform four years after the start of operations of the JITs collaboration platform and every four years thereafter. (34) Each Member State as well as Eurojust, Europol, the European Public Prosecutor’s Office, OLAF and any other competent Union body, office and agency should bear its own costs arising from their use of the JITs collaboration platform. (35) In order to establish conditions for the technical development and implementation of the JITs collaboration platform, implementing powers should be conferred on the Commission. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and the Council27. (36) The Commission should determine the date of the start of operations of the JITs collaboration platform once the relevant implementing acts necessary for the technical development of the JITs collaboration platform have been adopted and eu-LISA has carried out a comprehensive test of the JITs collaboration platform, in cooperation with the Member States. (37) Since the objective of this Regulation, namely to enable the effective and efficient cooperation, communication and exchange of information and evidence among JIT members, Eurojust, Europol, OLAF and other competent Union bodies, offices and agencies, cannot be sufficiently achieved by the Member States, but can rather, by setting out common rules, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union (TEU). In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary to achieve that objective. (38) In accordance with Articles 1 and 2 of Protocol No 22 on the position of Denmark, annexed to the Treaty on European Union and to the Treaty on the Functioning of the European Union, Denmark is not taking part in the adoption of this Regulation and is not bound by it or subject to its application. (39) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) No 2018/1725 and delivered an opinion on XXXX, 27 Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by Member States of the Commission’s exercise of implementing powers (OJ L 55, 28.2.2011, p. 13). EN 21 EN HAVE ADOPTED THIS REGULATION: CHAPTER I General provisions Article 1 Subject matter This Regulation: (a) establishes an IT platform (the ‘JITs collaboration platform’), to be used on a voluntary basis, to facilitate the cooperation of competent authorities participating in Joint Investigation Teams (‘JITs’) set up on the basis of Article 13 of the Convention established by the Council in accordance with Article 34 of the Treaty on European Union, on Mutual Assistance in Criminal Matters between the Member States of the European Union or on Framework Decision 2002/465/JHA; (b) lays down rules on the division of responsibilities between the JITs collaboration platform users and the agency responsible for the development and maintenance of the JITs collaboration platform; (c) sets out conditions, under which the JITs collaboration platform users may be granted access to the JITs collaboration platform; (d) lays down specific data protection provisions needed to supplement the existing data protection arrangements and to provide for an adequate overall level of data protection, data security and protection of the fundamental rights of the persons concerned. Article 2 Scope 1. This Regulation applies to the processing of information, including personal data, within the context of a JIT. That includes the exchange and storage of operational information and evidence as well as non-operational information. This Regulation applies to the operational and post-operational phases of a JIT, starting from the moment the relevant JIT agreement is signed by its members. 2. This Regulation does not amend or otherwise affect the existing legal provisions on the establishment, conduct or evaluation of JITs. Article 3 Definitions For the purposes of this Regulation, the following definitions apply: (1) ‘centralised information system’ means a central IT system where storing and processing of JITs related data takes place; (2) ‘communication software’ means software that facilitates remote access to systems and the exchange of files and messages in text, audio or video formats between JITs collaboration platform users; EN 22 EN (3) ‘competent authorities’ means the authorities competent to set up a JIT as referred to in Article 1 of Framework Decision 2002/465/JHA and Article 13 of the Convention established by the Council in accordance with Article 34 of the Treaty on European Union on Mutual Assistance in Criminal Matters between the Member States of the European Union, the European Public Prosecutor’s Office when acting pursuant to its competences as provided for by Articles 22, 23 and 25 of Council Regulation (EU) 2017/1939, as well as the competent authorities of a third country where they are party of a JIT agreement on the basis of an additional legal basis; (4) ‘JIT members’ means representatives of the competent authorities referred to in point 3 of this Article; (5) ‘JITs collaboration platform users’ means JIT members, Eurojust, Europol, OLAF and other competent Union bodies, offices and agencies; (6) ‘JIT collaboration space’ means an individual isolated space for each JIT hosted on the JITs collaboration platform; (7) ‘JIT space administrator” means a representative of the competent authorities of the Member State in charge of the JIT collaboration space; (8) ‘operational data’ means information and evidence processed by the JITs collaboration platform during the operational phase of a JIT to support cross-border investigations and prosecutions; (9) ‘non-operational data’ means administrative data processed by the JITs collaboration platform, notably to facilitate the management of the JIT and daily cooperation between JITs collaboration platform users. Article 4 Technical architecture of the JITs collaboration platform The JITs collaboration platform shall be composed of the following: (a) a centralised information system, which allows for temporary central data storage; (b) a communication software, which allows for local storage of communication data; (c) a connection between the centralised information system and relevant IT tools, supporting the functioning of JITs and managed by the JIT Secretariat. Article 5 Purpose of the JITs collaboration platform 1. The purpose of the JITs collaboration platform shall be to facilitate: (a) the daily coordination and management of a JIT, through a set of functionalities supporting the administrative and financial processes within the JIT; (b) the exchange and temporary storage of operational information and evidence, including large files, through an upload and download functionality; (c) secure communications through a functionality covering instant messaging, chats, audio and video-conferencing; EN 23 EN (d) evidence traceability through a business logging mechanism allowing to keep track of all evidence exchanged through the JITs collaboration platform; (e) the evaluation of a JIT through a dedicated collaborative evaluation process. 2. The centralised information system shall be hosted by eu-LISA at its technical sites. CHAPTER II Development and operational management Article 6 Adoption of implementing acts by the Commission The Commission shall adopt the implementing acts necessary for the technical development of the JITs collaboration platform as soon as possible, and in particular acts concerning: (a) the list of functionalities required for the daily coordination and management of a JIT; (b) the list of functionalities required for secure communications; (c) business specifications of the connection referred to in Article 4, point (c); (d) security in accordance with Article 15; (e) technical logs in accordance with Article 21; (f) technical statistics in accordance with Article 22; (g) performance and availability requirements of the JITs collaboration platform. The implementing acts referred to in the first subparagraph of this Article shall be adopted in accordance with the examination procedure referred to in Article 25. Article 7 Responsibilities of eu-LISA 1. The European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (‘eu-LISA’) shall establish the design of the physical architecture of the JITs collaboration platform including its technical specifications and evolution. That design shall be approved by its Management Board, subject to a favourable opinion of the Commission. 2. eu-LISA shall be responsible for the development of the JITs collaboration platform in accordance with the principle of data protection by design and by default. The development shall consist of the elaboration and implementation of the technical specifications, testing and overall project coordination. 3. eu-LISA shall make the communication software available to the JITs collaboration platform users. 4. eu-LISA shall develop and implement the JITs collaboration platform as soon as possible after the entry into force of this Regulation and following the adoption by the Commission of the implementing acts pursuant to Article 6. EN 24 EN 5. eu-LISA shall ensure that the JITs collaboration platform is operated in accordance with this Regulation, with the implementing act referred to in Article 6, as well as in accordance with Regulation (EU) 2018/1725. 6. eu-LISA shall be responsible for the operational management of the JITs collaboration platform. The operational management of the JITs collaboration platform shall consist of all the tasks necessary to keep the JITs collaboration platform operational in accordance with this Regulation, and in particular the maintenance work and technical developments necessary to ensure that the JITs collaboration platform functions at a satisfactory level in accordance with the technical specifications. 7. eu-LISA shall ensure the provision of training on the practical use of the JITs collaboration platform. 8. eu-LISA shall not have access to the JIT collaboration spaces. 9. Without prejudice to Article 17 of the Staff Regulations of Officials of the European Union, laid down in Council Regulation (EEC, Euratom, ECSC) No 259/6828, eu- LISA shall apply appropriate rules of professional secrecy or other equivalent duties of confidentiality to its entire staff required to work with data registered in the centralised information system. That obligation shall also apply after such staff leave office or employment or after the termination of their activities. Article 8 Responsibilities of the Member States Each Member State shall make the technical arrangements necessary for access of its competent authorities to the JITs collaboration platform in accordance with this Regulation. Article 9 Responsibilities of competent Union bodies, offices and agencies 1. Eurojust, Europol, the European Public Prosecutor’s Office, OLAF and other competent Union bodies, offices and agencies shall make the necessary technical arrangements to enable them to access the JITs collaboration platform. 2. Eurojust shall be responsible for the necessary technical adaptation of its systems, required to establish the connection referred to in Article 4, point (c). Article 10 Programme Management Board 1. Prior to the design and development phase of the JITs collaboration platform, the Management Board of eu-LISA shall establish a Programme Management Board. 2. The Programme Management Board shall be composed of ten members as follows: (a) eight members appointed by the Management Board; 28 Regulation (EEC, Euratom, ECSC) No 259/68 of the Council of 29 February 1968 laying down the Staff Regulations of Officials and the Conditions of Employment of Other Servants of the European Communities and instituting special measures temporarily applicable to officials of the Commission,(OJ L 56, 4.3.1968, p. 1). EN 25 EN (b) the Chair of the Advisory Group referred to in Article 11; (c) one member appointed by the Commission. 3. The Management Board of eu-LISA shall ensure that the members it appoints to the Programme Management Board have the necessary experience and expertise in the development and management of IT systems supporting judicial authorities. 4. eu-LISA shall participate in the work of the Programme Management Board. To that end, representatives of eu-LISA shall attend the meetings of the Programme Management Board in order to report on work regarding the design and development of the JITs collaboration platform and on any other related work and activities. 5. The Programme Management Board shall meet at least once every three months, and more often as necessary. It shall ensure the adequate management of the design and development phase of the JITs collaboration platform. The Programme Management Board shall submit written reports regularly to the Management Board of eu-LISA, and where possible every month, on the progress of the project. The Programme Management Board shall have no decision-making power nor any mandate to represent the members of the eu-LISA Management Board. 6. The Programme Management Board shall establish its rules of procedure which shall include in particular rules on chairmanship, meeting venues, preparation of meetings, admission of experts to the meetings, communication plans ensuring that non- participating Members of the eu-LISA Management Board are kept fully informed. 7. The chairmanship of the Programme Management Board shall be held by a Member State. 8. The Programme Management Board's secretariat shall be ensured by eu-LISA. Article 11 Advisory Group 1. eu-LISA shall establish an Advisory Group in order to obtain expertise related to the JITs collaboration platform, in particular in the context of preparation of its annual work programme and its annual activity report. 2. During the design and development phase of the JITs collaboration platform, the Advisory Group shall be composed of the representatives of the Member States, the Commission and the JIT Secretariat. It shall be chaired by eu-LISA. It shall: (a) meet regularly, where possible at least once a month, until the start of operations of the JITs collaboration platform; (b) report after each meeting to the Programme Management Board; (c) provide the technical expertise to support the tasks of the Programme Management Board. CHAPTER III Access to the JITs collaboration platform EN 26 EN Article 12 Access to the JIT collaboration spaces by Member States’ competent authorities 1. Following the signature of a JIT agreement, a JIT collaboration space shall be created within the JITs collaboration platform for each JIT. 2. The JIT collaboration space shall be opened by the JIT space administrator or administrators, with the technical support of eu-LISA. 3. The JIT space administrator or administrators shall establish the access rights of the JITs collaboration platform users to the JIT collaboration space, on the basis of the JIT agreement. Article 13 Access to the JIT collaboration spaces by competent Union bodies, offices and agencies 1. The JIT space administrator or administrators may decide to grant Eurojust, including the JIT Secretariat, access to a JIT collaboration space for the purpose of fulfilling its tasks set out in Regulation (EU) 2018/1727 of the European Parliament and of the Council29. In particular, the JIT space administrator or administrators may decide to grant the JIT Secretariat access to a JIT collaboration space for the purpose of technical and administrative support, including access rights management. 2. The JIT space administrator or administrators may decide to grant Europol access to a JIT collaboration space for the purpose of fulfilling its tasks set out in Regulation (EU) 2016/794 of the European Parliament and of the Council30. 3. The JIT space administrator or administrators may decide to grant OLAF access to a JIT collaboration space for the purpose of fulfilling its tasks set out in Regulation (EU, Euratom) No 883/2013 of the European Parliament and of the Council31. 4. The JIT space administrator or administrators may decide to grant the European Public Prosecutor’s Office access to a JIT collaboration space for the purpose of fulfilling its tasks set out in Council Regulation (EU) 2017/1939. 5. The JIT space administrator or administrators may decide to grant other competent Union bodies, offices and agencies access to a JIT collaboration space for the purpose of fulfilling tasks set out in their basic acts. Article 14 Access to the JIT collaboration spaces by third countries’ competent authorities 29 Regulation (EU) 2018/1727 of the European Parliament and of the Council of 14 November 2018 on the European Union Agency for Criminal Justice Cooperation (Eurojust) (OJ L 295, 21.11.2018, p. 138). 30 Regulation (EU) 2016/794 of the European Parliament and of the Council of 11 May 2016 on the European Union Agency for Law Enforcement Cooperation (Europol) (OJ L 135, 24.5.2016, p. 53) 31 Regulation (EU, Euratom) No 883/2013 of the European Parliament and of the Council of 11 September 2013 concerning investigations conducted by the European Anti-Fraud Office (OLAF) and repealing Regulation (EC) No 1073/1999 of the European Parliament and of the Council and Council Regulation (Euratom) No 1074/1999 (OJ L 248, 18.9.2013, p. 1). EN 27 EN 1. For the purposes listed in Article 5, the JIT space administrator or administrators may decide to grant access to a JIT collaboration space to the competent authorities of third countries which have signed a particular JITs agreement. 2. The JIT space administrator or administrators shall ensure that the exchanges of operational data with the competent authorities of third countries that have been granted access to a JIT collaboration space are limited to what is required for the purposes of the JIT agreement and subject to the conditions laid therein. 3. Member States shall ensure that their transfers of personal data to third countries that have been granted access to a JIT collaboration space only take place where the conditions laid down in Chapter V of Directive 2016/680 are met. CHAPTER IV Security and liability Article 15 Security 1. eu-LISA shall take the necessary technical and organisational measures to ensure a high level of cyber security of the JITs collaboration platform and the information security of data within the JITs collaboration platform, in particular in order to ensure the confidentiality and integrity of operational and non-operational data stored in the centralised information system. 2. eu-LISA shall prevent unauthorised access to the JITs collaboration platform and shall ensure that persons authorised to access the JITs collaboration platform have access only to the data covered by their access authorisation. 3. For the purposes of paragraphs 1 and 2, eu-LISA shall adopt a security plan, a business continuity and disaster recovery plan, to ensure that the centralised information system may, in case of interruption, be restored. 4. eu-LISA shall monitor the effectiveness of the security measures referred to in this Article and shall take the necessary organisational measures related to self- monitoring and supervision to ensure compliance with this Regulation. Article 16 Liability 1. Where a Member State, Eurojust, Europol, the European Public Prosecutor’s Office, OLAF or any other competent Union body, office or agency, as a consequence of a failure on their part to comply with their obligations under this Regulation, cause damage to the JITs collaboration platform, that Member State, Eurojust, Europol, the European Public Prosecutor’s Office, OLAF or other competent Union body, office or agency respectively, shall be held liable for such damage, insofar as eu-LISA fails to take reasonable measures to prevent the damage from occurring or to minimise its impact. 2. Claims for compensation against a Member State for the damage referred to in paragraph 1 shall be governed by the law of the defendant Member State. Claims for compensation against Eurojust, Europol, the European Public Prosecutor’s Office, EN 28 EN OLAF or any other competent Union body, office or agency for the damage referred to in paragraph 1 shall be governed by their respective founding acts. CHAPTER V Data protection Article 17 Retention period for storage of operational data 1. Operational data pertaining to each JIT collaboration space shall be stored in the centralised information system for as long as needed for all concerned JITs collaboration platform users to complete the process of its downloading. The retention period shall not exceed four weeks. 2. Upon expiry of the retention period referred to in paragraph 1, the data record shall be automatically erased from the centralised system. Article 18 Retention period for storage of non-operational data 1. Where an evaluation of the JIT is envisaged, non-operational data pertaining to each JIT collaboration space shall be stored in the centralised information system until the JIT evaluation has been completed. The retention period shall not exceed five years. 2. Upon expiry of the retention period referred to in paragraph 1, the data record shall be automatically erased from the centralised system. Article 19 Data controller and data processor 1. Each competent national authority of a Member State, and where appropriate, Eurojust, Europol, the European Public Prosecutor’s Office, OLAF or any other competent Union body, office or agency shall be considered to be data controllers in accordance with applicable Union data protection rules for the processing of personal data under this Regulation. 2. With regard to data uploaded to the JITs collaboration platform by the competent authorities of third countries, one of the JIT space administrators is to be considered data controller as regards the personal data exchanged through, and stored in the JITs collaboration platform. 3. eu-LISA shall be considered to be data processor in accordance with Regulation (EU) 2018/1725 as regards the personal data exchanged through, and stored in the JITs collaboration platform. 4. The JITs collaboration platform users shall be jointly responsible for managing non- operational data in the JITs collaboration platform. EN 29 EN Article 20 Purpose of the processing of personal data 1. The data entered into the JITs collaboration platform shall only be processed for the purposes of: (a) the exchange of operational information and evidence between the JITs collaboration platform users; (b) the exchange of non-operational data between the JITs collaboration platform users, for the purposes of managing the JIT. 2. Access to the JITs collaboration platform shall be limited to duly authorised staff of the competent Member States’ and third country authorities, Eurojust, Europol, the European Public Prosecutor’s Office, OLAF and other competent Union bodies, offices or agencies, to the extent needed for the performance of their tasks in accordance with the purposes referred to in paragraph 1, and to what is necessary and proportionate to the objectives pursued. Article 21 Technical logs 1. eu-LISA shall ensure that a log is kept of all access to the centralised information system and all data processing operations in the centralised information system, in accordance with paragraph 2. 2. The logs shall show: (a) the date, time zone and exact time of accessing the centralised information system; (b) the identifying mark of JIT’s collaboration platform user who accessed the centralised information system; (c) the date, time zone and access time of the operation carried out by the JIT’s collaboration platform user; (d) the operation carried out by the JIT’s collaboration platform user. 3. The logs shall be protected by appropriate technical measures against unauthorised access and shall be kept for three years or for such longer period as required for the termination of ongoing monitoring procedures. 4. On request, eu-LISA shall make the logs available to the competent authorities of the Member States without undue delay. 5. Within the limits of their competences and for the purpose of fulfilling their duties, the national supervisory authorities responsible for monitoring the lawfulness of data processing shall have access to logs upon request. 6. Within the limits of its competences and for the purpose of fulfilling its supervisory duties in accordance with Regulation (EU) 2018/1725, the European Data Protection Supervisor shall have access to logs upon request. CHAPTER VI Final provisions EN 30 EN Article 22 Monitoring and evaluation 1. eu-LISA shall establish procedures to monitor the development of the JITs collaboration platform as regards the objectives relating to planning and costs and to monitor the functioning of the JITs collaboration platform as regards the objectives relating to the technical output, cost-effectiveness, security and quality of service. 2. The procedures referred to in paragraph 1 shall provide for the possibility to produce regular technical statistics for monitoring purposes. 3. In the event of substantial delays in the development process, eu-LISA shall inform the European Parliament and the Council as soon as possible of the reasons for the delays and of their impact in terms of timeframes and finances. 4. Once the development of the JITs collaboration platform is finalised, eu-LISA shall submit a report to the European Parliament and to the Council explaining how the objectives, in particular relating to planning and costs, were achieved and justifying any divergences. 5. In the event of a technical upgrade of the JITs collaboration platform, which could result in substantial costs, eu-LISA shall inform the European Parliament and the Council before making the upgrade. 6. Two years after the start of operations of the JITs collaboration platform and every year thereafter, eu-LISA shall submit to the Commission a report on the technical functioning of the JITs cooperation platform, including its security. 7. Four years after the start of operations of the JITs collaboration platform and every four years thereafter, the Commission shall conduct an overall evaluation of the JITs collaboration platform. The Commission shall transmit the overall evaluation report to the European Parliament and the Council. 8. The Member States’ competent authorities, Eurojust, Europol, the European Public Prosecutor’s Office, OLAF and other competent Union bodies, offices and agencies shall provide eu-LISA and the Commission with the information necessary to draft the reports referred to in paragraphs 4 and 7. That information shall not jeopardise working methods or include information that reveals sources, names of staff members or investigations. 9. eu-LISA shall provide the Commission with the information necessary to produce the overall evaluation referred to in paragraph 7. Article 23 Costs The costs incurred in connection with the establishment and operation of the JITs collaboration platform shall be borne by the general budget of the Union. Article 24 Start of operations 1. The Commission shall determine the date of the start of operations of the JITs collaboration platform, once it is satisfied that the following conditions are met: EN 31 EN (a) the relevant implementing acts referred to in Article 6 have been adopted; (b) eu-LISA has carried out a comprehensive test of the JITs collaboration platform, in cooperation with the Member States, using anonymous test data. 2. Where the Commission has determined the date of start of operations in accordance with paragraph 1, it shall communicate that date to the Member States, Eurojust, Europol, the European Public Prosecutor’s Office and OLAF. 3. The decision of the Commission determining the date of the start of operations of the JITs collaboration platform, as referred to in paragraph 1, shall be published in the Official Journal of the European Union. 4. The JITs collaboration platform users shall start using the JITs collaboration platform from the date determined by the Commission in accordance with paragraph 1. Article 25 Committee procedure 1. The Commission shall be assisted by a committee. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011. 2. Where reference is made to this Article, Article 5 of Regulation (EU) No 182/2011 shall apply. 3. Where the committee delivers no opinion, the Commission shall not adopt the draft- implementing act and the third subparagraph of Article 5(4) of Regulation (EU) No 182/2011 shall apply. Article 26 Amendments to Regulation (EU) 2018/1726 Regulation (EU) 2018/1726 is amended as follows: (1) in Article 1, the following paragraph 4a is inserted: “4a. The Agency shall be responsible for the development and operational management, including technical evolutions, of the Joint Investigation Teams (‘JITs’) collaboration platform”; (2) the following Article 8b is inserted: “Article 8b Tasks related to the JITs collaboration platform In relation to the JITs collaboration platform, the Agency shall perform: (a) the tasks conferred on it by Regulation (EU) No XXX/20XX of the European Parliament and of the Council*; (b) tasks relating to training on the technical use of the JITs collaboration platform, including provision of online training materials. __________ EN 32 EN * Regulation (EU) No XXX/20XX of the European Parliament and of the Council establishing a centralised collaboration platform to support the functioning of Joint Investigation Teams and amending Regulation (EU) 2018/1726 (OJ L …).”; (3) in Article 14, paragraph 1 is replaced by the following: “1.The Agency shall monitor developments in research relevant for the operational management of SIS II, VIS, Eurodac, the EES, ETIAS, DubliNet, ECRIS-TCN, e-CODEX, the JITs collaboration platform and other large-scale IT systems as referred to in Article 1(5).”; (4) in Article 19(1), point (ff) is replaced by the following: “(ff) adopt reports on the technical functioning of the following: (i) SIS pursuant to Article 60(7) of Regulation (EU) 2018/1861 of the European Parliament and of the Council* and Article 74(8) of Regulation (EU) 2018/1862 of the European Parliament and of the Council**; (ii) VIS pursuant to Article 50(3) of Regulation (EC) No 767/2008 and Article 17(3) of Decision 2008/633/JHA; (iii) EES pursuant to Article 72(4) of Regulation (EU) 2017/2226; (iv) ETIAS pursuant to Article 92(4) of Regulation (EU) 2018/1240; (v) ECRIS-TCN and of the ECRIS reference implementation pursuant to Article 36(8) of Regulation (EU) 2019/816 of the European Parliament and of the Council***; (vi) the interoperability components pursuant to Article 78(3) of Regulation (EU) 2019/817 and Article 74(3) of Regulation (EU) 2019/818; (vii) the e-CODEX system pursuant to Article 14(1) of Regulation (EU) XXX****; (viii) the JITs collaboration platform pursuant to Article xx of Regulation (EU) XXX***** [this Regulation]; __________ * Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of border checks, and amending the Convention implementing the Schengen Agreement, and amending and repealing Regulation (EC) No 1987/2006 (OJ L 312, 7.12.2018, p. 14). ** Regulation (EU) 2018/1862 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of police cooperation and judicial cooperation in criminal matters, amending and repealing Council Decision 2007/533/JHA, and repealing Regulation (EC) No 1986/2006 of the European Parliament and of the Council and Commission Decision 2010/261/EU (OJ L 312, 7.12.2018, p. 56). *** Regulation (EU) 2019/816 of the European Parliament and of the Council of 17 April 2019 establishing a centralised system for the identification of Member States holding conviction information on third-country nationals and stateless persons (ECRIS-TCN) to EN 33 EN supplement the European Criminal Records Information System and amending Regulation (EU) 2018/1726 (OJ L 135, 22.5.2019, p. 1). **** Regulation (EU) XXX of … (OJ L …). ***** Regulation (EU) XXX of … (OJ L …).”; (5) in Article 27(1), the following point (dc) is inserted: “(dc) the JITs collaboration platform Advisory Group;”. Article 27 Entry into force This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. This Regulation shall be binding in its entirety and directly applicable in all Member States in accordance with the Treaties. Done at Brussels, For the European Parliament For the Council The President The President EN 34 EN LEGISLATIVE FINANCIAL STATEMENT Contents 1. FRAMEWORK OF THE PROPOSAL/INITIATIVE ............................................... 37 1.1. Title of the proposal/initiative .................................................................................... 37 1.2. Policy area(s) concerned ............................................................................................ 37 1.3. The proposal relates to: .............................................................................................. 37 1.4. Objective(s) ................................................................................................................ 37 1.4.1. General objective(s) ................................................................................................... 37 1.4.2. Specific objective(s) ................................................................................................... 37 1.4.3. Expected result(s) and impact .................................................................................... 37 1.4.4. Indicators of performance .......................................................................................... 37 1.5. Grounds for the proposal/initiative ............................................................................ 38 1.5.1. Requirement(s) to be met in the short or long term including a detailed timeline for roll-out of the implementation of the initiative .......................................................... 38 1.5.2. Added value of Union involvement (it may result from different factors, e.g. coordination gains, legal certainty, greater effectiveness or complementarities). For the purposes of this point 'added value of Union involvement' is the value resulting from Union intervention which is additional to the value that would have been otherwise created by Member States alone. ............................................................... 38 1.5.3. Lessons learned from similar experiences in the past ................................................ 38 1.5.4. Compatibility with the Multiannual Financial Framework and possible synergies with other appropriate instruments............................................................................. 38 1.5.5. Assessment of the different available financing options, including scope for redeployment .............................................................................................................. 39 1.6. Duration and financial impact of the proposal/initiative ........................................... 39 1.7. Management mode(s) planned ................................................................................... 39 2. MANAGEMENT MEASURES................................................................................. 40 2.1. Monitoring and reporting rules .................................................................................. 40 2.2. Management and control system(s) ........................................................................... 40 2.2.1. Justification of the management mode(s), the funding implementation mechanism(s), the payment modalities and the control strategy proposed ........................................ 40 2.2.2. Information concerning the risks identified and the internal control system(s) set up to mitigate them.......................................................................................................... 40 2.2.3. Estimation and justification of the cost-effectiveness of the controls (ratio of "control costs ÷ value of the related funds managed"), and assessment of the expected levels of risk of error (at payment & at closure) .................................................................. 41 2.3. Measures to prevent fraud and irregularities .............................................................. 41 EN 35 EN 3. ESTIMATED FINANCIAL IMPACT OF THE PROPOSAL/INITIATIVE ............ 42 3.1. Heading(s) of the multiannual financial framework and expenditure budget line(s) affected ....................................................................................................................... 42 3.2. Estimated impact on expenditure ............................................................................... 43 3.2.1. Summary of estimated impact on expenditure ........................................................... 43 3.2.2. Estimated impact on Eurojust's appropriations .......................................................... 47 3.2.3. Estimated impact on eu-LISA's appropriations ......................................................... 49 3.2.4. Estimated impact on Eurojust's human resources ...................................................... 50 3.2.5. Estimated impact on eu-LISA's human resources...................................................... 52 3.2.6. Compatibility with the current multiannual financial framework.............................. 56 3.2.7. Third-party contributions ........................................................................................... 56 3.3. Estimated impact on revenue ..................................................................................... 57 EN 36 EN LEGISLATIVE FINANCIAL STATEMENT 1. FRAMEWORK OF THE PROPOSAL/INITIATIVE 1.1. Title of the proposal/initiative Proposal for a Regulation of the European Parliament and the Council concerning the establishment of a collaboration platform to support the functioning of Joint Investigation Teams 1.2. Policy area(s) concerned Policy area: Justice and consumers Activity: Justice 1.3. The proposal relates to:  a new action  a new action following a pilot project/preparatory action 32  the extension of an existing action  a merger or redirection of one or more actions towards another/a new action 1.4. Objective(s) 1.4.1. General objective(s) To provide technological support to those involved in JITs to increase the efficiency and effectiveness of their cross-border investigations and prosecutions. 1.4.2. Specific objective(s) 1. To ensure that the members and participants of JITs can more easily share information and evidence collected in the course of the JIT activities. 2. To ensure that the members and participants of JITs can more easily and more safely communicate with each other in the context of the JIT activities. 3. To facilitate the joint daily management of a JIT, including planning and coordination of parallel activities, enhanced traceability of exchanged evidence and coordination with third countries, especially where physical meetings are too expansive or time consuming. 1.4.3. Expected result(s) and impact Specify the effects which the proposal/initiative should have on the beneficiaries/groups targeted. The initiative is expected to increase the efficiency and effectiveness of cross-border investigations and prosecutions conducted by JITs. 1.4.4. Indicators of performance Specify the indicators for monitoring progress and achievements. – Number of JITs registered in the platform every year – Average duration of a JIT hosted in the platform 32 As referred to in Article 58(2) (a) or (b) of the Financial Regulation. EN 37 EN – Number of JITs collaboration platform users – Number of JITs collaboration platform users representing third countries – Number of JITs collaboration users representing the competent Union bodies, offices and agencies – Number of JIT evaluations carried out through the platform – Number of visits to the centralised information system – Number of downloads of the communication software 1.5. Grounds for the proposal/initiative 1.5.1. Requirement(s) to be met in the short or long term including a detailed timeline for roll-out of the implementation of the initiative The main requirements following entry into force of the Regulation are as follows: – Requirements gathering and procurement initiation by eu-LISA – in 2024 – Kick-off of the JITs collaboration platform’s implementation by eu-LISA – in 2025 – Going live of the JITs collaboration platform – 01/2026 – Maintenance and operation of the JITs collaboration platform – from 01/2026 onwards 1.5.2. Added value of Union involvement (it may result from different factors, e.g. coordination gains, legal certainty, greater effectiveness or complementarities). For the purposes of this point 'added value of Union involvement' is the value resulting from Union intervention which is additional to the value that would have been otherwise created by Member States alone. The creation of a standardised and homogenous IT platform to support JITs, allowing the Member States to make use of a technology solution that does not depend on the national IT infrastructure, can neither be achieved unilaterally at Member State level nor bilaterally between the Member States. The Union wide platform is the only way to provide JITs with a unified modern technical solution, which would allow them to carry out their cross-border investigations in a more efficient manner. 1.5.3. Lessons learned from similar experiences in the past There has been no similar projects pertaining to provision of technological support for JITs. 1.5.4. Compatibility with the Multiannual Financial Framework and possible synergies with other appropriate instruments The reinforcement of cross-border criminal investigations and prosecutions carried out by JITs is a crucial part of creating an area of freedom, security and justice. It is also in line with the EU Security Union strategy, the counter-terrorism agenda for the EU, the Communication on the digitalisation of justice and the EU strategy to tackle organised crime. The Commission’s Communication on digitalisation of justice refers to the present proposal as part of the overall toolbox of opportunities for further digitalisation of justice. This proposal is included in the Commission’s work programme for 2021. EN 38 EN 1.5.5. Assessment of the different available financing options, including scope for redeployment The costs concerning establishment and maintenance of the JITs collaboration platform should be borne by the Union budget and should be reflected in the budget of the concerned agencies – eu-LISA and Eurojust. 1.6. Duration and financial impact of the proposal/initiative  limited duration –  in effect from [DD/MM]YYYY to [DD/MM]YYYY –  Financial impact from YYYY to YYYY for commitment appropriations and from YYYY to YYYY for payment appropriations.  unlimited duration – Implementation with a start-up period from YYYY to YYYY, – followed by full-scale operation. 1.7. Management mode(s) planned  Direct management by the Commission –  by its departments, including by its staff in the Union delegations; –  by the executive agencies  Shared management with the Member States  Indirect management by entrusting budget implementation tasks to: –  third countries or the bodies they have designated; –  international organisations and their agencies (to be specified); –  the EIB and the European Investment Fund; –  bodies referred to in Articles 70 and 71 of the Financial Regulation; –  public law bodies; –  bodies governed by private law with a public service mission to the extent that they are provided with adequate financial guarantees; –  bodies governed by the private law of a Member State that are entrusted with the implementation of a public-private partnership and that are provided with adequate financial guarantees; –  persons entrusted with the implementation of specific actions in the CFSP pursuant to Title V of the TEU, and identified in the relevant basic act. EN 39 EN 2. MANAGEMENT MEASURES 2.1. Monitoring and reporting rules Specify frequency and conditions. Monitoring and evaluation of the development and technical functioning of the JITs collaboration platform is of crucial importance and will be applied by following the principles outlined in the common approach on decentralised agencies. To start with, eu-LISA and Eurojust must send each year to the Commission, the European Parliament and the Council a Single Programming Document (SPD) containing multi-annual and annual work programmes and resources programming. The SPD sets out the objectives, expected results and performance indicators to monitor the achievement of the objectives and the results. Once the development of the JITs collaboration platform is finalised, eu-LISA would submit a report to the European Parliament and to the Council explaining how the objectives, in particular relating to planning and costs, were achieved. Two years after the start of operations of the JITs collaboration platform and every year thereafter, eu-LISA would submit to the Commission a report on the technical functioning of the JITs cooperation platform, including its security. Four years after the start of operations of the JITs collaboration platform and every four years thereafter, the Commission would conduct an overall evaluation of the JITs collaboration platform. The Commission would transmit the overall evaluation report to the European Parliament and the Council. 2.2. Management and control system(s) 2.2.1. Justification of the management mode(s), the funding implementation mechanism(s), the payment modalities and the control strategy proposed Considering that the proposal impacts the annual EU contribution to eu-LISA and Eurojust, the Union budget will be implemented via indirect management. Pursuant to the principle of sound financial management, the budget of both agencies shall be implemented in compliance with effective and efficient internal control. Regarding ex-post controls, both agencies are subject to: – internal audit by the Internal Audit Service of the Commission; – annual reports by the European Court of Auditors, giving a statement of assurance as to the reliability of the annual accounts and the legality and regularity of the underlying transactions; – annual discharge granted by the European Parliament; – possible investigations conducted by OLAF to ensure, in particular, that the resources allocated to agencies are put to proper use; – a further layer of control and accountability by the European Ombudsman. 2.2.2. Information concerning the risks identified and the internal control system(s) set up to mitigate them No specific risks have been identified at this stage. EN 40 EN 2.2.3. Estimation and justification of the cost-effectiveness of the controls (ratio of "control costs ÷ value of the related funds managed"), and assessment of the expected levels of risk of error (at payment & at closure) The ratio of “control costs/payment of the related funds managed” is reported on by the Commission. The 2020 AAR of DG JUST reports 0.74% for this ratio in relation to Indirect Management Entrusted Entities and Decentralised Agencies. 2.3. Measures to prevent fraud and irregularities Specify existing or envisaged prevention and protection measures, e.g. from the Anti-Fraud Strategy. The measures related to combating fraud, corruption and other illegal activities are outlined, inter alia, in Article 50 of the eu-LISA Regulation and Article 75 of the Eurojust Regulation. Both agencies shall participate in fraud prevention activities of the European Anti-fraud Office and inform the Commission without delay on cases of presumed fraud and other financial irregularities EN 41 EN 3. ESTIMATED FINANCIAL IMPACT OF THE PROPOSAL/INITIATIVE 3.1. Heading(s) of the multiannual financial framework and expenditure budget line(s) affected • Existing budget lines In order of multiannual financial framework headings and budget lines. Type of Budget line expenditure Contribution Heading of multiannual from from within the meaning financial Number Diff./Non- EFTA from third of Article 21(2)(b) framework 33 candidate diff. countries 35 countries of the Financial 34 countries Regulation Diff./No 1 Single market, innovation and digital NO NO NO NO n-diff. Cohesion, resilience and values Diff./No 2 NO NO NO NO n-diff. Migration and border control Diff./No 4 NO NO NO NO n-diff. European public administration Non- 7 NO NO NO NO diff. • New budget lines requested In order of multiannual financial framework headings and budget lines. Type of Budget line expenditure Contribution Heading of multiannual within the financial Number from from meaning of Diff./Non- from third framework EFTA candidate Article 21(2)(b) of diff. countries the Financial countries countries Regulation [XX.YY.YY.YY] YES/NO YES/NO YES/NO YES/NO 33 Diff. = Differentiated appropriations / Non-diff. = Non-differentiated appropriations. 34 EFTA: European Free Trade Association. 35 Candidate countries and, where applicable, potential candidates from the Western Balkans. EN 42 EN 3.2. Estimated impact on expenditure 3.2.1. Summary of estimated impact on expenditure EUR million (to three decimal places) Single market, innovation and digital (budget line 02.04). The appropriations will be made available from the Digital Europe Programme Heading of multiannual financial in the context of the preparation of the Work Programmes 2023-2027 and 1 through contribution agreement based on Article 7 of the Financial Regulation. framework Their ultimate allocation will be subject to the prioritisation for funding in the context of the underpinning adoption procedure and agreement of the respective Programme Committee. Year Year Year Year TOTAL 2024- eu-LISA 202436 2025 2026 2027 2027 Commitments (1) 0.608 1.216 1.380 1.380 4.584 Title 1: Staff expenditures Payments (2) 0.608 1.216 1.380 1.380 4.584 Commitments (1a) Title 2: Infrastructure and operating expenditures Payments (2a) Title 3: Operational expenditures Commitments (3a) 3.000 2.900 1.700 1.700 9.300 Payments (3b) 3.000 4.600 1.700 9.300 =1+1a Commitments +3a 3.608 4.116 3.080 3.080 13.884 TOTAL appropriations for eu-LISA =2+2a Payments 0.608 4.216 5.980 3.080 13.884 +3b 36 Year 2024 is the year in which implementation of the proposal starts – following the planned adoption in 2023. EN 43 EN EUR million (to three decimal places) Heading of multiannual financial 2 Cohesion, resilience and values framework Year Year Year Year TOTAL 2024- Eurojust 202437 2025 2026 2027 2027 Commitments (1) 0.086 0.346 0.519 0.951 Title 1: Staff expenditures Payments (2) 0.086 0.346 0.519 0.951 Commitments (1a) Title 2: Infrastructure and operating expenditures Payments (2a) Commitments (3a) 0.250 0.250 Title 3: Operational expenditures Payments (3b) 0.250 0.250 =1+1a Commitments +3a 0.336 0.346 0.519 1.201 TOTAL appropriations for Eurojust =2+2a Payments 0.336 0.346 0.519 1.201 +3b 37 Year 2024 is the year in which implementation of the proposal starts – following the planned adoption in 2023. EN 44 EN EUR million (to three decimal places) Heading of multiannual financial 4 Migration and border control framework Year Year Year Year TOTAL 2024- eu-LISA 202438 2025 2026 2027 2027 Commitments (1) Title 1: Staff expenditures Payments (2) Commitments (1a) Title 2: Infrastructure and operating expenditures Payments (2a) Title 3: Operational expenditures Commitments (3a) 2.500 2.500 Payments (3b) 2.500 2.500 =1+1a Commitments +3a 2.500 2.500 TOTAL appropriations for eu-LISA =2+2a Payments 2.500 2.500 +3b 38 Year 2024 is the year in which implementation of the proposal starts – following the planned adoption in 2023. EN 45 EN EUR million (to three decimal places) Heading of multiannual financial 7 European public administration framework Year Year Year Year TOTAL 2024- 2024 2025 2026 2027 2027 DG JUST  Human Resources 0.152 0.152 0.152 0.152 0.608  Other administrative expenditure TOTAL DG JUST Appropriations 0.152 0.152 0.152 0.152 0.608 TOTAL appropriations (Total commitments = under HEADING 7 Total payments) 0.152 0.152 0.152 0.152 0.608 of the multiannual financial framework Year Year Year Year TOTAL 2024- 2024 2025 2026 2027 2027 TOTAL appropriations Commitments 3.760 7.104 3.578 3.751 18.193 under HEADINGS 1 to 7 Payments 0.760 4.704 8.978 3.751 18.193 of the multiannual financial framework EN 46 EN 3.2.2. Estimated impact on Eurojust's appropriations –  The proposal/initiative does not require the use of operational appropriations –  The proposal/initiative requires the use of operational appropriations, as explained below: Commitment appropriations in EUR million (to three decimal places) Year Year Year Year TOTAL 2024-2027 Indicate 2024 2025 2026 2027 objectives and outputs Eurojust Avera Total No No No No Type Cost Cost Cost Cost Total cost  ge cost No SPECIFIC OBJECTIVE No 1 To develop the necessary technical adaptations of the relevant Eurojust IT systems Development of 0.250 0.250 the necessary technical adaptations of the relevant Eurojust IT systems 0.086 0.173 0.173 0.432 Internal staff required for development of the technical adaptations Subtotal for specific objective No 1 0.336 0.173 0.173 0.682 EN 47 EN SPECIFIC OBJECTIVE No 2 To provide administrative support to the JITs collaboration platform users Internal staff 0.173 0.346 0.519 required to provide administrative support to the JITs collaboration platform users Subtotal for specific objective No 2 0.173 0.346 0.519 TOTAL COST 1.201 EN 48 EN 3.2.3. Estimated impact on eu-LISA's appropriations –  The proposal/initiative does not require the use of operational appropriations –  The proposal/initiative requires the use of operational appropriations, as explained below: Commitment appropriations in EUR million (to three decimal places) Year Year Year Year TOTAL 2024- Indicate 2024 2025 2026 2027 2027 objectives and outputs eu-LISA Avera Total Total No No No No Type ge Cost Cost Cost Cost  No cost cost SPECIFIC OBJECTIVE No 1 To develop the JITs collaboration platform Professional 0.500 0.200 0.700 Services – design, development & testing costs (contractors) Security 1.000 1.000 design, management, testing and compliance Infrastructure 0.500 4.500 5.000 (hardware, software and network provisions) Infrastructure - 1.000 0.700 1.700 security controls development, security capabilities analysis, integration and monitoring Internal staff 0.608 1.216 1.824 required for development of the JITs collaboration platform Subtotal for specific objective No 1 3.608 6.616 10.224 SPECIFIC OBJECTIVE No 2 To maintain and operate the JITs collaboration platform EN 49 EN Infrastructure - 0.700 0.700 1.400 security controls Security & 0.300 0.300 0.600 management Corrective & 0.700 0.700 1.400 adaptive maintenance – including software, licencing & hosting, security provisions & technical evolutions Internal staff 1.380 1.380 2.760 required for the maintenance of the JITs collaboration platform Subtotal for specific objective No 2 3.080 3.080 6.160 TOTAL COST 3.608 6.616 3.080 3.080 16.384 3.2.4. Estimated impact on Eurojust's human resources 3.2.4.1. Summary –  The proposal/initiative does not require the use of appropriations of an administrative nature –  The proposal/initiative requires the use of appropriations of an administrative nature, as explained below39: EUR million (to three decimal places) Eurojust Year Year Year Year TOTAL 2024 2025 2026 2027 2024-2027 Temporary agents (AD Grades) 0.086 0.346 0.519 0.951 Temporary agents (AST grades) Contract staff Seconded National Experts 39 The costs estimates for staff are cumulative and have been made on the basis of the average costs for temporary staff, indexed to the correction coefficient applicable for the Netherlands as of 07/2020 (113,9%). EN 50 EN TOTAL 0.086 0.346 0.519 0.951 Staff requirements40 (FTE): Eurojust Year Year Year Year TOTAL 2024 2025 2026 2027 2024-2027 Temporary agents (AD Grades) 1 3 3 3 Temporary agents (AST grades) Contract staff Seconded National Experts TOTAL 1 3 3 3 Recruitement dates are planned at beginning of the year. No assumptions have been made for a potential increase of the salary indexation or the correction coefficient applicable to the Netherlands. Staff required for the SPECIFIC OBJECTIVE No 1 - to develop the necessary technical adaptations of the relevant Eurojust IT systems: Profile No. Type IT Officer - Architecture 1 TA (AD) TOTAL 1 - Staff required for the SPECIFIC OBJECTIVE No 2 - to provide administrative support to the JITs collaboraton platform users: Profile No. Type Administrative support 2 TA (AD) TOTAL 2 - 40 Cumulative. The number indicated under each year is the number of old staff from the previous year(s) and newly recruited staff. EN 51 EN Description of the profiles: IT Officer – Architecture - to work with the contractors on the design documents and validate (at solution and application level). Also, to be involved in any business/use cases/architectural assessments and Implementing & Delegated Acts. Administrative support – managing individual JIT collaboration spaces on behalf of the JIT members, creating accounts, enabling access to persons authorised by national authorities, training and tutorials for users, uploading tools and materials for platform, support users. 3.2.5. Estimated impact on eu-LISA's human resources 3.2.5.1. Summary –  The proposal/initiative does not require the use of appropriations of an administrative nature –  The proposal/initiative requires the use of appropriations of an administrative nature, as explained below41: EUR million (to three decimal places) eu-LISA Year Year Year Year TOTAL 2024 2025 2026 2027 2024-2027 Temporary agents (AD Grades) 0.608 1.216 1.216 1.216 4.256 Temporary agents (AST grades) Contract staff 0.164 0.164 0.328 Seconded National Experts TOTAL 0.608 1.216 1.380 1.380 4.584 Staff requirements42 (FTE): eu-LISA Year Year Year Year TOTAL 2024 2025 2026 2027 2024-2027 Temporary agents (AD Grades) 4 8 8 8 8 41 The costs estimates for staff are cumulative and have been made on the basis of the average costs for temporary and contract staff. 42 Cumulative. The number indicated under each year is the number of old staff from the previous year(s) and newly recruited staff. EN 52 EN Temporary agents (AST grades) Contract staff 2 2 2 Seconded National Experts TOTAL 4 8 10 10 10 Recruitement dates are planned at beginning of the year. No assumptions have been made for a potential increase of the salary indexation or the correction coefficient applicable to Estonia and France. Staff required for the SPECIFIC OBJECTIVE No 1 - to develop the JITs collaboration platform: Profile No. Type IT Officer - Architecture 1 TA (AD) Test Management 1 TA (AD) Network Management 1 TA (AD) Security Management 1 TA (AD) Infrastructure Management 0.5 TA (AD) Programme and Project management 1 TA (AD) System & Application Administration 0.5 TA (AD) Transversal Services (Finance & Procurement and HR) 1 TA (AD) Business Relationship & Stakeholders’ Management 1 TA (AD) TOTAL 8 - Staff required for the SPECIFIC OBJECTIVE No 2 - to maintain and operate the JITs collaboration platform: Profile No. Type IT Officer - Architecture 0.5 TA (AD) Test Management 0.5 TA (AD) Release & Change Management 0.5 TA (AD) Network Management 1 TA (AD) EN 53 EN Security Management 1 TA (AD) 1st level support operator (24x7) 1 CA 2nd level support administrator (24x7) 1 CA Infrastructure Management 0.5 TA (AD) Product/Service Owner 1 TA (AD) System & Application Administration 1 TA (AD) Transversal Services (Finance & Procurement and HR) 1 TA (AD) Business Relationship & Stakeholders’ Management 1 TA (AD) TOTAL 10 - Description of the profiles: IT Officer – Architecture - to work with the contractors on the design documents and validate (at solution and application level). Also, to be involved in any business/use cases/architectural assessments and Implementing & Delegated Acts. Test Management – to test the overall solution Release & Change Management – to ensure the transition management including Software Development Lifecycle Development (SDLC) Network Management – to administer and to architect the network Security Management - to work on the security architecture and all the security controls/solution to be put in place, including data protection. 1st level support operator (24x7) – to ensure the 1st level support for the JITs collaboration platform, as per SLA 2nd level support administrator (24x7) - to ensure the 2nd level support for the JITs collaboration platform, as per SLA Infrastructure Management – to be in charge of the infrastructure Programme and Project management - to take care of the coordination of the overall programme/project management Product/Service Owner – to be in charge of the product once operational System & Application Administration – to take care of the infrastructure (hardware, software, application) build & further administration Transversal Services (Finance & Procurement and HR) – to work on horizontal aspects related with transversal services. Business Relationship & Stakeholders’ Management - to work on business requirements, the implementing acts, stakeholders’ meetings (e.g. Advisory Group, Expert Group, etc.). EN 54 EN 3.2.5.2. Estimated requirements of human resources for the parent DG –  The proposal/initiative does not require the use of human resources. –  The proposal/initiative requires the use of human resources, as explained below: Estimate to be expressed in full amounts (or at most to one decimal place) Year Year Year Year 2024 2025 2026 2027 • Establishment plan posts (officials and temporary staff) 20 01 02 01 and 20 01 02 02 (Headquarters and Commission’s 1 1 1 1 Representation Offices) 20 01 02 03 (Delegations) 01 01 01 01 (Indirect research) 10 01 05 01 (Direct research)  External staff (in Full Time Equivalent unit: FTE)43 20 02 01 (AC, END, INT from the ‘global envelope’) 20 02 03 (AC, AL, END, INT and JPD in the Delegations) - at Budget Headquarters45 line(s) (specify) 44 - in Delegations 01 01 01 02 (AC, END, INT – Indirect research) 10 01 05 02 (AC, END, INT – Direct research) Other budget lines (specify) TOTAL 1 1 1 1 The human resources required will be met by staff from the DG who are already assigned to management of the action and/or have been redeployed within the DG, together if necessary with any additional allocation which may be granted to the managing DG under the annual allocation procedure and in the light of budgetary constraints. Description of tasks to be carried out: 43 AC = Contract Staff; AL = Local Staff; END = Seconded National Expert; INT = agency staff; JPD = Junior Professionals in Delegations. 44 Sub-ceiling for external staff covered by operational appropriations (former ‘BA’ lines). 45 Mainly for the EU Cohesion Policy Funds, the European Agricultural Fund for Rural Development (EAFRD) and the European Maritime Fisheries and Aquaculture Fund (EMFAF). EN 55 EN Officials and temporary staff • to represent the Commission in the Programme Management Board and the Advisory Group; • to carry out collection of business requirements during the design phase of the project; • to prepare and negotiate the required Implementing Acts; • to manage meetings of the respective Expert Group; • to assist eu-LISA throughout the development phase of the project; • to monitor the platform’s operations and maintenance. External staff N/A Description of the calculation of cost for FTE units should be included in the Annex V, section 3. 3.2.6. Compatibility with the current multiannual financial framework –  The proposal/initiative can be partially financed through redeployment within the relevant heading of the Multiannual Financial Framework (MFF). Concerning appropriations for eu-LISA, the proposal requires use of heading 1 of MFF - the Digital Europe Programme (budget line 02.04) - as well as margin under the heading 4 of the MFF. –  The proposal/initiative requiresuse of the unallocated margin under the relevant heading of the MFF and/or use of the special instruments as defined in the MFF Regulation. Concerning appropriations for Eurojust, the proposal requires use of the unallocated margin under the heading 2b of the MFF. 3.2.7. Third-party contributions –  The proposal/initiative does not provide for co-financing by third parties. –  The proposal/initiative provides for the co-financing estimated below: EUR million (to three decimal places) Enter as many years as necessary Year Year Year Year to show the duration of the Total N N+1 N+2 N+3 impact (see point 1.6) Specify the co-financing body TOTAL appropriations co-financed EN 56 EN 3.3. Estimated impact on revenue –  The proposal/initiative has no financial impact on revenue. –  The proposal/initiative has the following financial impact: –  on own resources –  on other revenue – please indicate, if the revenue is assigned to expenditure lines  EUR million (to three decimal places) Appropriations Impact of the proposal/initiative46 available for Budget revenue line: the current Year Year Year Year Enter as many years as necessary to show financial year N N+1 N+2 N+3 the duration of the impact (see point 1.6) Article …………. For assigned revenue, specify the budget expenditure line(s) affected. Other remarks (e.g. method/formula used for calculating the impact on revenue or any other information). 46 As regards traditional own resources (customs duties, sugar levies), the amounts indicated must be net amounts, i.e. gross amounts after deduction of 20 % for collection costs. EN 57 EN EUROPEAN COMMISSION Brussels, 1.12.2021 SWD(2021) 390 final COMMISSION STAFF WORKING DOCUMENT Analytical Supporting Document Accompanying the document Proposal for a Regulation of the European Parliament and the Council concerning the establishment of a collaboration platform to support the functioning of Joint Investigation Teams and amending Regulation (EU) 2018/1726 {COM(2021) 756 final} EN EN TABLE OF CONTENTS 1. INTRODUCTION............................................................................................................................... 2 2. PROBLEM DEFINITION..................................................................................................................... 3 2.1 UNSECURE AND TOO SLOW EXCHANGE OF EVIDENCE AND INFORMATION .......................................................... 4 2.2 UNSECURE AND INEFFECTIVE TOOLS/CHANNELS USED FOR THE COMMUNICATION............................................... 5 2.3 DIFFICULTIES CONCERNING DAILY MANAGEMENT OF A JIT ............................................................................. 5 3. LEGAL BASIS, SUBSIDIARITY AND ADDED VALUE............................................................................. 6 3.1 LEGAL BASIS ......................................................................................................................................... 6 3.2 SUBSIDIARITY ........................................................................................................................................ 6 4 OBJECTIVES ..................................................................................................................................... 7 5 THE PREFERRED OPTION ................................................................................................................. 7 5.1 HORIZONTAL ASPECTS ............................................................................................................................ 8 5.2 KEY FUNCTIONS..................................................................................................................................... 8 5.3 OTHER FUNCTIONS ................................................................................................................................ 9 5.4 ACCESS RIGHTS ................................................................................................................................... 10 6 STAKEHOLDER VIEWS ................................................................................................................... 11 7 ASSESSMENT OF THE PREFERRED OPTION .................................................................................... 14 7.1 EFFECTIVENES ..................................................................................................................................... 14 7.2 TECHNICAL AND OPERATIONAL FEASIBILITY................................................................................................ 15 7.3 EFFICIENCY ......................................................................................................................................... 15 7.4 IMPACT ON FUNDAMENTAL RIGHTS ......................................................................................................... 20 7.5 INFORMATION CONTROL AND SECURITY. .................................................................................................. 21 7.6 PROPORTIONALITY ............................................................................................................................... 21 8 IMPACT MONITORING .................................................................................................................. 22 1. INTRODUCTION Joint Investigation Teams (JITs) are teams set up for specific criminal investigations and for a limited period of time. They are set up by the competent authorities of two or more Member States and possibly non-EU countries (third countries), to carry out together criminal investigations that cross borders. A JIT can be set up, in particular, when a Member State's investigations into criminal offences require difficult and demanding investigations having links with other Member States or third countries. It can also be set up when a number of Member States are conducting investigations into criminal offences in which the circumstances of the case necessitate coordinated, concerted action in the Member States involved. JITs can be composed of the competent authorities of the Member States as well as the competent authorities of third countries (JIT members) or the competent Union bodies, offices and agencies such as Eurojust, Europol and the European Anti-Fraud Office (OLAF) (JIT participants). The legal basis for setting up a JIT are Article 13 of the European Union (EU) Convention on Mutual Assistance in Criminal Matters1 and Council Framework Decision 2002/465/JHA of 13 June 2002 on joint investigation teams2. Third countries can be parties in JITs if the legal basis allow for this. For example, Article 20 of the Second Additional Protocol of the 1959 Council of Europe Convention3 and Article 5 of the Agreement on Mutual Legal Assistance between the European Union and the United States of America4. JITs are one of the most successful tools for cross-border investigations and prosecutions in the EU. They enable direct cooperation and communication between judicial and law enforcement authorities of several States to organise their actions and investigations to efficiently investigate cross-border cases. It has recently become clear that the speed and efficiency of the exchange between those involved in these teams could be considerably enhanced by creating a dedicated IT platform to support their functioning. The second evaluation report on JITs5, prepared in 2018 by the Network of National Experts on Joint Investigation Teams (the JITs Network), a body established to support Member States and share best practices and experience in the area of JITs, already indicated that the JITs’ work could be improved and sped up if supported by a dedicated IT platform. The IT platform would enable those involved in JITs to securely communicate among themselves, and share information and evidence. The Digital Criminal Justice study6 confirmed the findings of that report and recommended creating an IT platform for JITs to ensure that JITs function more efficiently and more securely. 1 OJ C 197, 12.7.2000, p. 3–23. 2 OJ L 162, 20.6.2002, p. 1–3. 3 CET No 182. 4 OJ L 181, 19.7.2003, p. 34. 5 https://www.eurojust.europa.eu/sites/default/files/Partners/JITs/2018-02_2nd-Report-JIT- Evaluation_EN.pdf 6 https://op.europa.eu/en/publication-detail/-/publication/e38795b5-f633-11ea-991b-01aa75ed71a1 2 Following these findings, the Commission announced plans7 to propose legislation establishing a dedicated ‘collaboration platform to support the functioning of Joint Investigation Teams’ (the platform). Following up on the above research, the European Commission has announced its plans to come up with a legal proposal concerning creation of a dedicated “collaboration platform to support the functioning of Joint Investigation Teams” (hereinafter “the platform”). This proposal has been announced in the Commission’s Communication on the digitalisation of justice in the EU8, as part of a broader initiative to enable the secure electronic communication and exchange of information and documents between courts, national authorities, and justice and home affairs agencies. It also constitutes part of the digitalisation of justice package contained in the Commission’s work programme for 2021 under the heading ‘A New Push for European Democracy’9. This analytical document has been prepared in order to support and accompany the above-mentioned legal proposal. The data contained in this document has been mainly obtained from evaluation reports on JITs prepared by the JITs Network, the Digital Criminal Justice study and through a targeted consultation process involving various stakeholders involved in JITs. 2. PROBLEM DEFINITION Although JITs have proven to be a successful tool for cross-border investigations and prosecutions in the EU, practice shows that they have been facing several technical difficulties preventing them from being efficient in their daily work and from fostering their operations. The main difficulties concern secure electronic exchange of information and evidence (including large files), secure electronic communication, as well as a joint daily management of a JIT. 7 Commission Communication on the Digitalisation of justice in the European Union - A toolbox of opportunities, COM (2020) 710 final, 2.12.2020. 8 Commission Communication on the Digitalisation of justice in the European Union - A toolbox of opportunities, COM (2020) 710 final, 2.12.2020. 9 Commission Communication Commission Work Programme 2021, A Union of vitality in a world of fragility, COM(2020) 690 final. 3 2.1 Unsecure and too slow exchange of evidence and information The problem Exchange of information and evidence among those involved in JITs is of crucial importance for successful investigations. So far, the landscape for this exchange, if not done in person, is fractured as all actors rely on their systems that usually are not interoperable. There is no single system available, to which the JIT members and, when involved, the JIT participants could connect, allowing for a properly functioning electronic flow of voluminous information and evidence, e.g. content of hard drives or CD-ROMs containing documents, images and videos. The main requirements for such electronic flows are security of the exchanged data, widespread access to the electronic means of data transportation and the possibility to transfer large files (files bigger than 50 MB). Unfortunately, in the current context, judicial authorities have a major problem as regards each of the above requirements. The problem drivers Until now, there is no unified technical solution, which would allow judicial authorities to exchange large amounts of data in a secure and reliable manner. While some secure information exchange channels already exist (the Secure Information Exchange Network Application - SIENA - for Europol, and a secure Eurojust e-mail mechanism), judicial authorities rarely use them, either because they are not widely accessible or because they do not offer appropriate functionalities. The effects of the problem A direct consequence of the above problem is that national authorities involved in JITs are very often required to apply one of the following scenarios:  to exchange information and evidence about ongoing investigations by non-secured emails (via the internet) and thus prone to interception, or hacking; 4  to share the information and evidence in non-digital ways (e.g. during face to face meetings, or using registered snail post services);  to refrain from transmitting data to the other JIT members and participants until a physical meeting takes place. Consequently, the documents exchanged are at risk of being leaked, which could expose all national investigations associated with a given JIT. In addition, organisation of in person meetings or usage of regular postal services creates additional costs and lengthens the whole process making the JIT cooperation costly and ineffective. 2.2 Unsecure and ineffective tools/channels used for the communication The problem A need to communicate with other members and participants of a given JIT is critical for the proper functioning of the JIT. The investigators must share information among themselves, be it through short messages, longer email-like messages and/or audio/video conferencing calls. It is not possible to manage a JIT or to coordinate its specific actions without efficient communication tool(s) guaranteeing security and confidentiality. In practical terms, for every JIT, the Member States need to agree on procedures and technological solutions to support the activities of the individual JIT. In addition, the investigators are often forced to use non-secure communication channels, such as the most popular instant messaging and video calls commercial tools or regular emails over the internet. It is mainly due to their ease to use and convenient functionalities, in particular when quick communication is compulsory during action days. It also happens very often that physical meetings are organised at Eurojust in order to coordinate work and plan next steps of the JIT. The problem drivers The problem derives from the fact that there is no unified tool at present that would allow various judicial authorities constituting a JIT and coming from various Member States, to efficiently and securely communicate cross-border, either through text, audio or video. The effects of the problem The usage of non-secure communication tools results in non-compliance with the highest security standards (e.g. to ensure that data about national criminal cases is not stored on servers of private entities, often outside of Europe) and exposes sensitive data which is prone to interception or hacking. The fact that physical coordination meetings have to be organised represents a disadvantage in terms of cost and time spent on their organisation. The whole JIT cooperation becomes more time consuming and more costly. 2.3 Difficulties concerning daily management of a JIT The problem There are several activities concerning the daily management of a JIT, which currently cannot be carried out in a fully effective and collective manner. JIT members and participants have no common tool at hand that would allow them to plan their activities (also from a distance) with a dedicated calendar, compare their JIT related agendas, 5 coordinate parallel activities and, where feasible, divide JIT related tasks, or collaboratively edit or machine translate relevant documents. Especially where third countries come into play and the exchange of larger files is needed, those involved in JITs face technical challenges. The lack of traceability of evidence might pose difficulties as well. The above issues concern both the operational and post operational phases of a JIT as well as various administrative processes that accompany them. The problem drivers The above problems are caused by the lack of a standard technical means, which could be used by all JIT members and participants, including third countries, in order to manage the daily activities of a JIT. These activities require a unified tool allowing all stakeholders involved in a given JIT to cooperate in a collaborative manner. Some of the Member States use various national tools. However, due to the cross-border dimension and specificity of JITs, these tools cannot offer all functionalities required to manage a JIT. The tools can also not be used by other Member States in a cross-border (multilingual) environment. Obviously, there is also no dedicated platform at EU level that could be used by all parties involved in JITs. Consequently, the current ways of coordinating the daily work of JITs do not make use of the possibilities offered by digital technologies. The effects of the problem Because of the above problems, coordination of investigations carried out by the JITs is time consuming and very often requires offline means, e.g. face-to-face meetings having an impact on the financial side of every JIT. Meeting and exchanging information and evidence more frequently in a secure online environment would enable the JIT members and participants to enhance their cooperation. The process of agreeing on cooperation procedures, which needs to happen for each individual JIT and for all activities that need a coordinated approach, is also time consuming and causes an administrative burden. These aspects get even more complicated in case of participation of third countries that might sometimes not be a direct neighbouring country. There are also other repercussions: for instance, the lack of a tool to properly trace evidence exchanged among all members of a JIT might cause problems during the court proceedings. 3. LEGAL BASIS, SUBSIDIARITY AND ADDED VALUE 3.1 Legal basis The legal basis for the proposal is Article 82(1)(d) of the Treaty on the Functioning of the European Union (TFEU). In line with that Article, the EU has the power to adopt measures to ease cooperation between judicial or equivalent authorities of the Member States in relation to proceedings in criminal matters. 3.2 Subsidiarity According to the principle of subsidiarity laid down in Article 5(3) of the TEU, action at EU level should be taken only when the aims envisaged cannot be achieved sufficiently by Member States alone and can therefore, by reason of the scale or effects of the 6 proposed action, be better achieved by the EU. Furthermore, there is a need to match the nature and intensity of a given measure to the identified problem. The creation of a common Union wide IT platform to support JITs, allowing the Member States to make use of a technology solution that does not depend on the national IT infrastructure, can neither be achieved unilaterally at Member State level nor bilaterally between the Member States. It is by its nature a task to be undertaken at EU level. Therefore, it is also for the Union to establish a legally binding instrument to create such a system and to lay down the conditions under which that system will function. 4 OBJECTIVES The general objective of the proposal is to provide technological support to those involved in JITs to increase the efficiency and effectiveness of their cross-border investigations and prosecutions. The specific objectives of the proposal are to: 1. Ensure that the members and participants of JITs can more easily share information and evidence collected in the course of the JIT activities. 2. Ensure that the members and participants of JITs can more easily and more safely communicate with each other in the context of the JIT activities. 3. Facilitate the joint daily management of a JIT, including planning and coordination of parallel activities, enhanced traceability of shared evidence and coordination with third countries, especially where physical meetings are too expansive or time consuming. 5 THE PREFERRED OPTION In order to address the problems defined in section 2 and to achieve the objectives listed in section 4, a dedicated IT platform consisting of both centralised and decentralised components – the JITs collaboration platform – is proposed. The platform would be a highly secure online collaboration tool aiming to facilitate the exchanges and cooperation within JITs throughout their duration. The platform would be accessible to all actors involved in JIT proceedings, i.e. Member States’ representatives fulfilling the role of members of a given JIT, representatives of third countries invited to cooperate in the context of a given JIT, and the competent Union bodies, offices and agencies such as Eurojust, Europol, the European Public Prosecutor’s Office and OLAF. The key functions, described in detail below, will ease electronic communication, allow information and evidence to be shared, including large amounts of data, ensure traceability of evidence as well as planning and coordination of JIT operations. The design, development, technical management and maintenance of the platform would be entrusted to the European Union Agency for the Operational Management of Large- Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA), which is the Union agency in charge of large-scale IT systems in the in the Area of Freedom, Security and Justice. 7 Assuming that the proposal establishing the platform is adopted in 2023, the platform would be operational as of beginning of 2026. 5.1 Horizontal aspects The platform would be of a voluntary nature, so the authorities involved in JITs would have full discretion in deciding whether they want to use the platform for a specific JIT. In addition, the JIT members and participants would be free to use other tools while making use of the platform. For instance, if they decide to pass on evidence in person at a working meeting or through SIENA. The platform’s architecture would enable the creation of (non-interoperable) sessions in silo, the ‘JIT collaboration spaces,’ specific to each JIT and open only for the duration of the JIT. There would be no cross-cutting functions or any interactions between different JITs hosted by the platform. The platform would support the functioning of JITs throughout their operational and post-operational phases. In practical terms, an individual JIT collaboration space could be created on the platform as soon as all establishing parties sign the JIT agreement. The space would be closed following the end of the evaluation process. Access to the platform would be granted through regular computers (desktops, laptops, etc.) as well as through mobile devices. Its interface would be made available in all EU languages. From a technical perspective, the platform would be composed of two distinctive elements, (i) a centralised information system, which would allow for a temporary central storage of data, and (ii) a communication software, a mobile application, which would enable communication and local communication data storage. From a security perspective, while the platform will operate over the internet to offer flexible means of accessing it, the focus will be to guarantee confidentiality by design. This will be achieved by using robust end-to-end encryption algorithms to encrypt data in transit or at rest (i.e. stored on a physical storage). This feature is crucial for gaining the trust of JITs practitioners who deal with sensitive data and must be reassured regarding any risk of uncontrolled disclosure. In addition, appropriate multi-step identification and authentication mechanisms will be put in place to ensure that only authorised JIT members and participants have access to the platform. When designing the JITs collaboration platform, eu-LISA should ensure technical interoperability with SIENA. 5.2 Key functions The platform would offer the following key functionalities:  secure, untraceable communication stored locally at the devices of the users, including a communication tool offering an instant messaging system, a chat feature, audio/video-conferencing and a function replacing standard emails;  exchange of information and evidence, including large files, through an upload/download system designed to store the data centrally only for the limited time 8 needed to technically transfer the data. As soon as the data are downloaded by all addresses, it would be automatically deleted from the platform.  evidence traceability – an advanced logging mechanism logging a trail of who did what and when regarding all evidence shared through the platform, and supporting the need to ensure admissibility of evidence before a court. 5.3 Other functions Apart from the above-mentioned key functions, the platform is also planned to offer the following:  functions related to daily management of the JIT during its operational and post- operational (evaluation) phase, i.e.: o a JIT dashboard containing general information about JIT, the JIT agreement, overall contact details of the JIT members and participants, etc.; o calendars/planners facilitating planning activities; o a task management module allowing to assign, monitor and follow-up on various tasks within the JIT.  support for the administrative and financial processes, i.e.: o a JIT funding dashboard providing for information about deadlines, awarded funding, budget overview, etc., pertaining to JIT financing obtained from Eurojust and/or Europol; o upload/download of administrative documents; o a documents repository; o an administrative reporting module; o access to various documents, e.g. templates, best practices, leaflets, guidelines, model JIT agreements, etc. - covering all phases of a JIT, developed by the Network of JITs national experts and used on a regular basis by those involved in JITs.  various technical capabilities supporting operational and administrative processes, e.g.: o an automatic translation service; o collaborative editing of documents, e.g. reports of meetings or administrative documents like press releases, memos, common requests to third countries, etc.; o the integration with the JITs-related electronic services already hosted at Eurojust and managed by the JIT Secretariat10, i.e. JITs Funding, JITs Evaluation and JITs Restricted Area, allowing relevant information and documents to be obtained without needing to connect separately to the platform and the services offered by the JIT Secretariat. 10 Since the establishment of the JITs Network, the JIT Secretariat supports its work by organising annual meetings, trainings, collecting and analysing the JIT evaluation reports and managing the Eurojust’s JIT funding programme. Since 2011, the JIT Secretariat is hosted by Eurojust as a separate unit. 9 5.4 Access rights Particular attention will be given to the platform’s access rights. The platform’s starting principle will be that the management of access rights rests with the JIT space administrator(s) from the JITs participating Member States. They will be in charge of granting access, during the operational and post-operational phases of the JIT, to:  representatives of the other Member States participating in the JIT;  representatives of third countries which are also members of a given JIT;  representatives of Eurojust, Europol, the European Public Prosecutor’s Office, OLAF and other competent Union bodies, offices and agencies; and  representatives of the JIT Secretariat. In addition, the JIT space administrator(s) will have the option to limit access to parts of information and evidence only to those who are concerned by it, including case-by-case granular access permissions. This restriction would concern all users of the JITs collaboration platform, be it the Member States, third countries, the competent Union bodies, offices and agencies or the JIT Secretariat. It must be underlined that eu-LISA, as the hosting provider, will not have access to the data stored or exchanged through the platform. It will also not be involved in the access rights management, except for the initial process of granting access rights to JIT space administrator(s) based on the signed JIT agreement. The platform’s architecture must offer sufficient guarantees for this to happen. The access rights of the competent Union bodies, offices and agencies should be defined in view of the operational support they provide to JITs, covering all steps of the proceedings, from the moment of the signed JIT agreement until the end of the evaluation phase. On the latter, the platform must provide for access rights for the JIT Secretariat, which plays an important role in that process. The JIT Secretariat could also be in charge of the platform’s administrative support, including access rights management, as long as the JIT space administrator(s) of each individual JIT envisage such a role. Keeping in mind the increasing role of third countries in the successful prosecution of serious organised crime and terrorism, the platform will also be available to them, if they are part of a JIT agreement. However, specific access rights will depend on their role in a given JIT and should be set out by the JIT space administrator(s) for each respective JIT. To guarantee the respect for fundamental rights, including data protection, and in line with the currently applicable procedures, before granting access to a specific third country, the JIT space administrator(s) will need to thoroughly assess the data protection aspects against the applicable rules, notably Directive 2016/68011. 11 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data. 10 6 STAKEHOLDER VIEWS Whereas no public consultations were conducted due to a specific character of the proposal, the Commission has carried out an extensive targeted consultation campaign to ensure that all stakeholders concerned have an opportunity to express their views. The campaign has involved:  prosecutors, judges and law enforcement representatives from the Member States;  Member States’ national authorities;  experts of the JITs Network  academics and practitioners in EU criminal law;  data protection experts,  representatives of Eurojust, Europol and OLAF. Stakeholders have had an opportunity to voice their opinion through bilateral contacts, expert meetings, online surveys and written contributions. The targeted consultations organised between March and July 2021, gathered views on the platform related elements of the Digital Criminal Justice study, functions that are to be covered by the future platform, as well as the applicable data protection regime(s). First and foremost, all stakeholders welcomed the initiative and provided a positive opinion about establishment of a platform as a much-needed step towards the digitalisation of JITs cooperation. As far as cross-cutting issues are concerned, most stakeholders focused on:  the simplicity of the platform so that it can be used by all practitioners concerned – a too cumbersome tool with complex workflows could create problems for the users and would be a main reason for not using it;  the prevention of an impact on the substantial or legal requirements of investigators’ work, so the proper functioning of a JIT is not jeopardised by the platform;  the security of the platform – the level of protection is of crucial importance so practitioners can be confident that outcomes of their national investigations that are shared through the platform would not be disclosed in an uncontrolled way. Some discussions have also taken place on the entity in charge of the platform’s future development and management. The following scenarios were considered:  creation of the platform by the Commission and making it available to the Member States to implement when needed within their own infrastructure;  creation of the platform and its establishment at the Commission; 11  creation of the platform and its establishment at one of the JHA agencies directly involved in supporting the Member State’s authorities in combating crime (e.g. Eurojust);  creation of the platform and its establishment at eu-LISA. All stakeholders consulted, including Eurojust and Europol, supported the option to entrust the platform’s development and maintenance to eu-LISA. They all recognised eu- LISA’s expertise in the area as well as its experience with large-scale IT systems meeting state-of-the-art security standards. Also, this option takes into account, that JITs can be conducted without the financial support or operational involvement of either Eurojust or Europol. Undoubtedly, the two key functions of the platform debated the most during the targeted consultations were a possible coverage by the platform of a JIT set-up process and the central storage. Administrative process to set-up a JIT The starting point for this discussion was the final report of the Digital Criminal Justice study, which recommends that the JITs collaboration platform covers also the pre- operational phase of JITs, i.e. the administrative process to set up a JIT. There are many advantages of such a solution, including:  the possibility to securely and efficiently exchange documents cross-border, leading to the signature of a JIT agreement;  a machine translations function;  an inventory of the procedures to be followed during the JIT set-up process;  support for various electronic signatures. However, it has been established during the stakeholder consultations that in most Member States, actors participating in the JIT set-up process are completely different from those who are members of JITs once they are established. Moreover, the decision to join a JIT is very often taken by someone who will not necessarily be a member of the JIT itself, e.g. the Prosecutor General or even the Minister of Justice. Therefore, the inclusion of the administrative JIT set-up process in the platform would require a complete departure from the above-described model of isolated JIT spaces, as well as a separate access rights management workflow. Such a scenario would heavily complicate the envisaged easy-to-use concept of the platform and would require implementation of rather incomprehensible and time-consuming administrative workflows. Therefore, following the targeted consultations, the recommended scenario would be to cover the JIT set-up process within the e-Evidence Digital Exchange System (eEDES) that is currently being implemented by the Commission. This solution would on the one- hand cover administrative needs of the stakeholders and, on the other, not complicate the daily functioning of the future platform. 12 Central storage One of the most crucial functions of the platform will be to exchange information and evidence among the JIT members and other participants. That function could be implemented in three different ways: 1. A plain upload/download function - data would be uploaded on the platform by one member/participant of the JIT and would be stored centrally only until the other JIT member(s)/participant(s) download(s) it. 2. A temporary flexible storage – in addition to the plain upload/download, data could be optionally stored at the platform for some period of time, e.g. one week, one month, etc. The member/participant uploading the data would define duration and access rights. 3. A permanent storage – all exchanged data would be stored throughout the JIT’s lifespan – precise access rights to the data would be defined by the member/participant uploading the data. This option would constitute a "common JIT case-file". Though JITs allow for the direct communication, cooperation and coordinated action, the underlying national investigations remain separate and independent. The possibility to create a common case-file to supplement national investigations is not envisaged by the current legal framework. Therefore, almost all stakeholders rejected the permanent storage option (option 3). Indeed, the creation of such a common case-file would raise serious questions related to criminal procedures in certain Member States since not all JIT information is necessarily shared among all members of the JIT. Investigators from one country often do not need access to all relevant information from the investigation of the other country participating in the same JIT. Whereas the other two options had more or less the same degree of support among the practitioners, a preferred option is to equip the platform with the plain upload/download function (option 1). This function would prevent platform’s users to view the data before downloading it. It would also prevent any central storage of exchanged data, i.e. the data would be stored centrally until it is downloaded by the other party, but for not more than four weeks. The main reason for that has been a concern that any storage of operational data, going beyond a technical requirement to send it from one party to another, would lead to at least a temporary common file and to possible follow–up questions. For example, access requests to that file. However, this instrument should not change the separate investigations and separate national files, to which the respective national rules still apply. Although the lack of central storage would prevent including in the platform various additional technical functions, e.g. an interface with a crime analysis tool, a search tool, a text to speech converter, a speech to text converter, Optical Character Recognition, etc., stakeholders took the view that such functions would duplicate the tools already provided by other agencies (primarily by Europol). It also must be underlined that even in the absence of a central storage of information and evidence, some basic information would be stored centrally to allow the JIT members to trace the exchanged data. 13 7 ASSESSMENT OF THE PREFERRED OPTION The preferred option is discussed and assessed hereunder against the following criteria:  effectiveness: measured against the general and specific objectives;  technical and operational feasibility;  efficiency: the total costs incurred for eu-LISA, Eurojust and for the Member States as well as the administrative costs incurred for the Member States and the Commission;  impact on fundamental rights: in particular on data protection;  information control and security;  proportionality. 7.1 Effectivenes General objective: to provide technological support to those involved in JITs to increase the efficiency and effectiveness of their cross-border investigations and prosecutions. The establishment of the platform is expected to render cooperation within JITs more efficient and effective. All future functionalities of the platform, starting with the communication tools, through exchange of data mechanism, to collaborative management of JITs, are intended to save time and cost of the JIT members and participants. Although voluntary in nature, it is anticipated that those involved in JITs will quickly realise the platform’s added value and systematically use it in cross-border cases. The platform would allow speeding up the flow of information among its users, increase security of the exchanged data as well as enhance transparency. In addition, impacts on simplification and administrative burdens are anticipated. Consequently, more efficient functioning of JITs would improve overall collaboration between Member States in investigating and prosecuting cross-border crime. Specific objectives:  To ensure that that the members and participants of JITs can more easily share information and evidence collected in the course of the JIT activities. The envisaged upload/download mechanism for the exchange of operational information and evidence, including large files, would be a crucial step forward towards a secure and unified process to exchange data collected by the JIT members in the course of the JIT activities and at the same time allow for the traceability of the exchanged evidence. The data would flow between JIT members using a secure channel and a highly secure central data storage, designed to keep the data stored centrally only for a limited period of time necessary for technical reasons. The exchanged data would be properly encrypted in transit and at rest. The option would facilitate exchanges of large amounts of data, e.g. content of hard drives or CD-ROMs, which currently cannot be efficiently transferred.  To ensure that the members and participants of JITs can more easily and more safely communicate with each other in the context of the JIT activities. 14 A set of communication tools, consisting of an instant messaging system, a chat feature, audio/video-conferencing and a functionality replacing regular emails, would clearly increase the safety and effectiveness of the communication among the JIT members and participants. Since all the above features would guarantee a top level of security, the safety of the exchanged data would increase radically compared to the currently used non-secure communication channels, such as the most popular instant messaging and video call commercial tools. The possibility to have a single set of communication tools, available in one place for all members and participants of JITs, would undoubtedly foster the communication process and improve the efficiency of the exchanges. In addition, the platform could also provide for a speedy process to book online and offline meetings.  To facilitate the joint daily management of a JIT, including planning and coordination of parallel activities, enhanced traceability of shared evidence and coordination with third countries, especially where physical meetings are too expansive or time consuming. Thanks to the platform, all JIT members and participants would be able to jointly cooperate and manage the JIT through one unified IT tool. Activities like planning, coordination of parallel activities, task management, collaborative editing of documents, or machine translation of documents could be carried out in a much more efficient way than it is currently the case. In addition, exchange and communication with third countries, especially when they are not direct neighbouring countries, would be facilitated because of one standard technical mean that could be used by all entities involved in a JIT. 7.2 Technical and operational feasibility The envisaged solution is fully feasible from a technical and operational point of view. The platform’s implementation would be based on a commercially available off-the-shelf product, customised in order to provide all required functionalities. The so-called software as a service (SaaS) model would be used. It is a software licensing and delivery model in which software is licensed on a subscription basis and is centrally hosted. The platform would offer a collection of services such as collaborative tools with workflow capabilities, decentralised secure communication tools, upload/download mechanism and logging capabilities. The users would be accessing the platform through the internet using the “EU Login” authentication service while their access rights in the platform would be defined following a flexible fine grained role definition at the level of every JIT collaboration space. Data in the platform, categorised as sensitive not classified, would be managed under strict security requirements including data encryption in both transit and while temporarily stored at server side. The platform would guarantee high availability since it would be operational from two geographically diverse locations, namely eu-LISA’s operational site in Strasbourg/France and the back-up site in Sankt Johann/Austria. 7.3 Efficiency Costs (set-up and recurring) The establishment of the platform is envisaged to incur the following costs:  development of the platform – the one-off cost incurred for eu-LISA; 15  technical maintenance and operation of the platform – the recurring cost incurred for eu-LISA;  development of the necessary technical adaptations of the relevant IT systems hosted at Eurojust, i.e. JITs Funding, JITs Evaluation and JITs Restricted Area to partially integrate them with the platform – the one-off cost incurred for Eurojust;  technical maintenance and operations concerning on the adaptations of the IT systems hosted at Eurojust - the recurring cost incurred for Eurojust;  administrative support to the platform’s users on behalf of the JIT space administrator(s) - the recurring cost incurred for Eurojust (the JIT Secretariat). As far as Member States’ access to the platform is concerned, no technical costs are envisaged because of the web-based nature of the centralised component of the platform. It would not require any adaptations of the national technical infrastructure. The same applies to the communication software, which would simply need to be downloaded on each device of the JIT platform’s users. Access to the platform for the competent Union bodies, offices and agencies would be driven by the same principles and would not incur any costs for them. The costs for eu-LISA and Eurojust are explained in detail below. They would be borne by the Union general budget and would need to be reflected in the budget of both agencies. The costs for eu-LISA apply to hosting of the platform in its operational site in Strasbourg/France and the back-up site in Sankt Johann/Austria. The costs cover the period between 2024, when the proposal is expected to be adopted, and 2027, when the current EU's multiannual financial framework (MFF) finishes. eu-LISA costs eu-LISA would require the following financial resources to cover the costs related to the activities to be performed: Year Year Year Year TOTAL 2024- 2024 2025 2026 2027 2027 Phase 1 – development of the JITs 3.000 5.400 8.400 collaboration platform Phase 2 - maintainance and operation of the 1.700 1.700 3.400 JITs collaboration platform TOTAL (EUR 3.000 5.400 1.700 1.700 11.800 million) 16 eu-LISA would also require the following human resources: Year Year Year Year TOTAL FTEs 2024 2025 2026 2027 per type Temporary agents 4 4 8 (AD grades) Contractual staff 2 2 TOTAL FTEs 10 The total estimated number of resources is ten (10) FTEs (2 CA and 8 AD). Eight (8) FTEs combining expertise in IT Architecture, Testing, Security & Data Protection, Project & Programme Management and Infrastructure Management would work on the elaboration of specifications as well as on all analysis and design tasks in cooperation with the contractors. They would perform the necessary assessments (including data protection, risk assessments etc.), would kick off all work packages and would ultimately conclude this part of implementation with the production of the detailed design of the solution. A combination of transversal resources (procurement, finance, HR, business relationship & stakeholders’ management) is also included. For the “build & run” and “operations” phases, on top of the expertise described above eu-LISA would additionally require two (2) resources, adding expertise on product management, change management and release & deployment. Building a customised commercial off-the-shelf product with additional modules installed on desktops and smartphones would require a combination of skills in the area of infrastructure, networking, security and testing. These resources would be supplemented by 1st level and 2nd level support staff in order to properly monitor, operate and debug the platform, to meet the agreed level of the required service level agremeents and to respond to intense monitoring and security requirements. The costs related to the above staff expenditures are as follows: Year Year Year Year TOTAL 2024- 2024 2025 2026 2027 2027 Temporary agents 0.608 1.216 1.216 1.216 4.256 (AD Grades) Contractual staff 0.164 0.164 0.328 TOTAL (EUR 0.608 1.216 1.380 1.380 4.584 million) Staff required for phase 1 - development of the JITs collaboration platform: Profile No. Type IT Officer - Architecture 1 TA (AD) Test Management 1 TA (AD) 17 Network Management 1 TA (AD) Security Management 1 TA (AD) Infrastructure Management 0.5 TA (AD) Programme and Project management 1 TA (AD) System & Application Administration 0.5 TA (AD) Transversal Services (Finance & Procurement TA (AD) 1 and HR) Business Relationship & Stakeholders’ TA (AD) 1 Management TOTAL 8 - Staff required for phase 2 – maintenance and operation of the JITs collaboration platform: Profile No. Type IT Officer - Architecture 0.5 TA (AD) Test Management 0.5 TA (AD) Release & Change Management 0.5 TA (AD) Network Management 1 TA (AD) Security Management 1 TA (AD) 1st level support operator (24x7) 1 CA 2nd level support administrator (24x7) 1 CA Infrastructure Management 0.5 TA (AD) Product/Service Owner 1 TA (AD) System & Application Administration 1 TA (AD) Transversal Services (Finance & Procurement TA (AD) 1 and HR) Business Relationship & Stakeholders’ TA (AD) 1 Management TOTAL 10 - 18 Description of the profiles: IT Officer – Architecture - to work with the contractors on the design documents and validate (at solution and application level). Also, to be involved in any business/use cases/architectural assessments and Implementing & Delegated Acts. Test Management – to test the overall solution Release & Change Management – to ensure the transition management including Software Development Lifecycle Development (SDLC) Network Management – to administer and to architect the network Security Management - to work on the security architecture and all the security controls/solution to be put in place, including data protection. 1st level support operator (24x7) – to ensure the 1st level support for the JITs collaboration platform, as per SLA 2nd level support administrator (24x7) - to ensure the 2nd level support for the JITs collaboration platform, as per SLA Infrastructure Management – to be in charge of the infrastructure Programme and Project management - to take care of the coordination of the overall programme/project management Product/Service Owner – to be in charge of the product once operational System & Application Administration – to take care of the infrastructure (hardware, software, application) build & further administration Transversal Services (Finance & Procurement and HR) – to work on horizontal aspects related with transversal services. Business Relationship & Stakeholders’ Management - to work on business requirements, the implementing acts, stakeholders’ meetings (e.g. Advisory Group, Expert Group, etc.). Eurojust costs The following costs pertain to Eurojust (including the work of the JIT Secretariat):  concerning development maintenance and operations of the necessary technical adaptations of relevant IT systems hosted at Eurojust, i.e. JITs Funding, JITs Evaluation and JITs Restricted Area, in order to partially integrate them with the platform: 0.250 EUR million in 2025 (one-off) and 1 FTE – a technical profile – as of 2025 onwards;  concerning administrative support of the JIT Secretariat to the platform’s users on behalf of JIT space administrator(s): 2 FTEs as of 2026 onwards. 19 Administrative costs The impact on administrative costs would be rather limited. As far as the Member States are concerned, their administrative costs would be related to appointment of staff for the project’s governing bodies, i.e. the Programme Management Board and the Advisory Group. Concerning the Commission, it is estimated that a total of one (1) FTE official staff would be required on a permanent basis to:  represent the Commission in the Programme Management Board and the Advisory Group;  carry out collection of business requirements during the design phase of the project;  prepare and negotiate the required Implementing Acts;  manage meetings of the respective Expert Group;  assist eu-LISA throughout the development phase of the project;  monitor the platform’s operations and maintenance. 7.4 Impact on fundamental rights No major impact on fundamental rights is expected, as the legal basis for the exchanges of information and evidence within a JIT would not be altered. Nevertheless, as explained further below, the preferred option would respect fundamental rights and freedoms enshrined, in particular, in the Charter of Fundamental Rights of the European Union12, including the right to protection of personal data. In this regard, it would also respect the European Convention for the Protection of Human Rights and Fundamental Freedoms, the International Covenant on Civil and Political Rights, and other human rights obligations under international law. Since establishing the platform at EU level would imply the processing of personal data, it must be subject to appropriate data protection safeguards. The platform would fully comply with EU data protection rules on the legality of exchanging information and evidence. Directive (EU) 2016/680 of the European Parliament and of the Council would apply to the processing of personal data by competent national authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies would also apply. These legal safeguards would need to dovetail with the alignment of the data protection approach for JITs with the current data protection rules, as proposed by the Commission on 20 January 202113. 12 OJ C 326, 26.10.2012, p. 391–407 13 COM (2021) 21 Final - Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Directive 2014/41/EU, as regards its alignment with EU rules on the protection of personal data. 20 Concerning the centralised component of the platform, i.e. the upload/download mechanism allowing temporarily storing of the operational data until the moment it is downloaded, the impact on data protection is considered to be limited, because:  the personal data would be exchanged by a very limited group of individuals who are part of an isolated JIT collaboration space;  the personal data would be stored centrally only for technical reasons and would be deleted right after it is downloaded by all addresses;  the retention period would be set to maximum 4 weeks and would be enforced automatically;  exchange of personal data would be limited to serve the purpose for which it was obtained;  eu-LISA would not have any access to the data and would fulfil the data processor role;  a separate data controllership of each entity uploading the personal data, apart from third countries, would be warranted;  exchanges of personal data that qualify as international transfers to third countries that are part of a given JIT would always require a legal ground in EU or Member State law applicable to such transfers;  personal data uploaded to a JIT collaboration space by third countries would be within responsibility of a JIT space administrator who would need to verify such data before it can be downloaded by other users. 7.5 Information control and security. Appropriate definition of the access right policy is crucial in the context of data integrity and security. Section 5.4 of this document specifies precisely the platform’s access right management and role of each entity involved in that process. Security considerations, equally important, are described in section 5.1 of this document. They would be taken into account during each phase of the development process as well as maintenance and operations, so by no means the exchanged data could be disclosed in an uncontrolled way. Concerning the logging mechanisms, eu-LISA would be entrusted with a task to ensure that accessing the centralised information system and all data processing operations in the centralised information system are properly logged in for the purposes of monitoring data integrity and security, the lawfulness of the data processing as well as for the purposes of self-monitoring. 7.6 Proportionality According to the principle of proportionality laid down in Article 5(4) of the TEU, there is a need to match the nature and intensity of a given measure to the identified problem. All problems described in this document require EU-level support to tackle them effectively. Addressing the problems individually, for instance by creating separate tools tackling the communication issue, the lack of data exchange mechanism, etc. would be 21 much more costly and would create an administrative burden for the JITs. The Union wide IT platform is the only way to provide JITs with a common modern technical solution that will allow them to carry out their cross-border investigations more efficiently. Therefore, it can be concluded that the action at EU level to establish the platform to support functioning of JITs is proportionate to the identified problems that JITs encounter in their daily work. 8 IMPACT MONITORING Four years after the start of operations of the platform and every four years thereafter, the Commission shall conduct an overall evaluation of the system. The report established on this basis should contain feedback of the platform’s users, an assessment of the platform’s usage and a list of necessary recommendations. 22 Rahandusministeerium Meie 06.01.2022 nr 7-1/7885 Keskkonnaministeerium Harju Maakohus Tallinna kohtumaja Pärnu Maakohus Tartu Maakohus Viru Maakohus Tallinna Ringkonnakohus Tartu Ringkonnakohus Õiguskantsleri Kantselei Riigiprokuratuur Eesti Advokatuur Tartu Ülikooli õigusteaduskond Registrite ja Infosüsteemide Keskus Andmekaitse Inspektsioon Üleskutse arvamuse avaldamiseks ühiste uurimisrühmade teabevahetusplatvormi loomise eelnõu osas Pöördume teie poole üleskutsega avaldada arvamust Euroopa Komisjoni 1. detsembril 2021 avaldatud ühiste uurimisrühmade teabevahetusplatvormi loomise eelnõu ettepaneku kohta (algatusega seotud täiendav info kättesaadav siin). Algatus hõlmab ühte eelnõud: määrust, millega luuakse ühiste uurimisrühmade teabevahetusplatvorm (koostööplatvorm) ja muudetakse määrust (EL) 2018/17261. Ühised uurimisrühmad on ühed tõhusamad vahendid piiriüleste kriminaaluurimiste läbiviimiseks, võimaldades otsest koostööd ja suhtlust mitme riigi õiguskaitseasutuse vahel, kaasates vajadusel Europoli ja Eurojusti. Uurimisrühm luuakse piiratud ajaks konkreetseks kriminaaluurimiseks kahe või enama liikmesriigi, teatud juhtudel kolmandate riikide pädevate asutuste poolt, ühendades erinevate riikide uurijaid ja prokuröre ühiseks uurimismeeskonnaks. Praktika näitab siiski, et ühised uurimisrühmad on olnud silmitsi mitmete tehniliste raskustega, mis takistavad kiiret ja täielikku infovahetust. Peamised raskused on seotud turvalise elektroonilise teabevahetuse ja tõenditega (sh suuremahuliste failidega), turvalise elektroonilise suhtlusega teiste ühiste uurimisasutuste liikmetega ning pädevate liidu organite, ametite ja asutustega. Tagamaks ühiste uurimisrühmade tõhusa ja turvalise toimimise teatas2 detsembris 2020 komisjon kavast teha ettepanek õigusakti kohta, millega luuakse spetsiaalne koostööplatvorm ühiste uurimisrühmade toimimise toetamiseks. Vabatahtlikkuse alusel kasutatav koostööplatvorm võimaldaks kiiremat ja tõhusamat teabevahetust pädevate asutuste ja EL ametite vahel ning mõjutaks positiivselt julgeoleku tagamist Schengeni alal. Paraneks ka teabevahetuse turvalisus. Täpsemalt on määrusega kavas: a) luua ühine IT- platvorm (ühiste uurimisrühmade koostööplatvorm); b) sätestada ühiste uurimisrühmade koostööplatvormi arendamise, hooldamise ja kasutamisega seotud tingimused ja eeskirjad, asutuste pädevused ning vastutus; c) täiendada olemasolevaid andmekaitsesätteid isikute põhiõiguste kaitse tagamiseks. 1 Euroopa Parlamendi ja nõukogu määrus (EL) 2018/1726, 14. november 2018, mis käsitleb Vabadusel, Turvalisusel ja Õigusel Rajaneva Ala Suuremahuliste IT-süsteemide Operatiivjuhtimise Euroopa Liidu Ametit (eu-LISA) ning millega muudetakse määrust (EÜ) nr 1987/2006 ja nõukogu otsust 2007/533/JSK ja tunnistatakse kehtetuks määrus (EL) nr 1077/2011 2 Komisjoni teatis õiguse digitaliseerimise kohta Euroopa Liidus – võimaluste kogum, KOM (2020) 710 lõplik, 2.12.2020 Suur-Ameerika 1 / 10122 Tallinn / +372 620 8100 / [email protected] / www.just.ee Registrikood 70000898 Kõnesoleva eelnõuga viiakse ellu Euroopa Komisjoni eelpool viidatud 2020. aasta detsembri teatises esitatud eesmärk digivahendite ajakohastamiseks õigusalaseks koostööks ning teabevahetuseks kriminaaluurimistes ja - menetlustes. Justiitsministeerium valmistab kõnesoleva otsuse eelnõu osas ette Vabariigi Valitsuse seisukohti. Palume teil seisukohtade kujundamisel silmas pidada, et Euroopa Komisjoni esitatud eelnõud võivad institutsioonide vaheliste läbirääkimiste tulemusel muutuda ning Eestil, nagu ka teistel liikmesriikidel, on võimalus eelnõu sisu läbirääkimiste käigus mõjutada. Seega palume teil võimalusel arvamuse avaldamisel peegeldada nii seda, mis on eelnõus asjakohane ja peaks säilima, kui ka seda, mida tuleks kõneluste käigus täiendavalt adresseerida. Kirjale on lisatud nii määruse ettepaneku tekst kui ka analüüsidokument, mõlemad inglisekeelsed. Hetkel ei ole Euroopa Liidu Teatajas veel algatuse eestikeelset tõlget, kuid tõlke valmimisel on see kättesaadav siit. Teie arvamusi ja ettepanekuid Eesti seisukohtade kujundamiseks ootame hiljemalt 19. jaanuariks. Palume need saata aadressile [email protected]. Küsimuste korral kirjutage palun aadressil [email protected]. Lugupidamisega (allkirjastatud digitaalselt) Markus Kärner Asekantsler Lisad (inglise keeles): 1. Ühiste uurimisrühmade teabevahetusplatvormi loomise määruse ettepaneku tekst 2. Analüüsidokument EIS link: https://eelnoud.valitsus.ee/main/mount/docList/4ebbd13a-630c-4bfe-a9a0- 072306274a34#97Q6vQB7 Mari Keskküla 620 8162 [email protected] Saatja: [email protected] <[email protected]> Saaja: Harjumk info, pmkparnu menetlus, Tartumk info, virumk.info, Tallinna Ringkonnakohus info, Tarturk info, Tartu Ülikooli õigusteaduskond Teema: Üleskutse arvamuse avaldamiseks ühiste uurimisrühmade teabevahetusplatvormi loomise eelnõu osas Tere! Teile on saadetud Justiitsministeeriumi dokumendihaldussüsteemi Delta kaudu dokument. Pealkiri: Üleskutse arvamuse avaldamiseks ühiste uurimisrühmade teabevahetusplatvormi loomise eelnõu osas Registreerimise kuupäev: 06.01.2022 Registreerimise number: 7-1/7885. <http://www2.rik.ee/delta/JM_logo.jpg> Suur-Ameerika 1, 10122, Tallinn Tel. 620 8100, Faks 620 8109 e-mail: [email protected] www.just.ee <http://www.just.ee>
Allikas: Tartu Maakohus dokumendiregister →
dokumendiregister.eeAsutusedEesti avalike dokumendiregistrite otsing · nimistu.ee andmetel