Ref. Ares(2021)5830370 - 24/09/2021
EUROPEAN INNOVATION COUNCIL AND SMES
EXECUTIVE AGENCY (EISMEA)
Compliance, People and Budget
Head of Department
Brussels, 23 September 2021
EISMEA.C/ES/eismea.c.dir(2021)6552090
Mr Andres SOONISTE
TARBIJAKAITSEAMET
PRONSKI 12
10117 TALLINN
ESTONIA
by e-mail:
[email protected]
Subject: Financial audit – Consumer Programme
Dear Mr SOONISTE,
Pursuant to the General Conditions of the grant agreement mentioned below, I hereby
inform you that the European Innovation Council and SMEs Executive Agency (EISMEA)
decided to carry out a financial audit relating to the Consumer Programme (CP).
The relevant grant agreement to be audited is:
ECC-NET EE SGA 2018 800797 (01/01/2018-31/12/2018)
For the purposes of this assignment, the Agency has appointed Deloitte Réviseurs
D'Entreprises, to co-ordinate and conduct the audit mission. Therefore, Deloitte Réviseurs
D'Entreprises staff should, within the framework of the assignment, be regarded as the
EISMEA authorised representative.
In order to facilitate the execution and the completion of the audit, you are kindly
requested to ensure that, in conformity with your contractual obligations (Art. 22.1.3 of the
Framework Partnership Agreement), the auditors will have complete and unhindered
access to all necessary data to complete their assignment.
The appointed auditors will contact you in due course to confirm the start date for the
audit, its likely duration and all other necessary planning and documentation issues
including a list of the information and documents that need to be presented to the auditors.
For the timely implementation of the audit it is crucial that these documents are duly
prepared prior to the beginning of the on-site audit.
European Innovation Council and SMEs Executive Agency (EISMEA), B-1049 Brussels, BELGIUM
[email protected]
Please provide to Deloitte Réviseurs D'Entreprises contact person, Mr Alexandre DASSÉ,
the details of the contact person within your organization – including her/his full name,
email, and phone number within one week of the reception of this letter.
Should you have any further questions concerning the nature, conduct, probable timing or
any other matter relating to the audit, please contact Mr Alexandre DASSÉ (email:
[email protected], Tel.: +32 26002239) of Deloitte Réviseurs D'Entreprises
audit coordination office.
Please do not hesitate to contact the EISMEA Ex-Post team at EISMEA-
[email protected] in case you have any further questions.
Yours faithfully,
(e-signed)
Nathalie STEFANOWICZ
Enclosures: Articles 28 and 22 of the of the Framework Partnership Agreement (FPA)
Annex 1: Data protection Notice for ex-post controls by EISMEA
c.c.: Mr Alexandre DASSÉ (Deloitte Réviseurs D'Entreprises)
2
ARTICLE 28 of the FPA - PROCESSING OF PERSONAL DATA
28.1 Processing of personal data by the Agency and the Commission
Any personal data under the Framework Partnership Agreement and the Specific
Agreements will be processed by the Agency or the Commission under Regulation No
28/20017 and according to the ‘notifications of the processing operations’ to the Data
Protection Officer (DPO) of the Agency or the Commission (publicly accessible in the
DPO register).
Such data will be processed by the ‘data controller’ of the Agency or the Commission for
the purposes of implementing, managing and monitoring of those agreements or protecting
the financial interests of the EU or Euratom (including checks, reviews, audits and
investigations; see Article 22).
The persons whose personal data are processed have the right to access and correct their
own personal data. For this purpose, they must send any queries about the processing of
their personal data to the data controller, via the contact point indicated in the 'privacy
statement(s)' that are published on the Agency and Commission websites.
They also have the right to have recourse at any time to the European Data Protection
Supervisor (EDPS).
3
ARTICLE 22 of the FPA - CHECKS, REVIEWS, AUDITS AND
INVESTIGATIONS - EXTENSION OF FINDINGS
22.1 Checks, reviews and audits by the Agency and the Commission
22.1.3 Right to carry out audits
The Agency or the Commission may — during the implementation of the specific actions
or afterwards — carry out audits on the proper implementation of the specific actions and
compliance with the obligations under the Framework Partnership Agreement and the
Specific Agreements.
Audits may be started up to five (and, for low value specific grants, up to three) years
after the payment of the balance. They will be formally notified to the partner and will be
considered to have started on the date of the formal notification.
If the audit is carried out on a third party (see Articles 14 to 16), the partner must inform
the third party.
The Agency or the Commission may carry out audits directly (using its own staff) or
indirectly (using external persons or bodies appointed to do so). It will inform the partner
of the identity of the external persons or bodies. The partner has the right to object to the
appointment on grounds of commercial confidentiality.
The partner must provide — within the deadline requested — any information (including
complete accounts, individual salary statements or other personal data) to verify
compliance with the Framework Partnership Agreement and Specific Agreements. The
Agency or the Commission may request the partner to provide such information to it
directly.
For on-the-spot audits, the partner must allow access to its sites and premises, including to
external persons or bodies, and must ensure that information requested is readily
available.
Information provided must be accurate, precise and complete and in the format requested,
including electronic format.
On the basis of the audit findings, a ‘draft audit report’ will be drawn up.
The Agency or the Commission will formally notify the draft audit report to the partner
concerned, which has 30 days to formally notify observations (‘contradictory audit
procedure’). This period may be extended by the Agency or the Commission in justified
cases.
The ‘final audit report’ will take into account observations by the partner concerned. The
report will be formally notified to it.
Audits (including audit reports) are in the language of the Specific Agreements.
The Agency or the Commission may also access the partner’s statutory records for the
periodical assessment of flat-rate amounts.
4
Annex 1 - Data protection Notice for ex-post controls by EISMEA
Your personal data are processed in accordance with Regulation (EU) No 2018/17251 on
the protection of individuals with regard to the processing of personal data by the Union
institutions, bodies, offices and agencies and on the free movement of such data.
The controller of the processing operation is the Team Leader of the Anti-Fraud, Internal
and Ex-post Controls Team of Department C – Compliance, People and Budget of the
European Innovation Council and SMEs Executive Agency.
The following entity processes your personal data on our behalf: Deloitte Réviseurs
D'entreprises.
The purpose of this processing operation is to ensure the legality and regularity of the use
of the EU funds in the framework of the grant agreements signed by EISMEA.
The legal basis of the processing operation is Article 5(a) of Regulation (EU) 2018/1725
because processing is necessary for the performance of a task carried out in the public
interest (or in the exercise of official authority vested in the Union institution or body) 2 in
relation with Article 74(5) (6) the EU Financial Regulation3, and the corresponding
articles on audits and checks of the grant agreements to be audited.
Personal data collected and further processed are all relevant data that may be
requested by the Agency to verify that the co-financed action is properly managed and
performed in accordance with the provisions of the grant agreements.
Indicative list of personal data requested: Name, Function, Grade, Activities and
expertise, CV, Professional address, Timesheets, Salary, Employment contracts Accounts,
Cost accounting, Missions, Information coming from local IT system used to declare costs
as eligible, Supporting documents linked to travel costs, Minutes from mission and other
similar data depending of the nature of the action. No data which fall under Article 10 of
Regulation (EU) 2018/1725.
This list of data requested is indicative, without prejudice for the Agency and its
contractors to ask any other relevant information as foreseen under the relevant Articles of
the grant agreements.
The recipients of your data will be the Director of the Agency, Heads of
Departments/Heads of Units of the responsible operational units, the Team Leader and
relevant members of the ex-post control team of EISMEA, the staff of the external auditors
performing the audit and the staff of their subcontractors, and bodies charged with
1 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons
with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of
such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L295/39 of 21.11.2018).
2
Act of Establishment: Commission Implementing Decision (EU) 2021/173 of 12 February 2021 establishing the European Innovation
Council and SMEs Executive Agency and repealing Decision 2013/771/EU and Commission Decision C(2021) 949 final of 12
February 2021 delegating powers to the European Innovation Council and SMEs Executive Agency with a view to the performance of
tasks linked to the implementation of Union programmes in the field of Innovative Europe, Single Market and Interregional
Innovation Investments comprising, in particular, implementation of appropriations entered in the general budget of the Union.
3
Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable
to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No
1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and
repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193/1 of 30.07.2018).
5
monitoring or inspection tasks in application of EU law (e.g. internal audits, Court of
Auditors, European Anti-fraud Office (OLAF)).
Your personal data will not be transferred to third countries or international
organisations.
The processing of your data will not include automated decision-making (such as
profiling).
Your data will be retained for a maximum period of 5 years after the end of the audit and
will be automatically removed at the end of this period.
You have the right to access your personal data and to request your personal data to be
rectified, if the data is inaccurate or incomplete; where applicable, you have the right to
request restriction or to object to processing, to request a copy or erasure of your personal
data held by the data controller. If processing is based on your consent, you have the right
to withdraw your consent at any time, without affecting the lawfulness of the processing
based on your consent before its withdrawal.
Your request to exercise one of the above rights will be dealt with without undue delay and
within one month.
If you have any queries concerning the processing of your personal data, you may address
them to the Team Leader of the Anti-Fraud, Internal and Ex-post controls team of
EISMEA (entity acting as data controller), at the following email address: EISMEA-
[email protected]. You shall have the right of recourse at any time to EISMEA Data
Protection Officer at
[email protected] and the European Data Protection
Supervisor https://edps.europa.eu.
Version January 2019
Electronically signed on 24/09/2021 01:20 (UTC+02) in accordance with article 11 of Commission
6 Decision C(2020) 4482
Saatja: SDOUKOU Eleni <
[email protected]>
Saadetud: 24.09.2021 16:43
Adressaat: TKA Info <
[email protected]>
Koopia: <
[email protected]>; <
[email protected]>; <EISMEA-
[email protected]>
Teema: FW: CP B15-05 - Notification letter financial audit
Manused: image001.gif; CP B15-05 TARBIJAKAITSEAMET Estonia Notification letter
ARES.pdf
Dear Madam/Sir,
Following the reception of the attached automated email of failure delivery, please find
herewith a letter addressed to Mr SOONISTE.
We are kindly asking you to confirm the receipt of our letter.
Kind regards,
Eleni SDOUKOU
Ex-post Control Adviser
European Innovation Council and SMEs
Executive Agency (EISMEA)
Established by the European Commission
Department C Finance and administration
Anti-Fraud, Internal & Ex-post controls
COV2 12/045
Place Rogier 16
B-1049 Brussels/Belgium
Tel: +32 2 29 80391
Email:
[email protected]
https://eismea.ec.europa.eu/
From: SDOUKOU Eleni (EISMEA)
Sent: Friday, September 24, 2021 12:00 PM
To: '
[email protected]' <
[email protected]>
Cc: '
[email protected]' <
[email protected]>; 'BE-EISMEA-
[email protected]' <
[email protected]>; EISMEA EPC <EISMEA-
[email protected]>
Subject: CP B15-05 - Notification letter financial audit
Dear Mr SOONISTE,
Please find herewith a letter addressed to you.
We are kindly asking you to confirm the receipt of our letter.
Kind regards,
Eleni SDOUKOU
Ex-post Control Adviser
European Innovation Council and SMEs
Executive Agency (EISMEA)
Established by the European Commission
Department C Finance and administration
Anti-Fraud, Internal & Ex-post controls
COV2 12/045
Place Rogier 16
B-1049 Brussels/Belgium
Tel: +32 2 29 80391
Email:
[email protected]
https://eismea.ec.europa.eu/