Home

Commission Implementing Regulation (EU) 2021/2225 of 16 November 2021 laying down the details of the automated data quality control mechanisms and procedures, the common data quality indicators and the minimum quality standards for storage of data, pursuant to Article 37(4) of Regulation (EU) 2019/817 of the European Parliament and of the Council

Commission Implementing Regulation (EU) 2021/2225 of 16 November 2021 laying down the details of the automated data quality control mechanisms and procedures, the common data quality indicators and the minimum quality standards for storage of data, pursuant to Article 37(4) of Regulation (EU) 2019/817 of the European Parliament and of the Council

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2019/817 of the European Parliament and of the Council of 20 May 2019 on establishing a framework for interoperability between EU information systems in the field of borders and visa and amending Regulations (EC) No 767/2008, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1726 and (EU) 2018/1861 of the European Parliament and of the Council and Council Decisions 2004/512/EC and 2008/633/JHA(1), and in particular Article 37(4) thereof,

Whereas:

  1. Regulation (EU) 2019/817, together with Regulation (EU) 2019/818 of the European Parliament and of the Council(2) establishes a framework to ensure interoperability between the EU information systems in the field of borders, visa, police and judicial cooperation, asylum and migration.

  2. In order to improve data quality and harmonise the quality requirements, it is necessary to lay down the details of the automated data quality control mechanisms and procedures, the common data quality indicators and the minimum quality standards for the data entered and stored in the underlying EU information systems, the shared biometric matching service and the common identity repository.

  3. Those measures should be implemented and assessed by the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) taking into consideration the specific provisions laid down for each EU information system and the interoperability component. To perform these tasks, eu-LISA should be advised by experts from the Commission, the Member States and the Union agencies using the EU information systems and interoperability components.

  4. Data quality control mechanisms and procedures should determine the compliance of the input data with the blocking and soft rules applicable to the underlying EU information systems, the shared biometric matching service and the common identity repository. eu-LISA should be responsible for ensuring that the data quality rules remain appropriate for achieving the objectives of the EU information systems and the interoperability components.

  5. For each quality control indicator, eu-LISA should determine and assess the appropriateness of the minimum quality standard indispensible to store the data in the EU information systems and the interoperability components. Data quality standards should enable the automatic identification of apparently incorrect or inconsistent data submissions, so that the originating Member State is able to verify the data and carry out any necessary remedial action.

  6. The data cleaning and issue detection mechanisms should be established in order to regularly check the validity and compliance of the data stored in the underlying EU information systems and the interoperability components with the data quality standards.

  7. eu-LISA should ensure a central monitoring capacity for data quality and for producing reports on data quality on a regular basis to the Member States. These reports should be produced by the central repository for reporting and statistics in accordance with Article 39(1) of Regulation (EU) 2019/817 and the rules laid down in Commission Delegated Regulation 2021/2223(3).

  8. Given that Regulation (EU) 2019/817 builds upon the Schengen acquis, in accordance with Article 4 of Protocol No 22 on the Position of Denmark, annexed to the Treaty on European Union and to the Treaty on the Functioning of the European Union, Denmark notified the implementation of Regulation (EU) 2019/817 in its national law. It is therefore bound by this Regulation.

  9. This Regulation constitutes a development of the provisions of the Schengen acquis in which Ireland does not take part(4). Ireland is therefore not taking part in the adoption of this Regulation and is not bound by it or subject to its application.

  10. As regards Iceland and Norway, this Regulation constitutes a development of the provisions of the Schengen acquis within the meaning of the Agreement concluded by the Council of the European Union and the Republic of Iceland and the Kingdom of Norway concerning the association of those two States with the implementation, application and development of the Schengen acquis(5), which fall within the area referred to in Article 1, point A of Council Decision 1999/437/EC(6).

  11. As regards Switzerland, this Regulation constitutes a development of the provisions of the Schengen acquis within the meaning of the Agreement between the European Union, the European Community and the Swiss Confederation on the Swiss Confederation’s association with the implementation, application and development of the Schengen acquis(7), which fall within the area referred to in Article 1, point A of Decision 1999/437/EC, read in conjunction with Article 3 of Council Decision 2008/146/EC(8).

  12. As regards Liechtenstein, this Regulation constitutes a development of the provisions of the Schengen acquis within the meaning of the Protocol between the European Union, the European Community, the Swiss Confederation and the Principality of Liechtenstein on the accession of the Principality of Liechtenstein to the Agreement between the European Union, the European Community and the Swiss Confederation on the Swiss Confederation’s association with the implementation, application and development of the Schengen acquis(9) which fall within the area referred to in Article 1, point A of Decision 1999/437/EC read in conjunction with Article 3 of Council Decision 2011/350/EU(10).

  13. As regards Cyprus, Bulgaria and Romania and Croatia, this Regulation constitutes an act building upon, or otherwise relating to, the Schengen acquis within, respectively, the meaning of Article 3(1) of the 2003 Act of Accession, Article 4(1) of the 2005 Act of Accession and Article 4(1) of the 2011 Act of Accession.

  14. The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council(11) and delivered an opinion on 30 April 2021.

  15. The measures provided for in this Regulation are in accordance with the opinion of the Interoperability Committee,

HAS ADOPTED THIS REGULATION:

Article 1 Scope and subject matter

1.

This Regulation lays down the details of the automated data quality control mechanisms and procedures on the data stored in the EU information systems and interoperability components referred to in Article 37(1) of Regulation (EU) 2019/817.

2.

This Regulation also lays down details concerning the common data quality indicators and the minimum quality standards for storage of data, in particular regarding biometric data, in the EU information systems and interoperability components referred to in Article 37(1) of Regulation (EU) 2019/817.

3.

The measures referred to in paragraphs 2 and 3 are without prejudice to any specific provisions concerning data quality related to the EU information systems laid down in Union law.

4.

This Regulation applies to the EU information systems and interoperability components referred to in Article 37(1) of Regulation (EU) 2019/817.

Article 2 Definitions

For the purposes of this Regulation, the following definitions apply:

  1. ‘input data’ means data, subject to data quality checks for the purpose of being stored in a EU information system or interoperability component referred to in Article 37(1) of Regulation (EU) 2019/817;

  2. ‘data cleaning mechanism’ means a mechanism carrying out checks in order to ensure the scheduled erasure of data stored in a EU information system or interoperability component in accordance with Union law;

  3. ‘issue detection mechanism’ means a mechanism carrying out checks in order to identify data that does not meet the data quality rules or standards;

  4. ‘blocking rules’ means rules or a set of rules that measure the degree to which input data is compliant with defined data requirements conditioning their storage or use or both. They also include data quality rules governing each EU information system that must be complied with before data can be entered in the system. Input data not complying with a blocking rule will be rejected from being entered and stored in the EU information system and interoperability component;

  5. ‘soft rules’ means rules or a set of rules that measure the degree to which the input data is compliant with the defined data requirements conditioning its relevance or optimal use or both. Soft rules shall not prevent the entry and storage of non-compliant input data. They also include data quality rules governing each EU information system that should be complied with before data can be entered in the system. Input data not complying with a soft rule shall be entered into the EU information system or interoperability component with a data quality issue flag, notification or warning message.

Article 3 Automated data quality control mechanisms and procedures

1.

Automated quality checks shall be conducted on the data entered and stored in the shared biometric matching service and the common identity repository in accordance with the rules laid down in Article 4.

2.

Automated quality checks shall be conducted on the data entered and stored in the EU information systems referred to in Article 37(1) of Regulation (EU) 2019/817 in accordance with the rules governing data quality control mechanisms in those systems.

3.

Data quality control mechanisms shall be triggered in accordance with the rules governing data quality in those EU information systems and interoperability components.

4.

In order to determine compliance of input data with the blocking or soft rules applying to them, the data quality control mechanisms referred to in paragraph 3 shall comply with Section 1 of the Annex to this Regulation.

5.

If the input data is to be entered into the EU information system or interoperability components referred to in Article 37(1) of Regulation (EU) 2019/817, the data quality control mechanisms shall assess the extent to which the data complies with each data quality indicator by applying the data quality standard of each indicator. As a result of that assessment, the data quality control mechanisms shall assign to the input data a data quality classification pursuant to the process laid down in Sections 2 and 3 of the Annex to this Regulation.

6.

The common data quality indicators shall be the following: completeness, accuracy, timeliness, uniqueness and consistency.

7.

eu-LISA shall implement the data quality standards for each indicator pursuant to the procedures laid down in Article 5.

8.

Data cleaning and issue detection mechanisms shall regularly check the validity and the data quality compliance of the data stored in the EU information systems and interoperability components referred to in Article 37(1) of Regulation (EU) 2019/817, in accordance with Section 4 of the Annex to this Regulation.

Article 4 Automated data quality control mechanisms for data entered and stored

1.

To enhance data quality, automated data quality control mechanisms shall be set up to support the entering and storage of data complying with data quality requirements in the EU information systems and interoperability components referred to in Article 37(1) of Regulation (EU) 2019/817. The data shall be entered and stored in accordance with the rules governing data quality in those EU information systems or interoperability components.

2.

For the purpose of the entry of data by the duly authorised staff in the EU information systems and interoperability components referred to in Article 37(1) of Regulation (EU) 2019/817, the automated quality control mechanisms shall verify the common quality indicators referred to in Section 2 of the Annex to this Regulation.

3.

Data quality control mechanisms shall allow the application of blocking rules and soft rules in accordance with Article 3(4) governing data quality in the EU Information Systems and interoperability components referred to in Article 37(1) of Regulation (EU) 2019/817.

Article 5 Procedures governing the data quality control indicators, standards and mechanisms

Article 6 Reports on automated data quality control mechanisms and procedures and common data quality indicators pursuant to Article 37(3) of Regulation (EU) 2019/817

Article 7 Entry into force

ANNEX