keyboard_tab EIDAS 2014/0910 EN
BG CS DA DE EL EN ES ET FI FR GA HR HU IT LV LT MT NL PL PT RO SK SL SV print pdf
- Article 1 Subject matter
- Article 2 Scope
- Article 3 Definitions
- Article 4 Internal market principle
- Article 5 Data processing and protection
- Article 6 Mutual recognition
- Article 7 Eligibility for notification of electronic identification schemes
- Article 8 Assurance levels of electronic identification schemes
- Article 9 Notification
- Article 10 Security breach
- Article 11 Liability
- Article 12 Cooperation and interoperability
- Article 13 Liability and burden of proof
- Article 14 International aspects
- Article 15 Accessibility for persons with disabilities
- Article 16 Penalties
- Article 17 Supervisory body
- Article 18 Mutual assistance
- Article 19 Security requirements applicable to trust service providers
- Article 20 Supervision of qualified trust service providers
- Article 21 Initiation of a qualified trust service
- Article 22 Trusted lists
- Article 23 EU trust mark for qualified trust services
- Article 24 Requirements for qualified trust service providers
- Article 25 Legal effects of electronic signatures
- Article 26 Requirements for advanced electronic signatures
- Article 27 Electronic signatures in public services
- Article 28 Qualified certificates for electronic signatures
- Article 29 Requirements for qualified electronic signature creation devices
- Article 30 Certification of qualified electronic signature creation devices
- Article 31 Publication of a list of certified qualified electronic signature creation devices
- Article 32 Requirements for the validation of qualified electronic signatures
- Article 33 Qualified validation service for qualified electronic signatures
- Article 34 Qualified preservation service for qualified electronic signatures
- Article 35 Legal effects of electronic seals
- Article 36 Requirements for advanced electronic seals
- Article 37 Electronic seals in public services
- Article 38 Qualified certificates for electronic seals
- Article 39 Qualified electronic seal creation devices
- Article 40 Validation and preservation of qualified electronic seals
- Article 41 Legal effect of electronic time stamps
- Article 42 Requirements for qualified electronic time stamps
- Article 43 Legal effect of an electronic registered delivery service
- Article 44 Requirements for qualified electronic registered delivery services
- Article 45 Requirements for qualified certificates for website authentication
- Article 46 Legal effects of electronic documents
- Article 47 Exercise of the delegation
- Article 48 Committee procedure
- Article 49 Review
- Article 50 Repeal
- Article 51 Transitional measures
- Article 52 Entry into force
CHAPTER I
GENERAL PROVISIONS
CHAPTER II
ELECTRONIC IDENTIFICATION
CHAPTER III
TRUST SERVICES
SECTION 1
General provisions
SECTION 2
Supervision
SECTION 3
Qualified trust services
SECTION 4
Electronic signatures
SECTION 5
Electronic seals
SECTION 6
Electronic time stamps
SECTION 7
Electronic registered delivery services
SECTION 8
Website authentication
CHAPTER IV
ELECTRONIC DOCUMENTS
CHAPTER V
DELEGATIONS OF POWER AND IMPLEMENTING PROVISIONS
CHAPTER VI
FINAL PROVISIONS
- whereas (1)
- whereas (2)
- whereas (3)
- whereas (4)
- whereas (5)
- whereas (6)
- whereas (7)
- whereas (8)
- whereas (9)
- whereas (10)
- whereas (11)
- whereas (12)
- whereas (13)
- whereas (14)
- whereas (15)
- whereas (16)
- whereas (17)
- whereas (18)
- whereas (19)
- whereas (20)
- whereas (21)
- whereas (22)
- whereas (23)
- whereas (24)
- whereas (25)
- whereas (26)
- whereas (27)
- whereas (28)
- whereas (29)
- whereas (30)
- whereas (31)
- whereas (32)
- whereas (33)
- whereas (34)
- whereas (35)
- whereas (36)
- whereas (37)
- whereas (38)
- whereas (39)
- whereas (40)
- whereas (41)
- whereas (42)
- whereas (43)
- whereas (44)
- whereas (45)
- whereas (46)
- whereas (47)
- whereas (48)
- whereas (49)
- whereas (50)
- whereas (51)
- whereas (52)
- whereas (53)
- whereas (54)
- whereas (55)
- whereas (56)
- whereas (57)
- whereas (58)
- whereas (59)
- whereas (60)
- whereas (61)
- whereas (62)
- whereas (63)
- whereas (64)
- whereas (65)
- whereas (66)
- whereas (67)
- whereas (68)
- whereas (69)
- whereas (70)
- whereas (71)
- whereas (72)
- whereas (73)
- whereas (74)
- whereas (75)
- whereas (76)
- whereas (77)
- electronic identification
- electronic identification means
- person identification data
- electronic identification scheme
- authentication
- relying party
- public sector body
- body governed by public law
- signatory
- electronic signature
- advanced electronic signature
- qualified electronic signature
- electronic signature creation data
- certificate for electronic signature
- qualified certificate for electronic signature
- trust service
- qualified trust service
- conformity assessment body
- trust service provider
- qualified trust service provider
- product
- electronic signature creation device
- qualified electronic signature creation device
- creator of a seal
- electronic seal
- advanced electronic seal
- qualified electronic seal
- electronic seal creation data
- certificate for electronic seal
- qualified certificate for electronic seal
- electronic seal creation device
- qualified electronic seal creation device
- electronic time stamp
- qualified electronic time stamp
- electronic document
- electronic registered delivery service
- qualified electronic registered delivery service
- certificate for website authentication
- qualified certificate for website authentication
- validation data
- validation
- security 11
- shall 9
- trust_service 7
- integrity 6
- breach 6
- loss 6
- body 5
- supervisory 5
- providers 4
- measures 4
- inform 3
- applicable 3
- bodies 2
- person 2
- delay 2
- undue 2
- without 2
- legal 2
- public 2
- enisa 2
- the 2
- incidents 2
- impact 2
- data 2
- implementing 2
- particular 2
- such 2
- non-qualified 2
- qualified 2
- provide 2
- appropriate 2
- natural 2
- provider 2
- trust_services 2
- referred 2
- member 2
- having 2
- states 2
- provided 2
- notified 2
- notify 2
- paragraph 2
- article 2
- require 1
- more 1
- concerns 1
- also 1
- concerned 1
- determines 1
- received 1
Article 19
Security requirements applicable to trust_service providers
1. Qualified and non-qualified trust_service providers shall take appropriate technical and organisational measures to manage the risks posed to the security of the trust_services they provide. Having regard to the latest technological developments, those measures shall ensure that the level of security is commensurate to the degree of risk. In particular, measures shall be taken to prevent and minimise the impact of security incidents and inform stakeholders of the adverse effects of any such incidents.
2. Qualified and non-qualified trust_service providers shall, without undue delay but in any event within 24 hours after having become aware of it, notify the supervisory body and, where applicable, other relevant bodies, such as the competent national body for information security or the data protection authority, of any breach of security or loss of integrity that has a significant impact on the trust_service provided or on the personal data maintained therein.
Where the breach of security or loss of integrity is likely to adversely affect a natural or legal person to whom the trusted service has been provided, the trust_service provider shall also notify the natural or legal person of the breach of security or loss of integrity without undue delay.
Where appropriate, in particular if a breach of security or loss of integrity concerns two or more Member States, the notified supervisory body shall inform the supervisory bodies in other Member States concerned and ENISA.
The notified supervisory body shall inform the public or require the trust_service provider to do so, where it determines that disclosure of the breach of security or loss of integrity is in the public interest.
3. The supervisory body shall provide ENISA once a year with a summary of notifications of breach of security and loss of integrity received from trust_service providers.
4. The Commission may, by means of implementing acts,:
(a) | further specify the measures referred to in paragraph 1; and |
(b) | define the formats and procedures, including deadlines, applicable for the purpose of paragraph 2. |
Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
SECTION 3
Qualified trust_services
whereas