keyboard_tab EIDAS 2014/0910 EN
BG CS DA DE EL EN ES ET FI FR GA HR HU IT LV LT MT NL PL PT RO SK SL SV print pdf
- 1 Article 8 Assurance levels of electronic identification schemes
- 1 Article 12 Cooperation and interoperability
CHAPTER I
GENERAL PROVISIONS
CHAPTER II
ELECTRONIC IDENTIFICATION
CHAPTER III
TRUST SERVICES
SECTION 1
General provisions
SECTION 2
Supervision
SECTION 3
Qualified trust services
SECTION 4
Electronic signatures
SECTION 5
Electronic seals
SECTION 6
Electronic time stamps
SECTION 7
Electronic registered delivery services
SECTION 8
Website authentication
CHAPTER IV
ELECTRONIC DOCUMENTS
CHAPTER V
DELEGATIONS OF POWER AND IMPLEMENTING PROVISIONS
CHAPTER VI
FINAL PROVISIONS
- electronic identification
- electronic identification means
- person identification data
- electronic identification scheme
- authentication
- relying party
- public sector body
- body governed by public law
- signatory
- electronic signature
- advanced electronic signature
- qualified electronic signature
- electronic signature creation data
- certificate for electronic signature
- qualified certificate for electronic signature
- trust service
- qualified trust service
- conformity assessment body
- trust service provider
- qualified trust service provider
- product
- electronic signature creation device
- qualified electronic signature creation device
- creator of a seal
- electronic seal
- advanced electronic seal
- qualified electronic seal
- electronic seal creation data
- certificate for electronic seal
- qualified certificate for electronic seal
- electronic seal creation device
- qualified electronic seal creation device
- electronic time stamp
- qualified electronic time stamp
- electronic document
- electronic registered delivery service
- qualified electronic registered delivery service
- certificate for website authentication
- qualified certificate for website authentication
- validation data
- validation
- electronic_identification 28
- shall 17
- means 14
- technical 13
- assurance 13
- article 11
- schemes 10
- which 10
- levels 9
- reference 8
- standards 8
- identity 8
- interoperability 8
- under 6
- substantial 6
- specifications 6
- paragraph 6
- the 6
- related 5
- scheme 5
- states 5
- member 5
- implementing 5
- acts 5
- minimum 5
- procedure 5
- person 5
- procedures 5
- level 5
- high 5
- degree 4
- purpose 4
- between 4
- framework 4
- cooperation 4
- notified 4
- referred 4
- security 4
- alteration 3
- commission 3
- examination 3
- accordance 3
- national 3
- issuance 3
- pursuant 3
- by 3
- confidence 3
- requirements 3
- misuse 3
- thereto 3
Article 8
Assurance levels of electronic_identification schemes
1. An electronic_identification scheme notified pursuant to Article 9(1) shall specify assurance levels low, substantial and/or high for electronic_identification means issued under that scheme.
2. The assurance levels low, substantial and high shall meet respectively the following criteria:
(a) | assurance level low shall refer to an electronic_identification means in the context of an electronic_identification scheme, which provides a limited degree of confidence in the claimed or asserted identity of a person, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of misuse or alteration of the identity; |
(b) | assurance level substantial shall refer to an electronic_identification means in the context of an electronic_identification scheme, which provides a substantial degree of confidence in the claimed or asserted identity of a person, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease substantially the risk of misuse or alteration of the identity; |
(c) | assurance level high shall refer to an electronic_identification means in the context of an electronic_identification scheme, which provides a higher degree of confidence in the claimed or asserted identity of a person than electronic_identification means with the assurance level substantial, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent misuse or alteration of the identity. |
3. By 18 September 2015, taking into account relevant international standards and subject to paragraph 2, the Commission shall, by means of implementing acts, set out minimum technical specifications, standards and procedures with reference to which assurance levels low, substantial and high are specified for electronic_identification means for the purposes of paragraph 1.
Those minimum technical specifications, standards and procedures shall be set out by reference to the reliability and quality of the following elements:
(a) | the procedure to prove and verify the identity of natural or legal persons applying for the issuance of electronic_identification means; |
(b) | the procedure for the issuance of the requested electronic_identification means; |
(c) | the authentication mechanism, through which the natural or legal person uses the electronic_identification means to confirm its identity to a relying_party; |
(d) | the entity issuing the electronic_identification means; |
(e) | any other body involved in the application for the issuance of the electronic_identification means; and |
(f) | the technical and security specifications of the issued electronic_identification means. |
Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
Article 12
Cooperation and interoperability
1. The national electronic_identification schemes notified pursuant to Article 9(1) shall be interoperable.
2. For the purposes of paragraph 1, an interoperability framework shall be established.
3. The interoperability framework shall meet the following criteria:
(a) | it aims to be technology neutral and does not discriminate between any specific national technical solutions for electronic_identification within a Member State; |
(b) | it follows European and international standards, where possible; |
(c) | it facilitates the implementation of the principle of privacy by design; and |
(d) | it ensures that personal data is processed in accordance with Directive 95/46/EC. |
4. The interoperability framework shall consist of:
(a) | a reference to minimum technical requirements related to the assurance levels under Article 8; |
(b) | a mapping of national assurance levels of notified electronic_identification schemes to the assurance levels under Article 8; |
(c) | a reference to minimum technical requirements for interoperability; |
(d) | a reference to a minimum set of person_identification_data uniquely representing a natural or legal person, which is available from electronic_identification schemes; |
(e) | rules of procedure; |
(f) | arrangements for dispute resolution; and |
(g) | common operational security standards. |
5. Member States shall cooperate with regard to the following:
(a) | the interoperability of the electronic_identification schemes notified pursuant to Article 9(1) and the electronic_identification schemes which Member States intend to notify; and |
(b) | the security of the electronic_identification schemes. |
6. The cooperation between Member States shall consist of:
(a) | the exchange of information, experience and good practice as regards electronic_identification schemes and in particular technical requirements related to interoperability and assurance levels; |
(b) | the exchange of information, experience and good practice as regards working with assurance levels of electronic_identification schemes under Article 8; |
(c) | peer review of electronic_identification schemes falling under this Regulation; and |
(d) | examination of relevant developments in the electronic_identification sector. |
7. By 18 March 2015, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements to facilitate the cooperation between the Member States referred to in paragraphs 5 and 6 with a view to fostering a high level of trust and security appropriate to the degree of risk.
8. By 18 September 2015, for the purpose of setting uniform conditions for the implementation of the requirement under paragraph 1, the Commission shall, subject to the criteria set out in paragraph 3 and taking into account the results of the cooperation between Member States, adopt implementing acts on the interoperability framework as set out in paragraph 4.
9. The implementing acts referred to in paragraphs 7 and 8 of this Article shall be adopted in accordance with the examination procedure referred to in Article 48(2).
CHAPTER III
TRUST SERVICES
SECTION 1
General provisions
whereas