search


keyboard_tab EIDAS 2014/0910 EN

BG CS DA DE EL EN ES ET FI FR GA HR HU IT LV LT MT NL PL PT RO SK SL SV print pdf

2014/0910 EN cercato: 'order' . Output generated live by software developed by IusOnDemand srl


just index order:


whereas order:


definitions:


cloud tag: and the number of total unique words without stopwords is: 943

 

Article 1

Subject matter

With a view to ensuring the proper functioning of the internal market while aiming at an adequate level of security of electronic_identification means and trust_services this Regulation:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Article 3

Definitions

For the purposes of this Regulation, the following definitions apply:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Article 6

Mutual recognition

1.   When an electronic_identification using an electronic_identification means and authentication is required under national law or by administrative practice to access a service provided by a public_sector_body online in one Member State, the electronic_identification means issued in another Member State shall be recognised in the first Member State for the purposes of cross-border authentication for that service online, provided that the following conditions are met:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Such recognition shall take place no later than 12 months after the Commission publishes the list referred to in point (a) of the first subparagraph.

2.   An electronic_identification means which is issued under an electronic_identification scheme included in the list published by the Commission pursuant to Article 9 and which corresponds to the assurance level low may be recognised by public sector bodies for the purposes of cross-border authentication for the service provided online by those bodies.

Article 7

Eligibility for notification of electronic_identification schemes

An electronic_identification scheme shall be eligible for notification pursuant to Article 9(1) provided that all of the following conditions are met:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Article 8

Assurance levels of electronic_identification schemes

1.   An electronic_identification scheme notified pursuant to Article 9(1) shall specify assurance levels low, substantial and/or high for electronic_identification means issued under that scheme.

2.   The assurance levels low, substantial and high shall meet respectively the following criteria:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

3.   By 18 September 2015, taking into account relevant international standards and subject to paragraph 2, the Commission shall, by means of implementing acts, set out minimum technical specifications, standards and procedures with reference to which assurance levels low, substantial and high are specified for electronic_identification means for the purposes of paragraph 1.

Those minimum technical specifications, standards and procedures shall be set out by reference to the reliability and quality of the following elements:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 9

Notification

1.   The notifying Member State shall notify to the Commission the following information and, without undue delay, any subsequent changes thereto:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

2.   One year from the date of application of the implementing acts referred to in Articles 8(3) and 12(8), the Commission shall publish in the Official Journal of the European Union a list of the electronic_identification schemes which were notified pursuant to paragraph 1 of this Article and the basic information thereon.

3.   If the Commission receives a notification after the expiry of the period referred to in paragraph 2, it shall publish in the Official Journal of the European Union the amendments to the list referred to in paragraph 2 within two months from the date of receipt of that notification.

4.   A Member State may submit to the Commission a request to remove an electronic_identification scheme notified by that Member State from the list referred to in paragraph 2. The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list within one month from the date of receipt of the Member State’s request.

5.   The Commission may, by means of implementing acts, define the circumstances, formats and procedures of notifications under paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 10

Security breach

1.   Where either the electronic_identification scheme notified pursuant to Article 9(1) or the authentication referred to in point (f) of Article 7 is breached or partly compromised in a manner that affects the reliability of the cross-border authentication of that scheme, the notifying Member State shall, without delay, suspend or revoke that cross-border authentication or the compromised parts concerned, and shall inform other Member States and the Commission.

2.   When the breach or compromise referred to in paragraph 1 is remedied, the notifying Member State shall re-establish the cross-border authentication and shall inform other Member States and the Commission without undue delay.

3.   If the breach or compromise referred to in paragraph 1 is not remedied within three months of the suspension or revocation, the notifying Member State shall notify other Member States and the Commission of the withdrawal of the electronic_identification scheme.

The Commission shall publish in the Official Journal of the European Union the corresponding amendments to the list referred to in Article 9(2) without undue delay.

Article 11

Liability

1.   The notifying Member State shall be liable for damage caused intentionally or negligently to any natural or legal person due to a failure to comply with its obligations under points (d) and (f) of Article 7 in a cross-border transaction.

2.   The party issuing the electronic_identification means shall be liable for damage caused intentionally or negligently to any natural or legal person due to a failure to comply with the obligation referred to in point (e) of Article 7 in a cross-border transaction.

3.   The party operating the authentication procedure shall be liable for damage caused intentionally or negligently to any natural or legal person due to a failure to ensure the correct operation of the authentication referred to in point (f) of Article 7 in a cross-border transaction.

4.   Paragraphs 1, 2 and 3 shall be applied in accordance with national rules on liability.

5.   Paragraphs 1, 2 and 3 are without prejudice to the liability under national law of parties to a transaction in which electronic_identification means falling under the electronic_identification scheme notified pursuant to Article 9(1) are used.

Article 12

Cooperation and interoperability

1.   The national electronic_identification schemes notified pursuant to Article 9(1) shall be interoperable.

2.   For the purposes of paragraph 1, an interoperability framework shall be established.

3.   The interoperability framework shall meet the following criteria:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

4.   The interoperability framework shall consist of:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

5.   Member States shall cooperate with regard to the following:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

6.   The cooperation between Member States shall consist of:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

7.   By 18 March 2015, the Commission shall, by means of implementing acts, establish the necessary procedural arrangements to facilitate the cooperation between the Member States referred to in paragraphs 5 and 6 with a view to fostering a high level of trust and security appropriate to the degree of risk.

8.   By 18 September 2015, for the purpose of setting uniform conditions for the implementation of the requirement under paragraph 1, the Commission shall, subject to the criteria set out in paragraph 3 and taking into account the results of the cooperation between Member States, adopt implementing acts on the interoperability framework as set out in paragraph 4.

9.   The implementing acts referred to in paragraphs 7 and 8 of this Article shall be adopted in accordance with the examination procedure referred to in Article 48(2).

CHAPTER III

TRUST SERVICES

SECTION 1

General provisions

Article 14

International aspects

1.   Trust services provided by trust_service providers established in a third country shall be recognised as legally equivalent to qualified trust_services provided by qualified trust_service providers established in the Union where the trust_services originating from the third country are recognised under an agreement concluded between the Union and the third country in question or an international organisation in accordance with Article 218 TFEU.

2.   Agreements referred to in paragraph 1 shall ensure, in particular, that:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Article 17

Supervisory body

1.   Member States shall designate a supervisory body established in their territory or, upon mutual agreement with another Member State, a supervisory body established in that other Member State. That body shall be responsible for supervisory tasks in the designating Member State.

Supervisory bodies shall be given the necessary powers and adequate resources for the exercise of their tasks.

2.   Member States shall notify to the Commission the names and the addresses of their respective designated supervisory bodies.

3.   The role of the supervisory body shall be the following:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

4.   For the purposes of paragraph 3 and subject to the limitations provided therein, the tasks of the supervisory body shall include in particular:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

5.   Member States may require the supervisory body to establish, maintain and update a trust infrastructure in accordance with the conditions under national law.

6.   By 31 March each year, each supervisory body shall submit to the Commission a report on its previous calendar year’s main activities together with a summary of breach notifications received from trust_service providers in accordance with Article 19(2).

7.   The Commission shall make the annual report referred to in paragraph 6 available to Member States.

8.   The Commission may, by means of implementing acts, define the formats and procedures for the report referred to in paragraph 6. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 18

Mutual assistance

1.   Supervisory bodies shall cooperate with a view to exchanging good practice.

A supervisory body shall, upon receipt of a justified request from another supervisory body, provide that body with assistance so that the activities of supervisory bodies can be carried out in a consistent manner. Mutual assistance may cover, in particular, information requests and supervisory measures, such as requests to carry out inspections related to the conformity assessment reports as referred to in Articles 20 and 21.

2.   A supervisory body to which a request for assistance is addressed may refuse that request on any of the following grounds:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

3.   Where appropriate, Member States may authorise their respective supervisory bodies to carry out joint investigations in which staff from other Member States’ supervisory bodies is involved. The arrangements and procedures for such joint actions shall be agreed upon and established by the Member States concerned in accordance with their national law.

Article 19

Security requirements applicable to trust_service providers

1.   Qualified and non-qualified trust_service providers shall take appropriate technical and organisational measures to manage the risks posed to the security of the trust_services they provide. Having regard to the latest technological developments, those measures shall ensure that the level of security is commensurate to the degree of risk. In particular, measures shall be taken to prevent and minimise the impact of security incidents and inform stakeholders of the adverse effects of any such incidents.

2.   Qualified and non-qualified trust_service providers shall, without undue delay but in any event within 24 hours after having become aware of it, notify the supervisory body and, where applicable, other relevant bodies, such as the competent national body for information security or the data protection authority, of any breach of security or loss of integrity that has a significant impact on the trust_service provided or on the personal data maintained therein.

Where the breach of security or loss of integrity is likely to adversely affect a natural or legal person to whom the trusted service has been provided, the trust_service provider shall also notify the natural or legal person of the breach of security or loss of integrity without undue delay.

Where appropriate, in particular if a breach of security or loss of integrity concerns two or more Member States, the notified supervisory body shall inform the supervisory bodies in other Member States concerned and ENISA.

The notified supervisory body shall inform the public or require the trust_service provider to do so, where it determines that disclosure of the breach of security or loss of integrity is in the public interest.

3.   The supervisory body shall provide ENISA once a year with a summary of notifications of breach of security and loss of integrity received from trust_service providers.

4.   The Commission may, by means of implementing acts,:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

SECTION 3

Qualified trust_services

Article 20

Supervision of qualified trust_service providers

1.   Qualified trust_service providers shall be audited at their own expense at least every 24 months by a conformity_assessment_body. The purpose of the audit shall be to confirm that the qualified trust_service providers and the qualified trust_services provided by them fulfil the requirements laid down in this Regulation. The qualified trust_service providers shall submit the resulting conformity assessment report to the supervisory body within the period of three working days after receiving it.

2.   Without prejudice to paragraph 1, the supervisory body may at any time audit or request a conformity_assessment_body to perform a conformity assessment of the qualified trust_service providers, at the expense of those trust_service providers, to confirm that they and the qualified trust_services provided by them fulfil the requirements laid down in this Regulation. Where personal data protection rules appear to have been breached, the supervisory body shall inform the data protection authorities of the results of its audits.

3.   Where the supervisory body requires the qualified trust_service provider to remedy any failure to fulfil requirements under this Regulation and where that provider does not act accordingly, and if applicable within a time limit set by the supervisory body, the supervisory body, taking into account, in particular, the extent, duration and consequences of that failure, may withdraw the qualified status of that provider or of the affected service it provides and inform the body referred to in Article 22(3) for the purposes of updating the trusted lists referred to in Article 22(1). The supervisory body shall inform the qualified trust_service provider of the withdrawal of its qualified status or of the qualified status of the service concerned.

4.   The Commission may, by means of implementing acts, establish reference number of the following standards:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 24

Requirements for qualified trust_service providers

1.   When issuing a qualified certificate for a trust_service, a qualified trust_service provider shall verify, by appropriate means and in accordance with national law, the identity and, if applicable, any specific attributes of the natural or legal person to whom the qualified certificate is issued.

The information referred to in the first subparagraph shall be verified by the qualified trust_service provider either directly or by relying on a third party in accordance with national law:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

2.   A qualified trust_service provider providing qualified trust_services shall:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

3.   If a qualified trust_service provider issuing qualified certificates decides to revoke a certificate, it shall register such revocation in its certificate database and publish the revocation status of the certificate in a timely manner, and in any event within 24 hours after the receipt of the request. The revocation shall become effective immediately upon its publication.

4.   With regard to paragraph 3, qualified trust_service providers issuing qualified certificates shall provide to any relying_party information on the validity or revocation status of qualified certificates issued by them. This information shall be made available at least on a per certificate basis at any time and beyond the validity period of the certificate in an automated manner that is reliable, free of charge and efficient.

5.   The Commission may, by means of implementing acts, establish reference numbers of standards for trustworthy systems and products, which comply with the requirements under points (e) and (f) of paragraph 2 of this Article. Compliance with the requirements laid down in this Article shall be presumed where trustworthy systems and products meet those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

SECTION 4

Electronic signatures

Article 26

Requirements for advanced electronic_signatures

An advanced electronic_signature shall meet the following requirements:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Article 27

Electronic signatures in public services

1.   If a Member State requires an advanced electronic_signature to use an online service offered by, or on behalf of, a public_sector_body, that Member State shall recognise advanced electronic_signatures, advanced electronic_signatures based on a qualified certificate for electronic_signatures, and qualified electronic_signatures in at least the formats or using methods defined in the implementing acts referred to in paragraph 5.

2.   If a Member State requires an advanced electronic_signature based on a qualified certificate to use an online service offered by, or on behalf of, a public_sector_body, that Member State shall recognise advanced electronic_signatures based on a qualified certificate and qualified electronic_signatures in at least the formats or using methods defined in the implementing acts referred to in paragraph 5.

3.   Member States shall not request for cross-border use in an online service offered by a public_sector_body an electronic_signature at a higher security level than the qualified electronic_signature.

4.   The Commission may, by means of implementing acts, establish reference numbers of standards for advanced electronic_signatures. Compliance with the requirements for advanced electronic_signatures referred to in paragraphs 1 and 2 of this Article and in Article 26 shall be presumed when an advanced electronic_signature meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

5.   By 18 September 2015, and taking into account existing practices, standards and Union legal acts, the Commission shall, by means of implementing acts, define reference formats of advanced electronic_signatures or reference methods where alternative formats are used. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 28

Qualified certificates for electronic_signatures

1.   Qualified certificates for electronic_signatures shall meet the requirements laid down in Annex I.

2.   Qualified certificates for electronic_signatures shall not be subject to any mandatory requirement exceeding the requirements laid down in Annex I.

3.   Qualified certificates for electronic_signatures may include non-mandatory additional specific attributes. Those attributes shall not affect the interoperability and recognition of qualified electronic_signatures.

4.   If a qualified certificate for electronic_signatures has been revoked after initial activation, it shall lose its validity from the moment of its revocation, and its status shall not in any circumstances be reverted.

5.   Subject to the following conditions, Member States may lay down national rules on temporary suspension of a qualified certificate for electronic_signature:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

6.   The Commission may, by means of implementing acts, establish reference numbers of standards for qualified certificates for electronic_signature. Compliance with the requirements laid down in Annex I shall be presumed where a qualified certificate for electronic_signature meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 30

Certification of qualified electronic_signature creation devices

1.   Conformity of qualified electronic_signature creation devices with the requirements laid down in Annex II shall be certified by appropriate public or private bodies designated by Member States.

2.   Member States shall notify to the Commission the names and addresses of the public or private body referred to in paragraph 1. The Commission shall make that information available to Member States.

3.   The certification referred to in paragraph 1 shall be based on one of the following:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

The Commission shall, by means of implementing acts, establish a list of standards for the security assessment of information technology products referred to in point (a). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

4.   The Commission shall be empowered to adopt delegated acts in accordance with Article 47 concerning the establishment of specific criteria to be met by the designated bodies referred to in paragraph 1 of this Article.

Article 32

Requirements for the validation of qualified electronic_signatures

1.   The process for the validation of a qualified electronic_signature shall confirm the validity of a qualified electronic_signature provided that:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

2.   The system used for validating the qualified electronic_signature shall provide to the relying_party the correct result of the validation process and shall allow the relying_party to detect any security relevant issues.

3.   The Commission may, by means of implementing acts, establish reference numbers of standards for the validation of qualified electronic_signatures. Compliance with the requirements laid down in paragraph 1 shall be presumed where the validation of qualified electronic_signatures meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 33

Qualified validation service for qualified electronic_signatures

1.   A qualified validation service for qualified electronic_signatures may only be provided by a qualified trust_service provider who:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

2.   The Commission may, by means of implementing acts, establish reference numbers of standards for qualified validation service referred to in paragraph 1. Compliance with the requirements laid down in paragraph 1 shall be presumed where the validation service for a qualified electronic_signature meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 36

Requirements for advanced electronic_seals

An advanced electronic_seal shall meet the following requirements:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

Article 37

Electronic seals in public services

1.   If a Member State requires an advanced electronic_seal in order to use an online service offered by, or on behalf of, a public_sector_body, that Member State shall recognise advanced electronic_seals, advanced electronic_seals based on a qualified certificate for electronic_seals and qualified electronic_seals at least in the formats or using methods defined in the implementing acts referred to in paragraph 5.

2.   If a Member State requires an advanced electronic_seal based on a qualified certificate in order to use an online service offered by, or on behalf of, a public_sector_body, that Member State shall recognise advanced electronic_seals based on a qualified certificate and qualified electronic_seal at least in the formats or using methods defined in the implementing acts referred to in paragraph 5.

3.   Member States shall not request for the cross-border use in an online service offered by a public_sector_body an electronic_seal at a higher security level than the qualified electronic_seal.

4.   The Commission may, by means of implementing acts, establish reference numbers of standards for advanced electronic_seals. Compliance with the requirements for advanced electronic_seals referred to in paragraphs 1 and 2 of this Article and Article 36 shall be presumed when an advanced electronic_seal meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

5.   By 18 September 2015, and taking into account existing practices, standards and legal acts of the Union, the Commission shall, by means of implementing acts, define reference formats of advanced electronic_seals or reference methods where alternative formats are used. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 38

Qualified certificates for electronic_seals

1.   Qualified certificates for electronic_seals shall meet the requirements laid down in Annex III.

2.   Qualified certificates for electronic_seals shall not be subject to any mandatory requirements exceeding the requirements laid down in Annex III.

3.   Qualified certificates for electronic_seals may include non-mandatory additional specific attributes. Those attributes shall not affect the interoperability and recognition of qualified electronic_seals.

4.   If a qualified certificate for an electronic_seal has been revoked after initial activation, it shall lose its validity from the moment of its revocation, and its status shall not in any circumstances be reverted.

5.   Subject to the following conditions, Member States may lay down national rules on temporary suspension of qualified certificates for electronic_seals:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

6.   The Commission may, by means of implementing acts, establish reference numbers of standards for qualified certificates for electronic_seals. Compliance with the requirements laid down in Annex III shall be presumed where a qualified certificate for electronic_seal meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

Article 42

Requirements for qualified electronic_time_stamps

1.   A qualified electronic_time_stamp shall meet the following requirements:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

2.   The Commission may, by means of implementing acts, establish reference numbers of standards for the binding of date and time to data and for accurate time sources. Compliance with the requirements laid down in paragraph 1 shall be presumed where the binding of date and time to data and the accurate time source meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

SECTION 7

Electronic registered delivery services

Article 44

Requirements for qualified electronic_registered_delivery_services

1.   Qualified electronic_registered_delivery_services shall meet the following requirements:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

In the event of the data being transferred between two or more qualified trust_service providers, the requirements in points (a) to (f) shall apply to all the qualified trust_service providers.

2.   The Commission may, by means of implementing acts, establish reference numbers of standards for processes for sending and receiving data. Compliance with the requirements laid down in paragraph 1 shall be presumed where the process for sending and receiving data meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).

SECTION 8

Website authentication

Article 52

Entry into force

1.   This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

2.   This Regulation shall apply from 1 July 2016, except for the following:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

3.   Where the notified electronic_identification scheme is included in the list published by the Commission pursuant to Article 9 before the date referred to in point (c) of paragraph 2 of this Article, the recognition of the electronic_identification means under that scheme pursuant to Article 6 shall take place no later than 12 months after the publication of that scheme but not before the date referred to in point (c) of paragraph 2 of this Article.

4.   Notwithstanding point (c) of paragraph 2 of this Article, a Member State may decide that electronic_identification means under electronic_identification scheme notified pursuant to Article 9(1) by another Member State are recognised in the first Member State as from the date of application of the implementing acts referred to in Articles 8(3) and 12(8). Member States concerned shall inform the Commission. The Commission shall make this information public.

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 23 July 2014.

For the Parliament

The President

M. SCHULZ

For the Council

The President

S. GOZI


(1)  OJ C 351, 15.11.2012, p. 73.

(2)  Position of the European Parliament of 3 April 2014 (not yet published in the Official Journal) and decision of the Council of 23 July 2014.

(3)  Directive 1999/93/EC of the European Parliament and of the Council of 13 December 1999 on a Community framework for electronic_signatures (OJ L 13, 19.1.2000, p. 12).

(4)  OJ C 50 E, 21.2.2012, p. 1.

(5)  Directive 2006/123/EC of the European Parliament and of the Council of 12 December 2006 on services in the internal market (OJ L 376, 27.12.2006, p. 36).

(6)  Directive 2011/24/EU of the European Parliament and of the Council of 9 March 2011 on the application of patients’ rights in cross-border healthcare (OJ L 88, 4.4.2011, p. 45).

(7)  Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ L 281, 23.11.1995, p. 31).

(8)  Council Decision 2010/48/EC of 26 November 2009 concerning the conclusion, by the European Community, of the United Nations Convention on the Rights of Persons with Disabilities (OJ L 23, 27.1.2010, p. 35).

(9)  Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and market surveillance relating to the marketing of products and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p. 30).

(10)  Commission Decision 2009/767/EC of 16 October 2009 setting out measures facilitating the use of procedures by electronic means through the ‘points of single contact’ under Directive 2006/123/EC of the European Parliament and of the Council on services in the internal market (OJ L 274, 20.10.2009, p. 36).

(11)  Commission Decision 2011/130/EU of 25 February 2011 establishing minimum requirements for the cross-border processing of documents signed electronically by competent authorities under Directive 2006/123/EC of the European Parliament and of the Council on services in the internal market (OJ L 53, 26.2.2011, p. 66).

(12)  Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission’s exercise of implementing powers (OJ L 55, 28.2.2011, p. 13).

(13)  Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (OJ L 8, 12.1.2001, p. 1).

(14)  OJ C 28, 30.1.2013, p. 6.

(15)  Directive 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC (OJ L 94, 28.3.2014, p. 65).


ANNEX I

REQUIREMENTS FOR QUALIFIED CERTIFICATES FOR ELECTRONIC SIGNATURES

Qualified certificates for electronic_signatures shall contain:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

ANNEX II

REQUIREMENTS FOR QUALIFIED ELECTRONIC SIGNATURE CREATION DEVICES

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

ANNEX III

REQUIREMENTS FOR QUALIFIED CERTIFICATES FOR ELECTRONIC SEALS

Qualified certificates for electronic_seals shall contain:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

ANNEX IV

REQUIREMENTS FOR QUALIFIED CERTIFICATES FOR WEBSITE AUTHENTICATION

Qualified certificates for website authentication shall contain:

order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0"> order="0" cellspacing="0" cellpadding="0">

whereas









keyboard_arrow_down