The requirements and technical specifications for RIS should ensure in particular that: RIS data which constitute personal data under Regulation (EU) 2016/679 can be processed solely in accordance with a comprehensive, rights-based access-control system that provides assigned functionalities; all competent authorities can have immediate access to those data in accordance with their respective regulatory competences; appropriate technical and organisational measures are implemented to ensure that the processing by electronic means of personal data can be carried out in accordance with Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 of the European Parliament and of the Council, including for the purposes of protection against personal data breaches; and the processing of sensitive commercial information can be carried out in a way that respects the confidentiality of that information.
Text as published in the Official Journal, reproduced verbatim (including any typographical quirks of the source). For the authentic version, see EUR-Lex.