Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

LIBE-PR-736469 → A-9-2023-0200

From
LIBE-PR-736469 report parliamentary committee draft of 19 Sept 2022
To
A-9-2023-0200 Plenary report of 26 May 2023
Changes
157 changes to the text
Paragraphs
+115 added · −64 removed · 128 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on automated data exchange for police cooperation (“Prüm II”), amending Council Decisions 2008/615/JHA and 2008/616/JHA and Regulations (EU) 2018/1726, 2019/817 and 2019/818 of the European Parliament and of the Council
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on automated data exchange for police cooperation (“Prüm II”), amending Council Decisions 2008/615/JHA and 2008/616/JHA and Regulations (EU) 2018/1726, 2019/817 and 2019/818 of the European Parliament and of the Council

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 5 of 7: Paragraphs 241–300

Change 103

ChangedArticle 49 – paragraph 1: 1. Without prejudice to any restrictions indicated by the provider of the information to Europol in accordance with Article 19(2) of Regulation (EU) 2016/794, Member States shall, in accordance with Regulation (EU) 2016/794, have access to, and be able to search via the router, biometric data which has been provided to Europol by third-countrythird authoritiescountries for the purposes of Article 18(2), points(a),points (a), (b) and (c), of Regulation (EU) 2016/794.

Change 104

ChangedArticle 49 – paragraph 2: 2. Where the search referred to in paragraph 1 results in a match between the data used for the search and third-country-sourced data held by Europol, the follow-up shall take place in accordance with Regulation (EU) 2016/794.

Change 105

ChangedArticle 50 – paragraph 1: 1. Where necessary to achieve itsthe objectives and carryset out its tasks, Europol shall, in accordanceArticle with3 of Regulation (EU) 2016/794, have access, for the purposes of Article 18(2), pointsEuropol (a)shall, andin (c),accordance ofwith Regulation (EU) 2016/794, have access to data which are stored by Member States in their national databases and police records indexes in accordance with this Regulation.

Change 106

ChangedArticle 50 – paragraph 3:4: 3.4. Europol queries performed with vehicle registrationbiographical data as referred to in Article 1825 as a search criterion shall be carried out using Eucaris.EPRIS.

Change 107

ChangedArticle 50 – paragraph 4:5: 4.5. Europol queriesshall performedcarry without the biographicalsearches datain ofaccordance suspectswith andparagraph convicted1 personsof asthis referredArticle toonly infor Articlesthe 25purpose andof 26Article as18(2), apoint search(a), criterionof shallRegulation be(EU) carried2016/794, when carrying out usingits EPRIS.tasks referred to in Regulation (EU) 2016/794.

Change 108

RemovedArticle 50 – paragraph 5: deleted

AddedArticle 50 – paragraph 6 – introductory part: 6. Where the procedures referred to in Article 6, 7, 13 or 22 show a match between the data used for the search or comparison and data held in the national database of the requested Member State(s), and upon human review of that match by qualified staff of Europol in accordance with this Regulation and the transmission of the name of the third country which provided the data, the requested Member State shall decide whether to return a set of core data via the router within 24 hours. Where a judicial authorisation is required under national law, the core data shall be returned within 72 hours. That set of core data, if available, shall contain the following data:

Change 109

ChangedArticle 50 – paragraph 67: –7. introductoryEuropol's part:use 6.of Whereinformation theobtained proceduresfrom referreda tosearch made in Articleaccordance 6,with 7,paragraphs 131 orand 225, showand afrom matchthe betweenexchange theof datacore useddata forin theaccordance searchwith orparagraph comparison6, andshall databe heldsubject into the national databaseconsent of the requested Member State(s), and uponState manualin confirmationwhose ofdatabase thatthe match byoccurred. Europol,If the requested Member State shall decide whether to return a set of core data viaallows the router within 24 hours. Where a judicial authorisation isuse requiredof undersuch nationalinformation, law,its thehandling coreby dataEuropol shall be returned within 72 hours. That set of core data, if available, shallgoverned containby theRegulation following(EU) data:2016/794.

Change 110

RemovedArticle 50 – paragraph 7: 7. Europol's use of information obtained from a search made in accordance with paragraph 1 and from the exchange of core data in accordance with paragraph 6 shall be subject to the consent of the Member State in whose database the match occurred. If the Member State allows the use of such information, its handling by Europol shall be governed by Regulation (EU) 2016/794.

Article 51 – title: Purpose of the data processing

Change 111

ChangedArticle 51 – paragraph 1: 1. Processing of personal data received by the requesting Member State or Europol shall be permitted solely for the purposes for which the data have been supplied by the requested Member State.State Processingin accordance with this Regulation. Without prejudice to Directive (EU) 2016/680 or Regulation (EU) 2018/1725, as applicable, processing for other purposes shall be permitted solely with the prior authorisation of the requested Member State or Europol, as relevant.

Article 51 – paragraph 2 – introductory part: 2. Processing of data supplied pursuant to Article 6, 7, 13, 18, 22 or 26 by the requesting Member State or Europol shall be permitted solely where necessary in order to:

Change 112

ChangedArticle 51 – paragraph 2 – point a a (new): (aa) exchange a set of core data in accordancepursuant withto Article 47;

Article 51 – paragraph 2 – point b: (b) prepare and submit a police or judicial request for legal assistance if those data match;

Article 51 – paragraph 2 – point c: (c) logging within the meaning of Articles 20, 40 and 45.

Change 113

ChangedArticle 51 – paragraph 3: 3. The personal data received by the requesting Member State or Europol shall be deleted immediately following data comparison or automated replies to searches unless further processing is necessary by the requesting Member State is strictly necessary and proportionate for the purposes of the prevention, detection and investigation of criminal offences.

Change 114

ChangedArticle 5251 – paragraph 1: 1. Member States and Europol shall ensure the accuracy and current4: relevance4. ofData personalsupplied datain whichaccordance arewith processedArticle pursuant18 tomay thisbe Regulation.used Shouldby athe requestedrequesting Member State or Europol become aware that incorrect data or data which should not have been supplied have beensolely supplied,where this shallis bestrictly notifiednecessary withoutand delayproportionate to anyachieve requestingthe Memberpurposes State.of Allthis requestingRegulation. MemberThe Statesdata concernedsupplied shall be obliged to correct or delete the data accordinglydeleted withoutimmediately unduefollowing delay.automated Moreover,replies personalto datasearches suppliedunless shallfurther beprocessing correctedis ifnecessary theyfor arerecording foundpursuant to be incorrect.Article If20. theThe requesting Member State or Europol has reason to believeshall thatuse the supplied data arereceived incorrectin ora shouldreply besolely deletedfor the requestedprocedure Memberfor Statewhich shallthe besearch informed.was made.

Change 115

AddedArticle 51 – paragraph 4 a (new): 4a. Prior to connecting their national databases to the router, EPRIS or Eucaris, Member States shall conduct a data protection impact assessment as referred to in Article 27 of Directive (EU) 2016/680 and consult the supervisory authority as referred to in Article 28 of that Directive. The supervisory authority may use any of its powers referred to in Article 47 of Directive (EU) 2016/680, in accordance with paragraph 5 of Article 28 of that Directive.

AddedArticle 51 – paragraph 4 b (new): 4b. Member States shall ensure that data subjects are provided with information pursuant to Article 13 of Directive (EU) 2016/680 to allow them to exercise their rights.

AddedArticle 51 – paragraph 4 c (new): 4c. The European Data Protection Board shall issue guidelines on the implementation of Directive (EU) 2016/680 concerning the criminal databases and cross-border exchanges of personal data, in particular concerning accuracy, strict necessity and how to ensure respect for the right to data protection.

AddedArticle 52 – paragraph 1: 1. Member States and Europol shall ensure the accuracy and current relevance of personal data which are processed pursuant to this Regulation. Should a requested Member State or Europol become aware that data that are incorrect or no longer up to date or data which should not have been supplied have been supplied, this shall be notified without delay to any requesting Member State. All requesting Member States concerned shall be obliged to correct or delete the data accordingly without delay. Moreover, personal data supplied shall be corrected if they are found to be incorrect. If the requesting Member State or Europol has reason to believe that the supplied data are incorrect or should be deleted the requested Member State shall be informed without delay.

AddedArticle 52 – paragraph 1 – subparagraph 1 a (new): Member States and Europol shall put in place appropriate measures for updating their databases, including as regards acquittals of persons whose personal data are in the databases.

Article 52 – paragraph 2: 2. Where a data subject contested the accuracy of data in possession of a Member State or Europol, where the accuracy cannot be reliably established by the Member State concerned or Europol and where it is requested by the data subject, the data concerned shall be marked with a flag. Where such a flag exists, Member States or Europol may remove it only with the permission of the data subject or based on a decision of the competent court or national supervisory authority or the European Data Protection Supervisor, as relevant.

Change 116

ChangedArticle 52 – paragraph 3 – subparagraph 1 – point b: (b) following the expiry of the maximum period for keeping data laid down under the national law of the requested Member State where the requested Member State or Europol informed the requesting Member State of that maximum period at the time of supplying the data;

Change 117

ChangedArticle 52 – paragraph 3 – subparagraph 1 – point b a (new): (ba) following the expiry of the maximum period for keeping data laid down in Regulation (EU) 2016/794.

Change 118

ChangedArticle 52 – paragraph 3 – subparagraph 1:2: Where there is reason to believe that the deletion of data would prejudice the interests of the data subject, the data shall be restricted instead of being deleted. Restricted data shall be processed solely for the purpose which prevented their deletion.

Article 53 – paragraph 2 a (new): 2a. Member States shall be the processors for the processing of personal data via Eucaris.

Article 54 – paragraph 1: 1. Europol, eu-LISA and Member States’ competent law enforcement authorities shall ensure the security of the processing of personal data that takes place pursuant to this Regulation. Europol, eu-LISA and Member States’ competent law enforcement authorities shall cooperate on security-related tasks.

Article 54 – paragraph 2: 2. Without prejudice to Article 91 of Regulation (EU) 2018/1725 and Article 32 of Regulation (EU) 2016/794, eu-LISA and Europol shall take the necessary measures to ensure the security of the router and EPRIS respectively as well as their related communication infrastructure.

Change 119

RemovedArticle 55 – paragraph 3 – subparagraph 1: Without prejudice to Article 34 of Regulation (EU) 2016/794 and Article 92 of Regulation (EU) 2018/1725, Europol shall notify CERT-EU of significant cyber threats, significant vulnerabilities and significant incidents without undue delay and in any event no later than 24 hours after becoming aware of them. Actionable and appropriate technical details of cyber threats, vulnerabilities and incidents that enable proactive detection, incident response or mitigating measures shall be disclosed to CERT-EU without undue delay.

AddedArticle 55 – paragraph 2: 2. Security incidents shall be managed in close cooperation between the Member States concerned or Europol and eu-LISA, as relevant, so as to ensure a quick, effective and proper response.

Change 120

ChangedArticle 55 – paragraph 3 – subparagraph 2: In the event of a security incident inWithout relationprejudice to the centralArticle infrastructure34 of the router and without prejudice toRegulation Articles(EU) 342016/794 and Article 92 of Regulation (EU) 2018/1725, eu-LISAEuropol shall notify CERT-EU of significant cyber threats, significant vulnerabilities and significant incidents without undue delay and in any event no later than 24 hours after becoming aware of them. Actionable and appropriate technical details of cyber threats, vulnerabilities and incidents that enable proactive detection, incident response or mitigating measures shall be disclosed to CERT-EU without undue delay.

Change 121

RemovedArticle 56 – paragraph 1: 1. Member States shall ensure that each authority entitled to use Prüm II takes the measures necessary to monitor its compliance with this Regulation and cooperates, where necessary, with the supervisory authority.

AddedArticle 55 – paragraph 3 – subparagraph 3: In the event of a security incident in relation to the central infrastructure of the router and without prejudice to Article 92 of Regulation (EU) 2018/1725, eu-LISA shall notify CERT-EU of significant cyber threats, significant vulnerabilities and significant incidents without undue delay and in any event no later than 24 hours after becoming aware of them. Actionable and appropriate technical details of cyber threats, vulnerabilities and incidents that enable proactive detection, incident response or mitigating measures shall be disclosed to CERT-EU without undue delay.

Change 122

ChangedArticle 5655 – paragraph 15 –a subparagraph(new): 15a. (new):This EuropolArticle shallis takewithout prejudice to the measuresreporting necessaryobligations pursuant to monitorArticles its92 complianceand with93 thisof Regulation and(EU) shall2018/1725 cooperate,and whereArticles necessary,30 withand the31 Europeanof DataDirective Protection(EU) Supervisor.2016/680.

Change 123

ChangedArticle 56 – paragraph 2: 2.1: The1. dataMember controllersStates shall takeensure thethat necessaryeach measuresauthority entitled to monitoruse thePrüm complianceII oftakes datathe processingmeasures pursuantnecessary to thismonitor Regulation,includingits throughcompliance frequentwith verificationthis ofRegulation theand logscooperates, referredwhere tonecessary, inwith Articlesthe 20,supervisory 40authority. andEuropol 45,shall andtake cooperate,the wheremeasures necessary andto asmonitor appropriate,its withcompliance thewith supervisorythis authoritiesRegulation and shall cooperate, where necessary, with the European Data Protection Supervisor.

Change 124

ChangedArticle 6156 – paragraph 1:2: 1.2. The supervisorydata authoritiescontrollers andshall implement the Europeannecessary Datatechnical Protectionand Supervisororganisational shall,measures eachto actingensure withineffective supervision and monitor the scopecompliance of theirdata respectiveprocessing competences,pursuant cooperateto activelythis withinRegulation, theincluding frameworkthrough offrequent theirverification respectiveof responsibilitiesthe tologs ensurereferred theto coordinatedin supervisionArticles of20, the40 applicationand of45 thisconcerning Regulation,the inadmissibility particularof ifqueries, the Europeanlawfulness Dataof Protectiondata Supervisorprocessing orand adata supervisorysecurity authorityand findsintegrity, majorand discrepanciescooperate, betweenwhere practicesnecessary ofand Memberas Statesappropriate, orwith findsthe potentiallysupervisory unlawfulauthorities transfersand usingwith the PrümEuropean IIData communicationProtection channels.Supervisor.

Change 125

RemovedArticle 62 – title: Transfer of personal data to third countries and international organisations

AddedArticle 56 – paragraph 2 a (new): 2a. The data controllers and Europol shall be provided with adequate human, financial and technical resources to fulfil their tasks pursuant to this Article.

Change 126

ChangedArticle 6258 – paragraph 1: 1.If Aany requestingfailure of a Member State shallto transfercomply anywith dataits itobligations hasunder obtainedthis inRegulation accordancecauses withdamage thisto Regulationthe torouter aor thirdEPRIS, countrythat orMember anState internationalshall organisationbe onlyliable infor accordancesuch withdamage, Chapterunless Vand ofin Directiveso (EU)far 2016/680as andeu-LISA, whereEuropol theor requestedanother Member State hasbound grantedby itsthis authorisationRegulation priorfailed to take reasonable measures to prevent the transfer.damage from occurring or to minimise the impact.

Change 127

ChangedArticle 6259 – paragraph 12: a2. (new):Without 1a.prejudice Europolto shallArticle transfer43(3) anyof dataRegulation it(EU) has2016/794, obtainedeu-LISA inand accordanceEuropol withshall thissupply Regulationinformation requested by the European Data Protection Supervisor to ait, thirdgrant countrythe orEuropean anData internationalProtection organisationSupervisor onlyaccess whereto all the conditionsdocuments laidit downrequests inand Articleto 25their oflogs Regulationreferred (EU)to 2016/794in areArticles fulfilled40 and 45 and allow the requestedEuropean MemberData StateProtection hasSupervisor grantedaccess itsto authorisationall priortheir premises at any time. This paragraph is without prejudice to the transfer.powers of the European Data Protection Supervisor pursuant to Article 58 of Regulation (EU) 2018/1725.

Change 128

RemovedArticle 63 – paragraph 1 – point g: (g) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to the router in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;

AddedArticle 59 – paragraph 2 a (new): 2a. The European Data Protection Supervisor shall be provided with the staff and financial resources necessary to carry out the audits referred to in paragraph 1.

RemovedArticle 63 – paragraph 1 – point h: (h) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to EPRIS in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;

AddedArticle 60 – paragraph 1: 1. The supervisory authorities and the European Data Protection Supervisor shall, each acting within the scope of their respective competences, cooperate actively within the framework of their respective responsibilities to ensure the coordinated supervision of the application of this Regulation, in particular if the European Data Protection Supervisor or a supervisory authority finds major discrepancies between practices of Member States or finds potentially unlawful transfers using the Prüm II communication channels.

RemovedArticle 63 – paragraph 1 – point i: (i) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to Eucaris in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;

AddedArticle 60 – paragraph 3: 3. The European Data Protection Supervisor and the European Data Protection Board shall send a joint report of its activities under this Article to the European Parliament, to the Council, to the Commission, to Europol and to eu-LISA by 2 years after entry into operation of the router and EPRIS and every two years thereafter. That report shall include a chapter on each Member State prepared by the supervisory authority of the Member State concerned.

RemovedArticle 63 – paragraph 1 – point m: (m) correcting or deleting any data received from a requested Member State within 48 hours following the notification from the requested Member State that the personal data submitted was incorrect, no longer up-to-date or was unlawfully transmitted.

AddedArticle 61 – title: Transfer of personal data to third countries and international organisations

RemovedArticle 63 – paragraph 2: 2. Each Member State shall be responsible for connecting its competent national law enforcement authorities to the router, EPRIS and Eucaris.

AddedArticle 61 – paragraph 1: A requesting Member State shall transfer personal data it has obtained in accordance with this Regulation to a third country or an international organisation only in accordance with Chapter V of Directive (EU) 2016/680 and where the requested Member State has granted its authorisation prior to the transfer.

Change 129

ChangedArticle 6461 – paragraph 3:1 3.a Without(new): prejudiceEuropol toshall Articletransfer 26(6c)personal ofany Regulationdata (EU)it 2016/794has andobtained Europol’sin searchesaccordance pursuantwith this Regulation to Articlea 50(4)third ofcountry thisor Regulation,an Europolinternational shallorganisation notonly havewhere accessthe toconditions anylaid down in Article 25 of Regulation (EU) 2016/794 are fulfilled and the personalrequested dataMember processedState throughhas EPRIS.granted its authorisation prior to the transfer.

Change 130

RemovedArticle 66 – paragraph 1 – subparagraph 2: The router shall be developed and managed in such a way as to ensure fast, efficient and controlled access, full and uninterrupted availability of the router, and a response time in line with the operational needs of the competent law enforcement authorities of the Member States and Europol.

AddedArticle 61 a (new): Article 61 a / Relation to other legal acts on data protection / Any processing of personal data for the purposes of this Regulation shall be carried out in compliance with this Chapter and with Directive (EU) 2016/680, Regulation (EU) 2018/1725 or Regulation (EU) 2016/794, as applicable.

AddedArticle 62 – paragraph 1 – point g: (g) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to the router in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;

AddedArticle 62 – paragraph 1 – point h: (h) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to EPRIS in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;

AddedArticle 62 – paragraph 1 – point i: (i) the management of, and arrangements for, access by the duly authorised staff of the competent national law enforcement authorities to Eucaris in accordance with this Regulation and the creation and regular update of a list of those staff and their profiles;

AddedArticle 62 – paragraph 1 – point j: (j) the human confirmation by qualified staff of a match as referred to in Article 6(3), Article 7(3), Article 13(2) and Article 22(2);

AddedArticle 62 – paragraph 1 – point m: (m) correcting, updating or deleting any data received from a requested Member State within 24 hours following the notification from the requested Member State that the personal data submitted was incorrect, is no longer up-to-date or was unlawfully transmitted.

AddedArticle 62 – paragraph 2: 2. Each Member State shall be responsible for connecting their competent national law enforcement authorities to the router, EPRIS and Eucaris.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2023). “Changes between LIBE-PR-736469 and A-9-2023-0200”. Text, 26 May 2023. from LIBE-PR-736469, to A-9-2023-0200. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-736469/compare/A-9-2023-0200?all=1&part=5 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-05-26,
  author = {{European Parliament}},
  title = {{Changes between LIBE-PR-736469 and A-9-2023-0200}},
  year = {2023},
  date = {2023-05-26},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-736469/compare/A-9-2023-0200?all=1&part=5}},
  url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-736469/compare/A-9-2023-0200?all=1&part=5},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from LIBE-PR-736469, to A-9-2023-0200. Data: European Parliament Open Data (CC BY 4.0)}
}