This document is an excerpt from the EUR-Lex website
Document 02015R1501-20150909
Commission Implementing Regulation (EU) 2015/1501 of 8 September 2015 on the interoperability framework pursuant to Article 12(8) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance)
Consolidated text: Commission Implementing Regulation (EU) 2015/1501 of 8 September 2015 on the interoperability framework pursuant to Article 12(8) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance)
Commission Implementing Regulation (EU) 2015/1501 of 8 September 2015 on the interoperability framework pursuant to Article 12(8) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance)
ELI: http://data.europa.eu/eli/reg_impl/2015/1501/2015-09-09
02015R1501 — EN — 09.09.2015 — 000.001
This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex. Those official texts are directly accessible through the links embedded in this document
COMMISSION IMPLEMENTING REGULATION (EU) 2015/1501 of 8 September 2015 on the interoperability framework pursuant to Article 12(8) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (OJ L 235 9.9.2015, p. 1) |
Corrected by:
COMMISSION IMPLEMENTING REGULATION (EU) 2015/1501
of 8 September 2015
on the interoperability framework pursuant to Article 12(8) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market
(Text with EEA relevance)
Article 1
Subject matter
This Regulation lays down technical and operational requirements of the interoperability framework in order to ensure the interoperability of the electronic identification schemes which Member States notify to the Commission.
Those requirements include in particular:
minimum technical requirements related to the assurance levels and the mapping of national assurance levels of notified electronic identification means issued under notified electronic identification schemes under Article 8 of Regulation (EU) No 910/2014 as set out in Articles 3 and 4;
minimum technical requirements for interoperability, as set out in Articles 5 and 8;
the minimum set of person identification data uniquely representing a natural or legal person as set out in Article 11 and in the Annex;
common operational security standards as set out in Articles 6, 7, 9 and 10;
arrangements for dispute resolution as set out in Article 13.
Article 2
Definitions
For the purposes of this Regulation, the following definitions shall apply:
‘node’ means a connection point which is part of the electronic identification interoperability architecture and is involved in cross-border authentication of persons and which has the capability to recognise and process or forward transmissions to other nodes by enabling the national electronic identification infrastructure of one Member State to interface with national electronic identification infrastructures of other Member States;
‘node operator’ means the entity responsible for ensuring that the node performs correctly and reliably its functions as a connection point.
Article 3
Minimum technical requirements related to the assurance levels
Minimum technical requirements related to the assurance levels shall be as set out in Commission Implementing Regulation (EU) 2015/1502 ( 4 ).
Article 4
Mapping of national assurance levels
The mapping of national assurance levels of the notified electronic identification schemes shall follow the requirements laid down in Implementing Regulation (EU) 2015/1502. ►C1 The results of the mapping shall be notified to the Commission using the notification template laid down in Commission Implementing Decision (EU) 2015/1984 ( 5 ). ◄
Article 5
Nodes
Article 6
Data privacy and confidentiality
Article 7
Data integrity and authenticity for the communication
Communication between the nodes shall ensure data integrity and authenticity to make certain that all requests and responses are authentic and have not been tampered with. For this purpose, nodes shall use solutions which have been successfully employed in cross-border operational use.
Article 8
Message format for the communication
The nodes shall use for syntax common message formats based on standards that have already been deployed more than once between Member States and proven to work in an operational environment. The syntax shall allow:
proper processing of the minimum set of person identification data uniquely representing a natural or legal person;
proper processing of the assurance level of the electronic identification means;
distinction between public sector bodies and other relying parties;
flexibility to meet the needs of additional attributes relating to identification.
Article 9
Management of security information and metadata
The node operator shall store data which, in the event of an incident, enable reconstruction of the sequence of the message exchange for establishing the place and the nature of the incident. The data shall be stored for a period of time in accordance with national requirements and, as a minimum, shall consist of the following elements:
node's identification;
message identification.
message date and time.
Article 10
Information assurance and security standards
Article 11
Person identification data
Article 12
Technical specifications
Article 13
Dispute resolution
Article 14
Entry into force
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
This Regulation shall be binding in its entirety and directly applicable in all Member States
ANNEX
Requirements concerning the minimum set of person identification data uniquely representing a natural or a legal person, referred to in Article 11
1. The minimum data set for a natural person
The minimum data set for a natural person shall contain all of the following mandatory attributes:
current family name(s);
current first name(s);
date of birth;
a unique identifier constructed by the sending Member State in accordance with the technical specifications for the purposes of cross-border identification and which is as persistent as possible in time.
The minimum data set for a natural person may contain one or more of the following additional attributes:
first name(s) and family name(s) at birth;
place of birth;
current address;
gender.
2. The minimum data set for a legal person
The minimum data set for a legal person shall contain all of the following mandatory attributes:
current legal name;
a unique identifier constructed by the sending Member State in accordance with the technical specifications for the purposes of cross-border identification and which is as persistent as possible in time.
The minimum data set for a legal person may contain one or more of the following additional attributes:
current address;
VAT registration number;
tax reference number;
the identifier related to Article 3(1) of Directive 2009/101/EC of the European Parliament and of the Council ( 6 );
Legal Entity Identifier (LEI) referred to in Commission Implementing Regulation (EU) No 1247/2012 ( 7 );
Economic Operator Registration and Identification (EORI) referred to in Commission Implementing Regulation (EU) No 1352/2013 ( 8 );
excise number provided in Article 2(12) of Council Regulation (EC) No 389/2012 ( 9 ).
( 1 ) OJ L 257, 28.8.2014, p. 73.
( 2 ) Regulation (EU) No 1316/2013 of the European Parliament and of the Council of 11 December 2013 establishing the Connecting Europe Facility, amending Regulation (EU) No 913/2010 and repealing Regulations (EC) No 680/2007 and (EC) No 67/2010 (OJ L 348, 20.12.2013, p. 129).
( 3 ) Commission Implementing Decision (EU) 2015/296 of 24 February 2015 establishing procedural arrangements for cooperation between Member States on electronic identification pursuant to Article 12(7) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (OJ L 53, 25.2.2015, p. 14).
( 4 ) Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015 on setting out minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to Article 8(3) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (see page 7 of this Official Journal).
►C1 ( 5 ) Commission Implementing Decision (EU) 2015/1984 of 3 November 2015 defining the circumstances, formats and procedures of notification pursuant to Article 9(5) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (OJ L 289, 5.11.2015, p. 18). ◄
( 6 ) Directive 2009/101/EC of the European Parliament and of the Council of 16 September 2009 on coordination of safeguards which, for the protection of the interests of members and third parties, are required by Member States of companies within the meaning of the second paragraph of Article 48 of the Treaty, with a view to making such safeguards equivalent (OJ L 258, 1.10.2009, p. 11).
( 7 ) Commission Implementing Regulation (EU) No 1247/2012 of 19 December 2012 laying down implementing technical standards with regard to the format and frequency of trade reports to trade repositories according to Regulation (EU) No 648/2012 of the European Parliament and of the Council on OTC derivatives, central counterparties and trade repositories (OJ L 352, 21.12.2012, p. 20).
( 8 ) Commission Implementing Regulation (EU) No 1352/2013 of 4 December 2013 establishing the forms provided for in Regulation (EU) No 608/2013 of the European Parliament and of the Council concerning customs enforcement of intellectual property rights (OJ L 341, 18.12.2013, p. 10).
( 9 ) Council Regulation (EU) No 389/2012 of 2 May 2012 on administrative cooperation in the field of excise duties and repealing Regulation (EC) No 2073/2004 (OJ L 121, 8.5.2012, p. 1).