Legal provisions of COM(2017)352 - European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice

Please note

This page contains a limited version of this dossier in the EU Monitor.



CHAPTER I

SUBJECT MATTER AND OBJECTIVES

Article 1

Subject matter

1. A European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (the Agency) is hereby established.

2. The Agency, as established by this Regulation, shall replace and succeed the European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice, as established by Regulation (EU) No 1077/2011.

3. The Agency shall be responsible for the operational management of the Schengen Information System (SIS II), the Visa Information System (VIS) and Eurodac.

4. The Agency shall be responsible for the preparation, development or operational management of the Entry/Exit System (EES), DubliNet, and the European Travel Information and Authorisation System (ETIAS).

5. The Agency may be made responsible for the preparation, development or operational management of large-scale IT systems in the area of freedom, security and justice other than those referred to in paragraphs 3 and 4 of this Article, including existing systems, only if so provided by relevant Union legal acts governing those systems, based on Articles 67 to 89 TFEU, taking into account, where appropriate, the developments in research referred to in Article 14 of this Regulation and the results of pilot projects and proofs of concept referred to in Article 15 of this Regulation.

6. Operational management shall consist of all the tasks necessary to keep large-scale IT systems functioning in accordance with the specific provisions applicable to each of them, including responsibility for the communication infrastructure used by them. Those large-scale IT systems shall not exchange data or enable sharing of information or knowledge, unless so provided in a specific Union legal act.

7. The Agency shall also be responsible for the following tasks:

(a)ensuring data quality in accordance with Article 12;

(b)developing the necessary actions to enable interoperability in accordance with Article 13;

(c)carrying out research activities in accordance with Article 14;

(d)carrying out pilot projects, proofs of concept and testing activities in accordance with Article 15; and

(e)providing support to Member States and the Commission in accordance with Article 16.

Article 2

Objectives

Without prejudice to the respective responsibilities of the Commission and of the Member States under the Union legal acts governing large-scale IT systems, the Agency shall ensure:

(a)the development of large-scale IT systems using an adequate project management structure for efficiently developing such systems;

(b)the effective, secure and continuous operation of large-scale IT systems;

(c)the efficient and financially accountable management of large-scale IT systems;

(d)an adequately high quality of service for users of large-scale IT systems;

(e)continuity and uninterrupted service;

(f)a high level of data protection, in accordance with Union data protection law, including specific provisions for each large-scale IT system;

(g)an appropriate level of data and physical security, in accordance with the applicable rules, including specific provisions for each large-scale IT system.

CHAPTER II

TASKS OF THE AGENCY

Article 3

Tasks relating to SIS II

In relation to SIS II, the Agency shall perform:

(a)the tasks conferred on the Management Authority by Regulation (EC) No 1987/2006 and Decision 2007/533/JHA; and

(b)tasks relating to training on the technical use of SIS II, in particular for SIRENE staff (SIRENE — Supplementary Information Request at the National Entries), and training of experts on the technical aspects of SIS II in the framework of Schengen evaluation.

Article 4

Tasks relating to the VIS

In relation to the VIS, the Agency shall perform:

(a)the tasks conferred on the Management Authority by Regulation (EC) No 767/2008 and Decision 2008/633/JHA; and

(b)tasks relating to training on the technical use of the VIS and training of experts on the technical aspects of the VIS in the framework of Schengen evaluation.

Article 5

Tasks relating to Eurodac

In relation to Eurodac, the Agency shall perform:

(a)the tasks conferred on it by Regulation (EU) No 603/2013; and

(b)tasks relating to training on the technical use of Eurodac.

Article 6

Tasks relating to the EES

In relation to the EES, the Agency shall perform:

(a)the tasks conferred on it by Regulation (EU) 2017/2226; and

(b)tasks relating to training on the technical use of the EES and training of experts on the technical aspects of the EES in the framework of Schengen evaluation.

Article 7

Tasks relating to ETIAS

In relation to ETIAS, the Agency shall perform:

(a)the tasks conferred on it by Regulation (EU) 2018/1240; and

(b)tasks relating to training on the technical use of ETIAS and training of experts on the technical aspects of ETIAS in the framework of Schengen evaluation.

Article 8

Tasks relating to DubliNet

In relation to DubliNet, the Agency shall perform:

(a)the operational management of DubliNet, a separate secure electronic transmission channel between the authorities of Member States, set up under Article 18 of Regulation (EC) No 1560/2003, for the purposes of Articles 31, 32 and 34 of Regulation (EU) No 604/2013 of the European Parliament and of the Council (43); and

(b)tasks relating to training on the technical use of DubliNet.

Article 9

Tasks relating to the preparation, development and operational management of other large-scale IT systems

When entrusted with the preparation, development or operational management of other large-scale IT systems referred to in Article 1(5), the Agency shall perform the tasks conferred on it pursuant to the Union legal act governing the relevant system, as well as tasks relating to training on the technical use of those systems, as appropriate.

Article 10

Technical solutions requiring specific conditions before implementation

Where the Union legal acts governing the systems require the Agency to keep those systems functioning 24 hours a day, 7 days a week and without prejudice to those Union legal acts, the Agency shall implement technical solutions to meet those requirements. Where those technical solutions require a duplication of a system or a duplication of components of a system, they shall only be implemented where an independent impact assessment and cost-benefit analysis to be commissioned by the Agency has been carried out and following the consultation of the Commission and the positive decision of the Management Board. The impact assessment shall also examine existing and future needs in terms of the hosting capacity of the existing technical sites related to the development of such technical solutions and the possible risks related to the current operational set up.

Article 11

Tasks relating to the communication infrastructure

1. The Agency shall carry out all the tasks relating to the communication infrastructure of the systems conferred on it by the Union legal acts governing the systems, with the exception of those systems that make use of the EuroDomain for their communication infrastructure. In the case of those systems that make such use of the EuroDomain, the Commission shall be responsible for the tasks of the implementation of the budget, acquisition and renewal, and contractual matters. In accordance with the Union legal acts governing the systems using the EuroDomain, the tasks regarding the communication infrastructure, including the operational management and security, are to be divided between the Agency and the Commission. In order to ensure coherence between the exercise of their respective responsibilities, operational working arrangements shall be concluded between the Agency and the Commission and reflected in a memorandum of understanding.

2. The communication infrastructure shall be adequately managed and controlled in such a way as to protect it from threats and to ensure its security and that of the systems, including that of data exchanged through the communication infrastructure.

3. The Agency shall adopt appropriate measures, including security plans, inter alia, to prevent the unauthorised reading, copying, modification or deletion of personal data during transfers of personal data or transport of data media, in particular by means of appropriate encryption techniques. All system-related operational information circulating in the communication infrastructure shall be encrypted.

4. Tasks relating to the delivery, setting up, maintenance and monitoring of the communication infrastructure may be entrusted to external private-sector entities or bodies in accordance with Regulation (EU, Euratom) 2018/1046. Such tasks shall be carried out under the responsibility of the Agency and under its close supervision.

When carrying out the tasks referred to in the first subparagraph, all external private-sector entities or bodies, including network providers, shall be bound by the security measures referred to in paragraph 3 and shall have no access, by any means, to any operational data stored in the systems or transferred through the communication infrastructure or to the SIS II-related SIRENE exchange.

5. The management of the encryption keys shall remain within the competence of the Agency and shall not be outsourced to any external private-sector entity. This is without prejudice to the existing contracts on the communication infrastructures of SIS II, the VIS and Eurodac.

Article 12

Data quality

Without prejudice to Member States’ responsibilities with regard to the data entered into the systems, the Agency, closely involving its Advisory Groups, together with the Commission, shall work towards establishing for all the systems automated data quality control mechanisms and common data quality indicators and towards developing a central repository containing only anonymised data for reporting and statistics, subject to specific provisions in the Union legal acts governing the development, establishment, operation and use of the systems.

Article 13

Interoperability

Where interoperability of large-scale IT systems has been stipulated in a relevant Union legal act, the Agency shall develop the necessary actions to enable that interoperability.

Article 14

Monitoring of research

1. The Agency shall monitor developments in research relevant for the operational management of SIS II, the VIS, Eurodac, the EES, ETIAS, DubliNet and other large-scale IT systems as referred to in Article 1(5).

2. The Agency may contribute to the implementation of the parts of the European Union Framework Programme for Research and Innovation that relate to large-scale IT systems in the area of freedom, security and justice. For that purpose, and where the Commission has delegated the relevant powers to it, the Agency shall have the following tasks:

(a)managing some stages of programme implementation and some phases in the lifetime of specific projects on the basis of the relevant work programmes adopted by the Commission;

(b)adopting the instruments of budget execution and for revenue and expenditure and carrying out all the operations necessary for the management of the programme; and

(c)providing support in programme implementation.

3. The Agency shall, on a regular basis and at least once a year, keep the European Parliament, the Council, the Commission, and, where processing of personal data is concerned, the European Data Protection Supervisor, informed on the developments referred to in this Article without prejudice to the reporting requirements in relation to the implementation of parts of the European Union Framework Programme for Research and Innovation referred to in paragraph 2.

Article 15

Pilot projects, proofs of concept and testing activities

1. Upon the specific and precise request of the Commission, which shall have informed the European Parliament and the Council at least three months in advance of making such a request, and after a positive decision of the Management Board, the Agency may, in accordance with point (u) of Article 19(1) of this Regulation and by way of a delegation agreement be entrusted with carrying out pilot projects as referred to in point (a) of Article 58(2) of Regulation (EU, Euratom) 2018/1046 for the development or the operational management of large-scale IT systems pursuant to Articles 67 to 89 TFEU in accordance with point (c) of Article 62(1) of Regulation (EU, Euratom) 2018/1046.

The Agency shall keep the European Parliament, the Council and, where the processing of personal data is concerned, the European Data Protection Supervisor informed on a regular basis of the evolution of the pilot projects carried out by the Agency under the first subparagraph.

2. Financial appropriations for pilot projects as referred to in point (a) of Article 58(2) of Regulation (EU, Euratom) 2018/1046, that have been requested by the Commission under paragraph 1, shall be entered in the budget for no more than two consecutive financial years.

3. At the request of the Commission or the Council, after having informed the European Parliament and after a positive decision of the Management Board, the Agency may be entrusted, by way of a delegation agreement, with budget implementation tasks for proofs of concept funded under the instrument for financial support for external borders and visa established by Regulation (EU) No 515/2014 in accordance with point (c) of Article 62(1) of Regulation (EU, Euratom) 2018/1046.

4. Following a positive decision of the Management Board, the Agency may plan and implement testing activities on matters covered by this Regulation and by any of the Union legal acts governing the development, establishment, operation and use of the systems.

Article 16

Support to Member States and the Commission

1. Any Member State may request the Agency to provide advice with regard to the connection of its national system to the central systems of the large-scale IT systems managed by the Agency.

2. Any Member State may submit a request for ad hoc support to the Commission, which, subject to its positive assessment that such support is required by virtue of extraordinary security or migratory needs, shall transmit it, without delay, to the Agency. The Agency shall inform the Management Board of such requests. The Member State shall be informed where the Commission’s assessment is negative.

The Commission shall monitor whether the Agency has provided a timely response to the Member State's request. The Agency’s annual activity report shall report in detail on the actions the Agency has carried out to provide ad hoc support to Member States and on the costs incurred in that respect.

3. The Agency may also be requested to provide advice or support to the Commission on technical issues related to existing or new systems, including by way of studies and testing. The Agency shall inform the Management Board of such requests.

4. A group of at least five Member States may entrust the Agency with the task of developing, managing or hosting a common IT component to assist them in implementing technical aspects of obligations deriving from Union law on decentralised systems in the area of freedom, security and justice. Those common IT solutions shall be without prejudice to the obligations of the requesting Member States under the applicable Union law, in particular with regard to the architecture of those systems.

In particular, the requesting Member States may entrust the Agency with the task of establishing a common component or router for advance passenger information and passenger name record data as a technical support tool to facilitate connectivity with air carriers in order to assist Member States in the implementation of Council Directive 2004/82/EC (44) and Directive (EU) 2016/681 of the European Parliament and of the Council (45). In such a case the Agency shall centrally collect the data from air carriers and transmit those data to the Member States via the common component or router. The requesting Member States shall adopt the necessary measures to ensure that air carriers transfer the data via the Agency.

The Agency shall be entrusted with the task of developing, managing or hosting a common IT component only after prior approval by the Commission and subject to a positive decision of the Management Board.

The requesting Member States shall entrust the Agency with the tasks referred to in the first and second subparagraphs by way of a delegation agreement setting out the conditions for the delegation of the tasks and the calculation of all relevant costs and the invoicing method. All relevant costs shall be covered by the participating Member States. The delegation agreement shall comply with the Union legal acts governing the systems in question. The Agency shall inform the European Parliament and the Council of the approved delegation agreement and of any modifications thereto.

Other Member States may request to participate in a common IT solution where this possibility is provided for in the delegation agreement setting out, in particular, the financial implications of such participation. The delegation agreement shall be modified accordingly following the prior approval by the Commission and after a positive decision of the Management Board.

CHAPTER III

STRUCTURE AND ORGANISATION

Article 17

Legal status and location

1. The Agency shall be a body of the Union and shall have legal personality.

2. The Agency shall enjoy the most extensive legal capacity accorded to legal persons under national law in each Member State. It may, in particular, acquire or dispose of movable and immovable property and may be a party to legal proceedings.

3. The seat of the Agency shall be Tallinn, Estonia.

The tasks relating to development and operational management referred to in Article 1(4) and (5) and Articles 3, 4, 5, 6, 7, 8, 9 and 11 shall be carried out at the technical site in Strasbourg, France.

A backup site capable of ensuring the operation of a large-scale IT system in the event of failure of such a system shall be installed in Sankt Johann im Pongau, Austria.

4. Both technical sites may be used for the simultaneous operation of the systems, provided that the backup site remains capable of ensuring their operation in the event of the failure of one or more of the systems.

5. Due to the specific nature of the systems, should it become necessary for the Agency to establish a second separate technical site either in Strasbourg or in Sankt Johann im Pongau, or in both locations, as required, in order to host the systems, such need shall be justified on the basis of an independent impact assessment and cost-benefit analysis. The Management Board shall consult the Commission and take into account its views before notifying the budgetary authority of its intention to implement any project related to property in accordance with Article 45(9).

Article 18

Structure

1. The administrative and management structure of the Agency shall comprise:

(a)a Management Board;

(b)an Executive Director;

(c)Advisory Groups.

2. The structure of the Agency shall include:

(a)a data protection officer;

(b)a security officer;

(c)an accounting officer.

Article 19

Functions of the Management Board

1. The Management Board shall:

(a)provide the general orientation for the Agency’s activities;

(b)adopt, by a majority of two-thirds of members entitled to vote, the annual budget of the Agency and exercise other functions in respect of the Agency’s budget pursuant to Chapter V;

(c)appoint the Executive Director and the Deputy Executive Director and, where relevant, extend their respective terms of office or remove them from office in accordance with Articles 25 and 26 respectively;

(d)exercise disciplinary authority over the Executive Director and oversee his or her performance, including the implementation of the Management Board’s decisions, and exercise disciplinary authority over the Deputy Executive Director in agreement with the Executive Director;

(e)take all decisions on the establishment of the Agency’s organisational structure and, where necessary, its modification, taking into consideration the Agency’s activity needs and having regard to sound budgetary management;

(f)adopt the Agency’s staff policy;

(g)establish the Agency’s rules of procedure;

(h)adopt an anti-fraud strategy, proportionate to the risk of fraud, taking into account the costs and benefits of the measures to be implemented;

(i)adopt rules for the prevention and management of conflicts of interest in respect of its members and publish them on the Agency’s website;

(j)adopt detailed internal rules and procedures for the protection of whistleblowers, including appropriate channels of communication for reporting misconduct;

(k)authorise the conclusion of working arrangements in accordance with Articles 41 and 43;

(l)approve, following a proposal by the Executive Director, the Headquarters Agreement concerning the seat of the Agency and the agreements concerning the technical and backup sites, set up in accordance with Article 17(3), to be signed by the Executive Director and the host Member States;

(m)exercise, in accordance with paragraph 2, with respect to the staff of the Agency, the powers conferred by the Staff Regulations of Officials on the Appointing Authority and by the Conditions of Employment of Other Servants on the Authority Empowered to Conclude a Contract of Employment (‘the appointing authority powers’);

(n)adopt, in agreement with the Commission, the necessary implementing rules for giving effect to the Staff Regulations in accordance with Article 110 of the Staff Regulations of Officials;

(o)adopt the necessary rules on the secondment of national experts to the Agency;

(p)adopt a draft estimate of the Agency’s revenue and expenditure, including the draft establishment plan, and submit them by 31 January each year to the Commission;

(q)adopt the draft single programming document, containing the Agency’s multiannual programming and its work programme for the following year and a provisional draft estimate of the Agency’s revenue and expenditure, including the draft establishment plan, and submit it by 31 January each year, as well as any updated version of that document, to the European Parliament, to the Council and to the Commission;

(r)adopt, before 30 November each year, by a two-thirds majority of its members with the right to vote, and in accordance with the annual budgetary procedure, the single programming document taking into account the opinion of the Commission and ensure that the definitive version of this single programming document is transmitted to the European Parliament, to the Council and to the Commission and is published;

(s)adopt an interim report by the end of August of each year on the progress of the implementation of the planned activities for the current year and submit it to the European Parliament, to the Council and to the Commission;

(t)assess and adopt the consolidated annual activity report of the Agency’s activities for the previous year, comparing, in particular, the results achieved with the objectives of the annual work programme, and send both the report and its assessment by 1 July of each year to the European Parliament, to the Council, to the Commission and to the Court of Auditors and ensure that the annual activity report is published;

(u)carry out its functions relating to the Agency’s budget, including the implementation of pilot projects and proofs of concept as referred to in Article 15;

(v)adopt the financial rules applicable to the Agency in accordance with Article 49;

(w)appoint an accounting officer, who may be the Commission’s accounting officer, subject to the Staff Regulations, who shall be completely independent in the performance of his or her duties;

(x)ensure adequate follow-up to the findings and recommendations stemming from the various internal or external audit reports and evaluations as well as from investigations by the European Anti-Fraud Office (OLAF) and the European Public Prosecutor’s Office (EPPO);

(y)adopt the communication and dissemination plans referred to in Article 34(4) and regularly update them;

(z)adopt the necessary security measures, including a security plan and a business continuity and disaster recovery plan, taking into account the possible recommendations of the security experts present in the Advisory Groups;

(aa)adopt the security rules on the protection of classified information and non-classified sensitive information following approval by the Commission;

(bb)appoint a security officer;

(cc)appoint a data protection officer in accordance with Regulation (EU) 2018/1725;

(dd)adopt the detailed rules for implementing Regulation (EC) No 1049/2001;

(ee)adopt the reports on the development of the EES pursuant to Article 72(2) of Regulation (EU) 2017/2226 and the reports on the development of ETIAS pursuant to Article 92(2) of Regulation (EU) 2018/1240;

(ff)adopt the reports on the technical functioning of SIS II pursuant to Article 50(4) of Regulation (EC) No 1987/2006 and Article 66(4) of Decision 2007/533/JHA respectively, of the VIS pursuant to Article 50(3) of Regulation (EC) No 767/2008 and Article 17(3) of Decision 2008/633/JHA, of the EES pursuant to Article 72(4) of Regulation (EU) 2017/2226 and of ETIAS pursuant to Article 92(4) of Regulation (EU) 2018/1240;

(gg)adopt the annual report on the activities of the Central System of Eurodac pursuant to Article 40(1) of Regulation (EU) No 603/2013;

(hh)adopt formal comments on the European Data Protection Supervisor’s reports on the audits carried out pursuant to Article 45(2) of Regulation (EC) No 1987/2006, Article 42(2) of Regulation (EC) No 767/2008 and Article 31(2) of Regulation (EU) No 603/2013, Article 56(2) of Regulation (EU) 2017/2226 and Article 67 of Regulation (EU) 2018/1240 and ensure appropriate follow-up of those audits;

(ii)publish statistics related to SIS II pursuant to Article 50(3) of Regulation (EC) No 1987/2006 and Article 66(3) of Decision 2007/533/JHA respectively;

(jj)compile and publish statistics on the work of the Central System of Eurodac pursuant to Article 8(2) of Regulation (EU) No 603/2013;

(kk)publish statistics related to the EES pursuant to Article 63 of Regulation (EU) 2017/2226;

(ll)publish statistics related to ETIAS pursuant to Article 84 of Regulation (EU) 2018/1240;

(mm)ensure annual publication of the list of competent authorities authorised to search directly the data contained in SIS II pursuant to Article 31(8) of Regulation (EC) No 1987/2006 and Article 46(8) of Decision 2007/533/JHA, together with the list of Offices of the national systems of SIS II (N.SIS II Offices) and SIRENE Bureaux pursuant to Article 7(3) of Regulation (EC) No 1987/2006 and Article 7(3) of Decision 2007/533/JHA respectively as well as the list of competent authorities pursuant to Article 65(2) of Regulation (EU) 2017/2226 and the list of competent authorities pursuant to Article 87(2) of Regulation (EU) 2018/1240;

(nn)ensure annual publication of the list of units pursuant to Article 27(2) of Regulation (EU) No 603/2013;

(oo)ensure that all decisions and actions of the Agency affecting large-scale IT systems in the area of freedom, security and justice respect the principle of independence of the judiciary;

(pp)perform any other tasks conferred on it in accordance with this Regulation.

Without prejudice to the provisions on publication of the lists of relevant authorities provided for in the Union legal acts referred to in point (mm) of the first subparagraph and where an obligation to publish and continuously update those lists on the Agency’s website is not provided for in those legal acts, the Management Board shall ensure such publication and continuous update.

2. The Management Board shall adopt, in accordance with Article 110 of the Staff Regulations of Officials, a decision based on Article 2(1) of the Staff Regulations of Officials and on Article 6 of the Conditions of Employment of Other Servants delegating relevant appointing authority powers to the Executive Director and defining the conditions under which this delegation of powers can be suspended. The Executive Director shall be authorised to sub-delegate those powers.

Where exceptional circumstances so require, the Management Board may, by way of a decision, temporarily suspend the delegation of the appointing authority powers to the Executive Director and those sub-delegated by him or her and exercise them itself or delegate them to one of its members or to a staff member other than the Executive Director.

3. The Management Board may advise the Executive Director on any matter strictly related to the development or operational management of large-scale IT systems and on activities related to research, pilot projects, proofs of concept and testing activities.

Article 20

Composition of the Management Board

1. The Management Board shall be composed of one representative of each Member State and two representatives of the Commission. Each representative shall have a right to vote in accordance with Article 23.

2. Each member of the Management Board shall have an alternate. The alternate shall represent the member in his or her absence or in the event that the member is elected Chairperson or Deputy Chairperson of the Management Board and is chairing the Management Board meeting. The members of the Management Board and their alternates shall be appointed on the basis of the high level of their relevant experience and expertise in the field of large-scale IT systems in the area of freedom, security and justice, and their knowledge with respect to data protection, taking into account their relevant managerial, administrative and budgetary skills. All parties represented on the Management Board shall make efforts to limit the turnover of their representatives in order to ensure continuity of the Management Board’s work. All parties shall aim to achieve a balanced representation between men and women on the Management Board.

3. The term of office of the members and their alternates shall be four years and shall be renewable. Upon expiry of their terms of office or in the event of their resignation, members shall remain in office until their appointments are renewed or until they are replaced.

4. Countries associated with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures shall participate in the activities of the Agency. They shall each appoint one representative and an alternate to the Management Board.

Article 21

Chairperson of the Management Board

1. The Management Board shall elect a Chairperson and a Deputy Chairperson from among those members of the Management Board that are appointed by Member States which are fully bound under Union law by all the Union legal acts governing the development, establishment, operation and use of all the large-scale IT systems managed by the Agency. The Chairperson and the Deputy Chairperson shall be elected by a majority of two-thirds of the members of the Management Board with the right to vote.

The Deputy Chairperson shall automatically replace the Chairperson if he or she is prevented from attending to his or her duties.

2. The term of office of the Chairperson and the Deputy Chairperson shall be four years. Their terms of office may be renewed once. Where their membership of the Management Board ends at any time during their term of office, their term of office shall automatically expire on that date.

Article 22

Meetings of the Management Board

1. The Chairperson shall convene the meetings of the Management Board.

2. The Executive Director shall take part in the deliberations, without the right to vote.

3. The Management Board shall hold at least two ordinary meetings a year. In addition, it shall meet on the initiative of its Chairperson, at the request of the Commission, at the request of the Executive Director or at the request of at least one third of the members of the Management Board with the right to vote.

4. Europol and Eurojust may attend the meetings of the Management Board as observers when a question concerning SIS II in relation to the application of Decision 2007/533/JHA is on the agenda. The European Border and Coast Guard Agency may attend the meetings of the Management Board as observer when a question concerning SIS II in relation to the application of Regulation (EU) 2016/1624 is on the agenda.

Europol may attend the meetings of the Management Board as observer when a question concerning the VIS in relation to the application of Decision 2008/633/JHA or a question concerning Eurodac in relation to the application of Regulation (EU) No 603/2013 is on the agenda.

Europol may attend the meetings of the Management Board as observer when a question concerning the EES in relation to the application of Regulation (EC) No 2017/2226 is on the agenda or when a question concerning ETIAS in relation to Regulation (EU) 2018/1240 is on the agenda. The European Border and Coast Guard Agency may also attend the meetings of the Management Board as observer when a question concerning ETIAS in relation with the application of Regulation (EU) 2018/1240 is on the agenda.

The Management Board may invite any other person whose opinion may be of interest to attend its meetings as an observer.

5. The members of the Management Board and their alternates may be assisted by advisers or experts, subject to the rules of procedure for the Management Board, in particular those that are members of the Advisory Groups.

6. The Agency shall provide the secretariat for the Management Board.

Article 23

Voting rules of the Management Board

1. Without prejudice to paragraph 5 of this Article, and to points (b) and (r) of Article 19(1), Article 21(1) and Article 25(8), decisions of the Management Board shall be taken by a majority of its members with the right to vote.

2. Without prejudice to paragraphs 3 and 4, each member of the Management Board shall have one vote. In the absence of a member with the right to vote, his or her alternate shall be entitled to exercise his or her right to vote.

3. Each member appointed by a Member State which is bound under Union law by any Union legal act governing the development, establishment, operation and use of a large-scale IT system managed by the Agency may vote on a question which concerns that large-scale IT system.

Denmark may vote on a question which concerns a large-scale IT system if it decides under Article 4 of the Protocol No 22 to implement the Union legal act governing the development, establishment, operation and use of that particular large-scale IT system in its national law.

4. Article 42 shall apply as regards the voting rights of the representatives of countries that have entered into agreements with the Union on their association with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures.

5. In the event of a disagreement among members about whether a vote concerns a specific large-scale IT system, any decision which finds that this vote does not concern that specific large-scale IT system shall be taken by a two-thirds majority of the members of the Management Board with the right to vote.

6. The Chairperson, or the Deputy Chairperson when he or she is replacing the Chairperson, shall not vote. The right to vote of the Chairperson, or of the Deputy Chairperson when he or she is replacing the Chairperson, shall be exercised by his or her alternate member.

7. The Executive Director shall not vote.

8. The rules of procedure for the Management Board shall establish more detailed voting arrangements, in particular the conditions under which a member may act on behalf of another member and any quorum requirements, where appropriate.

Article 24

Responsibilities of the Executive Director

1. The Executive Director shall manage the Agency. The Executive Director shall assist and be accountable to the Management Board. The Executive Director shall report to the European Parliament on the performance of his or her duties when invited to do so. The Council may invite the Executive Director to report on the performance of his or her duties.

2. The Executive Director shall be the legal representative of the Agency.

3. The Executive Director shall be responsible for the implementation of tasks assigned to the Agency by this Regulation. In particular, the Executive Director shall be responsible for:

(a)the day-to-day administration of the Agency;

(b)the operation of the Agency in accordance with this Regulation;

(c)preparing and implementing the procedures, decisions, strategies, programmes and activities adopted by the Management Board, within the limits set out by this Regulation, its implementing rules and the applicable Union law;

(d)preparing the single programming document and submitting it to the Management Board after consulting the Commission and the Advisory Groups;

(e)implementing the single programming document and reporting to the Management Board on its implementation;

(f)preparing the interim report on the progress of the implementation of the planned activities for the current year and, after consulting the Advisory Groups, submitting it to the Management Board for adoption by the end of August of each year;

(g)preparing the consolidated annual report of the Agency’s activities and, after consulting the Advisory Groups, submitting it to the Management Board for assessment and adoption;

(h)preparing an action plan following up on the conclusions of internal or external audit reports and evaluations, as well as on investigations by OLAF and by the EPPO, and reporting on progress twice a year to the Commission and regularly to the Management Board;

(i)protecting the financial interests of the Union by applying preventive measures against fraud, corruption and any other illegal activities, without prejudicing the investigative competence of the EPPO and OLAF, by effective checks and, if irregularities are detected, by recovering amounts wrongly paid and, where appropriate, by imposing effective, proportionate and dissuasive administrative, including financial, penalties;

(j)preparing an anti-fraud strategy for the Agency and submitting it to the Management Board for approval as well as monitoring the proper and timely implementation of that strategy;

(k)preparing draft financial rules applicable to the Agency and submitting them to the Management Board for adoption after consulting the Commission;

(l)preparing the draft budget for the following year, established on the basis of activity-based budgeting;

(m)preparing the Agency’s draft statement of estimates of revenue and expenditure;

(n)implementing the budget of the Agency;

(o)establishing and implementing an effective system to enable the regular monitoring and evaluation of:

(i)large-scale IT systems, including statistics, and

(ii)the Agency, including the effective and efficient achievement of its objectives;

(p)establishing, without prejudice to Article 17 of the Staff Regulations of Officials, confidentiality requirements in order to comply with Article 17 of Regulation (EC) No 1987/2006, Article 17 of Decision 2007/533/JHA, Article 26(9) of Regulation (EC) No 767/2008, Article 4(4) of Regulation (EU) No 603/2013; Article 37(4) of Regulation (EC) No 2017/2226 and Article 74(2) of Regulation (EU) 2018/1240;

(q)negotiating and, after approval by the Management Board, signing a Headquarters Agreement concerning the seat of the Agency and agreements concerning the technical and backup sites with the host Member States;

(r)preparing the practical arrangements for implementing Regulation (EC) No 1049/2001 and submitting them to the Management Board for adoption;

(s)preparing the necessary security measures, including a security plan and a business continuity and disaster recovery plan, and, after consulting the relevant Advisory Group, submitting them to the Management Board for adoption;

(t)preparing the reports on the technical functioning of each large-scale IT system referred to in point (ff) of Article 19(1) and the annual report on the activities of the Central System of Eurodac referred to in point (gg) of Article 19(1) on the basis of the results of monitoring and evaluation and, after consulting the relevant Advisory Group, submitting them to the Management Board for adoption;

(u)preparing the reports on the development of the EES referred to in Article 72(2) of Regulation (EC) No 2017/2226 and on the development of ETIAS referred to in Article 92(2) of Regulation (EU) 2018/1240 and submitting them to the Management Board for adoption;

(v)preparing the annual list for publication of competent authorities authorised to search directly the data contained in SIS II, including the list of N.SIS II Offices and SIRENE Bureaux, and the list of competent authorities authorised to search directly the data contained in the EES and ETIAS referred to in point (mm) of Article 19(1) and the list of units referred to in point (nn) of Article 19(1), and submitting them to the Management Board for adoption.

4. The Executive Director shall perform any other tasks in accordance with this Regulation.

5. The Executive Director shall decide whether it is necessary to locate one or more staff members in one or more Member States in order to carry out the Agency’s tasks in an efficient and effective manner and to establish a local office for that purpose. Before adopting such a decision, the Executive Director shall obtain the prior consent of the Commission, the Management Board and the Member State or Member States concerned. The decision of the Executive Director shall specify the scope of the activities to be carried out at the local office in a manner that avoids unnecessary costs and duplication of administrative functions of the Agency. Activities carried out in technical sites shall not be carried out in a local office.

Article 25

Appointment of the Executive Director

1. The Management Board shall appoint the Executive Director from a list of at least three candidates proposed by the Commission following an open and transparent selection procedure. The selection procedure shall provide for publication in the Official Journal of the European Union and in other appropriate media of a call for expressions of interest. The Management Board shall appoint the Executive Director on the grounds of merit, proven experience in the field of large-scale IT systems, administrative, financial and management skills and knowledge with respect to data protection.

2. Before appointment, the candidates proposed by the Commission shall be invited to make a statement before the competent committee or committees of the European Parliament and answer questions from the committee members. After hearing the statement and the responses, the European Parliament shall adopt an opinion setting out its view and may indicate a preferred candidate.

3. The Management Board shall appoint the Executive Director taking those views into account.

4. If the Management Board takes a decision to appoint a candidate other than the candidate whom the European Parliament indicated as its preferred candidate, the Management Board shall inform the European Parliament and the Council in writing of the manner in which the opinion of the European Parliament was taken into account.

5. The term of office of the Executive Director shall be five years. By the end of that period, the Commission shall undertake an assessment that takes into account its evaluation of the Executive Director’s performance and the Agency’s future tasks and challenges.

6. The Management Board, acting on a proposal from the Commission that takes into account the assessment referred to in paragraph 5, may extend the term of office of the Executive Director once for no more than five years.

7. The Management Board shall inform the European Parliament if it intends to extend the Executive Director’s term of office. Within the one-month period before any such extension, the Executive Director shall be invited to make a statement before the competent committee or committees of the European Parliament and answer questions from the committee members.

8. An Executive Director whose term of office has been extended may not participate in another selection procedure for the same post at the end of the overall period.

9. The Executive Director may be removed from office only upon a decision of the Management Board, acting on a proposal from a majority of its members with the right to vote or from the Commission.

10. The Management Board shall reach decisions on appointment, extension of the term of office or removal from office of the Executive Director on the basis of a two-thirds majority of votes of its members with the right to vote.

11. For the purpose of concluding the employment contract with the Executive Director, the Agency shall be represented by the Chairperson of the Management Board. The Executive Director shall be engaged as a temporary agent of the Agency under Article 2(a) of the Conditions of Employment of other Servants.

Article 26

Deputy Executive Director

1. A Deputy Executive Director shall assist the Executive Director. The Deputy Executive Director shall also replace the Executive Director in his or her absence. The Executive Director shall set out the duties of the Deputy Executive Director.

2. On the proposal of the Executive Director, the Management Board shall appoint the Deputy Executive Director. The Deputy Executive Director shall be appointed on the grounds of merit and appropriate administrative and management skills, including relevant professional experience. The Executive Director shall propose at least three candidates for the post of Deputy Executive Director. The Management Board shall take its decision by a two-thirds majority of its members with a right to vote. The Management Board shall have the power to dismiss the Deputy Executive Director by means of a decision adopted by a two-thirds majority of its members with a right to vote.

3. The term of office of the Deputy Executive Director shall be five years. The Management Board may extend that term once, for a period of no more than five years. The Management Board shall adopt such a decision by a two-thirds majority of its members with the right to vote.

Article 27

Advisory Groups

1. The following Advisory Groups shall provide the Management Board with expertise relating to large-scale IT systems and, in particular, in the context of the preparation of the annual work programme and the annual activity report:

(a)SIS II Advisory Group;

(b)VIS Advisory Group;

(c)Eurodac Advisory Group;

(d)EES-ETIAS Advisory Group;

(e)any other advisory group relating to a large-scale IT system when so provided in the relevant Union legal act governing the development, establishment, operation and use of that large-scale IT system.

2. Each Member State that is bound under Union law by any Union legal act governing the development, establishment, operation and use of a particular large-scale IT system, and the Commission shall appoint one member to the Advisory Group relating to that large-scale IT system for a four-year term, which may be renewed.

Denmark shall also appoint a member to an Advisory Group relating to a large-scale IT system if it decides under Article 4 of the Protocol No 22 to implement the Union legal act governing the development, establishment, operation and use of that particular large-scale IT system in its national law.

Each country associated with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures that participates in a particular large-scale IT system shall appoint a member to the Advisory Group relating to that large-scale IT system.

3. Europol, Eurojust and the European Border and Coast Guard Agency may each appoint a representative to the SIS II Advisory Group. Europol may also appoint a representative to the VIS, Eurodac and EES-ETIAS Advisory Groups. The European Border and Coast Guard Agency may also appoint a representative to the EES-ETIAS Advisory Group.

4. Members of the Management Board and their alternates shall not be members of any of the Advisory Groups. The Executive Director or a representative of the Executive Director shall be entitled to attend all the meetings of the Advisory Groups as an observer

5. Advisory Groups shall cooperate with each other as necessary. The procedures for the operation and cooperation of the Advisory Groups shall be laid down in the Agency’s rules of procedure.

6. When preparing an opinion, the members of each Advisory Group shall do their best to reach consensus. If consensus is not reached, the reasoned position of the majority of members shall be considered the opinion of the Advisory Group. The minority reasoned position or positions shall also be recorded. Article 23(3) and (5) shall apply accordingly. The members representing the countries associated with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures shall be allowed to express opinions on issues on which they are not entitled to vote.

7. Each Member State and each country associated with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures shall facilitate the activities of the Advisory Groups.

8. Article 21 shall apply mutatis mutandis as regards the chair of the Advisory Groups.

CHAPTER IV

GENERAL PROVISIONS

Article 28

Staff

1. The Staff Regulations and the rules adopted by agreement between the institutions of the Union for giving effect to the Staff Regulations shall apply to the staff of the Agency, including the Executive Director.

2. For the purpose of implementing the Staff Regulations, the Agency shall be considered an agency within the meaning of Article 1a(2) of the Staff Regulations of Officials.

3. The staff of the Agency shall consist of officials, temporary staff and contract staff. The Management Board shall, on an annual basis, give its consent in the case of contracts that the Executive Director plans to renew where, following renewal, those contracts would be of an indefinite period pursuant to the Conditions of Employment of Other Servants.

4. The Agency shall not recruit interim staff to perform what are deemed to be sensitive financial duties.

5. The Commission and the Member States may second officials or national experts to the Agency on a temporary basis. The Management Board shall adopt a decision laying down rules on the secondment of national experts to the Agency.

6. Without prejudice to Article 17 of the Staff Regulations of Officials, the Agency shall apply appropriate rules of professional secrecy or other equivalent duties of confidentiality.

7. The Management Board shall, in agreement with the Commission, adopt the necessary implementing measures referred to in Article 110 of the Staff Regulations of Officials.

Article 29

Public interest

The members of the Management Board, the Executive Director, the Deputy Executive Director and the members of the Advisory Groups shall undertake to act in the public interest. For that purpose, they shall issue an annual, written, public statement of commitment which shall be published on the Agency’s website.

The list of members of the Management Board and of members of the Advisory Groups shall be published on the Agency’s website.

Article 30

Headquarters Agreement and agreements concerning the technical sites

1. The necessary arrangements concerning the accommodation to be provided for the Agency in the host Member States and the facilities to be made available by those Member States, together with the specific rules applicable in the host Member States to the members of the Management Board, to the Executive Director, to the other members of staff of the Agency and to the members of their families, shall be laid down in a Headquarters Agreement concerning the seat of the Agency and in agreements concerning the technical sites. Such agreements shall be concluded between the Agency and the host Member States, following approval by the Management Board.

2. The Agency’s host Member States shall provide the necessary conditions to ensure the proper functioning of the Agency, including, inter alia, multilingual, European-oriented schooling and appropriate transport connections.

Article 31

Privileges and immunities

The Protocol on the Privileges and Immunities of the European Union shall apply to the Agency.

Article 32

Liability

1. The contractual liability of the Agency shall be governed by the law applicable to the contract in question.

2. The Court of Justice of the European Union shall have jurisdiction to give judgment pursuant to any arbitration clause contained in a contract concluded by the Agency.

3. In the case of non-contractual liability, the Agency shall, in accordance with the general principles common to the laws of the Member States, make good any damage caused by its departments or by its staff in the performance of their duties.

4. The Court of Justice of the European Union shall have jurisdiction in disputes over compensation for the damage referred to in paragraph 3.

5. The personal liability of the Agency’s staff towards the Agency shall be governed by the provisions laid down in the Staff Regulations of Officials or Conditions of Employment of Other Servants applicable to them.

Article 33

Language arrangements

1. Council Regulation No 1 (46) shall apply to the Agency.

2. Without prejudice to decisions taken pursuant to Article 342 TFEU, the single programming document referred to in point (r) of Article 19(1) and the annual activity report referred to in point (t) of Article 19(1) shall be produced in all official languages of the institutions of the Union.

3. The Management Board may adopt a decision on working languages without prejudice to the obligations set out in paragraphs 1 and 2.

4. The translation services necessary for the activities of the Agency shall be provided by the Translation Centre for the Bodies of the European Union.

Article 34

Transparency and communication

1. Regulation (EC) No 1049/2001 shall apply to documents held by the Agency.

2. On the basis of a proposal by the Executive Director, the Management Board shall adopt the detailed rules for applying Regulation (EC) No 1049/2001 without delay.

3. Decisions taken by the Agency pursuant to Article 8 of Regulation (EC) No 1049/2001 may form the subject of a complaint to the European Ombudsman or of an action before the Court of Justice of the European Union, under the conditions laid down in Articles 228 and 263 TFEU respectively.

4. The Agency shall communicate in accordance with the Union legal acts governing the development, establishment, operation and use of large-scale IT-systems and may engage in communication activities on its own initiative within its field of competence. The Agency shall ensure, in particular, that in addition to the publications specified in points (r), (t), (ii), (jj), (kk) and (ll) of Article 19(1) and Article 47(9), the public and any interested party are promptly given objective, accurate, reliable comprehensive and easily understandable information with regard to its work. The allocation of resources to communication activities shall not be detrimental to the effective exercise of the Agency’s tasks as referred to in Articles 3 to 16. Communication activities shall be carried out in accordance with the relevant communication and dissemination plans adopted by the Management Board.

5. Any natural or legal person shall be entitled to address written correspondence to the Agency in any of the official languages of the Union. The person concerned shall have the right to receive an answer in the same language.

Article 35

Data protection

1. The processing of personal data by the Agency shall be subject to Regulation (EU) 2018/1725.

2. The Management Board shall adopt measures for the application of Regulation (EU) 2018/1725 by the Agency, including measures concerning the data protection officer. Those measures shall be adopted after consulting the European Data Protection Supervisor.

Article 36

Purposes of processing personal data

1. The Agency may process personal data only for the following purposes:

(a)where necessary for the performance of its tasks related to the operational management of large-scale IT systems entrusted to it under Union law;

(b)where necessary for its administrative tasks.

2. Where the Agency processes personal data for the purpose referred to in point (a) of paragraph 1 of this Article, Regulation (EU) 2018/1725 shall apply without prejudice to the specific provisions concerning data protection and data security of the Union legal acts governing the development, establishment, operation and use of the systems.

Article 37

Security rules on the protection of classified information and sensitive non-classified information

1. The Agency shall adopt its own security rules based on the principles and rules laid down in the Commission’s security rules for protecting European Union Classified Information (EUCI) and sensitive non-classified information, including, inter alia, provisions for the exchange with third states, processing and storage of such information as set out in Commission Decisions (EU, Euratom) 2015/443 (47) and 2015/444 (48). Any administrative arrangement on the exchange of classified information with the relevant authorities of a third state or, in the absence of such arrangement, any exceptional ad hoc release of EUCI to such authorities shall have received the Commission’s prior approval.

2. The Management Board shall adopt the security rules referred to in paragraph 1 of this Article following approval by the Commission. The Agency may take all necessary measures to facilitate the exchange of information relevant to its tasks with the Commission and the Member States and, where appropriate, the relevant Union agencies. The Agency shall develop and operate an information system capable of exchanging classified information with the Commission, the Member States and relevant Union agencies in accordance with Decision (EU, Euratom) 2015/444. The Management Board shall, pursuant to Article 2 and point (z) of Article 19(1) of this Regulation, decide on the Agency’s internal structure necessary to comply with the appropriate security principles.

Article 38

Security of the Agency

1. The Agency shall be responsible for the security and the maintenance of order within the buildings, premises and land used by it. The Agency shall apply the security principles and relevant provisions of the Union legal acts governing the development, establishment, operation and use of large-scale IT systems.

2. The host Member States shall take all effective and adequate measures to maintain order and security in the immediate vicinity of the buildings, premises and land used by the Agency and shall provide the Agency with the appropriate protection in accordance with the Headquarters Agreement concerning the seat of the Agency and the agreements concerning the technical and backup sites, whilst guaranteeing the free access of persons authorised by the Agency to those buildings, premises and land.

Article 39

Evaluation

1. By 12 December 2023, and every five years thereafter, the Commission, after consulting the Management Board, shall evaluate, in accordance with the Commission’s guidelines, the performance of the Agency in relation to its objectives, mandate, locations and tasks. That evaluation shall also include an examination of the implementation of this Regulation and the way and extent to which the Agency effectively contributes to the operational management of large-scale IT systems and to the establishment of a coordinated, cost-effective and coherent IT environment at Union level in the area of freedom, security and justice. That evaluation shall, in particular, assess the possible need to modify the mandate of the Agency and the financial implications of any such modification. The Management Board may issue recommendations regarding amendments to this Regulation to the Commission.

2. Where the Commission considers that the continuation of the Agency is no longer justified with regard to its assigned objectives, mandate and tasks, it may propose that this Regulation be amended accordingly or repealed.

3. The Commission shall report to the European Parliament, to the Council and to the Management Board on the findings of the evaluation referred to in paragraph 1. The findings of the evaluation shall be made public.

Article 40

Administrative inquiries

The activities of the Agency shall be subject to the inquiries of the European Ombudsman in accordance with Article 228 TFEU.

Article 41

Cooperation with Union institutions, bodies, offices and agencies

1. The Agency shall cooperate with the Commission, with other Union institutions and with other Union bodies, offices and agencies, in particular those established in the area of freedom, security and justice, and in particular the European Union Agency for Fundamental Rights, in matters covered by this Regulation, in order to achieve, inter alia, coordination and financial savings, to avoid duplication and to promote synergy and complementarity as regards their respective activities.

2. The Agency shall cooperate with the Commission within the framework of a working arrangement laying down operational working methods.

3. The Agency shall consult and follow the recommendations of the European Network and Information Security Agency regarding network and information security, where appropriate.

4. Cooperation with Union bodies, offices and agencies shall take place within the framework of working arrangements. The Management Board shall authorise such working arrangements, taking into account the opinion of the Commission. Where the Agency does not follow the Commission’s opinion, it shall justify its reasons. Such working arrangements may provide for the sharing of services between agencies, where appropriate, either by proximity of locations or by policy area within the limits of the respective mandates and without prejudice to their core tasks. Such working arrangements may establish a mechanism for cost recovery.

5. Union institutions, bodies, offices and agencies shall use information received from the Agency only within the limits of their competences and insofar as they respect fundamental rights, including data protection requirements. Onward transmission or other communication of personal data processed by the Agency to Union institutions, bodies, offices or agencies shall be subject to specific working arrangements regarding the exchange of personal data and subject to the prior approval by the European Data Protection Supervisor. Any transfer of personal data by the Agency shall be in accordance with Articles 35 and 36. As regards the handling of classified information, such working arrangements shall provide that the Union institution, body, office or agency concerned comply with security rules and standards equivalent to those applied by the Agency.

Article 42

Participation by countries associated with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures

1. The Agency shall be open to the participation of countries that have entered into agreements with the Union on their association with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures.

2. Under the relevant provisions of the agreements referred to in paragraph 1, arrangements shall be made specifying, in particular, the nature and extent of, and the detailed rules for, the participation of countries as referred to in paragraph 1 in the work of the Agency, including provisions on financial contributions, staff and voting rights.

Article 43

Cooperation with international organisations and other relevant entities

1. Where so provided by a Union legal act, in so far as it is necessary for the performance of its tasks, the Agency may, by means of the conclusion of working arrangements, establish and maintain relations with international organisations and their subordinate bodies, governed by public international law, or other relevant entities or bodies, which are set up by, or on the basis of, an agreement between two or more countries.

2. In accordance with paragraph 1, working arrangements may be concluded specifying, in particular, the scope, nature, purpose and extent of such cooperation. Such working arrangements may be concluded only with the authorisation of the Management Board after having received the Commission’s prior approval.

CHAPTER V

ESTABLISHMENT AND STRUCTURE OF THE BUDGET

SECTION 1

Single programming document

Article 44

Single programming document

1. Each year the Executive Director shall draw up a draft single programming document for the following year, as set out in Article 32 of Delegated Regulation (EU) No 1271/2013 and in the relevant provision of the Agency’s financial rules adopted pursuant to Article 49 of this Regulation and taking into account guidelines set by the Commission.

The single programming document shall contain a multiannual programme, an annual work programme and the Agency’s budget and information on its resources, as set out in detail in the Agency’s financial rules adopted pursuant to Article 49.

2. The Management Board shall adopt the draft single programming document after consulting the Advisory Groups and shall send it to the European Parliament, to the Council and to the Commission by 31 January each year, as well as any updated version of that document.

3. Before 30 November each year, the Management Board shall adopt, by a two-thirds majority of its members with the right to vote, and in accordance with the annual budgetary procedure, the single programming document, taking into account the opinion of the Commission. The Management Board shall ensure that the definitive version of this single programming document is sent to the European Parliament, to the Council and to the Commission and is published.

4. The single programming document shall become definitive after the final adoption of the general budget of the Union and, if necessary, shall be adjusted accordingly. The adopted single programming document shall then be sent to the European Parliament, the Council and the Commission and shall be published.

5. The annual work programme for the following year shall comprise detailed objectives and expected results, including performance indicators. It shall also contain a description of the actions to be financed and an indication of financial and human resources allocated to each action, in accordance with the principles of activity-based budgeting and management. The annual work programme shall be coherent with the multiannual work programme referred to in paragraph 6. It shall clearly indicate tasks that have been added, changed or deleted in comparison with the previous financial year. The Management Board shall amend the adopted annual work programme when a new task is given to the Agency. Any substantial amendment to the annual work programme shall be adopted by the same procedure as the initial annual work programme. The Management Board may delegate the power to make non-substantial amendments to the annual work programme to the Executive Director.

6. The multiannual programme shall set out the overall strategic programming, including objectives, expected results and performance indicators. It shall also set out resource programming, including multiannual budget and staff. The resource programming shall be updated annually. The strategic programming shall be updated where appropriate and in particular to address the outcome of the evaluation referred to in Article 39.

Article 45

Establishment of the budget

1. Each year the Executive Director shall draw up, taking into account the activities carried out by the Agency, a draft statement of estimates of the Agency’s revenue and expenditure for the following financial year, including a draft establishment plan, and shall submit it to the Management Board.

2. The Management Board shall, on the basis of the draft statement of estimates drawn up by the Executive Director, adopt a draft estimate of the revenue and expenditure of the Agency for the following financial year, including the draft establishment plan. By 31 January each year, the Management Board shall send it to the Commission and to the countries associated with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures, as a part of the single programming document.

3. The Commission shall send the draft estimate to the budgetary authority together with the preliminary draft general budget of the Union.

4. On the basis of the draft estimate, the Commission shall enter in the draft general budget of the Union the estimates it deems necessary for the establishment plan and the amount of the subsidy to be charged to the general budget, which it shall place before the budgetary authority in accordance with Articles 313 and 314 TFEU.

5. The budgetary authority shall authorise the appropriations for the contribution to the Agency.

6. The budgetary authority shall adopt the establishment plan for the Agency.

7. The Management Board shall adopt the Agency’s budget. It shall become final following the final adoption of the general budget of the Union. Where appropriate, the Agency’s budget shall be adjusted accordingly.

8. Any modification to the Agency’s budget, including the establishment plan, shall follow the same procedure as that applicable to the establishment of the initial budget.

9. Without prejudice to Article 17(5), the Management Board shall, as soon as possible, notify the budgetary authority of its intention to implement any project which may have significant financial implications for the funding of its budget, in particular any projects relating to property, such as the rental or purchase of buildings. The Management Board shall inform the Commission thereof. If either branch of the budgetary authority intends to issue an opinion, it shall, within two weeks of the receipt of the information on the project, notify the Management Board of its intention to issue such an opinion. In the absence of a reply, the Agency may proceed with the planned operation. Delegated Regulation (EU) No 1271/2013 shall apply to any building project likely to have any significant implications for the Agency’s budget.

SECTION 2

Presentation, implementation and control of the budgET

Article 46

Structure of the budget

1. Estimates of all revenue and expenditure for the Agency shall be prepared each financial year, corresponding to the calendar year, and shall be shown in the Agency’s budget.

2. The Agency’s budget shall be balanced in terms of revenue and of expenditure.

3. Without prejudice to other types of income, the revenue of the Agency shall consist of:

(a)a contribution from the Union entered in the general budget of the Union (Commission section);

(b)a contribution from the countries associated with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures that participate in the work of the Agency, as established in the respective association agreements and in the arrangements referred to in Article 42 that specify their financial contribution;

(c)Union funding in the form of delegation agreements in accordance with the Agency’s financial rules adopted pursuant to Article 49 and with the provisions of the relevant instruments supporting the policies of the Union;

(d)contributions paid by Member States for the services provided to them in accordance with the delegation agreement referred to in Article 16;

(e)cost recovery paid by Union bodies, offices and agencies for services provided to them in accordance with the working arrangements referred to in Article 41; and

(f)any voluntary financial contribution from the Member States.

4. The expenditure of the Agency shall include staff remuneration, administrative and infrastructure expenses and operational expenditure.

Article 47

Implementation and control of the budget

1. The Executive Director shall implement the Agency’s budget.

2. Each year the Executive Director shall forward to the budgetary authority all information relevant to the findings of evaluation procedures.

3. By 1 March of a financial year N+1, the Agency’s accounting officer shall communicate the provisional accounts for financial year N to the Commission’s accounting officer and the Court of Auditors. The Commission’s accounting officer shall consolidate the provisional accounts of the institutions and decentralised bodies in accordance with Article 245 of Regulation (EU, Euratom) 2018/1046.

4. The Executive Director shall send a report on the budgetary and financial management for year N to the European Parliament, to the Council, to the Commission and to the Court of Auditors by 31 March of year N+1.

5. The Commission’s accounting officer shall send the Agency’s provisional accounts for year N, consolidated with the Commission’s accounts, to the Court of Auditors by 31 March of year N+1.

6. On receipt of the Court of Auditors’ observations on the Agency’s provisional accounts, pursuant to Article 246 of Regulation (EU, Euratom) 2018/1046, the Executive Director shall draw up the Agency’s final accounts under his or her own responsibility and forward them to the Management Board for an opinion.

7. The Management Board shall deliver an opinion on the Agency’s final accounts for year N.

8. By 1 July of year N+1, the Executive Director shall send the final accounts, together with the opinion of the Management Board, to the European Parliament, to the Council, to the Commission and to the Court of Auditors as well as to the countries associated with the implementation, application and development of the Schengen acquis and with Dublin- and Eurodac-related measures.

9. The final accounts for year N shall be published in the Official Journal of the European Union by 15 November of year N+1.

10. The Executive Director shall send the Court of Auditors a reply to its observations by 30 September of year N+1. The Executive Director shall also send that reply to the Management Board.

11. The Executive Director shall submit to the European Parliament, at the latter’s request, any information required for the smooth application of the discharge procedure for year N, in accordance with Article 261(3) of Regulation (EU, Euratom) 2018/1046.

12. On a recommendation from the Council acting by a qualified majority, the European Parliament shall, before 15 May of year N+2, grant discharge to the Executive Director in respect of the implementation of the budget for year N.

Article 48

Prevention of conflicts of interest

The Agency shall adopt internal rules requiring the members of its Management Board and its Advisory Groups and its staff members to avoid any situation liable to give rise to a conflict of interest during their employment or term of office and to report such situations. Those internal rules shall be published on the website of the Agency.

Article 49

Financial rules

The financial rules applicable to the Agency shall be adopted by the Management Board after consulting the Commission. They shall not depart from Delegated Regulation (EU) No 1271/2013 unless such departure is specifically required for the operation of the Agency and the Commission has given its prior consent.

Article 50

Combating fraud

1. In order to combat fraud, corruption and other unlawful activities, Regulation (EU, Euratom) No 883/2013 and Regulation (EU) 2017/1939 shall apply.

2. The Agency shall accede to the Interinstitutional Agreement of 25 May 1999 concerning internal investigations by OLAF and shall adopt, without delay, the appropriate provisions applicable to all the employees of the Agency using the template set out in the Annex to that Agreement.

3. The Court of Auditors shall have the power of audit, on the basis of documents and of on-the-spot inspections, over all grant beneficiaries, contractors and subcontractors who have received Union funds from the Agency.

4. OLAF may carry out investigations, including on-the-spot checks and inspections, in accordance with the provisions and procedures laid down in Regulation (EU, Euratom) No 883/2013 and Council Regulation (Euratom, EC) No 2185/96 (49), with a view to establishing whether there has been fraud, corruption or any other illegal activity affecting the financial interests of the Union in connection with a grant or a contract funded by the Agency.

5. Without prejudice to paragraphs 1, 2, 3 and 4, contracts, grant agreements and grant decisions of the Agency shall contain provisions expressly empowering the Court of Auditors, OLAF and the EPPO to conduct audits and investigations, in accordance with their respective competences.

CHAPTER VI

AMENDMENTS TO OTHER UNION LEGAL ACTS

Article 51

Amendment to Regulation (EC) No 1987/2006

In Regulation (EC) No 1987/2006, Article 15(2) and (3) are replaced by the following:

‘2.   The Management Authority shall be responsible for all tasks relating to the Communication Infrastructure, in particular:

(a)supervision;

(b)security;

(c)the coordination of relations between the Member States and the provider;

(d)tasks relating to implementation of the budget;

(e)acquisition and renewal, and

(f)contractual matters.’.

Article 52

Amendment to Decision 2007/533/JHA

In Decision 2007/533/JHA, Article 15(2) and (3) are replaced by the following:

‘2.   The Management Authority shall also be responsible for all tasks relating to the Communication Infrastructure, in particular:

(a)supervision;

(b)security;

(c)the coordination of relations between the Member States and the provider;

(d)tasks relating to implementation of the budget;

(e)acquisition and renewal, and

(f)contractual matters.’.

CHAPTER VII

TRANSITIONAL PROVISIONS

Article 53

Legal succession

1. The Agency, as established by this Regulation, shall be the legal successor in respect of all contracts concluded by, liabilities incumbent on, and properties acquired by the European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice as established by Regulation (EU) No 1077/2011.

2. This Regulation shall not affect the legal force of agreements, working arrangements and memoranda of understanding concluded by the Agency as established by Regulation (EU) No 1077/2011, without prejudice to any amendments thereto required by this Regulation.

Article 54

Transitional arrangements concerning the Management Board and the Advisory Groups

1. The members and the Chairperson and Deputy Chairperson of the Management Board, appointed on the basis of Articles 13 and 14 of Regulation (EU) No 1077/2011 respectively, shall continue to exercise their functions for the remaining terms of their office.

2. The members, Chairpersons and deputy Chairpersons of the Advisory groups, appointed on the basis of Article 19 of Regulation (EU) No 1077/2011, shall continue to exercise their functions for their remaining terms of office.

Article 55

Maintenance in force of the internal rules adopted by the Management Board

Internal rules and measures adopted by the Management Board on the basis of Regulation (EU) No 1077/2011 shall remain in force after 11 December 2018, without prejudice to any amendments thereto required by this Regulation.

Article 56

Transitional arrangements concerning the Executive Director

The Executive Director of the European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice, appointed on the basis of Article 18 of Regulation (EU) No 1077/2011, shall, for his or her remaining term of office, be assigned the responsibilities of the Executive Director of the Agency, as provided for in Article 24 of this Regulation. The other conditions of his or her contract shall remain unchanged. If a decision extending the mandate of the Executive Director in accordance with Article 18(4) of Regulation (EU) No 1077/2011 is adopted prior to 11 December 2018, the term of office shall be extended automatically until 31 October 2022.

CHAPTER VIII

FINAL PROVISIONS

Article 57

Replacement and repeal

Regulation (EU) No 1077/2011 is hereby replaced with regard to the Member States bound by this Regulation.

Therefore, Regulation (EU) No 1077/2011 is repealed.

With regard to the Member States bound by this Regulation, references to the repealed Regulation shall be construed as references to this Regulation and shall be read in accordance with the correlation table in the Annex to this Regulation.

Article 58

Entry into force and applicability

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

This Regulation shall apply from 11 December 2018. However point (x) of Article 19(1), points (h) and (i) of Article 24(3) and Article 50(5) of this Regulation, insofar as they refer to the EPPO, and Article 50(1) of this Regulation, insofar as it refers to Regulation (EU) 2017/1939, shall apply from the date determined by the Commission decision provided for in the second subparagraph of Article 120(2) of Regulation (EU) 2017/1939.

This Regulation shall be binding in its entirety and directly applicable in the Member States in accordance with the Treaties.