[ S.L. 164.04 SCHENGEN INFORMATION SYSTEM (SIS) SUBSIDIARY LEGISLATION 164.04 SCHENGEN INFORMATION SYSTEM (SIS) REGULATIONS 4th August 2023 LEGAL NOTICE 198 of 2023. 1. The title of these regulations is the Schengen Information System (SIS) Regulations. Citation. 2. These regulations complement and further implement the requirements of the relevant provisions of the following: Scope. (
- a)Regulation (EU) 2018/1860 of the European Parliament and of the Council of 28 November 2018 on the use of the Schengen Information System for the return of illegally staying third-country nationals; (
- b)Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of border checks, and amending the Convention implementing the Schengen Agreement, and amending and repealing Regulation (EC) No 1987/2006; (
- c)Regulation (EU) 2018/1862 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of police cooperation and judicial cooperation in criminal matters, amending and repealing Council Decision 2007/533/JHA, and repealing Regulation (EC) No 1986/2006 of the European Parliament and of the Council and Commission Decision 2010/261/EU, for the purposes of these regulations collectively referred to as the European Schengen Information System Regulations. 3. requires:
(1)In these regulations, unless the context otherwise "Data Protection Officer" means the designated Data Protection Officer for the Malta Police Force in terms of regulation 32 of the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations and Article 37 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation); Interpretation. S.L. 586.
- 1 2 [ S.L. 164.04 SCHENGEN INFORMATION SYSTEM (SIS) "General Data Protection Regulation" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation); Cap.
- Cap.
- "Information and Data Protection Commissioner" means the Information and Data Protection Commission established by article 11 of the Data Protection Act; "Malta Police Force" means the Malta Police Force established by article 3 of the Police Act; "N.SIS" means the national system for SIS pursuant to Article 4 of Regulation (EU) 2018/1860; "N.SIS Office" means the office which shall have central responsibility for its N.SIS pursuant to Article 7 of Regulation (EU) 2018/1860; "NI.SIS" means the uniform national interface pursuant to Article 4 of Regulation (EU) 2018/1862; "Regulation (EU) 2018/1860" means Regulation (EU) 2018/1860 of the European Parliament and of the Council of 28 November 2018 on the use of the Schengen Information System for the return of illegally staying third-country nationals; "Regulation (EU) 2018/1861" means Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of border checks, and amending the Convention implementing the Schengen Agreement, and amending and repealing Regulation (EC) No 1987/2006; "Regulation (EU) 2018/1862" means Regulation (EU) 2018/1862 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of police cooperation and judicial cooperation in criminal matters, amending and repealing Council Decision 2007/533/JHA, and repealing Regulation (EC) No 1986/2006 of the European Parliament and of the Council and Commission Decision 2010/ 261/EU; "SIRENE Manuals" means the Commission Implementing Decision of 18 November 2021 laying down detailed rules for the tasks of the SIRENE Bureaux and the exchange of supplementary information regarding alerts in the SCHENGEN INFORMATION SYSTEM (SIS) [ S.L. 164.04 Schengen Information System in the field of border checks and return ("SIRENE Manual - Borders and return") (and includes the annexes under Document C
(2021)7900), and Commission Implementing Decision of 18 November 2021 laying down detailed rules for the tasks of the SIRENE Bureaux and the exchange of supplementary information regarding alerts in the Schengen Information System in the field of police cooperation and judicial cooperation in criminal matters ("SIRENE Manual – Police") (and includes the annexes under Document No C
(2021)7901 final and its annexes).
(2)The definitions contained in the Schengen Information System Regulations shall be applicable for the purposes of these regulations. 4.
(1)The Commissioner of Police shall establish the SIRENE Bureau, which shall ensure the exchange of all supplementary information in accordance with the provisions of the SIRENE Manuals and the European Commission implementing acts thereof. Establishment of the SIRENE Bureau.
(2)The Head of the SIRENE Bureau shall be appointed by the Commissioner of Police, in consultation with the Permanent Secretary of the Ministry responsible for Police, and shall be assigned designated duties in accordance with the Schengen Information System Regulations, the provisions of the SIRENE Manuals and any other relevant national or European Union legislation.
(3)The SIRENE Bureau shall have easy direct or indirect access to all relevant information, including information from national databases and all the information on other Member States’ alerts, and to expert advice, in order to be able to react to requests for supplementary information: Provided that the SIRENE Bureau shall be able to receive accurate and updated information to be transferred in a timely manner: Provided further that in the case of inaccurate, incomplete information or information that is not updated, the rest of the information or updated information, as the case may be, shall be transferred to the SIRENE Bureau not later than six
(6)hours upon receipt of the notification by the SIRENE Bureau.
(4)The SIRENE Bureau shall coordinate the verification of the quality of the information entered in the Schengen Information System and, for this purpose, shall have access to the data processed in the Schengen Information System.
- The N.SIS Office, the SIRENE Bureau and the designated competent authorities referred to in the First Schedule shall ensure that all necessary measures relating to security are taken in accordance with Security. 3 4 [ S.L. 164.04 SCHENGEN INFORMATION SYSTEM (SIS) the provisions of Article 10 of Regulation (EU) 2018/
- Establishment of the National Schengen Information System Office (N.SIS). 6.
(1)The Commissioner of Police shall establish an office, that shall be the designated as the N.SIS Office and which shall be responsible for: (
- a)setting up, operating and maintaining the N.SIS and connecting N.SIS to NI-SIS for the smooth operation and security of the N.SIS; and (
- b)ensuring access to the competent authorities to the Schengen Information System and to take the necessary measures to ensure compliance with the provisions of the European Schengen Information System Regulations.
(2)The Head of the N.SIS Office shall be appointed by the Commissioner of Police, in consultation with the Permanent Secretary of the Ministry responsible for Police, and shall be assigned those duties in accordance with the European Schengen Information System Regulations, the provisions of the SIRENE Manuals and any other relevant national or European Union legislation. Authorities with access to the Schengen Information System (SIS). 7.
(1)The authorities listed in the First Schedule are the designated competent authorities that shall have access to alerts in the Schengen Information System for the purposes of performing the functions set out in the European Schengen Information System Regulations.
(2)The level and type of access to the authorities listed in the First Schedule shall be, determined by mutual agreement between the Commissioner of Police, the Information and Data Protection Commissioner and the respective authorities, on the basis of necessity and proportionality. Alerts. Cap. 602. 8.
(1)For the purpose of entering alerts in accordance with Article 32
(2)of Regulation (EU) 2018/1862, the Foundation for Social Welfare Services shall be responsible for issuing of decisions and for transferring essential information to the SIRENE Bureau.
(2)For the purpose of entering alerts on persons referred to in Article 32
(1)(
- c)and (
- d)of Regulation (EU) 2018/1862, the Director (Child Protection) may request the SIRENE Bureau to enter such alerts following the issue of a decision in relation to a minor.
(3)For the purpose of entering alerts on vulnerable adult persons referred to in Article 32
(1)(e) of Regulation (EU) 2018/1862, the Director for Aġenzija Appoġġ may request the SIRENE Bureau to enter such alerts following the issue of a decision in relation to such vulnerable adult persons. SCHENGEN INFORMATION SYSTEM (SIS) [ S.L. 164.04 9. The national authorities listed in the First Schedule shall establish a data retention policy for the purposes of these regulations in accordance with the General Data Protection Regulations, and the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal offences or the Execution of Criminal Penalties) Regulations. Retention of information. 10.
(1)The provisions of the General Data Protection Regulations and the Data Protection Act shall apply to the processing of personal data under these regulations, with the exception of the processing of personal data by competent authorities responsible for the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. Protection of personal data. Cap. 586.
(2)The provisions of the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations shall apply to the processing of personal data under these regulations when such processing is carried out by the competent authorities responsible for the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. S.L. 586.08. 11.
(1)The Data Protection Officer shall conduct an audit of the user log files related to the activities on the N.SIS. Self-Auditing. S.L. 586.08.
(2)The Data Protection Officers of the authorities having access to the SIS shall cooperate with, and provide any support, assistance and information to, the Data Protection Officer when conducting an audit as referred to under sub-regulation
(1), as may be required.
(3)The Data Protection Officers of the authorities having access to the SIS shall conduct an audit of the user log files of the users within their authority, at least on an annual basis, relating to data processing operations in the N.SIS, the reports of which shall be made available to the Data Protection Officer. 12. The Data Protection Officer, in the first quarter of every calendar year, shall provide to the Information and Data Protection Commissioner, the statistics pertaining to the previous year in relation to the personal data held in the SIS. The statistics have to relate to requests submitted by data subjects to exercise their right of access, rectification of inaccurate data, erasure of unlawfully stored data, and the number of cases where access to the data was granted and where the data was rectified or erased. Provision of statistics. 13.
(1)Without prejudice to the rights of data subjects to institute an action under article 30
(2)of the Data Protection Act, any Liability and penalties. Cap 586. 5 6 [ S.L. 164.04 SCHENGEN INFORMATION SYSTEM (SIS) person who suffers damages as a result of an unlawful personal data processing operation through the use of N.SIS or as a result of any other act incompatible with Regulation (EU) 2018/1862, may, by sworn application filed before the First Hall of the Civil Court, institute an action for damages against the authority that has conducted such unlawful personal data processing operation or such other incompatible action. Cap. 586.
(2)Where the claim for damages as referred to in subregulation
(1)is made by a data subject in relation, connection or consequent to an infringement in terms of article 30
(1)of the Data Protection Act, such claim shall be made concurrently and through the same action instituted under article 30
(2)of such Act.
(3)If the court, in determining an action under subregulation
(1)and
(2)decides that an authority is liable for the damage caused, that court shall determine the amount of damages due to the applicant, which shall include, but are not limited to, moral damages.
(4)Any action under this regulation shall be instituted within a period of twelve
(12)months from the date when the applicant became aware, or ought to have reasonably become aware, of such unlawful personal data processing operation through the use of N.SIS or of any other act incompatible with Regulation (EU) 2018/ 1862, whichever date is earlier. FIRST SCHEDULE (Regulation 7) List of authorities having access to the Schengen Information System alerts: 1. The Malta Police Force 2. The Principal Immigration Officer 3. The Department of Customs 4. Authority for Transport in Malta 5. Ministry for Foreign Affairs