News, events, publications

EDA-DPR-056 - ISP PoCs List - ISP National Experts/PoCs Lists

Records and compliance checklist

Under Article 31 of the new Regulation, EUIs have to keep records of their processing operations. This template covers two aspects:

1.Mandatory records under Article 31 of the new rules (recommendation: publicly available)
2.Compliance check and risk screening (internal).

The header and part 1 should be publicly available; part 2 is internal to the EUI. By way of example, column 3 contains a hypothetical record on badges and physical access control in a EUI.
Nr Item Explanation
Header - versioning and reference numbers (recommendation: publicly available)
1. Last update of this record 05-09-2022
2. Reference number EDA-DPR-056-ISP
part 1 - article 31 record (recommendation: publicly available)
3. Name and contact details of controller
European Defence Agency

Rue des Drapiers 17-23
B-1050 Brussels
Belgium
4. Name and contact details of DPO

Head of the Legal Office, Legal Advisor / Data Protection Mr Pedro ROSA PLAZA

dataprotection@eda.europa.eu

5. Name and contact details of joint controller (where applicable)
N/A
6. Name and contact details of processor (where applicable)
N/A
7. Purpose of the processing
The compilation of overall lists of Experts/PoCs' contact details has been designated to be used by EDA when a need for contact with the Experts/PoCs appears, as well as for the purpose of dissemination of the lists of Experts/PoCs' contact details among themselves to facilitate possible contact and exchange of information between the Expert/PoCs.
8. Description of categories of persons whose data EDA processes and list of data categories

Data are processed from the following individuals or group of people (1 group for each list): 1) EDA Defence Acquisition Expert Network (DAEN) members;

2) EDA SoS Working Group Experts (SoS Experts) and PoCs (SoS PoCs);

3) EDA REACH Experts Network members, and EDA REACH Task Force members;

4) EDA ESIF PoCs and deputies (i.e. ESIF Dep PoCs, ESIF RfP PoCs, ESF PoCs, ESF4KSC PoCs);

5) EDA Defence Industry Expert Network (DIEN);

6) EDA Defence Supply Chain Network (DSCN);

7) SME PoCs;

8) EDA SME Modelling & Simulation Platform For above lists par 1) to 5) and 7), the data subjects (members of the groups mentioned) are governmental representatives only, either from the MoDs or from other national Ministries, depending on the subject and in Member States' organisational structure and related competencies at national level. For list 6) and 8), the data subjects (members of the groups mentioned) are industry or other (e.g. Research and Technology Organisations) representatives. Data processed are the following: Full name and title, address, employer, division, position held, contact details (telephone, mobile, fax and email).

9. Time limit for keeping the data
Current contact information of Experts/PoCs available during their tenure. Subsequently, contact information of the person that no longer represents the Member State, or industry entity in the respective group are deleted and replaced by new Expert/PoC nominated, i.e. as decided by subject's Member State or industry entity. If not needed anymore, the data will be deleted within 3 months. No previous versions of the Experts/PoCs lists are kept.
10. Recipients of the data

Agency staff members and members (Experts/PoCs) of corresponding groups, as follows (1 list for each group):

1) EDA Defence Acquisition Expert Network (DAEN) members;

2) EDA SoS Working Group Experts (SoS Experts) and PoCs (SoS PoCs);

3) EDA REACH Experts Network members, and EDA REACH Task Force members;

4) EDA ESIF PoCs and deputies (i.e. ESIF Dep PoCs, ESIF RfP PoCs, ESF PoCs, ESF4KSC PoCs);

5) EDA Defence Industry Expert Network (DIEN);

6) EDA Defence Supply Chain Network (DSCN);

7) SME PoCs; 8) EDA SME Modelling & Simulation Platform For above lists par 1) to 5) and 7), the members of the groups mentioned are governmental representatives only, either from MoDs or from other national Ministries, depending on the subject and in Member States' organisational structure and related competencies at national level. For lists par 6) and 8), the members of the groups mentioned are industry or other (e.g. Research and Technology Organisations) representatives.

11. Are there any transfers of personal data to third countries or international organisations? If so, to which ones and with which safeguards?
N/A
12. General description of security measures, where possible.
Data will be processed in accordance with the high security standards established by EDA. Within the EDA network the data access is limited to RTI staff and IT administrators.
13. For more information, including how to exercise your rights to access, rectification, object and data portability (where applicable), see the privacy statement
Additional information is available by following the link to privacy statement here.