in force 2024-05-20 INSERTED+1,681 −0§
Amended by Regulation (EU) 2024/1183 32024R1183
applies from: unknown (an inserted provision states its own application date only in prose)
Sources disagree — the text comparison and the amending act's instructions found this change; the EU's own amendment metadata does not list it. All are shown; none is overruled.
This is a new article setting out obligations for non-qualified trust service providers, including maintaining policies to manage risks around registration, onboarding, procedural checks and management of trust services, and notifying supervisory bodies, affected individuals, the public where relevant, and other competent authorities of significant security breaches or disruptions within 24 hours of becoming aware of them.
It also directs the Commission to adopt implementing acts establishing reference standards and, where needed, specifications and procedures for the risk-management requirement, with compliance presumed where those standards are met.
Cited: Art. 19a, v2
text before / after
inserted text (02014R0910-20240520)
Article 19a Requirements for non-qualified trust service providers 1. A non-qualified trust service provider providing non-qualified trust services shall: (a) have appropriate policies and take corresponding measures to manage legal, business, operational and other direct or indirect risks to the provision of the non-qualified trust service, which shall, notwithstanding Article 21 of Directive (EU) 2022/2555, include at least measures relating to: (i) registration and onboarding procedures for a trust service; (ii) procedural or administrative checks needed to provide trust services; (iii) the management and implementation of trust services; (b) notifying the supervisory body, the identifiable affected individuals, the public if it is of public interest and, where applicable, other relevant competent authorities, of any security breaches or disruptions in the provision of the service or the implementation of the measures referred to in point (a) (i), (ii) or (iii), that have a significant impact on the trust service provided or on the personal data maintained therein, without undue delay and in any case no later than 24 hours of having become aware of any security breaches or disruptions. 2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for paragraph 1, point (a), of this Article. Compliance with the requirements laid down in this Article shall be presumed where those standards, specifications and procedures are met. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).