Commission Implementing Regulation (EU) 2023/2117 of 12 October 2023 laying down the necessary rules and detailed requirements for the functioning and management of a repository of information pursuant to Regulation (EU) 2018/1139 of the European Parliament and of the Council

Type Implementing Regulation
Publication 2023-10-12
Last updated 2025-04-23
State In force
Department European Commission, MOVE
Source EUR-Lex
articles 18
Reform history JSON API

COMMISSION IMPLEMENTING REGULATION (EU) 2023/2117 of 12 October 2023 laying down the necessary rules and detailed requirements for the functioning and management of a repository of information pursuant to Regulation (EU) 2018/1139 of the European Parliament and of the Council (Text with EEA relevance)

CHAPTER I

GENERAL PROVISIONS

Article 1
Subject matter

This Regulation lays down the rules and procedures for the functioning and management of a repository of information necessary to ensure effective cooperation between the Agency and the national competent authorities concerning the exercise of their tasks relating to certification, oversight and enforcement under Regulation (EU) 2018/1139.

Article 2
Definitions

The following definitions shall also apply:

(a) ‘authorised users’ means the Commission, the Agency, national competent authorities and any competent authority of the Member State entrusted with the investigation of civil aviation accidents and incidents as laid down in Article 74(6), first sentence, of Regulation (EU) 2018/1139;

(b) ‘interface’ means the point at which independent and often unrelated systems connect and act on or communicate with each other;

(c) ‘authorised staff’ means staff of the authorised users who have received access to the repository;

(d) ‘information object category’ means the type of information falling within the scope of Article 74(1) of Regulation (EU) 2018/1139 to be exchanged and accessed by the authorised users;

(e) ‘information object’ means an individually exchanged piece of information which shall always correspond to the information object category and be compatible with its information format;

(f) ‘information format’ means a pre-defined structure of the information object category consisting of a scheme of fields corresponding to detailed types of content within each information object category and vocabularies made of limited sets of permissible values associated to each field;

(g) ‘interested party’ means public authorities of the European Union institutions, agencies and bodies and Member States’ public authorities, natural and legal persons who are subject to an information object as defined in Annex I to this Regulation and qualified entities accredited pursuant to Article 69 of Regulation (EU) 2018/1139.

CHAPTER II

ESTABLISHMENT, MANAGEMENT AND MAINTENANCE OF THE REPOSITORY

Article 3
Establishment of the repository

The Storage interface referred to in paragraph 1 shall consist of:

(a) a central database containing information referred to in Article 74(1) of Regulation (EU) 2018/1139, encompassing both the existing and new information; and

(b) a history of changes to information and its current/archived status.

The Exchange interface referred to in paragraph 1 shall consist of:

(a) a communication infrastructure that provides secure Application Programmable Interfaces (APIs) for the issue, change, query/read, and archive of information between the authorised users’ systems and the repository; and

(b) information quality verification rules that ensure the consistency, integrity and accuracy of the information stored.

The Agency shall develop the necessary documentation supporting the authorised users’ integration with the repository. That documentation shall consist of:

(a) API standards and exchange mechanisms;

(b) security, network, and application configuration information required to communicate with the repository;

(c) rules specifying the valid structure and content of information exchanged with the repository.

Article 4
Management of the repository
Article 5
Maintenance of the repository

CHAPTER III

RULES ON THE INFORMATION STORED IN THE REPOSITORY

Article 6
Formats and standards of the information
Article 7
Classification of information

The Agency, in cooperation with the Commission and the national competent authorities, shall classify the information object categories according to the following markings:

(a) privacy: non personal data, non-sensitive or sensitive personal data;

(b) confidentiality: no impact, limited, significant, catastrophic;

(c) integrity: no impact, limited, significant, catastrophic;

(d) availability: no impact, limited, significant, catastrophic.

Article 8
Arrangements for the dissemination of information

When receiving a request, the Agency shall verify that:

(a) the request is made by an interested party; and

(b) the interested party demonstrates that the requested information is strictly necessary to the interested party’s own operations.

The Agency shall provide the requested information to the interested party only under the following conditions:

(a) the interested party does not receive access to the entire content of the repository;

(b) the information is strictly necessary for the interested party’s own operations;

(c) no personal data is disseminated unless such data concerns the interested party itself or if such dissemination is strictly necessary to perform the operations of the interested party.

The interested party shall:

(a) use the information only for the purpose specified in the request form;

(b) not disclose the information received without the authorisation of the authorised users;

(c) take the necessary measures to ensure the confidentiality of the information received.

Article 9
Logging of data-processing operations

The Agency shall ensure that all data-processing operations are logged. The logs shall provide the following information:

(a) the purpose of the request for access to the repository;

(b) the identification of the authorised user that retrieves the data;

(c) the date and exact time of the data-processing operations;

(d) the identification of the authorised staff that carry out the search.

Article 10
Access to the repository

The authorised users shall establish and maintain:

(a) a list of authorised staff;

(b) procedures regarding access to the repository; such procedures shall comply with the legal requirements applied to the access and processing of information laid down in Union and national law. They shall document the terms and conditions for authorised staff to access the repository.

Article 11
Security management of the repository

The Agency shall protect the infrastructure of the repository and its information, and shall develop:

(a) a security management plan;

(b) a business continuity plan;

(c) a disaster recovery plan.

The authorised users shall manage the security of their information before and during the transmission to the repository and shall protect their infrastructure by ensuring:

(a) the establishment of interfaces between their systems and the repository;

(b) the operation and maintenance of the interfaces;

(c) that authorised staff are properly trained in information security, applicable data protection legislation and fundamental rights before they are allowed to process information stored in the repository.

CHAPTER IV

PERSONAL DATA PROTECTION

Article 12
Processing of personal data stored in the repository
Article 13
Joint controllership of personal data processed in the repository
Article 14
Allocation of responsibilities among joint controllers

The Agency shall be responsible for:

(a) the setting up, operation and administration of the repository;

(b) the continued management of the repository, in particular the access rights and the security and confidentiality of the personal data processed in the repository in accordance with Articles 4, 5, 9 and 12;

(c) communicating any personal data breaches within the repository to the authorised users, to the European Data Protection Supervisor and, where required, to the data subjects in accordance with Article 34 of Regulation (EU) 2018/1725;

(d) defining and implementing the technical means to enable data subjects the exercise of their rights in accordance with Regulation (EU) 2018/1725.

The national competent authorities and the Commission shall be responsible for:

(a) processing personal data in the repository in accordance with the Storage, Exchange and User access interfaces referred to in Article 3 and security requirements defined in paragraph 4 of Article 12;

(b) ensuring the security of any processing of personal data outside the repository when such data is processed for the purposes of or in connection to the processing through the repository;

(c) designating and communicating to the Agency the authorised staff who shall be granted access to the repository in accordance with Article 11;

(d) acting as contact point for the data subjects falling under their responsibility as sole controllers, including when they exercise their rights, using where necessary the technical means provided by the Agency in accordance with point 1(d), or through the communication channels designated in point 3;

(e) notifying the Agency of any security incident, including personal data breaches that may compromise the security, confidentiality, availability or integrity of the personal data transmitted and/or stored in the repository;

(f) notify any data breaches relating to personal data processed in the repository to the respective competent supervisory authorities and, where so required, to data subjects, in accordance with Articles 33 and 34 of Regulation (EU) 2016/679 and Article 34 of Regulation (EU) 2018/1725 as applicable.

Each joint controller shall designate:

(a) a point of contact with a functional mailbox for the communication amongst them;

(b) a point of contact to support data subjects in the exercise of their rights according to the applicable data protection legislation.

Article 15
Restrictions

The controllers may restrict the exercise of the rights of data subjects only to the extent and for as long as strictly necessary to safeguard civil aviation safety. The exercise of data subjects’ rights may only be restricted in the following situations:

(a) ongoing investigations, inspections or monitoring activities referred to in Article 75(2), point (e), of Regulation (EU) 2018/1139 and performed by the Agency within the remit of its responsibilities, or by the competent authorities as provided for by national or Union law;

(b) ongoing proceedings before the Court of Justice of the European Union or any other competent court under national or international law.

Article 16
Storage period of personal data

The authorised users shall:

(a) store personal data within the repository for a maximum period of 10 years starting from the date of expiry of the document, or from the date it is no longer valid, including any documents necessary for the procedures referred to in Regulation (EU) 2018/1139 unless a different period is required by national law;

(b) delete personal data from the repository as soon as the storage period elapses.

The repository shall have the technical means to enable:

(a) the automated erasure of personal data upon expiry of the storage period;

(b) the automated pseudonymisation, or other technical solutions with equivalent effect, of personal data stored for archiving purposes.

Article 17
Processing for archiving and historical research purposes in the interest of safety of aviation

CHAPTER V

FINAL PROVISIONS

Article 18
Entry into force and application

The requirements concerning information objects issued after the entry into force of this Regulation shall be applicable:

(a) as of 1 January 2027 for Annex I, group A category;

(b) as of 1 January 2028 for Annex I, group B category;

(c) as of 1 January 2029 for Annex I, group C category.

This Regulation shall be binding in its entirety and directly applicable in all Member States.

ANNEX I

Information object Priority groups
Licences
Pilot licence A
Pilot licence validation A
Air traffic controller licence A
Aircraft maintenance licence B
Certificates – Organisations
ATM/ANS provider certificate B
Aerodrome operator certificate B
Air operator certificate (AOC) B
Aerodrome equipment certificate B
Certificate of airworthiness (CofA) B
Flight simulation training devices (FSTD) qualification certificate C
Light UAS operator certificate (LUC) A
—————
U-space service provider (USSP) certificate B
Common Information Service Provider certificate B
Certificates – Personnel
Certificate of remote pilot theoretical training C
Examiner certificate A
Instructor certificate A
Language proficiency assessment center certificate C
Certificates – Products/Equipment
Type-certificate (TC) B
Supplemental type-certificate (STC) B
Restricted type certificate (RTC) B
Type certificate data sheet C
Noise certificate C
Restricted noise certificate C
Airworthiness review certificate (ARC) C
Restricted certificate of airworthiness (RCofA) C
Major/Minor changes approval C
Major/Minor repair design approval C
ATM/ANS systems and ATM/ANS constituents certificate B
Certificates – Medical
Aeromedical examiner certificate A
Aeromedical centres (AeMC) certificate A
Air traffic controller (ATCO) aeromedical examiner certificate A
Air traffic controller (ATCO) medical certificate A
Application form for pilot medical certificate A
Pilot medical examination forms and supporting medical certificates A
Pilot medical certificate A
Declarations
Provider of flight information services (FIS) declaration B
Provider of apron management service declaration B
Ground handling provider declaration B
ATM/ANS systems and ATM/ANS constituents – declaration B
ATM/ANS systems and ATM/ANS constituents – Statement of compliance B
Declaration as provider of training for UAS operators C
NCC and SPO declarations of aircraft operators C
UAS operational declaration STS A
Attestations and reports
Cabin crew attestation C
Cabin crew medical report C
Exemptions
Exemption (cumulative) duration above 8 months – decision B
Exemption (cumulative) duration above 8 months – notification B
Exemption (cumulative) duration above 8 months – recommendation B
Exemption (cumulative) duration up to 8 months – notification B
Exemption from holding ATM/ANS certificate as provider – decision C
Exemption from holding ATM/ANS certificate as provider – notification C
Exemption from holding ATM/ANS certificate as provider C
Approvals
Permit to fly – approval of flight conditions C
Permit to fly C
Maintenance Review Board (MRB) Report approval C
Theoretical knowledge examinations (ECQB) C
Combined Airworthiness Organisation approvals (CAOA) – Part-CAO B
Continuing Airworthiness Management Organisation approvals (CAMOA) B
Maintenance Organisation approvals (MOA) – Part M Subpart F EASA Form 3-MF B
Maintenance Organisation Approvals (MOA) – Part-145 B
Maintenance Training Organisation approvals (MTOA) – Part-147 B
Letter of Agreement for production without production organisation approval C
Production organisation approvals (POA) B
Alternative procedure to design organisation approvals (APDOA) C
Design organisation approvals (DOA) B
Design or production of ATM/ANS equipment approval B
Air traffic controller (ATCO) training organisations B
Cabin crew training organisation (CCTO) approval C
Training organisation (ATO) approval (Pilot) C
Declared training organisation (DTO) for pilot C
Ramp Inspection Training Organisation (RITO) approval B
Decisions
Opt-in to apply specific provisions of Basic Regulation for listed activities – decision C
Invalidation and recognition of certificates or declarations C
Decision to exempt from provision of Basic Regulation for Aerodromes C
Joint responsibility for tasks relating to aircraft operators involved in commercial air transport C
Proposal for Implementing Act/Delegated Act amendment C
Accreditation as a Qualified Entity C
Proposal of Individual Flight Time Specification Scheme (IFTSS) C
Notifications of FTL schemes C
—————
Registration of UAS operator A
Decision of a Member State on the designation of a single common information service provider B
Measures
Immediate measure taken in reaction to a serious safety problem (decision) B
Immediate measure taken in reaction to a serious safety problem (recommendation) B
Immediate measure taken in reaction to a serious safety problem (notification) B
Conflict Zones Information Bulletins (CZIB) – Measures B
Opt-in (Art. 2(6)) to apply specific provisions of Basic Regulation for listed activities (notification) C
Opt-in to apply specific provisions of Basic Regulation for listed activities (recommendation) C
Opt-out to exempt categories of aircraft from specific provisions of the Basic Regulation C
Others
Air operator – operations specifications C
Third country operator’s (TCO) authorisation B
Operational authorisation for UAS operators A
High-Risk Commercial Specialized Operations – authorisation B
Registration of certified UAS B
European technical standard order authorisation (ETSOA) C
Deviation to ETSO C
Proposal for Implementing Act/Delegated Act amendment – notification B
Proposal for IA/DA amendment – recommendation B
List of Member States and Organisations having transferred responsibilities, reallocated task (in accordance with art 64 and 65) and competent authority responsible after reallocation C
Airworthiness directives (AD), Safety directives, Safety Information Bulletins (SIB) C
Draft recommendations for reply to ICAO State Letters C
ICAO Standards and recommended practices (SARPs) Compliance checklist C
Recommendations for reply to ICAO State Letters C
Alternative Means of Compliance requests C

ANNEX II

Detailed definitions of the markings in accordance with Article 7(2)

(a) PRIVACY is rated in accordance with the categories below: ID Privacy Rating Name Privacy Rating Description PRIV-2 Sensitive Personal Information Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership; processing of genetic data, biometric data for the purpose of uniquely identifying a natural person; data concerning health or data concerning a natural person’s sex life or sexual orientation; data concerning criminal convictions and offences PRIV-1 Non-Sensitive Personal Information Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his or her physical, physiological, mental, economic, cultural or social identity and as long as they do not reveal aspects of the data subject qualifying as sensitive personal information. PRIV-0 Non-Personal Information Information that does not relate to a natural person or which does not lead to the identification of a natural person such as anonymised personal data.

(b) CONFIDENTIALITY is classified in accordance with the levels below: ID Classification Level Name Classification Level Description CONF-3 Catastrophic Information whose unauthorised disclosure would have one or several of the following consequences: — Financial impact of > EUR 10 million — Significant liability/damage compensation claims by the Aviation Repository authorised users and/or interested parties — Significant competitive disadvantage for the Aviation Repository authorised users and/or interested parties — Impossibility for the Aviation Repository authorised users’ to meet their objectives — Total loss of confidence by interested parties and public — Total loss of reputation — The Agency questioned as an organisation CONF-2 Significant Information whose unauthorised disclosure would have one or several of the following consequences: — Financial impact of EUR 1-10 million — Medium liability/damage compensation claims by the Aviation Repository authorised users and/or interested parties — Significantly damaged reputation in the specific business area, negative exposure in both specialised and general press — Loss of confidence by the by interested parties related to the specific business process — Breach of regulatory obligations — Breach of legal obligations — Breach of contractual requirements CONF-1 Limited Information whose unauthorised disclosure would have one or several of the following consequences: — Financial impact of < EUR 1 million — Minor liability/damage compensation claims by the Aviation Repository authorised users and/or interested parties — Reputation – limited negative exposure in specialised media — Loss of confidence by the internal stakeholders related to the specific business process CONF-0 No Impact Information whose unauthorised disclosure would cause the reputation the Aviation Repository authorised users to become inconsistent with desired image but: — No press coverage – Information is already public — No impact on interested parties — No financial impact

(c) INTEGRITY is classified in accordance with the levels below: ID Integrity Level Name Classification Level Description INTGR-3 Catastrophic Information falling within this category is corrupted and/or compromised would have one or several of the following consequences: — Financial loss of > EUR 10 million — Significant liability/damage compensation claims by the Aviation Repository authorised users and/or interested parties — Significant competitive disadvantage for the Aviation Repository authorised users and/or interested parties Impossibility for the Aviation Repository authorised users to meet their objectives — Total loss of confidence by interested parties and public — Total loss of reputation — The Agency questioned as an organisation INTGR-2 Significant Information falling within this category is corrupted and/or compromised would have one or several of the following consequences: — Financial impact of EUR 1-10 million — Medium liability/damage compensation claims by the Aviation Repository authorised users and/or interested parties — Significantly damaged reputation in the specific business area, negative exposure in both specialised and general press — Loss of confidence by the by interested parties related to the specific business process — Breach of regulatory obligations — Breach of legal obligations — Breach of contractual requirements INTGR-1 Limited Information whose unauthorised disclosure would have one or several of the following consequences: — Financial impact of < EUR 1 million — Minor liability/damage compensation claims by the Aviation Repository authorised users and/or interested parties — Reputation – limited negative exposure in specialised media — Loss of confidence by the internal stakeholders related to the specific business process INTGR-0 No Impact Information whose unauthorised disclosure would cause the reputation the Aviation Repository authorised users to become inconsistent with desired image but: — No press coverage — Information is already public — No impact on interested parties — No financial impact

(d) AVAILABILITY is classified in accordance with the levels below: ID Availability Level Name Classification Level Description AVAIL-3 Catastrophic In case of disruption, access to information needs to be re-established in a maximum period of time of 24 hours (incl. nights and week-ends) AVAIL-2 Significant In case of disruption, access to information needs to be re-established in a maximum period of time of 1 calendar week AVAIL-1 Limited In case of disruption, access to information needs to be re-established in a maximum period of time of 2 calendar weeks AVAIL-0 No Impact In case of disruption, access to information needs to be re-established in a maximum period of time of 1 month

Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.

This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence. EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.