DECISION (EU) 2022/2359 OF THE EUROPEAN CENTRAL BANK | 32022D2359 — European Union law | Esheria

DECISION (EU) 2022/2359 OF THE EUROPEAN CENTRAL BANK

The ECB may restrict certain data-subject rights for internal personal-data processing when needed to protect listed ECB functions, but only after a case-by-case necessity and proportionality assessment.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
European Union
Instrument
Decision
Citation
32022D2359
Status
In force
Version
Undated source snapshot
Language
en
Official source
View official record ↗
IT security access control confidential information internal governance privacy compliance records management

Statute overview

About this statute

The ECB may restrict certain data-subject rights for internal personal-data processing when needed to protect listed ECB functions, but only after a case-by-case necessity and proportionality assessment. IT applications must be kept secure, access to ECB non-public information must follow need-to-know rules, privileged access must be tightly controlled, and security breaches must be detected and followed up.