News, events, publications

EDA-DPR-092 - Interoperability & Standardisation Activities

Records and compliance checklist

Under Article 31 of the new Regulation, EUIs have to keep records of their processing operations. This template covers two aspects:

1.Mandatory records under Article 31 of the new rules (recommendation: publicly available)
2.Compliance check and risk screening (internal).

The header and part 1 should be publicly available; part 2 is internal to the EUI. By way of example, column 3 contains a hypothetical record on badges and physical access control in a EUI.
Nr Item Explanation
Header - versioning and reference numbers (recommendation: publicly available)
1. Last update of this record 09-09-2026
2. Reference number EDA-DPR-092
part 1 - article 31 record (recommendation: publicly available)
3. Name and contact details of controller
European Defence Agency

Rue des Drapiers 17-23
B-1050 Brussels
Belgium
4. Name and contact details of DPO

Data Protection Officer

dataprotection@eda.europa.eu

5. Name and contact details of joint controller (where applicable)
N/A
6. Name and contact details of processor (where applicable)
N/A
7. Purpose of the processing
EDA processes personal data for the purpose of supporting and administering its activities in the fields of defence standardisation, military airworthiness and certification, and Test & Evaluation. These activities aim to enhance interoperability among participating Member States by promoting common technical standards, harmonised regulatory and certification frameworks, and aligned testing and evaluation practices. The processing supports cooperation between Member States and relevant stakeholders, facilitates the development, certification, testing, procurement and operation of defence capabilities under common frameworks, and contributes to the strengthening of European defence cooperation and operational effectiveness.
The processing includes the management of expert groups, committees, workshops, consultations and surveys, meetings, training activities, collaborative platforms and forums, and related communications necessary for the implementation of these activities.
8. Description of categories of persons whose data EDA processes and list of data categories

Depending on the specific activity, EDA may process the following categories of personal data:

(a)    Categories of data subjects:

Representatives of Member States, EU bodies and International organisations, stakeholders and experts from industry and academia.

(b)    Categories of personal data processed:

  • identification data and professional contact details (name, surname, title, rank, organisation, function, business email address, business telephone number, postal address);
  • participation-related information (membership in expert groups, advisory groups, committees, project teams or networks);
  • meeting and event management data (attendance lists, registration information, logistical arrangements and meeting contributions);
  • professional qualifications, expertise and areas of competence where relevant to participation in the activities;
  • contribution to consultations, surveys, standards, guidelines and best practices exchanged in the context of the activities; and
  • user account and access management data relating to collaborative platforms, portals, forums and information systems used to support the activities.
9. Time limit for keeping the data

Personal data shall be retained for up to 2 years after the purpose for which they were processed is fulfilled.

Personal data that are subject to financial or administrative audit may be retained for up to 6 years after the delivery of the relevant activities. 

10. Recipients of the data

Personal data may be disclosed, on a need-to-know basis, to:

  • authorised EDA staff responsible for managing the activities;
  • representatives of participating Member States and their competent authorities;
  • external contractors and service providers acting on behalf of EDA under appropriate contractual safeguards;
  • and other stakeholders participating in the relevant activities, where necessary for the achievement of the processing purposes.

Personal data of authors and contributors to standards, guidelines and best practices that are published by EDA or distributed to the Member States may become publicly available.

11. Are there any transfers of personal data to third countries or international organisations? If so, to which ones and with which safeguards?
N/A
12. General description of security measures, where possible.
User data is protected through strict technical and organizational measures aligned with EU data protection rules.  EDA has implemented appropriate technical and organisational measures (firewalls, checkpoints, antivirus) to ensure a level of security appropriate to the risks represented by the processing and the nature of the personal data to be protected. Such measures have been taken in particular to prevent any unauthorised disclosure or access, accidental or unlawful destruction or accidental loss, or alteration and to prevent all others unlawful forms of processing. 
13. For more information, including how to exercise your rights to access, rectification, object and data portability (where applicable), see the privacy statement
Information to data subjects on the processing of their data is available through the privacy statement. Information on the processing of personal data for the participation in surveys is available here