Data Privacy & Tech

#52026XG02668EU privacy notice for people listed under cyber-attack sanctions

🇪🇺European Union··Other·Low Impact·View source ↗

AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.

🇬🇧 English

This notice explains how the Council of the EU handles personal data for people listed under EU sanctions related to cyber-attacks. It applies to individuals subject to asset freezes or travel restrictions under the EU cyber sanctions framework. The Council may process identifying details, reasons for listing, and related information received from Member States or EU foreign policy bodies. Listed people can ask to access, correct, complete, erase, object to, or restrict use of their data, and they can complain to the European Data Protection Supervisor.

AI-generated summary. May contain errors. Refer to official sources for legal decisions.

Key Changes

  • Explains the Council’s data processing for people listed under EU cyber sanctions
  • Confirms what personal data may be processed, including identity details and reasons for listing
  • Sets out data subject rights and complaint routes under EU data protection rules

Obligations

What this law requires

medium

The Council of the European Union must retain personal data processed in the context of EU autonomous restrictive measures for 5 years after the data subject is removed from the asset-freeze list or the measure expires; if legal action is brought before the Court of Justice, retention continues until final judgment.

Council of the European Union
5 years from removal from the list or expiry of the measure, or until final judgment if legal action is brought
operational
medium

The Council must process only personal data necessary for correctly identifying listed persons, stating reasons for listing, and documenting data related to the grounds for listing under the EU cyber sanctions framework.

Council of the European Union
operational
low

When exercising data-subject rights, listed persons must send their request by email to the Council controller and copy the Council Data Protection Officer.

listed natural persons subject to EU cyber sanctions
disclosure
low

When submitting a data-subject rights request, listed persons must attach a copy of an identification document, such as an ID card or passport, containing an identification number, issuing country, validity period, name, address, and date of birth; other data such as photo or personal characteristics may be blacked out.

listed natural persons subject to EU cyber sanctions
disclosure
medium

The Council must not use automated decision-making when processing the personal data of listed persons under this restrictive-measures framework.

Council of the European Union
prohibition

Affected Parties

Individuals listed under EU cyber-attack sanctionsEU Council sanctions and data protection teams+1 more…

Tags

EU sanctions,data protection,cybersecurity
EU privacy notice for people listed under cyber-attack sanctions | Legiseye