#52026XG02668EU privacy notice for people listed under cyber-attack sanctions
AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.
This notice explains how the Council of the EU handles personal data for people listed under EU sanctions related to cyber-attacks. It applies to individuals subject to asset freezes or travel restrictions under the EU cyber sanctions framework. The Council may process identifying details, reasons for listing, and related information received from Member States or EU foreign policy bodies. Listed people can ask to access, correct, complete, erase, object to, or restrict use of their data, and they can complain to the European Data Protection Supervisor.
AI-generated summary. May contain errors. Refer to official sources for legal decisions.
Key Changes
- Explains the Council’s data processing for people listed under EU cyber sanctions
- Confirms what personal data may be processed, including identity details and reasons for listing
- Sets out data subject rights and complaint routes under EU data protection rules
Obligations
What this law requires
The Council of the European Union must retain personal data processed in the context of EU autonomous restrictive measures for 5 years after the data subject is removed from the asset-freeze list or the measure expires; if legal action is brought before the Court of Justice, retention continues until final judgment.
The Council must process only personal data necessary for correctly identifying listed persons, stating reasons for listing, and documenting data related to the grounds for listing under the EU cyber sanctions framework.
When exercising data-subject rights, listed persons must send their request by email to the Council controller and copy the Council Data Protection Officer.
When submitting a data-subject rights request, listed persons must attach a copy of an identification document, such as an ID card or passport, containing an identification number, issuing country, validity period, name, address, and date of birth; other data such as photo or personal characteristics may be blacked out.
The Council must not use automated decision-making when processing the personal data of listed persons under this restrictive-measures framework.