TheLawyer.sh
Tilbage

Commission Implementing Regulation (EU) 2025/2447of 4 December 2025laying down the rules for the application of Regulation (EU) 2018/1727 of the European Parliament and of the Council, as regards the technical specifications, measures and other requirements for the establishment and use of the decentralised IT system for secure processing and communication of information

32025R2447

Den Europæiske UnionForordning2025

European Union

§ Article 3

Article 3(9) of Regulation (EU) 2022/850 defines digital procedural standards as the technical specifications for business process models and data schemas which set out the electronic structure of the data exchanged through the e-CODEX system.

This Annex sets out the technical specifications for business process models and the technical specifications of data schemas.

  1. Technical specifications for the business process models under Regulation (EU) 2018/1727

The technical specifications for business process models are set out in points 1.1 to 1.5. They define the key aspects necessary for enabling electronic communication for the purposes of Regulation (EU) 2018/1727 through the decentralised IT system.

The decentralised IT system shall allow exchange of information only between the competent national authorities of a Member State and the national member from that Member State.

1.1.

Exchange of information related to the European Judicial Counter-Terrorism Register (CTR) Article 21a of Regulation (EU) 2018/1727

1.1.1.

Transmit CTR data model:

The competent national authority transmits data on terrorist proceedings for the CTR to the national member.

1.1.2.

Receive CTR data model:

The national member receives the CTR data.

1.1.3.

Request consent model:

The national member requests the consent of its competent national authority.

1.1.4.

Receive consent request model:

The competent national authority receives the consent request.

1.1.5.

Send reply to consent request model:

The competent national authority sends a reply to the consent request.

1.1.6.

Receive reply to consent request model:

The national member receives the reply to the consent request.

1.1.7.

Inform about link model:

The national member informs the competent national authority about the link with another case.

1.1.8.

Update CTR data model:

The competent national authority transmits data which require updating or deletion to its respective national member.

1.1.9.

Receive updated CTR data model:

The national member receives the CTR data which require updating or deletion.

1.2.

Exchange of information related to serious crime Article 21 of Regulation (EU) 2018/1727

1.2.1.

Transmit serious cross-border crime data model:

The national competent authority transmits data on serious cross-border crime to Eurojust.

1.2.2.

Receive serious cross-border crime data model:

The national member receives the serious cross-border crime data.

1.2.3.

Request consent model:

The national member requests the consent of its national competent authority.

1.2.4.

Receive consent request model:

The competent national authority receives the consent request.

1.2.5.

Send reply to consent request model:

The competent national authority sends a reply to the consent request.

1.2.6.

Receive reply to consent request model:

The national member receives the reply to the consent request.

1.2.7.

Inform about link model:

The national member informs the competent national authority about the link with another case.

1.2.8.

Update serious cross-border crime data model:

The competent national authority transmits data which require updating or deletion to its respective national member.

1.2.9.

Receive updated serious cross-border crime data model:

The national member receives the serious cross-border crime data which require updating or deletion.

1.3.

Exchange of general information

1.3.1.

Send information model:

The national member sends information to the competent national authority or vice versa.

1.3.2.

Receive information model:

The competent national authority or national member receives the information.

1.3.3.

Respond to information model:

The competent national authority responds to the information received from the national member or vice versa.

1.3.4.

Receive response model:

The national member receives the response from the competent national authority.

1.3.5.

Send information model:

The competent national authority sends information to the national member.

1.3.6.

Receive information model:

The national member receives the information.

1.3.7.

Respond to information model:

The national member responds to the information received from the competent national authority.

1.3.8.

Receive response model:

The competent national authority receives the response from the national member.

1.4.

Facilitation and support role Article 8(1) of Regulation (EU) 2018/1727

Note:

Where the facilitation and support models outlined in point 1.5 involve the exchange of statutory forms established by Union legal acts in the area of judicial cooperation in criminal matters, the models shall, where available, use the relevant structured data representations and XML schemas developed for those acts, for example those established for the purposes of implementing Regulation (EU) 2023/2844 or other relevant instruments.

1.5.

Facilitation or support request model:

1.5.1.

Transmit facilitation or support request model:

The national competent authority transmits a facilitation request or support request to its respective national member.

1.5.2.

Receive facilitation or support request model:

The national member receives the facilitation or support request and forwards it to the national member of the requested Member State outside of JUDEX.

1.5.3.

Forward facilitation or support request to competent national authority model:

The national member of the requested Member State sends the request to its respective competent national authority.

1.5.4.

Receive facilitation or support request model:

The competent national authority receives the facilitation or support request.

1.5.5.

Send response to facilitation or support request model:

The competent national authority sends a response to or information concerning the request to the national member of the requested Member State.

1.5.6.

Receive response to facilitation or support request model:

The national member receives the response to or information concerning the facilitation or support request from the competent national authority and shares it with the national member of the requesting Member State outside of JUDEX.

1.5.7.

Respond to facilitation or support request model:

The national member of the requesting Member State responds to or shares the information concerning the facilitation or support request from the competent national authority.

1.5.8.

Receive response model:

The competent national authority receives the response or information concerning the facilitation or support request.

  1. Technical specifications for data schemas

The technical specifications that are to serve as a basis for developing XML Schema Definitions (XSDs) for the digitalisation of Regulation (EU) 2018/1727 are set out in points 2.1 and 2.2 of this Annex. These specifications define the key components, and any other information in order to provide a comprehensive description for the production of these schemas.

The description is intended to be generic allowing the produced XSDs to be modified and extended without requiring significant changes to these specifications.

The specifications shall apply to the statutory form of the schemas as annexed to the Regulation (EU) 2018/1727, any predefined messages, or any free text messages used in exchanges under that Regulation.

2.1.

General considerations

For all schemas to be provided, the following provisions shall apply:

2.1.1.

Versioning

A version attribute shall be included that facilitates schema versioning management and allows the schema to be updated in future iterations as per business requirements. The version attribute shall indicate whether the new version is backward compatible when introducing new features or refinements.

2.1.2.

Schema declaration and metadata

Where applicable, the schema shall make use of relevant standards or vocabularies, required by e-CODEX to provide interoperability, which are necessary for the proper validation of the elements and types defined within this schema. This may include:

EU e-Justice Core Vocabulary

Unqualified Data Types

A code list for European Union Language Codes

Also, where applicable, the schema may incorporate relevant ETSI standards to make use of their definitions.

2.1.3.

Annotations and Documentation

Annotations: Each element in the schema shall typically be accompanied by annotations. The annotations provide human-readable information about the element, often defining its purpose or usage in a clear and concise manner.

2.1.4.

Usage and adaptability

The schema shall follow the rules set out in point (a) to (d):

(a) Modular structure: each section shall be designed with specific functionality and may be reused or adapted independently. This shall make the schema easy to customise for different use cases.

(b) Extensibility: the schema shall be designed to support the inclusion of new elements or attributes if additional information is needed in the future. This shall be achieved by using optional elements and sequences that may be extended without breaking existing implementations.

(c) Adaptable structure: the schema shall be designed in a manner allowing for the addition or modification of elements or data types as necessary. The schema’s structure shall accommodate changes in requirements without the need for major redesigns.

(d) Optional elements: elements within a schema may be marked as optional, that is to say they may be included or omitted based on specific circumstances.

The schema shall be designed to support the collection of structured data for specific requests.

2.1.5.

Modifications

The schema design shall be characterised by flexibility, modularity and ease of adaptation. Complex types and optional elements shall be incorporated into the design in such a way that it may handle diverse scenarios while remaining easy to modify and extend.

2.2.

Exchange of structured data

The structured data referred to in points 2.2.1 and 2.2.2 shall be provided in accordance with Article 22a(3) of Regulation (EU) 2018/1727. The schema shall also allow data sets to be indicated which are to be deleted in future updates.

2.2.1.

European Judicial Counter-Terrorism Register data

The following technical specifications for the data schema establish a structured framework for creating the schema in XML format.

(a) Top-level section

This top-level section corresponds to the information set out in Annex III to Regulation (EU) 2018/1727 information for the European Judicial Counter-Terrorism Register (CTR).

(b) Structure of the message

The structure of the CTR data shall consist of a sequence of elements and include the following as a minimum:

(i) information for the identification of natural persons:

surname (family name);

first names (given names);

any aliases;

date of birth;

place of birth (town and country);

nationality or nationalities;

identification document (type and document number);

gender;

place of residence;

(ii) information for the identification of legal persons:

business name;

legal form;

place of head office;

(iii) information for the identification of both natural and legal persons:

telephone numbers;

email addresses;

details of accounts held with banks or other financial institutions;

status in the proceedings;

(iv) information on the offence:

information concerning legal persons involved in the preparation or commission of a terrorist offence;

legal qualification of the offence under national law;

applicable form of serious crime from the list referred to in Annex I;

any affiliation with a terrorist group;

type of terrorism, such as jihadist, separatist, left-wing or right-wing;

brief summary of the case;

(v) information on the national proceedings:

status of such proceedings;

responsible public prosecutor’s office;

case number;

date of opening of formal judicial proceedings;

links with other relevant cases;

(vi) additional information field (free text);

(vii) prior authorisation code.

2.2.2.

Data transmitted in accordance with Article 21 of Regulation (EU) 2018/1727

(a) Article 21(4) of Regulation (EU) 2018/1727, setting up of joint investigation teams (JITs)

(i) Top-level section

This top-level section corresponds to the information set out in Article 21(4) of Regulation (EU) 2018/1727 information on the setting up of JITs.

(ii) Structure of the message

The structure of the data shall consist of a sequence of elements and include the following as a minimum:

National judicial authority in charge of the criminal proceedings

National reference number of the criminal proceedings

Status of the criminal proceedings

Criminal offences investigated

Other countries involved in the case

Case already supported by Eurojust?

If yes, Eurojust case ID?

If no, is this a request for support?

Case supported by Europol?

If yes, operational task force (OTF) and/or Secure Information Exchange Network Application (SIENA)?

JIT agreement:

Countries involved

JIT parties (national authorities in charge of the investigations)

National reference number of the criminal proceedings covered by the JIT

Date of signature

Duration

Criminal offences investigated

Brief summary of the case

Main suspects in the criminal proceedings covered by the JIT (name, surname, date and place of birth and possibly other relevant and necessary categories of data under Annex II)

Results of the work of the JITs:

Difficulties/delays in:

setting up the JIT

requesting/sharing evidence within the JIT

agreeing on/implementing a common prosecution strategy

Admissibility/inadmissibility/evaluation of JIT evidence in national proceedings

Outcome of judicial proceedings (successful/unsuccessful prosecutions and convictions/acquittals)

(iii) Prior authorisation code

(b) Article 21(5) of Regulation (EU) 2018/1727, serious complex cases

(i) Top-level section

This top-level section corresponds to the information set out in Article 21(5) of the Eurojust Regulation, i.e. serious complex cases.

(ii) Structure of the message

The structure of the data shall consist of a sequence of elements and include the following as a minimum:

National judicial authority in charge of the criminal proceedings

National reference number of the criminal proceedings

Status of the criminal proceedings

Criminal offences investigated

Other countries involved in the case

Case already supported by Eurojust?

If yes, Eurojust case ID?

If no, is this a request for support?

Case supported by Europol?

If yes, operational task force and/or SIENA?

Applicable form of serious crime

Involvement of an organised crime network

Mafia type

Transnational organised crime network

Repercussions at EU level

Main suspects in the criminal proceedings (name, surname, date and place of birth and possibly other relevant and necessary categories of data under Annex II)

Brief summary of the case

Other countries involved

Countries with which cooperation already initiated

Competent authorities involved in other country

Judicial cooperation instruments used

Number of requests sent/received

Existence of linked investigations

Countries with which cooperation to be activated/countries possibly affected

Type of cooperation needed (such as. extradition, evidence gathering, other cooperation)

Existence of linked investigations

(iii) Prior authorisation code

(c) Article 21(6), point (a), of Regulation (EU) 2018/1727, conflicts of jurisdiction

(i) Top-level section

This top-level section corresponds to the information set out in Article 21(6), point (a) of Regulation (EU) 2018/1727, i.e. conflicts of jurisdiction.

(ii) Structure of the message

The structure of the data shall consist of a sequence of elements and include the following as a minimum:

National judicial authority in charge of the criminal proceedings

National reference number of the criminal proceedings

Status of the criminal proceedings (e.g. investigation, prosecution, trial)

Criminal offences investigated

Other countries involved in the case

Case already supported by Eurojust?

If yes, Eurojust case ID?

If no, is this a request for support?

Case supported by Europol?

If yes, operational task force and/or SIENA?

Other countries involved

Competent national authorities in the other country, if known

National reference number of criminal proceedings in other country

Stage of proceedings in other country, if known

Positive or negative conflict

Actual or potential conflict

Coordination activities already undertaken (e.g. consultations under Council Framework Decision 2009/948/JHA

Council Framework Decision 2009/948/JHA of 30 November 2009 on prevention and settlement of conflicts of exercise of jurisdiction in criminal proceedings (OJ L 328, 15.12.2009, p. 42, ELI: http://data.europa.eu/eli/dec_framw/2009/948/oj).

)

Brief summary of the case

Main common suspects (name, surname, date and place of birth and possibly other relevant and necessary categories of data under Annex II)

(iii) Prior authorisation code

(d) Article 21(6), point (b), controlled deliveries

(i) Top-level section

This top-level section corresponds to the information set out in Article 21(6), point (b) of Regulation (EU) 2018/1727: controlled deliveries.

(ii) Structure of the message

The structure for the data shall consist of a sequence of elements and include the following as a minimum:

National judicial authority in charge of the criminal proceedings

National reference number of the criminal proceedings

Status of the criminal proceedings (e.g. investigation, prosecution, trial)

Criminal offences investigated

Other countries involved in the case

Case already supported by Eurojust?

If yes, Eurojust case ID?

If no, is this a request for support?

Case supported by Europol?

If yes, operational task force and/or SIENA?

Other countries involved

Country of origin/transit/destination

Competent national authorities in other countries

Existence of linked investigations in other countries

Type of goods delivered (e.g. drugs and type/money/weapons/cigarettes/other)

Status of the controlled delivery (e.g. planned, ongoing, completed)

Outcome of the controlled delivery, if already executed

Judicial cooperation instrument used

Main common suspects (name, surname, date and place of birth and possibly other relevant and necessary categories of data under Annex II)

(iii) Prior authorisation code

(e) Article 21(6), point (c), of Regulation (EU) 2018/1727, repeated issues with judicial cooperation instruments

(i) Top-level section

This top-level section corresponds to the information set out in Article 21(6), point (c) of Regulation (EU) 2018/1727: repeated issues with judicial cooperation instruments.

(ii) Structure of the message

The structure of the data shall consist of a sequence of elements and include the following as a minimum:

National judicial authority in charge of the criminal proceedings

National reference number of the criminal proceedings

Status of the criminal proceedings (e.g. investigation, prosecution, trial)

Criminal offences investigated

Other countries involved in the case

Case already supported by Eurojust?

If yes, Eurojust case ID?

If no, is this a request for support?

Case supported by Europol?

If yes, operational task force and/or SIENA?

Other countries involved

Competent national authorities, if known

Acting as issuing or executing authority

Judicial cooperation instrument involved (e.g. EAW, EIO, freezing and confiscation)

Specific request concerned (i.e. what investigative measure, what type of freezing, EAW for execution of sentence or for prosecution)

Refusal or repeated difficulty

If refusal, what specific ground invoked?

Brief description of the issue

Other national authorities affected by the same issue, if any

(iii) Prior authorisation code

2.3.

Prior authorisation codes

When sharing data with Eurojust through JUDEX, the competent national authorities shall indicate via prior authorisation codes the further handling, access and transfer of data following identification of a link. The prior authorisation codes shall indicate whether and to what extent information related to the link may be shared with other competent national authorities, other Union agencies and bodies, third countries or international organisations.

2.4.

Predefined messages

Predefined messages are representations of exchanges established by Regulation (EU) 2018/1727, but for which no specific form was provided in the legal act. Their types and number are determined during the business and technical analysis.

The XLM Schema Definitions (XSD) for predefined messages shall be designed to ensure consistency, structure, and compliance with business needs.

The following shall apply to those schemas:

(a) the Top-level Section in this schema shall be named according to the specific message type being defined;

(b) the necessary fields required for the specific message type shall be added and defined within this structure, ensuring proper representation of data elements.

2.5.

Free text messages

Free text messages are representations of exchanges that allow for unstructured or partially structured content, enabling flexibility while still adhering to regulatory and business requirements. The XSD for free text messages shall be designed to ensure consistency and proper formatting.

The following shall apply those schemas.

(a) the Top-level Section in the schema shall be named according to the specific free text message type being defined;

(b) the schema shall define the necessary structure for the free text message while allowing for appropriate ordering of elements as required;

(c) the necessary fields required for the specific free text message type shall be added and defined within this structure, ensuring proper representation of data element.

Annex

ANNEX III

TECHNICAL SPECIFICATIONS OF FINGERPRINTS AND PHOTOGRAPHS

Messages exchanged through the decentralised IT system may be accompanied by attachments, including by National Institute of Standards and Technology (NIST) files containing fingerprints and photographs, in accordance with the technical specifications set out in points 1 and 2.

  1. Fingerprints

The fingerprints which may be shared with Eurojust for the purpose of reliably identifying individuals subject to criminal proceedings related to terrorism offences, shall meet the following conditions:

(a) the fingerprints are provided in one file containing fingerprint digital images (the fingerprints NIST file) and are submitted in accordance with the ANSI/NIST-ITL 1-2011 Update 2015 standard (or newer version);

(b) the fingerprints NIST file consists of up to ten individual fingerprints: rolled, flat or both;

(c) all fingerprints are labelled;

(d) the fingerprints are captured by live scans or inked on paper, provided that the fingerprints inked on paper have been scanned in the required resolution and with the same quality;

(e) the fingerprints NIST file allows for the inclusion of complementary information such as the conditions of fingerprint registration and the method used for acquiring individual fingerprint images;

(f) the fingerprints have a nominal resolution of either 500 or 1000 ppi

Pixels per inch.

(with an acceptable deviation of +/– 10 ppi) with 256 grey levels;

(g) the fingerprints compression algorithm to be used follows the recommendations of National Institute of Standards and Technology (NIST). Fingerprint data with a resolution of 500 ppi is compressed using the WSQ algorithm (ISO/IEC 19794-5:2005). Fingerprint data with a resolution of 1000 ppi is compressed using the JPEG 2000 image compression standard (ISO/IEC 15444-1) and coding system. The target compression ratio is 15:1.

  1. Photographs

The photographs which may be shared with Eurojust for the purpose of reliably identifying individuals subject to criminal proceedings related to terrorism offences, shall meet the following conditions:

(a) only one facial image is provided in a photograph file (the photograph NIST file) and is submitted in accordance with the ANSI/NIST-ITL 1-2011 Update 2015 standard, or any newer version available;

(b) the photographs are either grayscale, colour or near infrared;

(c) the quality of the photographs is based on the image requirements of ISO/IEC 19794-5:2011 Frontal image type, or any newer version available;

(d) the photograph NIST file allows the inclusion of complementary information, including the date when the image was taken;

(e) the photographs, in portrait mode, are at a minimum resolution of 600 pixels by 800 pixels and a maximum resolution of 1200 pixels by 1600 pixels;

(f) the face occupies a space within the photograph which ensures a minimum of 120 pixels between the centre of each eye;

(g) the photographs compression algorithm used follows the recommendations of the National Institute of Standards and Technology (NIST). Photographs are compressed only once with JPG (ISO/IEC 10918) or JPEG 2000 (ISO/IEC 15444) image compression standard and coding system, at a 20:1 maximum allowed image compression ratio.

Metadata

Type
Forordning
År
2025
Ikrafttrædelsesdato
1. januar 1970