Operational notes Regulation

Eurodac: the databases are interconnected, the data rules come later

7 min read

A fibre-optic patch panel with rows of connectors and interlaced jumper cables inside a network cabinet, black-and-white photograph
Interconnection is the easy part. What needs documenting comes after: a security plan, access logging, deletion rules.

Today, 8 August 2026, the Official Gazette (General Series No. 183) publishes Law No. 145 of 7 August 2026, converting Decree-Law No. 100 of 12 June 2026, “containing urgent measures on justice and for the implementation of the EU’s Pact on Migration and Asylum of 14 May 2024” (translated throughout from the Italian text). Conversion without amendments; the same issue carries the consolidated decree-law text, in force since 12 June. Inside a decree titled after justice and the EU Pact, Article 13 does something worth reading on its own terms: it interconnects existing databases and links them to a single national access point onto a European system. Here we look at the data architecture — not migration policy.

What Article 13 provides

Paragraph 1: the automated fingerprint and facial-image identification system, from the digitisation of the Ministry of the Interior’s national identity register, “is interconnected with the data-processing centre” under Law No. 121 of 1981 — the Ministry’s CED.

Paragraph 2: the national access point sits at the Department of Public Security and “ensures communication to Eurodac of the data and information provided for by that regulation”. Six sources feed in: (1) the CED; (2) the fingerprint and facial-image system; (3) the system under Article 12(9-septies) of Legislative Decree 286/1998; (4) the residence-permit database; (5) the national asylum commission’s systems; (6) the Department for Civil Liberties and Immigration’s systems, for information on minors, status, and Italian citizenship.

The regulation, Article 3(4), is precise on cardinality: “Each Member State shall have a single national access point. Europol shall have a single access point (the Europol access point).” The infrastructure: it “shall use the existing network of the trans-European services for telematics between administrations (TESTA)”, and “personal data transmitted to or from Eurodac shall be encrypted”.

What is still missing

Interconnection is provided for; the rules governing it are deferred. Article 13(3)(c) assigns the implementing decrees the task of setting, for the purposes of Articles 48, 50 and 51: “the procedures for adopting the measures necessary to guarantee data security, including the related security plan”; “the procedures for transferring data to third countries for return purposes”; “the procedures for logging and documentation”. Point (d) adds “the technical arrangements for accessing, entering, updating, consulting, amending and deleting data”.

Paragraph 4 sets the deadline: the decrees “shall be issued, after consulting the Data Protection Authority, within one hundred and eighty days of this decree’s entry into force”. One hundred and eighty days from 12 June 2026 fall on 9 December 2026 — our own calculation, not a date written into the law. One clarification changes how this reads: Articles 48, 50 and 51 of the regulation are already directly applicable, and the decrees exist to give them national effect. The obligation is not missing. What is missing is the written procedure for discharging it here.

What the regulation asks of whoever holds the data

Article 48, “Data security”, requires “the necessary measures, including a data security plan”. Named controls: “physically protecting data, including by drawing up contingency plans for the protection of critical infrastructure”; “preventing data media from being read, copied, modified or removed without authorisation (data media control)”; “preventing unauthorised persons from using data-processing systems by means of data-transmission equipment (user control)”; “preventing the unauthorised entry of data and the unauthorised inspection, modification or deletion of personal data stored (storage control)”.

Article 51 requires every Eurodac comparison operation for law-enforcement purposes to be logged, to verify admissibility and lawfulness. Mandatory minimum content: “the exact purpose of the comparison request”; “the national file number”; “the exact date and time of the comparison request sent to Eurodac by the national access point”; “the name of the authority that requested the comparison and the official responsible who submitted the request and processed the data”; “the data used for the comparison” — a public list of what it means, technically, to log access to interconnected databases.

How we check it

When a client interconnects two archives that were previously separate, the first question we ask is not whether it can be done, but which register will show — months later, in front of an inspection — who queried what, for what purpose, at what exact moment, and how that data is deleted once its purpose lapses. It is the scheme Article 51 sets out: purpose, file, date and time, responsible official, data used. We build it before the interconnection goes live, not after.

See the service · Talk to an engineer

Third countries, and Chapter V

Article 50(2) anchors transfers to third countries for return purposes to the general framework: they “shall be carried out in accordance with the relevant provisions of Union law, in particular the provisions on data protection, including Chapter V of Regulation (EU) 2016/679, and, where applicable, readmission agreements, as well as the national law of the transferring Member State”. It is the only point where the Eurodac regulation explicitly defers to the general regime for transfers outside the EU.

The people, and minors

The text, reported without comment. Article 14 of the regulation: “The biometric data of minors aged six or older shall be taken by officials specifically trained to carry out this task in a child-friendly and child-sensitive manner and in full respect of the best interests of the child and the safeguards laid down in the United Nations Convention on the Rights […]”.

Article 10 of the decree-law: fact-finding checks and transmission to Eurodac “shall in any event be concluded within a maximum period of seventy-two hours”. For minors, “the relevant communications […] are sent to the public prosecutor’s office at the juvenile court, and the procedures take place in the presence of an adult family member or, if the minor is an unaccompanied foreign minor or no adult family member can be found, in the presence of a representative or, where none has been appointed, a trained person”.

The clause that avoids rewriting everything

Paragraph 5: “Where laws, regulations, decrees or other rules or measures refer to the Eurodac system under Regulation (EU) No. 603/2013, the reference shall be understood as referring to the ‘Eurodac system’ under Regulation (EU) 2024/1358”. A dynamic renvoi: every reference to the old Eurodac reads as a reference to the new one, without rewriting the instruments that cite it — a technique worth knowing for anyone maintaining an internal body of rules, though it shifts the work onto whoever keeps the cross-references current.

What any other organisation takes from this

For any organisation unifying separate archives, Article 13 offers a reusable pattern:

  • write the security plan before interconnection, not after the systems are already talking to each other;
  • decide in advance the minimum content of every log entry: purpose, file, exact date and time, authority and official responsible, data used;
  • design deletion alongside entry, not as an afterthought;
  • treat cross-border transfers as a chapter of their own;
  • date the assessment: an architecture is judged partly on when it was decided.

The two axes, applied

The security plan, the minimum content of log entries, the deletion rules and the transfer procedures become a control that runs on the client’s systems, with a dated trail ready for an inspection or the Data Protection Authority — not an opinion that ends with an email. That is the compliance axis.

That is the deciding axis: six sources, one access point, at national scale — the same work we do at organisational scale, where archives, management systems, sensors and documents scattered across an organisation become a single operating model, the entity’s data lake reduced to one, on which AI agents execute decisions with an operator in command, for large enterprises, defence, public administration and healthcare. Article 51’s logging requirements read as a specification, not a curiosity.

The principle we set out for RESTREINT UE systems in EU defence programmes applies here too: what gets accredited is the system, not merely the party using it. Always in two modes: on-premise, on autonomous machines requiring no deep integration into the client’s network, or dedicated cloud with a data centre in Italy — always with shared management.

To work out which register your organisation would need when two archives interconnect, the first session comes at no cost. Talk to us.

Sources