You will know who accesses which data, and for what purpose
Your data protection officer asks three questions before approving a digital euro account: which data are processed, who has access to them, and what becomes tamper-proof. You will find here how information is shared between roles. You will see what is recorded on the blockchain, and what stays off-chain. The documents that establish it are listed further down.
Personal data at a glance
- Off-chain Identity, contact details and file documents Held in systems where they can be rectified and erased
- Access by role Each role sees what concerns it Access table settled at the first discussion and written into the contract
- Data subject rights Access, rectification, erasure Restriction and objection, with the competent controller
For a payment in the digital euro account, the blockchain carries the amount, the date, the supplier, the rule applied and the digital euro account it belongs to. The identity of individuals, their contact details and the documents in their file stay off-chain, where they can be rectified and erased. Each role sees what concerns it: the funder how its funds are used, the user their balance and payments, the supplier the payments received, the operator the review of situations.
Purposes and roles
Two distinct processing operations
The data collected by this site and the data processed within a digital euro account each have their own purpose and their own allocation of roles
| Processing | Purpose | Roles |
|---|---|---|
| Site data | Contact and demonstration requests submitted through this site. | MAP is the controller for this processing. |
| Digital euro account data | Running a digital euro account: attachment of holders, applicable rules, operations, reports. | The split between controller and processor is established for each digital euro account and written into the contract. |
Categories of data What the service processes in order to run a digital euro account
The service processes what is necessary for issuance, for checking and for reporting. The exact categories depend on the digital euro account and are set out in the contract
Processed within the digital euro account
- Identification of the account holder, at the level required by the regulations.
- Attachment of the holder to the digital euro account and to the rules that apply to it.
- Operations: amount, date, supplier, rule applied, reason for a refusal.
- Exchanges necessary for support and for handling a complaint.
What stays with its holders
- The contents of the basket stay with the supplier: the service records the supplier category.
- The personal situation stays with the body that reviews it.
- The data of each digital euro account stays within that account.
Access by role
Each role sees what concerns it
This is the counterpart of transparency: the funder accounts for the use of funds, and the person’s life remains their own
- Funder
- Sees how its funds are used: amounts, dates, supplier categories, rules applied and reasons for refusal, for its digital euro account. Reporting stops at the supplier category.
- User
- Sees their own balance, their payments and the rules that apply to them, and only their own.
- Supplier
- Sees the payments it has received, and only those.
- Operator
- Sees what is necessary for reviewing situations and administering the digital euro account, within the scope set at the first discussion.
- MAP
- Accesses the data necessary for issuance, for checking operations and for reporting, according to the role of each party.
The access table for your digital euro account is settled at the first discussion and written into the contract. Each access matches the role of its holder.
On the chain and off the chain
Every payment in the digital euro account is recorded on a tamper-proof blockchain. What appears there is the amount, the date, the supplier, the rule applied and the attachment to the digital euro account. Personal data stays off-chain: the identity of individuals, their contact details and the documents in their file are kept in systems where they can be rectified and erased.
Retention
Retention periods are set by category and by purpose. They take into account the obligations specific to an electronic money institution, which require certain operation records to be kept. They are published here with the document that establishes them.
Rights and points of contact
Data subjects exercise their rights of access, rectification, erasure, restriction and objection with the competent controller. Where MAP acts as a processor for a digital euro account, the request is first a matter for the controller designated in the contract, and MAP assists. The exact contact is published here as soon as it is designated, and appears in the digital euro account contract.
Documents The documents that establish this page
A document appears here once it exists and can be provided in the mode indicated
Need a document for your assessment?
Tell us the document you need, your organisation and the context of your assessment.