IRImplementing rule
2.12Is my report confidential?
2.12 Is my report confidential? i. Within my organisation Reporting to the organisation is not necessarily anonymous. This may depend of the type of reporting system used, as some organisations run, next to their mandatory and voluntary reporting systems, confidential reporting systems. Regulation 376/2014 does not require organisations to fully anonymise reports collected but it requires organisations to take the necessary measures to ensure the appropriate confidentiality of the details of occurrences contained in its database (Article 15(1)).
| Key principle Organisations are required to take the necessary measures to ensure the appropriate confidentiality of occurrences they collect and to comply with rules on the processing of personal data. |
|---|
It is notably recognised by Regulation 376/2014 that a clear separation between the department handling occurrence reports and the rest of the organisation may be an efficient way to achieve this objective (Recital 34). This should therefore be encouraged where practicable. In addition Regulation 376/2014 requires organisations to process personal data only to the extent necessary for the purposes of this Regulation and in accordance with applicable personal data rules (Article 15(1)). The Regulation also includes a number of provisions limiting the possible disclosure and use of the information reported and protecting reporters and any person mentioned in a report (see section 2.13 below). ii. Outside of my organisation
| Key principle Member States and EASA are not allowed to record personal details in their databases. Furthermore, they are required to take the necessary measures to ensure the appropriate confidentiality of occurrences they collect and to comply with rules on the processing of personal data. |
|---|
Regulation 376/2014 ensures the confidentiality of individual reporter identity and of any other person involved in reports stored in Member States national occurrence databases and in the EASA database. Indeed it prohibits the recording of personal details (e.g. name of the reporter or anyone else mentioned in the report, addresses of natural persons) in the competent authority database (Article 16(1), (2) and (3) and Recital 35). To support this requirement, organisations are encouraged to refrain from including names and personal details when transferring occurrences reports to their competent authority. In addition, requirements on the confidentiality of information and processing of personnel data similar to those imposed to organisations are applicable to the Member States and to EASA. Finally, Recital 33 highlights the need for national rules on freedom of information to take into account the necessary confidentiality of information. See section 2.13 below for more information on limitation to disclosure and use of information coming from occurrence reports.
IR — Regulation (EU) No 376/2014 · GM to Reg. (EU) No 376/2014 and its IRs · Occurrence Reporting Easy Access Rules · EAR revision 27 Sep 2023