10.5.2019
EN
Official Journal of the European Union
L 123/21
(23)
National authorities investigating or prosecuting offences referred to in this Directive should be empowered to
cooperate with other national authorities within the same Member State and their counterparts in other Member
States.
(24)
In many cases, criminal activities are behind incidents that should be notified to the relevant national competent
authorities under Directive (EU) 2016/1148 of the European Parliament and of the Council (8). Such incidents
may be suspected to be of a criminal nature even if there is insufficient evidence of a criminal offence at that
stage. In such a context, relevant operators of essential services and digital service providers should be
encouraged to share the reports required under Directive (EU) 2016/1148 with law enforcement authorities so as
to form an effective and comprehensive response and to facilitate attribution and accountability by the
perpetrators for their actions. In particular, promoting a safe, secure and more resilient environment requires
systematic reporting of incidents of a suspected serious criminal nature to law enforcement authorities. Moreover,
when relevant, computer security incident response teams designated under Directive (EU) 2016/1148 should be
involved in law enforcement investigations with a view to providing information, as considered appropriate at
national level, and also to providing specialist expertise on information systems.
(25)
Major security incidents as referred to in Directive (EU) 2015/2366 of the European Parliament and of the
Council (9) may be of criminal origin. Where relevant, payment service providers should be encouraged to share
with law enforcement authorities the reports they are required to submit to the competent authority in their
home Member State under Directive (EU) 2015/2366.
(26)
A number of instruments and mechanisms exist at Union level to enable the exchange of information among
national law enforcement authorities for the purposes of investigating and prosecuting crimes. To facilitate and
speed up cooperation among national law enforcement authorities and make sure that those instruments and
mechanisms are used to the fullest extent, this Directive should strengthen the importance of the operational
points of contact introduced by Framework Decision 2001/413/JHA. It should be possible for Member States to
decide to make use of the existing networks of operational points of contact, such as the one set up in Directive
2013/40/EU. The points of contact should provide effective assistance, for example by facilitating the exchange of
relevant information and the provision of technical advice or legal information. To ensure the network runs
smoothly, each point of contact should be able to communicate quickly with the point of contact in another
Member State. Given the significant trans-border dimension of crimes covered by this Directive and in particular
the volatile nature of electronic evidence, Member States should be able to deal promptly with urgent requests
from the network and provide feedback within eight hours. In very urgent and serious cases, Member States
should inform the European Union Agency for Law Enforcement Cooperation (Europol).
(27)
Reporting crime to public authorities without undue delay is of great importance in combating fraud and
counterfeiting of non-cash means of payment, as it is often the starting point of criminal investigations. Measures
should be taken to encourage reporting by natural and legal persons, in particular financial institutions, to law
enforcement and judicial authorities. Those measures can be based on various types of action, including
legislative acts containing obligations to report suspected fraud, or non-legislative actions, such as setting up or
supporting organisations or mechanisms favouring the exchange of information, or awareness raising. Any such
measure that involves processing of the personal data of natural persons should be carried out in accordance
with Regulation (EU) 2016/679 of the European Parliament and of the Council (10). In particular, any
transmission of information for the purposes of preventing and combating offences relating to fraud and counter
feiting of non-cash means of payment should comply with the requirements laid down in that Regulation,
notably the lawful grounds for processing.
(28)
In order to facilitate the prompt and direct reporting of crime, the Commission should carefully assess the
establishment of effective online fraud-reporting systems by Member States and standardised reporting templates
at Union level. Such systems could facilitate the reporting of non-cash fraud which often takes place online,
thereby strengthening support for victims, the identification and analysis of cybercrime threats and the work and
cross-border cooperation of national competent authorities.
(8) Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level
of security of network and information systems across the Union (OJ L 194, 19.7.2016, p. 1).
(9) Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal
market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive
2007/64/EC (OJ L 337, 23.12.2015, p. 35).
10
( ) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with
regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data
Protection Regulation) (OJ L 119, 4.5.2016, p. 1).