10.5.2019 EN Official Journal of the European Union L 123/21 (23) National authorities investigating or prosecuting offences referred to in this Directive should be empowered to cooperate with other national authorities within the same Member State and their counterparts in other Member States. (24) In many cases, criminal activities are behind incidents that should be notified to the relevant national competent authorities under Directive (EU) 2016/1148 of the European Parliament and of the Council (8). Such incidents may be suspected to be of a criminal nature even if there is insufficient evidence of a criminal offence at that stage. In such a context, relevant operators of essential services and digital service providers should be encouraged to share the reports required under Directive (EU) 2016/1148 with law enforcement authorities so as to form an effective and comprehensive response and to facilitate attribution and accountability by the perpetrators for their actions. In particular, promoting a safe, secure and more resilient environment requires systematic reporting of incidents of a suspected serious criminal nature to law enforcement authorities. Moreover, when relevant, computer security incident response teams designated under Directive (EU) 2016/1148 should be involved in law enforcement investigations with a view to providing information, as considered appropriate at national level, and also to providing specialist expertise on information systems. (25) Major security incidents as referred to in Directive (EU) 2015/2366 of the European Parliament and of the Council (9) may be of criminal origin. Where relevant, payment service providers should be encouraged to share with law enforcement authorities the reports they are required to submit to the competent authority in their home Member State under Directive (EU) 2015/2366. (26) A number of instruments and mechanisms exist at Union level to enable the exchange of information among national law enforcement authorities for the purposes of investigating and prosecuting crimes. To facilitate and speed up cooperation among national law enforcement authorities and make sure that those instruments and mechanisms are used to the fullest extent, this Directive should strengthen the importance of the operational points of contact introduced by Framework Decision 2001/413/JHA. It should be possible for Member States to decide to make use of the existing networks of operational points of contact, such as the one set up in Directive 2013/40/EU. The points of contact should provide effective assistance, for example by facilitating the exchange of relevant information and the provision of technical advice or legal information. To ensure the network runs smoothly, each point of contact should be able to communicate quickly with the point of contact in another Member State. Given the significant trans-border dimension of crimes covered by this Directive and in particular the volatile nature of electronic evidence, Member States should be able to deal promptly with urgent requests from the network and provide feedback within eight hours. In very urgent and serious cases, Member States should inform the European Union Agency for Law Enforcement Cooperation (Europol). (27) Reporting crime to public authorities without undue delay is of great importance in combating fraud and counterfeiting of non-cash means of payment, as it is often the starting point of criminal investigations. Measures should be taken to encourage reporting by natural and legal persons, in particular financial institutions, to law enforcement and judicial authorities. Those measures can be based on various types of action, including legislative acts containing obligations to report suspected fraud, or non-legislative actions, such as setting up or supporting organisations or mechanisms favouring the exchange of information, or awareness raising. Any such measure that involves processing of the personal data of natural persons should be carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (10). In particular, any transmission of information for the purposes of preventing and combating offences relating to fraud and counter­ feiting of non-cash means of payment should comply with the requirements laid down in that Regulation, notably the lawful grounds for processing. (28) In order to facilitate the prompt and direct reporting of crime, the Commission should carefully assess the establishment of effective online fraud-reporting systems by Member States and standardised reporting templates at Union level. Such systems could facilitate the reporting of non-cash fraud which often takes place online, thereby strengthening support for victims, the identification and analysis of cybercrime threats and the work and cross-border cooperation of national competent authorities. (8) Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union (OJ L 194, 19.7.2016, p. 1). (9) Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (OJ L 337, 23.12.2015, p. 35). 10 ( ) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1).

Select target paragraph3