1. About EP Authenticator

EP Authenticator is a mobile application provided by the European Parliament to support multi-factor authentication for access to European Parliament information and communication technology resources.

The application enables authorised users to:

  • register a mobile device as an authentication method;
  • receive authentication requests through push notifications;
  • approve or reject authentication requests;
  • protect access through the authentication functions available on the device (such as via biometrics if configured by the user).

EP Authenticator does not create a new European Parliament user account. It is linked to an existing European Parliament IT account.

EP Authenticator forms part of the European Parliament Identity and Access Management processing activity described in Record of Processing Activity No 766.

2. Data controller

The controller[1] is the European Parliament, represented by:

European Parliament
Directorate-General for Information Technologies and Cybersecurity
Directorate for ICT Infrastructure and Security Operations
Cybersecurity Operations Unit
Luxembourg

For questions concerning the processing of personal data or to exercise your data protection rights, you may contact:
itec-inso-personal-data-protection@europarl.europa.eu

You may also contact the European Parliament Data Protection Officer through the contact details published on the European Parliament website.

3. Purpose of the processing

Personal data are processed in order to:

  • identify and authenticate authorised users;
  • register EP Authenticator as a multi-factor authentication method;
  • deliver authentication requests to the registered device;
  • allow users to approve or reject authentication requests;
  • prevent unauthorised access to European Parliament ICT resources;
  • support security monitoring, troubleshooting and fraud detection;
  • maintain the security, integrity and availability of the authentication service.

The processing is necessary to ensure that an appropriate and consistent level of security is applied to European Parliament IT services.

4. Legal basis

The processing is based on:

  • Article 5(1)(a) of Regulation (EU) 2018/1725, as it is necessary for the performance of tasks carried out in the public interest and for the management and functioning of the European Parliament; and
  • Article 5(1)(b) of Regulation (EU) 2018/1725, as it is necessary for compliance with the cybersecurity obligations applicable to Union institutions, bodies, offices and agencies, in particular Article 8(3)(c) of Regulation (EU, Euratom) 2023/2841.

5. Personal data processed by the mobile application

EP Authenticator processes only the personal and technical data necessary to register the application and deliver authentication requests:

  • the unique identifier of the European Parliament user account and related identifier information (i.e. name, surname and email);
  • a registration or device identifier;
  • the Apple Push Notification service (for iOS devices) or Firebase Cloud Messaging push token (for Android devices);
  • technical identifiers required to associate the application installation with the registered authentication method.

Additional information relating to authentication events, such as the application accessed, date and time, authentication result, IP address or country-level contextual information, may be processed by the European Parliament authentication backend.

The application does not use personal data for advertising, profiling or commercial purposes.

6. Camera access

EP Authenticator may request access to the device camera exclusively to scan the QR code used during registration and authentication.

Images captured for QR-code scanning are not stored or transmitted by the application.

7. Biometric authentication

EP Authenticator may use the biometric authentication functions provided by the device operating system, such as Face ID, Touch ID or the corresponding Android biometric functions.

Biometric data are:

  • processed exclusively by the device operating system (locally and never leaves the device);
  • not accessible to the European Parliament or Nevis Security GmbH;
  • not transmitted to the European Parliament, Nevis, Apple or Google;
  • not stored by EP Authenticator.

The application receives only confirmation of whether the local biometric verification succeeded or failed.

Remark: Biometric authentication is one of the authentication methods available to the users. As such, it is optional and can be activated only as per sole user choice.

8. Push notifications

Push notifications are used to inform the registered device that an authentication request is available.

The following services are used:

  • Apple Push Notification service (for iOS devices);
  • Firebase Cloud Messaging (for Android devices).

The notification sent through Apple or Google contains only a technical identifier required to retrieve the authentication request securely from the European Parliament authentication backend.

The notification does not contain the user’s name, European Parliament account identifier, details of the application being accessed or other authentication information.

Apple and Google receive only the push token and the technical information required to deliver the notification.

9. Local storage and security

EP Authenticator stores locally only the information and cryptographic material necessary to operate the registered authentication method.

Sensitive cryptographic material is protected using the security mechanisms provided by the mobile operating system, such as the iOS Keychain or Android Keystore, as applicable.

Appropriate technical and organisational measures are applied to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. Detailed security configurations are not published in order to protect the security of the authentication service.

10. Removal and deregistration

Users may remove EP Authenticator as an authentication method through the European Parliament self-service profile application.

Uninstalling EP Authenticator from the device revokes the corresponding device registration in the authentication backend and removes the application data stored locally.

Uninstalling the application does not delete or otherwise affect the user’s European Parliament IT account or profile.

11. Retention

Registration information and related personal data are:

  • Retained for as long as the user has a relationship with the European Parliament that grants access to an EP IT account, unless the authentication method is removed earlier (in such as case, data will be kept up to 6 months from the authentication method removal).

Authentication, technical and security logs are:

  • Retained for a maximum period of six months (from logs creation).

Furthermore, when the relationship granting an EP IT account ends, the account and associated personal data are disabled and subsequently deleted in accordance with the retention periods defined in the European Parliament Identity and Access Management Record of Processing Activity No 766.

Finally, data are not retained for historical, scientific or statistical purposes after the processing has ended.

12. Recipients

Recipients are as follows:

  • Authorised European Parliament staff and service providers who require access for:
    • operation and administration of the authentication service;
    • security monitoring;
    • analysis of technical issues;
    • debugging and user support;
    • investigation of security incidents;
    • compliance with applicable legal and cybersecurity obligations.
  • The processor providing the multi-factor authentication service to the European Parliament (processing personal data only if necessary and on documented instructions from the European Parliament and under contractual data protection, confidentiality and security obligations).

Technical information may also be processed through European Parliament cross-cutting ICT activities, including log management, backup, helpdesk support and business continuity operations.

13. International data transfers

The service (provided via the processor) is hosted and delivered from the selected European Union region. Limited technical access for support may take place from Switzerland, which is recognised by the European Commission as providing an adequate level of protection for personal data.

Where personal data are transferred outside the European Union or European Economic Area, such transfers are subject to the safeguards required by Regulation (EU) 2018/1725, including adequacy decisions or appropriate contractual safeguards, as applicable.

Remark: The use of Apple Push Notification service and Firebase Cloud Messaging may involve data routing or technical processing outside the European Economic Area. Only the limited technical information required to deliver the push notification is transmitted for this purpose.

14. Are any automated processes[2] and/or profiling[3] used to make decisions which could affect you?

No.

15. If personal data have not been obtained from you, what is their source?

The following data are indirectly collected from the data subjects:

  • Name, surname and email (collected from the EP corporate directory)

16. Your rights

Under Regulation (EU) 2018/1725, you may have the right to:

  • access your personal data;
  • request the rectification of inaccurate or incomplete personal data;
  • request the erasure of your personal data where the applicable conditions are met;
  • request restriction of processing;
  • object to processing where the applicable conditions are met.

To exercise your rights or request further information, contact:
itec-inso-personal-data-protection@europarl.europa.eu

Requests will be assessed in accordance with Regulation (EU) 2018/1725. Certain requests may be restricted where processing is necessary to comply with cybersecurity, security or account-management obligations.

17. Complaints

You may contact the European Parliament Data Protection Officer if you have concerns regarding the processing of your personal data.

You also have the right to lodge a complaint with the European Data Protection Supervisor:

European Data Protection Supervisor
Rue Wiertz 60
B-1047 Brussels
Belgium

18. Changes to this notice

This privacy policy (data protection notice) may be updated to reflect changes to EP Authenticator, the authentication service, applicable legal requirements or the European Parliament Identity and Access Management processing activity.

The most recent version will be made available through the European Parliament website and, where appropriate, through the application or the relevant application store.



[1] A Controller is the public authority, agency or other body which, alone or jointly with others, determines the

purposes and means of the processing of the personal data. The controller is represented by the head of the

entity.

[2] Making a decision solely by automated means and without any human involvement. {Theoretical Examples: internet page where selecting certain options will automatically place you in different mailing lists via which you are sent the corresponding monthly newsletter / using an automated system to mark “Multiple Choice” test answers and assign a pass mark according to the number of correct answers}

[3] Profiling analyses aspects of an individual’s personality, behaviour, interests and habits to make predictions or decisions about them. Used to analyse or predict aspects concerning the data subject’s performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, etc. {Theoretical Example: when using social media tools data is collected and your trends registered. This data is then used to form new/different predictions on you.}