of 13 July 2022
supplementing Regulation (EU) 2020/1503 of the European Parliament and of the Council with regard to regulatory technical standards specifying the measures and procedures for crowdfunding service providers’ business continuity plan
(Text with EEA relevance)
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) 2020/1503 of the European Parliament and of the Council of 7 October 2020 on European crowdfunding service providers for business, and amending Regulation (EU) 2017/1129 and Directive (EU) 2019/1937 (1), and in particular Article 12(16), fourth subparagraph, thereof,
(1) |
In order to ensure that the measures and procedures for the business continuity plan referred to in Article 12(2), point (j), of Regulation (EU) 2020/1503 are duly harmonised within the Union, the measures and procedures of such plan should be specified. |
(2) |
In order to properly address the risks associated with the cessation of critical services, the business continuity plan should ensure that critical services including those that are outsourced, continue to be performed despite the failure of the crowdfunding service provider, or the third party to which critical services have been outsourced. |
(3) |
Given the range of events that can have a detrimental impact on the performance of critical services, the business continuity plan should address situations triggering a significant defect or default in the performance of critical services. |
(4) |
To ensure that the business continuity plan is effective, it is appropriate to set out the minimum content of measures and procedures for the business continuity plan. |
(5) |
It is appropriate to clarify a limited number of technical terms. Those technical definitions are necessary to ensure the uniform application of this Regulation and, hence, contribute to the establishment of a single rulebook for Union crowdfunding service providers. Those definitions serve only for the purpose of setting out the obligations of crowdfunding service providers and should be strictly limited to understanding this Regulation. |
(6) |
This Regulation is based on the draft regulatory technical standards submitted to the Commission by the European Securities and Markets Authority. |
(7) |
European Securities and Markets Authority has conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential related costs and benefits and requested the advice of the Securities and Markets Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1095/2010 of the European Parliament and of the Council (2). |
(8) |
The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (3) and delivered an opinion on 1 June 2022, |
(1) OJ L 347, 20.10.2020, p. 1.
(2) Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission Decision No 2009/77/EC (OJ L 331, 15.12.2010, p. 84).
(3) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).