Data Act – Automatic Customs System (ACS)

1. General information

D+TB makes the Automatic Customs System (“ACS”) available to professional customers for the automated or semi-automated processing and exchange of customs, excise and related electronic data and messages.

To the extent that Chapter VI of Regulation (EU) 2023/2854 (“Data Act”) applies to the relevant ACS service, this page contains the information made available by D+TB concerning switching and data portability, the available export formats and data structures, and the ICT infrastructure used for ACS.

The official text of the Data Act is available via EUR-Lex .

2. Switching and data portability

An ACS customer wishing to terminate the relevant service, switch to another provider of data processing services or port its exportable data and digital assets to its own ICT infrastructure may submit a written request to D+TB via [email protected].

Where the Customer switches to another provider, the Customer shall provide the information relating to the destination environment that is reasonably necessary to carry out the switching process.

D+TB can make exportable ACS data available without requiring reactivation of the Customer's discontinued production connection. The data are transferred using an appropriate and secure electronic transfer method.

The standard method for ACS data portability consists of providing an electronic export package in accordance with the ACS Data Export Format described below.

The Customer and, where applicable, its destination provider are responsible for importing, configuring and further processing the exported data in the destination environment. Additional migration, conversion or implementation services may be agreed separately with D+TB.

3. Categories of exportable ACS data

Depending on the ACS Module concerned, the functionalities used by the Customer and the data actually available in relation to that Customer, the export package may contain the following categories:

  • original electronic data and messages submitted to ACS by or on behalf of the Customer;
  • messages generated or converted by ACS and transmitted to a competent authority;
  • electronic replies and system responses received from competent authorities;
  • MRNs and other reference numbers assigned by competent authorities;
  • acceptance and rejection messages;
  • status, release and clearance messages;
  • error messages and error codes;
  • relevant timestamps and other technical metadata relating to the processing of the relevant messages;
  • transferable customer-specific master, reference and configuration data;
  • other transferable digital assets introduced by the Customer in respect of which the Customer has a right of use independently of ACS.

4. ACS Data Portability Register

This section constitutes D+TB's current online Data Portability Register for ACS. It describes the data structures, data formats and relevant technical specifications in which exportable ACS data are made available.

4.1. ACS Data Export Format

The current standard is ACS Data Export Format 1.0.

A standard ACS data export is made available as a single electronic ZIP export package containing structured XML files encoded in UTF-8.

Component Content
manifest.xml Identification of the export package and metadata enabling the exported files and messages to be identified and linked to the relevant data flows.
incoming/ Original electronic messages submitted to ACS by or on behalf of the Customer.
outgoing/ Electronic messages transmitted from ACS to a competent authority.
responses/ Electronic replies received from competent authorities, including acceptance, rejection, status, release and error messages.
customer-data/ Transferable customer-specific master, reference and configuration data, where available and insofar as they do not contain protected internal D+TB information.

4.2. Manifest structure

The manifest.xml file may contain, where the relevant information is available, metadata including:

  • export format version;
  • date and time on which the export package was generated;
  • relevant ACS Module;
  • period covered by the export;
  • unique message identifier;
  • message type;
  • message direction;
  • timestamp;
  • competent authority reference;
  • MRN or other relevant reference, where available;
  • message or case status, where available;
  • reference to the corresponding XML file in the export package.

4.3. Electronic message structure

Wherever possible, electronic messages are included in the XML structure in which they were received by ACS, transmitted to the competent authority or received from that authority.

Where a publicly available technical specification, message standard or XML structure issued by a competent authority applies to a message, the original message structure is retained in the export package.

Internal processing, mappings or conversions used by D+TB within ACS to communicate between different message structures or systems do not form part of this export specification.

4.4. Formats and technical standards

Element Format / specification
Export package ZIP
Structured data XML
Character encoding UTF-8
Date and time values ISO 8601, where applicable
Customs, excise and authority messages Publicly available message specifications of the competent authority applicable to the original message, where relevant.

If harmonised standards, common specifications or other applicable open interoperability specifications become relevant to the ACS switching process in the future, D+TB will update this register accordingly.

4.5. Known technical limitations

The ACS Data Export Format is intended to make exportable data available in a structured, commonly used and machine-readable format. It does not guarantee that the exported data can be imported directly into another provider's system without additional technical processing.

Depending on the destination environment, additional mapping, conversion, configuration, data import or implementation work may be required.

The standard export package constitutes a transfer of data and does not constitute a transfer of the ACS software, its functionality, business logic or technical architecture.

D+TB is not required to develop new technology, functionality or services solely for the purpose of switching, except to the extent expressly required by applicable mandatory law.

5. Protected internal D+TB information

Data portability under the Data Act does not provide a right of access to the internal operation, technology or security architecture of ACS.

The export package and this register therefore do not contain:

  • ACS source code or source code of internal software components;
  • internal or generic mappings;
  • transformation rules or internal conversion logic;
  • algorithms or internal decision-making and processing logic;
  • internal database structures or database schemas;
  • internal technical data models that do not themselves constitute Customer data;
  • security architecture or internal security configurations;
  • authentication secrets or cryptographic keys;
  • vulnerability information;
  • data relating to other customers;
  • other information the disclosure of which would adversely affect the intellectual property rights, trade secrets, confidentiality or security of D+TB or third parties.

These protections are not applied in a manner that prevents or unreasonably delays a transfer to which the Customer is entitled under applicable mandatory law.

6. ICT infrastructure and applicable jurisdiction

The ICT infrastructure used for the processing of ACS data is hosted within the European Union.

Applicable jurisdiction: the European Union and, where applicable, the national law of the Member State or Member States to which the relevant ICT infrastructure is subject.

7. Protection against international governmental access

D+TB applies, directly and through its IT service providers, technical, organisational and contractual measures designed to protect non-personal data held in the European Union against international governmental access or transfer where such access or transfer would conflict with European Union law or applicable national law.

Depending on the systems and services concerned, these measures include:

  • hosting of the relevant ICT infrastructure within the European Union;
  • secure electronic communications;
  • user and access management;
  • authentication and authorisation measures;
  • logging and monitoring;
  • backup facilities;
  • network, endpoint and malware protection;
  • software and security updates;
  • restriction of access to authorised persons;
  • contractual confidentiality, data protection and security obligations imposed on relevant IT service providers.

A request by a public authority of a third country for access to or transfer of non-personal data held in the European Union is assessed in accordance with applicable law. D+TB does not grant access to or transfer such data to the extent that doing so would conflict with European Union law or applicable national law.

8. Contact

Questions regarding ACS data portability or a contemplated switching process may be submitted to:

D+TB
E-mail: [email protected]

9. Updates and legal status

D+TB keeps this page and the Data Portability Register contained herein up to date. The information may be amended following changes to ACS, the ICT infrastructure used, the export format, applicable technical standards, security measures or applicable law.

This page provides information in the context of the Data Act and does not, by itself, amend contractual rights or obligations. The applicable agreement, the contractual documents forming part thereof and applicable mandatory law govern the rights and obligations of D+TB and the Customer.

ACS Data Export Format: version 1.0
Last updated: