Changes between two versions
What changed between the plenary report and the adopted text
From · plenary report· 7 Dec 2023
on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
To · adopted text· 25 Apr 2024
Advance passenger information: enhancing and facilitating external border controls
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+9 added · −158 removed · 1 changed paragraphs, packaging included.
Part 3 of 4: Paragraphs 121–163
Removed:Article 19 – paragraph 1: 1. The independent supervisory authorities referred to in Article 51 of Regulation (EU) 2016/679 shall ensure that an audit of processing operations of API data constituting personal data performed by the competent border authorities for the purposes of this Regulation is carried out, in accordance with relevant international auditing standards, at least once every four years.
Removed:Article 19 – paragraph 2: 2. The European Data Protection Supervisor shall carry out an audit of processing operations of API data constituting personal data performed by eu-LISA for the purposes of this Regulation, in accordance with relevant international auditing standards at least once every year. A report of that audit shall be sent to the European Parliament, to the Council, to the Commission, to the Member States and to eu-LISA. eu-LISA shall be given an opportunity to make comments before the reports are adopted.
Removed:Article 20 – paragraph 1 – subparagraph 1: Member States shall ensure that their competent border authorities are connected to the router. They shall ensure that the competent border authorities’ systems and infrastructure for the reception of API data transferred pursuant to this Regulation are integrated with the router.
Removed:Article 20 – paragraph 2: 2. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the connections to and integration with the router referred to in paragraph 1, including on requirements for data security.
Removed:Article 21 – paragraph 2: 2. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the connections to and integration with the router referred to in paragraph 1, including on requirements for data security.
Removed:Article 22 – paragraph 3: 3. eu-LISA shall ensure that the router is designed and developed in such a manner that the router provides the functionalities specified in this Regulation, and that the router starts operations as soon as possible after the adoption by the Commission of the delegated acts provided for in Article 5(4), Article 6(3), Article 11(4), Article 20(2) and Article 21(2) and after the carrying out of a data protection impact assessment in accordance with Article 35 of Regulation (EU) 2016/679.
Removed:Article 22 – paragraph 4: 4. Where eu-LISA considers that the development phase has been completed, it shall, without undue delay, conduct a comprehensive test of the router, in cooperation with the competent border authorities and other relevant Member States’ authorities and air carriers and inform the Commission of the outcome of that test.
Removed:Article 23 – paragraph 2 – subparagraph 1: eu-LISA shall be responsible for the technical management of the router, including its maintenance and technical developments, in such a manner as to ensure that the API data are securely, effectively and swiftly transmitted through the router, in compliance with this Regulation.
Removed:Article 23 – paragraph 2 – subparagraph 2: The technical management of the router shall consist of carrying out all the tasks and enacting all technical solutions necessary for the proper functioning of the router in accordance with this Regulation in an uninterrupted manner, 24 hours a day, 7 days a week. It shall include the maintenance work and technical developments necessary to ensure that the router functions at a satisfactory level of technical quality, in particular as regards availability, accuracy and reliability of the transmission of API data, in accordance with the technical specifications and, as much as possible, in line with the operational needs of the competent border authorities and air carriers.
Removed:Article 24 – paragraph 1: 1. eu-LISA shall, upon their request, provide training to competent border authorities and other relevant Member States’ authorities and air carriers on the technical use of the router and on the connection and integration to the router.
Removed:Article 24 – paragraph 2: 2. eu-LISA shall provide support to the competent border authorities regarding the reception of API data through the router pursuant to this Regulation, in particular as regards the application of Articles 11 and 20.
Removed:Article 25 – title: Costs of eu-LISA, the European Data Protection Supervisor, the national supervisory authorities and of Member States
Removed:Article 25 – paragraph 1: 1. Costs incurred by eu-LISA in relation to the design, development, hosting and technical management of the router under this Regulation shall be borne by the general budget of the Union. In view of the Union interests at stake, in relation to its responsibilities for the design, development, hosting and technical management and maintenance of the router, eu-LISA shall be provided with the necessary resources under the Union budget in accordance with the applicable legislation.
Removed:Article 25 – paragraph 2 – subparagraph 1: Costs incurred by eu-LISA and Member States in relation to their connections to and integration with the router referred to in Article 20 shall be borne by the general budget of the Union.
Removed:Article 25 – paragraph 2 a (new): 2a. Costs incurred by the European Data Protection Supervisor in relation to the tasks entrusted to it under this Regulation shall be borne by the general budget of the Union.
Removed:Article 25 – paragraph 2 b (new): 2b. Costs incurred by independent national supervisory authorities in relation to the tasks entrusted to them under this Regulation shall be borne by the Member States.
Removed:Article 28 – title: Voluntary use of the router in application of Directive 2004/82/EC
Removed:Article 28 – paragraph 2: 2. Where an air carrier starts using the router in accordance with paragraph 1, it shall continue using the router to transmit such information to the responsible authorities of the Member State concerned until the date of application of this Regulation referred to in Article 39, second subparagraph. However, that use shall be discontinued, from an appropriate date set by that authority, where that authority considers that there are objective reasons that require such discontinuation and has informed the air carrier accordingly.
Removed:Article 29 – paragraph 3: 3. Member States shall, by the date of application of this Regulation referred to in Article 39, second subparagraph, notify the Commission of the name and the contact details of the authorities that they designated under paragraph 1 and of the detailed rules that they laid down pursuant to paragraph 2. They shall notify the Commission without delay of any subsequent changes or amendments thereto.
Removed:Article 30 – paragraph 1: 1. Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure they are implemented. The penalties provided for shall be effective, proportionate and dissuasive penalties.
Removed:Article 30 – paragraph 1 a (new): 1a. Member States shall ensure that when deciding whether to impose a penalty and when determining the type and level of penalty, the national supervisory authorities take into account relevant circumstances, which may include: / (a) the nature, gravity and duration of the infringement; / (b) the degree of the air carrier's fault; / (c) previous infringements by the air carrier; / (d) the overall level of cooperation of the air carrier with the competent authorities; / (e) the size of the air carrier, such as the annual number of passengers carried; / (f) whether previous penalties have already been applied by other national API supervisory authorities to the same carrier for the same infringement.
Removed:Article 30 – paragraph 1 b (new): 1b. Member States shall ensure that a systematic or persistent failure to comply with obligations set out in this Regulation is subject to financial penalties of up to 2% of an air carrier's global turnover of the preceding business year.
Removed:Article 31 – paragraph 1: 1. To support the implementation and supervision of this Regulation and based on the statistical information referred to in paragraph 5 of this Article, eu-LISA shall publish every quarter statistics on the functioning of the router, and on compliance by air carriers with the obligations set out in this Regulation. These statistics shall not allow for the identification of individuals. / The statistics shall show in particular: / (a) the number of passengers on which API data is transmitted, / (b) the number of flights for which API data is transmitted, / (c) the number of flights on which API data is not transmitted, / (d) the number of API messages transmitted on time to competent border authorities, / (e) the number of passengers who boarded the aircraft with inaccurate, incomplete or no longer up-to-date API data, with a non-recognised travel document.
Removed:Article 31 – paragraph 2: 2. For the purposes set out in paragraph 1, the router shall automatically transmit the data listed in paragraph 5 to the central repository for reporting and statistics established in Article 39 of Regulation (EU) 2019/817.
Removed:Article 31 – paragraph 3: 3. In order to support the implementation and supervision of this Regulation, at the end of each year, eu-LISA shall compile statistical data in an annual report for that year. It shall publish that annual report and transmit it to the European Parliament, the Council, the Commission, the European Data Protection Supervisor, the European Border and Coast Guard Agency and the national supervisory authorities referred to in Article 29.
Removed:Article 31 – paragraph 4: 4. At the request of the Commission, eu-LISA shall provide it with statistics on specific aspects related to the implementation of this Regulation as well as the statistics pursuant to paragraph 3.
Removed:Article 31 – paragraph 5 – introductory part: 5. The central repository for reporting and statistics shall provide eu-LISA with the statistical information necessary for the reporting referred to in Article 38 and for generating statistics in accordance with the present Article, without however such statistics on API allowing for the identification of the passengers concerned:
Removed:Article 31 – paragraph 5 – point a: deleted
Removed:Article 31 – paragraph 5 – point b: deleted
Removed:Article 31 – paragraph 5 – point e: (e) the number of passengers checked-in on the same flight;
Removed:Article 31 – paragraph 5 – point g: (g) whether the personal data of the passenger is accurate, complete and up-to-date.
Removed:Article 31 – paragraph 6: 6. For the purposes of the reporting referred to in Article 38 and for generating statistics in accordance with the present Article, eu-LISA shall store the data referred to in paragraph 5 of this Article in the central repository for reporting and statistics established by Article 39 of Regulation (EU) 2019/817. It shall store that data for a period of three years in accordance with paragraph 2, without the data allowing for the identification of the passengers concerned. / The central repository for reporting and statistics shall provide duly authorised staff of the competent border authorities and other relevant authorities of the Member States with customisable reports and statistics on API as referred to in paragraph 5 for the implementation and supervision of this Regulation.
Removed:Article 31 – paragraph 6 a (new): 6a. The use of the data referred to in paragraph 5 of this Article for automated or non-automated risk analysis, profiling or predictive risk assessment shall be prohibited.
Removed:Article 32 – paragraph 1: The Commission shall, in close cooperation with the competent border authorities, other relevant Member States’ authorities, the air carriers and relevant Union agencies, in particular the European Data Protection Supervisor and the Fundamental Rights Agency, prepare and make publicly available a practical handbook, containing guidelines, recommendations and best practices for the implementation of this Regulation, including on fundamental rights compliance as well as on penalties in accordance with Article 30.
Removed:Article 32 a (new): Article 32a / API Expert Group / 1. An API Expert Group shall be established with effect from [one month after the entry into force of this Regulation] in accordance with the horizontal rules on the creation and operation of Commission expert groups. It shall facilitate cooperation and the exchange of information on obligations stemming from and issues relating to this Regulation among Member States, EU institutions and stakeholders. / 2. The API Expert Group shall be composed of representatives of the European Commission, Member States’ relevant authorities, the European Parliament and eu-LISA. Where relevant for the performance of its tasks, the API Expert Group may invite relevant stakeholders, in particular representatives of air carriers, the EDPS and the independent national supervisory authorities, to participate in its work. The Commission’s representative shall chair the API Expert Group.
Removed:Regulation (EU) 2019/817
Removed:Article 35 – paragraph 1, Article 39 – paragraph 2: 2. eu-LISA shall establish, implement and host in its technical sites the CRRS containing the data and statistics referred to in Article 63 of Regulation (EU) 2017/2226, Article 17 of Regulation (EC) No 767/2008, Article 84 of Regulation (EU) 2018/1240, Article 60 of Regulation (EU) 2018/1861 and Article 16 of Regulation (EU) 2018/1860, logically separated by EU information system. eu-LISA shall also collect the data and statistics from the router referred to in Article 31(1) of Regulation (EU) …/… * [this Regulation]. Access to the CRRS shall be granted by means of controlled, secured access and specific user profiles, solely for the purpose of reporting and statistics, to the authorities referred to in Article 63 of Regulation (EU) 2017/2226, Article 17 of Regulation (EC) No 767/2008, Article 84 of Regulation (EU) 2018/1240, Article 60 of Regulation (EU) 2018/1861 and Article 38(2) of Regulation (EU) …/… [this Regulation ]. Especially the use of the CRRS for risk analysis, profiling or predictive risk assessment shall be prohibited.
Removed:Article 38 – paragraph 2: 2. By [one year after the date of entry into force of this Regulation] and every year thereafter during the development phase of the router, eu-LISA shall produce a report, and submit it to the European Parliament and to the Council on the state of play of the development of the router. That report shall contain detailed information about the costs incurred and about any risks which may impact the overall costs to be borne by the general budget of the Union in accordance with Article 25. From the date at which the router starts operations and every year thereafter, the Commission shall assess whether the budget under the MFF budget line 4.11.10.02 (“eu-LISA”) covers the needs necessary for good design, development, hosting and technical management of the router and, if appropriate, immediately propose amendment to the budget appropriations.
Removed:Article 38 – paragraph 4 – introductory part: 4. By [four years after the date of entry into force of this Regulation ] and every four years thereafter, the Commission shall produce a report containing an overall evaluation of this Regulation, demonstrating the necessity and the added value of the collection of API data, including an assessment of:
Removed:Article 38 – paragraph 4 – point c a (new): (ca) the impact of this Regulation on the travel experience of legitimate passengers.
Removed:Article 38 – paragraph 4 – point c b (new): (cb) the impact of this Regulation on the competitiveness of the aviation sector and the burden incurred by businesses. The Commission’s report shall also address this Regulation’s interaction with other relevant Union legislative acts, in particular Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008, in order to assess the overall impact of related reporting obligations on air carriers, identify provisions that could be updated and simplified, where appropriate, to mitigate the burden on air carriers, and consider actions and measures that could be taken to reduce the total cost pressure on air carriers.
Removed:Article 38 – paragraph 4 a (new): 4a. The evaluation referred to in paragraph 1 shall also include an assessment of the feasibility of including non-commercial business aviation within the scope of this Regulation.
Removed:Article 38 – paragraph 6: 6. The Member States and air carriers shall, upon request, provide eu-LISA and the Commission with the information necessary to draft the reports referred to in paragraphs 2, 3 and 4, including information not constituting personal data related to the results of the pre-checks of Union information systems and national databases at the external borders with API data. In particular, Member States shall provide quantitative and qualitative information on the necessity and added value of the collection of API data from an operational perspective. However, Member States may refrain from providing such information if, and to the extent necessary not to disclose confidential working methods or jeopardise ongoing investigations of the competent border authorities. The Commission shall ensure that any confidential information provided is appropriately protected.