Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 5 Jul 2023
on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
To · plenary report· 7 Dec 2023
on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
+96 added · −26 removed · 18 changed paragraphs, packaging included.
Part 1 of 4: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
5 unchanged paragraphs
on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
(COM(2022)0729 – C90428/2022 – 2022/0424(COD))
(Ordinary legislative procedure: first reading)
The European Parliament,
– having regard to the Commission proposal to Parliament and the Council (COM(2022)0729),
Changed:– having regard to Article 294(2) and Articles 77(2)77(2), points (b) and (d) and 79(2)79(2), point (c) of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90428/2022),
4 unchanged paragraphs
– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
– having regard to the opinion of the European Economic and Social Committee of 27 April 2023,
– having regard to Rule 59 of its Rules of Procedure,
– having regard to the opinion of the Committee on Transport and Tourism,
Changed:– having regard to the report of the Committee on Civil Liberties, Justice and Home Affairs (A90000/2023),(A9-0409/2023),
1. Adopts its position at first reading hereinafter set out;
2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Change 1
Removed:Recital 2: (2) The use of passenger data and flight information transferred ahead of the arrival of passengers, known as advance passenger information (‘API’) data, contributes to speeding up the process of carrying out the required checks during the border-crossing process. For the purposes of this Regulation that process concerns, more specifically, the crossing of borders between a third country or a Member State not participating in this Regulation, on the one hand, and a Member State participating in this Regulation, on the other hand. Such use strengthens checks at those external borders by providing sufficient time to enable detailed and comprehensive checks to be carried out on all passengers, without having a disproportionate negative effect on persons travelling in good faith. Therefore, in the interest of the effectiveness and efficiency of checks at external borders, an appropriate legal framework should be provided for to ensure that Member States’ competent border authorities at such external border crossing points have access to API data prior to the arrival of passengers.
Added:Recital 1: (1) The carrying-out of checks of persons at the external borders significantly contributes to guaranteeing the long-term security of the Union, Member States and its citizens and, as such, remains an important safeguard, especially in the area without internal border control (‘the Schengen area’). Border checks should be carried out according to in particular, Regulation (EU) 2016/399 of the European Parliament and of the Council32 where applicable, in order to help combat illegal immigration and prevent threats to the Member States’ internal security, public policy, public health and international relations. Such border checks should be carried out in such a way as to fully respect human dignity and be in full compliance with relevant Union law, including the Charter of Fundamental Rights of the European Union (‘the Charter’).
Removed:Recital 7: (7) In order to achieve its objectives, this Regulation should apply to all commercial carriers conducting flights into the Union, as defined in this Regulation, covering both scheduled and non-scheduled flights, irrespective of the place of establishment of the air carriers conducting those flights. General aviation such as flight schools, military or medical flights, should be exempted from this Regulation.
Added:Recital 2: (2) The use of passenger data and flight information transferred ahead of the arrival of passengers, known as advance passenger information (‘API’) data, contributes to speeding up the process of carrying out the required checks during the border-crossing process. For the purposes of this Regulation that process concerns, more specifically, the crossing of borders between a third country or a Member State not participating in this Regulation, and, a Member State participating in this Regulation. Such use strengthens checks at those external borders by providing sufficient time to enable detailed and comprehensive checks to be carried out on all passengers, without having a disproportionate negative effect on persons travelling in good faith. Therefore, in the interest of the effectiveness and efficiency of checks at external borders, an appropriate legal framework should be provided for to ensure that Member States’ competent border authorities at such external border crossing points have access to API data prior to the arrival of passengers.
Removed:Recital 7 a (new): (7a) For transit passengers whose initial point of departure and final destination are outside of the territory of the Member States participating in this Regulation, and who therefore will not cross the external borders, air carriers should not be under the obligation to transfer API data.
Added:Recital 3: (3) The existing legal framework on API data, which consists of Council Directive 2004/82/EC33 and national law transposing that Directive, has proven important in improving border checks, in particular by setting up a framework for Member States to introduce provisions for laying down obligations on air carriers to transfer API data on passengers transported into their territory. However, divergences remain at national level. In particular, API data is not systematically requested from air carriers and air carriers are faced with different requirements regarding the type of information to be collected and the conditions under which the API data needs to be transferred to competent border authorities. Those divergences lead not only to unnecessary costs and complications for the air carriers, but they are also prejudicial to ensuring effective and efficient pre-checks of persons arriving at external borders.
Change 2
Changed:Recital 8:5: (8)(5) In the interest of effectiveness andorder legalto certainty,ensure thea itemsconsistent ofapproach informationat thatboth jointlyunion constituteand theinternational APIlevel dataas tomuch beas collectedpossible and subsequently transferred under this Regulation should bein listedview clearlyof andthe exhaustively,rules coveringon boththe informationcollection relatingof toAPI eachdata passengerapplicable andat informationthat onlevel, the flightupdated oflegal thatframework passenger.established Suchby flightthis informationRegulation should covertake informationinto onaccount the border crossing point of entryrelevant intopractices theinternationally territoryagreed ofwith the Memberair Stateindustry, concernedspecifically in allthe casescontext coveredof bythe thisWorld Regulation,Customs butOrganisation, thatInternational informationAviation shouldTransport beAssociation collectedand onlyInternational whereCivil applicableAviation underOrganisation Regulation(ICAO) (EU)Guidelines [APIon lawAdvance enforcement].Passenger Information.
Change 3
Removed:Recital 10: (10) The passenger should be enabled to provide certain API data themselves during an online check-in process, either manually or by using automated means. Such means could, for example, include a secure app on a passengers’ smartphone, computer or webcam with the capability to read the machine-readable data of the travel document. Where the passenger did not check-in online, air carriers should in practice provide them with the possibility to provide the machine-readable API data concerned during check-in at the airport with the assistance of a self-service kiosk or of airline staff at the counter. This provision of data by the passenger should be made possible at no cost to the passenger.
Added:Recital 6: (6) The collection and transfer of API data affects the privacy of individuals and entails the processing of their personal data. In order to fully respect their fundamental rights, in particular the right of respect for private life and the right to the protection of personal data, in accordance with the Charter, adequate limits and safeguards should be provided for. In particular, any processing of API data and, in particular, API data constituting personal data, should remain strictly limited to what is necessary for and proportionate to achieving the objectives pursued by this Regulation. In addition, it should be ensured that the processing of any API data collected and transferred under this Regulation do not lead to any form of discrimination precluded by the Charter.
Removed:Recital 13: (13) In view of ensuring that the pre-checks carried out in advance by competent border authorities are effective and efficient, the API data transferred to those authorities should contain data of passengers that are effectively set to cross the external borders, that is, of passengers that are effectively on board of the aircraft. Therefore, the air carriers should transfer API data directly after flight closure. Moreover, API data helps the competent border authorities to distinguish legitimate passengers from passengers who may be of interest and therefore may require additional verifications, which would necessitate further coordination and preparation of follow-up measures to be taken upon arrival. That could occur, for example, in cases of unexpected number of passengers of interest whose physical checks at the borders could adversely affect the border checks and waiting times at the borders of other legitimate passengers. To provide the competent border authorities with an opportunity to prepare adequate and proportionate measures at the border, such as temporarily reinforcing or reaffecting staff, particularly for flights where the time between the flight closure and the arrival at the external borders is insufficient to allow the competent border authorities to prepare the most appropriate response, API data should also be transmitted prior to boarding, at the moment of check-in of each passenger. In order to reduce the impact on air carriers, and with a view to cre…
Added:Recital 7: (7) In order to achieve its objectives, this Regulation should apply to all commercial air carriers conducting flights into the Union, as defined in this Regulation, covering both scheduled and non-scheduled flights, irrespective of the place of establishment of the air carriers conducting those flights. In accordance with the relevant ICAO classifications, general aviation such as flight schools, military or medical flights, should be exempted from this Regulation;
Removed:Recital 13 a (new): (13a) In order to enhance data quality, the router should verify whether the API data transferred to it by the air carriers comply with the supported data formats. Where the router has verified that the data are not compliant with the supported data formats, the router should, immediately and in an automated manner, notify the air carrier concerned.
Added:Recital 8: (8) In the interest of effectiveness and legal certainty, the items of information that jointly constitute the API data to be collected and subsequently transferred under this Regulation should be listed clearly and exhaustively, covering both information relating to each passenger and information on the flight taken by that passenger. Such flight information should cover information on the border crossing point of entry into the territory of the Member State concerned in all cases covered by this Regulation.
Removed:Recital 16: (16) To ensure that competent border authorities have sufficient time to carry out pre-checks effectively on all passengers, including passengers on long-haul flights and those travelling on connecting flights, as well as sufficient time to ensure that the API data collected and transferred by the air carriers is complete, accurate and up-to-date, and where necessary to request additional clarifications, corrections or completions from the air carriers, the competent border authorities should store the API data that they received under this Regulation for a fixed time period that remains limited to what is strictly necessary for those purposes. Similarly, to be able to respond to such requests, air carriers should store the API data that they transferred under this Regulation for the same fixed and strictly necessary time period.
Added:Recital 9: (9) In order to allow for flexibility and innovation, it should in principle be left to each air carrier to determine how it meets its obligations regarding the collection of API data set out in this Regulation. However, considering that suitable technological solutions exist that allow collecting certain API data automatically while guaranteeing that the API data concerned is accurate, complete and up-to-date, and having regard the advantages of the use of such technology in terms of effectiveness and efficiency, air carriers should be required to collect the API data using automated means, specifically by reading information from the machine-readable data of the travel document. Where the use of such automated means is however not possible, air carriers should collect the API data manually, either as part of the online check-in process, or as part of the check-in at the airport, in such a manner as to ensure compliance with their obligations under this Regulation.
Removed:Recital 19: (19) The router should serve only to facilitate the transmission of API data from the air carriers to the competent border authorities in accordance with this Regulation and to PIUs in accordance with Regulation (EU) [API law enforcement], and should not be a repository of API data. Therefore, and in order to minimise any risk of unauthorised access or other misuse and in accordance with the principle of data minimisation, any storage of the API data on the router should remain limited to what is strictly necessary for technical purposes related to the transmission and the API data should be deleted from the router, immediately, permanently and in an automated manner, from the moment that the transmission has been completed.
Added:Recital 9 a (new): (9a) The collection of API data by automated means should be limited to the alphanumerical data contained in the travel document and should not lead to the collection of any biometric data from it.
Removed:Recital 23: (23) In view of the Union interests at stake, the costs incurred by the European Data Protection Supervisor and eu-LISA for the performance of its tasks under this Regulation and Regulation (EU) [API law enforcement] should be borne by the Union budget. The same should go for appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router, as required under this Regulation and in accordance with the applicable legislation, subject to certain exceptions. The costs covered by those exceptions should be borne by each Member State concerned itself. The costs incurred by the independent national supervisory authorities in relation to the tasks entrusted to them under this Regulation and Regulation (EU) [API law enforcement] shall be borne by the respective Member States as well.
Added:Recital 9 b (new): (9b) The requirements set out by this Regulation and by the corresponding delegated and implementing acts should lead to a uniform implementation by the airlines, thereby minimizing the cost of the interconnection of their respective systems. To facilitate a harmonized implementation of those requirements by the airlines, in particular as regards the data structure, format and transmission protocol, the Commission, based on its cooperation with the competent border authorities, other Member States authorities, air carriers, and relevant Union agencies, should ensure that the practical handbook to be prepared by the Commission provides all the necessary guidance and clarifications.
Added:Recital 9 c (new): (9c) In order to enhance data quality, the router should verify whether the API data transferred to it by the air carriers comply with the supported data formats. Where the router has verified that the data are not compliant with the supported data formats, the router should, immediately and in an automated manner, notify the air carrier concerned.
Added:Recital 9 d (new): (9d) The automatic data collection systems and other processes established under this Regulation should not negatively impact the employees in the aviation industry, who should benefit from upskilling and reskilling opportunities that would increase the efficiency and reliability of data collection and transfer as well as the working conditions in the sector.
Added:Recital 10: (10) The passenger should be enabled to provide certain API data themselves during an online check-in process, in accordance with Article 5. Such means could, for example, include a secure app on a passengers’ smartphone, computer or webcam with the capability to read the machine-readable data of the travel document. Where the passengers did not check-in online, air carriers should provide them with the possibility to provide the required machine-readable API data concerned during check-in at the airport with the assistance of a self-service kiosk or of airline staff at the counter. The Commission should ensure that the obligations under this Regulation do not lead to disproportionate obstacles for passengers unable to use online means for automated check-in, such as additional airport check-in fees.
Added:Recital 10 a (new): (10a) With a view to guaranteeing the fulfilment of the rights provided for under the Charter and to ensuring accessible and inclusive travel options, especially for vulnerable groups and persons with disabilities, air carriers, supported by the Member States, should ensure that an offline alternative for the check-in and for the provision of the necessary data by the passengers is possible at all times.
Added:Recital 11: (11) The Commission should be empowered to adopt technical requirements and procedural rules that air carriers should to comply with regarding the use of automated means for the collection of machine-readable API data under this Regulation, so as to increase clarity and legal certainty and contribute to ensuring data quality and the responsible use of the automated means.
Added:Recital 13: (13) In view of ensuring that the pre-checks carried out in advance by competent border authorities are effective and efficient, the API data transferred to those authorities should contain data of passengers that are effectively set to cross the external borders, that is, of passengers that are effectively on board of the aircraft. Therefore, the air carriers should transfer API data directly after flight closure. Moreover, API data helps the competent border authorities to distinguish legitimate passengers from passengers who may be of interest and therefore may require additional verifications, which would necessitate further coordination and preparation of follow-up measures to be taken upon arrival. That could occur, for example, in cases of unexpected number of passengers of interest whose physical checks at the borders could adversely affect the border checks and waiting times at the borders of other legitimate passengers. To provide the competent border authorities with an opportunity to prepare adequate and proportionate measures at the border, such as temporarily reinforcing or reaffecting staff, particularly for flights where the time between the flight closure and the arrival at the external borders is insufficient to allow the competent border authorities to prepare the most appropriate response, API data should also be transmitted prior to boarding, at the moment of check-in of each passenger.
Added:Recital 15: (15) In order to avoid any risk of misuse and in line with the principle of purpose limitation, the competent border authorities should be expressly precluded from processing the API data that they receive under this Regulation for any other purpose than those explicitly provided for in this Regulation.
Added:Recital 16: (16) To ensure that competent border authorities have sufficient time to carry out pre-checks effectively on all passengers, including passengers on long-haul flights and those travelling on connecting flights, as well as sufficient time to ensure that the API data collected and transferred by the air carriers is complete, accurate and up-to-date, and where necessary to request additional clarifications, corrections or completions from the air carriers, the competent border authorities should store the API data that they received under this Regulation for a fixed time period that remains limited to what is strictly necessary for those purposes. Similarly, to be able to respond to such requests, air carriers should store the API data that they transferred under this Regulation for the same fixed and strictly necessary time period. Beyond that, and with a view to enhance the travel experience of legitimate passengers, air carriers should be able to retain and use the API data where necessary for the normal course of their business in particular for travel facilitation, in compliance with the applicable law and in particular Regulation (EU) 2016/679.
Added:Recital 17: (17) In order to avoid that air carriers have to establish and maintain multiple connections with the competent border authorities of the Member States’ for the transfer of API data collected under this Regulation and the related inefficiencies and security risks, provision should be made for a single router, created and operated at Union level, that serves as a connection and distribution point for those transfers. In the interest of efficiency and cost effectiveness, the router should, to the extent technically possible and in full respect of the rules of this Regulation and Regulation (EU) [API law enforcement], rely on technical components from other relevant systems created under Union law, in particular the web service referred to in Regulation (EU) 2017/2226, the carrier gateway referred to in Regulation (EU) 2018/1240 and the carrier gateway referred to in Regulation (EC) 767/2008. In order to reduce the impact on air carriers and ensure a harmonised approach towards air carriers, eu-LISA should design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations put on air carriers by Regulation (EU) 2017/2226, Regulation (EU) 2018/1240 and Regulation (EC) 767/2008.
Added:Recital 17 a (new): (17a) In order to provide for the same level of clarity and certainty, the provisions related to the router, security and support tasks by eu-LISA should be mirrored in this Regulation and Regulation (EU) [API law enforcement], as eu-LISA should build and maintain only one router for the purposes of both Regulations.
Added:Recital 19: (19) The router should serve only to facilitate the transmission of API data from the air carriers to the competent border authorities in accordance with this Regulation, and should not be a repository of API data. Therefore, and in order to minimise any risk of unauthorised access or other misuse and in accordance with the principle of data minimisation, no storage should take place unless strictly necessary for technical purposes related to the transmission and the API data should be deleted from the router, immediately, permanently and in an automated manner, from the moment that the transmission has been completed.
Added:Recital 20: (20) With a view to ensuring the proper functioning of the transmission of API data from router, the Commission should be empowered to lay down detailed technical and procedural rules on that transmission. Those rules should be such as to ensure that the transmission is secure, effective and swift and impacts passengers’ travel rights and air carriers no more than necessary.
Added:Recital 22: (22) The router to be created and operated under this Regulation and Regulation (EU) [API Law Enforcement] should reduce and simplify the technical connections needed to transfer API data, limiting them to a single connection per air carrier and per competent border authority. Therefore, this Regulation provides for the obligation for the competent border authorities and air carriers to each establish such a connection to, and achieve the required integration with, the router, so as to ensure that the system for transferring API data established by this Regulation can function properly. The design and development of the router by eu-LISA should enable the effective and efficient connection and integration of air carriers’ systems and infrastructure by providing for all relevant standards and technical requirements. To ensure the proper functioning of the system set up by this Regulation, detailed rules should be provided. When designing and developing the router, eu-LISA should ensure that API data transferred by air carriers and transmitted to competent border authorities is encrypted in transit.
Added:Recital 23: (23) In view of the Union interests at stake, the costs incurred by the European Data Protection Supervisor and eu-LISA for the performance of its tasks under this Regulation in respect of the router should be borne by the Union budget. The same should go for appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router and costs related to the maintenance of those connections, as required under this Regulation and in accordance with the applicable legislation, subject to certain exceptions. The costs covered by those exceptions should be borne by each Member State concerned itself. The Union budget should also cover the support, such as training, by eu-LISA to air carriers and border authorities to enable effective transfer and transmission of API data through the router. The costs incurred by the independent national supervisory authorities in relation to the tasks entrusted to them under this Regulation shall be borne by the respective Member States as well.
Added:Recital 25: (25) In the interest of ensuring compliance with the fundamental right of the passengers to the protection of their personal data, this Regulation should identify the controller and processor and set out rules on audits. In the interest of effective monitoring, ensuring adequate protection of personal data and minimising security risks, rules should also be provided for on logging, security of processing and self-monitoring. Where they relate to the processing of personal data, those provisions should be understood as complementing the generally applicable acts of Union law on the protection of personal data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council34 and Regulation (EU) 2018/1725 of the European Parliament and the Council.35 Those acts, which also apply to the processing of personal data under this Regulation in accordance with the provisions thereof, should not be affected by this Regulation.
Added:Recital 25 a (new): (25a) Taking into account the right of passengers to be informed of the processing of their personal data, Member States should ensure that passengers are provided with accurate information about the collection of API data, the transfer of that data to the competent border authorities and their rights as data subjects that is easily accessible and easy to understand, at the moment of booking and at the moment of check-in .
Added:Recital 28 a (new): (28a) When providing for the penalties applicable to air carriers under this Regulation, Member States should take into account the technical and operational feasibility of ensuring complete data accuracy. Additionally, when penalties are imposed, their application and value should be established taking into consideration the actions undertaken by the air carrier to mitigate the issue as well as its level of cooperation with national authorities.
Added:Recital 30: (30) As the router should be designed, developed, hosted and technically managed by the eu-LISA, established by Regulation (EU) 2018/1726 of the European Parliament and of the Council36 , it is necessary to amend that Regulation by adding that task to the tasks of eu-LISA. In order to store reports and statistics of the router on the Central Repository for Reporting and Statistics it is necessary to amend Regulation (EU) 2019/817 of the European Parliament and of the Council37. The Central Repository for Reporting and Statistics should only provide statistics based on API data for the implementation and effective supervision of this Regulation. The data that the router automatically transmits to the Common Repository for Reporting and Statistics to that end should not allow for the identification of the passengers concerned.
Added:Recital 31: (31) In order to adopt measures relating to the technical requirements and operational rules for the automated means for the collection of machine-readable API data, to the common protocols and formats to be used for the transfer of API data by air carriers, to the technical and procedural rules for the transmission of API data from the router to the competent border authorities and to the PIUs and to the PIU’s and air carriers’ connections to and integration with the router, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of Articles 5, 6, 11, 20 and 21 respectively. It is of particular importance that the Commission carry out appropriate consultations with relevant stakeholders, including air carriers, during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement on Better Law-Making of 13 April 201638 . In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts. Taking into account the state of the art, these technical requirements and rules might change over time.
Added:Recital 31 a (new): (31a) It is important to collect reliable and useful statistics based on the implementation of this Regulation in order to support its objectives and inform the evaluations under this Regulation. Such statistics should not contain any personally identifiable data. All relevant stakeholders, including relevant Member State authorities, Europol and, where appropriate, air carriers, should have access to those statistics.
Added:Recital 34 a (new): (34a) This Regulation should be subject to regular evaluations to ensure the monitoring of its effective application. In particular, the collection of API data should not be to the detriment of the travel experience of legitimate passengers. Therefore, the Commission should include in its regular evaluation reports on the application of this Regulation an assessment of the impact of this Regulation on the travel experience of legitimate passengers.
Added:Recital 34 b (new): (34b) Given that this Regulation requires additional adjustment and administrative costs by the air carriers, the overall regulatory burden for the aviation sector should be kept under close review. Against this backdrop, the report evaluating the functioning of this Regulation should assess the extent to which the objectives of the Regulation have been met and to which extent it has impacted the competitiveness of the sector. Therefore, the Commission’s report should also conduct a holistic assessment and refer to the interaction of this Regulation with other relevant Union legislative acts, in particular Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008. The report should assess the overall impact of related reporting obligations on air carriers, identifying provisions that could be updated and simplified, where appropriate, to mitigate the burden on air carriers, as well as actions and measures that have been or could be taken to reduce the total cost pressure on the aviation sector.
Recital 35: deleted
Change 4
Removed:Article 2 – paragraph 1: This Regulation applies to air carriers conducting scheduled or non-scheduled flights into the Union. General aviation shall be exempted from this Regulation.
Added:Article 1 – paragraph 1 – subparagraph 1 a (new): This Regulation is without prejudice to Regulations (EU) 2016/679 and (EU) 2018/1725.
Removed:Article 3 – paragraph 1 – point a: (a) ‘air carrier’ means an air transport undertaking as defined in Article 3, point 1, of Directive (EU) 2016/681, other than air transport undertakings performing general aviation operations;