Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 4 Jul 2023
on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818
To · plenary report· 7 Dec 2023
on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818
+130 added · −17 removed · 6 changed paragraphs, packaging included.
Part 1 of 4: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
9 unchanged paragraphs
on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818
(COM(2022)0731 – C90427/2022 – 2022/0425(COD))
(Ordinary legislative procedure: first reading)
The European Parliament,
– having regard to the Commission proposal to Parliament and the Council (COM(2022)0731),
– having regard to Article 294(2) and Articles 82(1) point (d) and 87(2) point (a) of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90427/2022),
– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
– having regard to Rules 59 of its Rules of Procedure,
– having regard to the opinion of the Committee on Transport and Tourism,
Changed:– having regard to the report of the Committee on Civil Liberties, Justice and Home Affairs (A90000/2023),(A9-0411/2023),
1. Adopts its position at first reading hereinafter set out;
2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Change 1
Removed:Recital 11: (11) In order to ensure a consistent approach on the collection and transfer of API data by air carriers as much as possible, the rules set out in this Regulation should be aligned with those set out in the Regulation (EU) [API border management] where appropriate. That concerns, in particular, the rules on data quality, the air carriers’ mandatory use of automated means for such collection, except where travel documents do not contain machine-readable data, or where it is technically impossible to collect the API data using automated means, the precise manner in which they are to transfer the collected API data to the router and the deletion of the API data.
Added:Recital 1: (1) The transnational dimension of serious and organised crime and the continuous threat of terrorist attacks on European soil call for action at Union level to adopt appropriate measures to ensure security within an area of freedom, security and justice without internal borders. Information on air passengers, such as Passenger Name Records (PNR) and in particular Advance Passenger Information (API), is essential in order to identify high-risk passengers, including those who are not otherwise known to law enforcement authorities, and to establish links between members of criminal groups, and countering terrorist activities.
Removed:Recital 11 a (new): (11a) The Commission should ensure that the obligation to use automated means for the collection of API data does not lead to disproportionate obstacles, such as additional airport check-in fees, for passengers unable to use other means for automated check-in.
Added:Recital 2: (2) While Council Directive 2004/82/EC27 establishes a legal framework for the collection and transfer of API data by air carriers with the aims of improving border controls and combating illegal immigration, it also states that Member States may use API data for law enforcement purposes. However, only creating such a possibility leads to several gaps and shortcomings. In particular, it means that, API data is not systematically collected and transferred by air carriers for law enforcement purposes. It also means that, where Member States acted upon the possibility, air carriers are faced with diverging requirements under national law as regards when and how to collect and transfer API data for this purpose. Those divergences lead not only to unnecessary costs and complications for the air carriers, but can also negatively affect the Union’s internal security and complicate effective cooperation between the competent law enforcement authorities of the Member States. Moreover, in view of the different nature of the purposes of facilitating border controls and law enforcement, it is appropriate to establish a distinct legal framework for the collection and transfer of API data for each of those purposes
Removed:Recital 14: (14) As regards intra-EU flights, in line with the case law of the Court of Justice of the European Union (CJEU), in order to avoid unduly interfering with the relevant fundamental rights protected under the Charter and to ensure compliance with the requirements of Union law on the free movement of persons and the abolition of internal border controls, a selective approach should be provided for, except in situations of a genuine and present or foreseeable terrorist threat. In view of the importance of ensuring that API data can be processed together with PNR data, that approach should be aligned with that of Directive (EU) 2016/681. For those reasons, API data on those flights should only be transmitted from the router to the relevant PIUs, where the Member States have selected the flights concerned in application of Article 2 of Directive (EU) 2016/681. As recalled by the CJEU, the selection entails Member States targeting the obligations in question only at, inter alia, certain routes, travel patterns or airports, subject to the regular review of that selection. Furthermore, the selection criteria should be relevant for the prevention, detection, investigation and prosecution of terrorist offences and serious crime and should demonstrate an objective link or suspicion of a link, with the carriage of passengers by air.
Added:Recital 4: (4) It is therefore necessary to establish clear, harmonised and effective rules at Union level on the collection and transfer of API data for the purpose of preventing, detecting, investigating and prosecuting terrorist offences and serious crime.
Removed:Recital 15 a (new): (15a) In order to increase cohesion among the selective approaches taken by the different Member States, the Commission should facilitate the exchange of views on the choice of selection criteria, as well as, on a voluntary basis, of selected flights.
Added:Recital 5: (5) Considering the close relationship between both acts, this Regulation should be understood as complementing the rules provided for in Directive (EU) 2016/681. Therefore, API data is to be collected and transferred in accordance with the specific requirements of this Regulation, including as regards the situations and the manner in which that is to be done. However, the rules of that Directive apply in respect of matters not specifically covered by this Regulation, especially regarding the rules on the subsequent processing of the API data received by the PIUs, exchange of information between Member States, conditions of access by the European Union Agency for Law Enforcement Cooperation (Europol), transfers to third countries, retention and depersonalisation, as well as the protection of personal data. Insofar as those rules apply, the rules of that Directive on penalties and the national supervisory authorities apply as well. This Regulation should leave those rules unaffected.
Removed:Recital 19: (19) In view of the Union interests at stake, appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router, costs related to the maintenance of those connections and costs related to training needs, as required under this Regulation, should be borne by the Union budget, in accordance with the eligibility rules and co-financing rates set in the legal basis of the Internal Security Fund.
Added:Recital 6: (6) The collection and transfer of API data affects the privacy of individuals and entails the processing of their personal data. In order to fully respect their fundamental rights, in particular the right of respect for private life and the right to the protection of personal data, in accordance with the Charter of Fundamental Rights of the European Union (‘Charter’), adequate limits and safeguards should be provided for. In particular, any processing of API data and, in particular, API data constituting personal data, should remain strictly limited to what is necessary for and proportionate to achieving the objectives pursued by this Regulation. In addition, it should be ensured that the processing of any API data collected and transferred under this Regulation do not lead to any form of discrimination precluded by the Charter.
Change 2
Changed:Recital 20:7: (20)(7) In accordanceview withof Regulationthe (EU)complementary 2018/1726,nature Memberof Statesthis mayRegulation entrustin eu-LISArelation withto theDirective task(EU) of2016/681, facilitatingthe connectivityobligations withof commercial air carriers under this Regulation should apply in orderrespect toof assistall flights for which Member States inare theto implementationrequire ofair carriers to transmit PNR data under Directive (EU) 2016/681, particularlynamely byflights, collectingincluding both scheduled and transferringnon-scheduled PNRflights, databoth viabetween theMember routerStates asand athird secure,countries reliable(extra-EU flights), and cost-effectivebetween solution.several SuchMember streamliningStates would(intra-EU furtherflights) underlineinsofar theas complementarythose natureflights ofhave PNRbeen andselected APIin data.accordance Furthermore,with itDirective would(EU) extend2016/681, irrespective of the useplace of establishment of the automaticair filtercarriers forconducting selectedthose EUflights. flightsIn toaccordance PNRwith datathe transfers.relevant ICAO classifications, general aviation such as flight schools, military or medical flights, should be exempted from this Regulation.
Change 3
Removed:Recital 24: (24) In order to adopt measures relating to the technical requirements and operational rules for the automated means for the collection of machine-readable API data, to the common protocols and formats to be used for the transfer of API data by air carriers, to the technical and procedural rules for the transmission of API data from the router and to the PIUs and to the PIU’s and air carriers’ connections to and integration with the router, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of Articles 4, 5, 10 and 11, respectively. It is of particular importance that the Commission carry out appropriate consultations with relevant stakeholders including air carriers during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement on Better Law-Making of 13 April 201633. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated act.
Added:Recital 9: (9) In view of the close relationship between the acts of Union law concerned and in the interest of consistency and coherence, the definitions set out in this Regulation should be aligned with, interpreted and applied in the light of, the definitions set out in Directive (EU) 2016/681 and Regulation (EU) [API border management]29 .
Removed:Recital 24 a (new): (24a) The collection of API data should not be detrimental to the fundamental rights and travel experience of legitimate travellers. The application of this Regulation, in combination with the application of several other Union legal acts, such as Regulation (EU) 2017/2226 of the European Parliament and of the Council1a and Regulation (EU) 2018/1240 of the European Parliament and of the Council1b, should not place a disproportionate burden on air carriers. For these reasons, and in order to ensure the monitoring of the effective application of this Regulation by all stakeholders, this Regulation should be subject to regular evaluations. / 1a Regulation (EU) 2017/2226 of the European Parliament and of the Council of 30 November 2017 establishing an Entry/Exit System (EES) to register entry and exit data and refusal of entry data of third-country nationals crossing the external borders of the Member States and determining the conditions for access to the EES for law enforcement purposes, and amending the Convention implementing the Schengen Agreement and Regulations (EC) No 767/2008 and (EU) No 1077/2011 (OJ 327, 9.12.2017. p, 20). / 1b Regulation (EU) 2018/1240 of the European Parliament and of the Council of 12 September 2018 establishing a European Travel Information and Authorisation System (ETIAS) and amending Regulations (EU) No 1077/2011, (EU) No 515/2014, (EU) 2016/399, (EU) 2016/1624 and (EU) 2017/2226 (OJ L 236, 19.9.2018., p. 1).
Added:Recital 10: (10) In particular, the items of information that jointly constitute the API data to be collected and subsequently transferred under this Regulation should be the same as those listed clearly and exhaustively in Regulation (EU) API [border management], covering both information relating to each passenger and information on the flight of that passenger. Under this Regulation, such flight information should cover information on the border crossing point of entry into the territory of the Member State concerned only where applicable, that is, not when the API data relate to intra-EU flights
Removed:Recital 24 b (new): (24b) It is important to collect reliable and useful statistics based on the implementation of this Regulation in order to support its objectives and inform the evaluations described in Recital 24a and Article 20. Such statistics should not contain any personally identifiable data. All relevant stakeholders, including relevant Member State authorities, Europol and, where appropriate, air carriers, should have access to those statistics.
Added:Recital 11: (11) In order to ensure an approach that is as consistent as possible on the collection and transfer of API data by air carriers, the rules set out in this Regulation should be aligned with those set out in the Regulation (EU) [API border management] where appropriate. That alignment concerns, in particular, the rules on data quality, the precise manner in which they are to transfer the collected API data to the router, the encryption of API data in transit, and the deletion of the API data. Furthermore, and as set out in this Regulation and in the Regulation (EU) [API border management], air carriers should be required to collect the API data using automated means, specifically by reading information from the machine-readable data of the travel document. Where the use of such automated means is however not possible, air carriers should collect the API data manually, either as part of the online check-in process, or as part of the check-in at the airport, in such a manner as to ensure compliance with their obligations under this Regulation.
Removed:Article 1 – paragraph 1 – point a: (a) the collection by air carriers of advance passenger information data (‘API data’) on extra EU flights and intra-EU flights;
Added:Recital 11 a (new): (11a) The collection of API data by automated means should be strictly limited to the alphanumerical data contained in the travel document and should not lead to the collection of any biometric data from it. As the collection of API data is part of the check-in process, either online or at the airport, it should not include an obligation for air carriers to check a travel document of the passenger at the moment of boarding. Compliance with this regulation should not include any obligation for passenger to carry a travel document at the moment of boarding.
Added:Recital 11 b (new): (11b) The requirements set out by this Regulation and by the corresponding delegated and implementing acts should lead to a uniform implementation by the airlines, thereby minimising the cost of the interconnection of their respective systems. To facilitate a harmonised implementation of those requirements by the airlines, in particular as regards the data structure, format and transmission protocol, the Commission, based on its cooperation with the PIUs, other Member States authorities, air carriers, and relevant Union agencies, should ensure that the practical handbook to be prepared by Commission provides all the necessary guidance and clarifications.
Added:Recital 11 c (new): (11c) In order to enhance data quality, the router should verify whether the API data transferred to it by the air carriers complies with the supported data formats. Where the router has verified that the data is not compliant with the supported data formats, the router should, immediately and in an automated manner, notify the air carrier concerned thereof.
Added:Recital 11 d (new): (11d) In order to reduce the impact on air carriers, and with a view to create synergies with other reporting obligations on air carriers in Regulation (EU) 2017/2226, Regulation (EU) 2018/1240 and Regulation (EC) 767/2008 and avoid duplication, air carriers should transfer the API data at the moment of the check-in of each passenger by way of interactive API in accordance with international standards, using the existing carrier gateway. Air carriers should receive an acknowledgement of receipt to the transfer of interactive API, in line with international standards. The use of an interactive API should not lead to an automatic denial of boarding.
Added:Recital 11 e (new): (11e) The passengers should be enabled to provide certain API data themselves during an online check-in process. Such means could, for example, include a secure app on a passengers’ smartphone, computer or webcam with the capability to read the machine-readable data of the travel document. Where the passengers did not check-in online, air carriers should provide them with the possibility to provide the required machine-readable API data concerned during check-in at the airport with the assistance of a self-service kiosk or of airline staff at the check-in counter. The Commission should ensure that the obligations under this Regulation do not lead to disproportionate obstacles for passengers unable to use online means for automated check-in, such as additional airport check-in fees.
Added:Recital 11 f (new): (11f) The automatic data collection systems and other processes established under this Regulation should not have a negative impact on the employees in the aviation industry, who should benefit from upskilling and reskilling opportunities that would increase the efficiency and reliability of data collection and transfer as well as the working conditions in the sector.
Added:Recital 12: (12) In order to ensure the joint processing of API data and PNR data to effectively fight terrorism and serious crime in the Union and at the same time minimise the interference with passengers’ fundamental rights protected under the Charter, the PIUs should be the sole competent authorities in the Member States that are entrusted to receive, and subsequently further process and protect, API data collected and transferred under this Regulation. In the interest of efficiency and to minimise any security risks, the router, as designed, developed, hosted and technically maintained by the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) in accordance with Regulation (EU) [API border management], should transmit the API data, collected and transferred to it by the air carriers under this Regulation, to the relevant PIUs. Given the necessary level of protection of API data constituting personal data, including to ensure the confidentiality of the information concerned, the API data should be transmitted by the router to the relevant PIUs in an automated manner.
Added:Recital 12 a (new): (12a) With a view to guaranteeing the fulfilment of the rights provided for under the Charter and to ensuring accessible and inclusive travel options, especially for vulnerable groups and persons with disabilities, air carriers, supported by the Member States, should ensure that an offline alternative for the check-in and for the provision of the necessary data by the passengers is possible at all times.
Added:Recital 13: (13) For extra-EU flights, the PIU of the Member State on whose territory the flight will land and or from where the flight will depart should receive the API data from the router for all those flights, that PNR data is collected for in accordance with Directive (EU) 2016/681. The router should identify the flight and the corresponding PIUs using the information contained in the PNR record locator, a data element common to both the API and PNR data sets allowing for the joint processing of API data and PNR data by the PIUs.
Added:Recital 14: (14) As regards intra-EU flights, in line with the case law of the Court of Justice of the European Union (CJEU), in order to avoid unduly interfering with passengers’ relevant fundamental rights as protected under the Charter and to ensure compliance with the requirements of Union law on the free movement of persons and the abolition of internal border controls, a selective approach should be provided for. This is with the exception of situations of a genuine and present or foreseeable terrorist threat, where Member States should be able to apply Directive (EU) 2016/681 to all intra-EU flights arriving at or departing from its territory, in a decision that is limited in time to what is strictly necessary and that is open to effective review. In view of the importance of ensuring that API data can be processed together with PNR data, that approach should be aligned with that of Directive (EU) 2016/681. For those reasons, API data on those flights should only be transmitted from the router to the relevant PIUs, where the Member States have selected the flights concerned in application of Article 2 of Directive (EU) 2016/681. As recalled by the CJEU, the selection entails Member States targeting the obligations in question only at, inter alia, certain routes, travel patterns or airports, subject to the regular review of that selection. Furthermore, the selection criteria should be relevant for the prevention, detection, investigation and prosecution of terrorist offences and se…
Added:Recital 14 a (new): (14a) In order to comply with the requirements of the Court of Justice of the European Union (CJEU), this Regulation should lay down a common methodology for carrying out a threat assessment based on which the Member States should operate a selection of intra-EU flights. That common methodology should also help avoid divergent practices among Member States and allow for effective supervision by the national data protection authorities.
Added:Recital 15: (15) In order to enable the application of that selective approach under this Regulation in respect of intra-EU flights, the Member States should be required to draw up and submit to eu-LISA the lists of the flights they selected, so that eu-LISA can ensure that only API data for those flights is transmitted from the router to the relevant PIUs and that the API data on other intra-EU flights is immediately and permanently deleted.
Added:Recital 15 a (new): (15a) In order to increase cohesion among the selective approaches taken by the different Member States, the Commission should facilitate a regular exchange of views on the choice of selection criteria, including the sharing of best practices, as well as, on a voluntary basis, of selected flights.
Added:Recital 16: (16) In order not to endanger the effectiveness of the system that relies on the collection and transfer of API data set up by this Regulation, and of PNR data under the system set up by Directive (EU) 2016/681, for the purpose of preventing, detecting, investigating and prosecuting terrorist offences and serious crime, in particular by creating the risk of circumvention, information on which intra-EU flights the Member States selected should be treated in a confidential manner. For that reason, such information should not be shared with the air carriers and they should therefore be required to collect API data on all flights covered by this Regulation, including all intra-EU flights, and then transfer it to the router, where the necessary selection should be enacted. Moreover, by collecting API data on all intra-EU flights, passengers are not made aware on which selected intra-EU flights API data, and hence also PNR data, is transmitted to the PIUs in accordance with the assessment of Member States. That approach also ensures that any changes relating to that selection can be implemented swiftly and effectively, without imposing any undue economic and operational burdens on the air carriers. Nonetheless, API data should not be collected and transferred on those flights where neither the Member State of departure nor the Member State of arrival of intra-EU flights have notified the Commission of their decision to apply Directive (EU) 2016/681 to intra-EU flights, pursuant to …
Added:Recital 16 a (new): (16a) This Regulation does not permit the collection and transfer of API data on intra-EU flights for the purposes of combating illegal immigration, in accordance with Union law and the case law of the Court of Justice of the European Union.
Added:Recital 17: (17) In the interest of ensuring compliance with the passengers’ fundamental right to the protection of their personal data and in line with Regulation (EU) [API border management], this Regulation should identify the controllers. In the interest of effective monitoring, ensuring adequate protection of personal data and minimising security risks, rules should also be provided for on logging, security of processing and self-monitoring. Where they relate to the processing of personal data, those provisions should be understood as complementing the generally applicable acts of Union law on the protection of personal data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council30 , Directive (EU) 2016/680 of the European Parliament and the Council31 and Regulation (EU) 2018/1725 of the European Parliament and the Council32 . Those acts, which also apply to the processing of personal data under this Regulation in accordance with the provisions thereof, should not be affected by this Regulation.
Added:Recital 17 a (new): (17a) Taking into account the right of passengers to be informed of the processing of their personal data, Member States should ensure that passengers are provided with accurate information about the collection of API data, the transfer of that data to the PIU and their rights as data subjects that is easily accessible and easy to understand, at the moment of the flight booking and at the moment of check-in. .
Added:Recital 17 b (new): (17b) In order to ensure compliance with the fundamental right to the protection of personal data, this Regulation should also set out rules on audits. The audits that Member States are responsible for should be carried out by the supervisory authorities referred to in Article 41 of Directive (EU) 2016/680 or by an auditing body entrusted with this task by the supervisory authority.
Added:Recital 17 c (new): (17c) In order to avoid that air carriers have to establish and maintain multiple connections with PIUs for the transfer of API data and PNR data, and to avoid the related inefficiencies and security risks, provision should be made for a single router, created and operated at the Union level, that should serve as a connection, filter and distribution point for those transfers. In the interest of efficiency and cost effectiveness, the router should, to the extent technically possible and in full respect of the rules of this Regulation and Regulation (EU) [API border management], rely on technical components from other relevant systems created under Union law, in particular the web service referred to in Regulation (EU) 2017/2226, the carrier gateway referred to in Regulation (EU) 2018/1240 and the carrier gateway referred to in Regulation (EC) 767/2008. In order to reduce the impact on air carriers and ensure a harmonised approach towards air carriers, eu-LISA should design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations put on air carriers by Regulation (EU) 2017/2226, Regulation (EU) 2018/1240 and Regulation (EC) 767/2008.
Added:Recital 17 d (new): (17d) Furthermore, in order to provide for the same level of clarity and certainty, the provisions related to the router, security and support tasks by the eu-LISA should be mirrored in this Regulation and Regulation (EU) [API border management].
Added:Recital 17 e (new): (17e) The router should serve only to facilitate the transmission of API data from the air carriers to the PIUs in accordance with this Regulation, and should not be a repository of API data. Therefore, and in order to minimise any risk of unauthorised access or other misuse and in accordance with the principle of data minimisation, no storage should take place unless strictly necessary for technical purposes related to the transmission and the API data should be deleted from the router, immediately, permanently and in an automated manner, from the moment that the transmission has been completed.
Added:Recital 17 f (new): (17f) With a view to ensuring the proper functioning of the transmission of API data from router, the Commission should be empowered to lay down detailed technical and procedural rules on that transmission. Those rules should be such as to ensure that the transmission is secure, effective and swift and impacts passengers’ travel rights and air carriers no more than necessary.
Added:Recital 18: (18) The router to be created and operated under this Regulation and Regulation (EU) [API border management] should reduce and simplify the technical connections needed to transfer API data and PNR data, limiting them to a single connection per air carrier and per PIU. Therefore, this Regulation provides for the obligation for the PIUs and air carriers to each establish such a connection to, and achieve the required integration with, the router, so as to ensure that the system for transferring API data established by this Regulation can function properly. The design and development of the router by eu-LISA should enable the effective and efficient connection and integration of air carriers’ systems and infrastructure by providing for all relevant standards and technical requirements. To ensure the proper functioning of the system set up by this Regulation, detailed rules should be provided. When designing and developing the router, eu-LISA should ensure that API data transferred by air carriers and transmitted to PIUs is encrypted in transit.
Added:Recital 19: (19) In view of the Union interests at stake, the costs incurred by the European Data Protection Supervisor and eu-LISA for the performance of its tasks under this Regulation in respect of the router should be borne by the Union budget. The same should go for appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router and costs related to the maintenance of those connections as required under this Regulation, should be borne by the Union budget, in accordance with the applicable legislation and subject to certain exceptions. The costs covered by those exceptions should be borne by each Member State concerned itself. The Union budget should also cover the support, such as training, by eu-LISA to air carriers and PIUs to enable effective transfer and transmission of API data through the router. The costs incurred by the independent national supervisory authorities in relation to the tasks entrusted to them under this Regulation shall also be borne by the respective Member States.
Added:Recital 20: deleted
Added:Recital 20 a (new): (20a) In order to allow both the air carriers and the PIUs to make the most efficient use of their connections to the router, to prevent any duplication of passenger data transfers and processing, and to ensure compliance with the CJEU case-law and enhance the related monitoring and supervision, this Regulation should provide for the mandatory use of the router by the air carriers for transferring PNR data, and for the PIUs for receiving such data. The router should constitute the only necessary and available means for the Member States to require air carriers to comply with the obligations related to transfer of PNR data as foreseen by the PNR Directive.
Added:Recital 21: (21) It cannot be excluded that, due to exceptional circumstances and despite all reasonable measures having been taken in accordance with this Regulation and Regulation (EU) [API border management], the router or the systems or infrastructure connecting the PIUs and the air carriers thereto fail to function properly, thus leading to a technical impossibility to use the router to transmit API data. Given the unavailability of the router and that it will generally not be reasonably possible for air carriers to transfer the API data affected by the failure in a lawful, secure, effective and swift manner through alternative means, the obligation for air carriers to transfer that API data to the router should cease to apply for as long as the technical impossibility persist. In order to minimise the duration and negative consequences thereof, the parties concerned should in such a case immediately inform each other and immediately take all necessary measures to address the technical impossibility. This arrangement should be without prejudice to the obligations under this Regulation of all parties concerned to ensure that the router and their respective systems and infrastructure function properly, as well as the fact that air carriers are subject to penalties when they fail to meet those obligations, including when they seek to rely on this arrangement where such reliance is not justified. In order to deter such abuse and to facilitate supervision and, where necessary, the imposi…
Added:Recital 23: (23) Effective, proportionate and dissuasive penalties, including financial ones, should be provided for by Member States against those air carriers failing to meet their obligations regarding the collection and transfer of API and PNR data under this Regulation.