Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 4 Jul 2023

LIBE-PR-750253

on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818

To · plenary report· 7 Dec 2023

A-9-2023-0411

on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818

+130 added · −17 removed · 6 changed paragraphs, packaging included.

Part 2 of 4: Paragraphs 61–120

Added:Recital 23 a (new): (23a) When providing for the penalties applicable to air carriers under this Regulation, Member States should take into account the technical and operational feasibility of ensuring complete data accuracy. Additionally, when penalties are imposed, their application and value should be established taking into consideration the actions undertaken by the air carrier to mitigate the issue as well as its level of cooperation with national authorities.

Added:Recital 23 b (new): (23b) In order to store the reports and statistics of the router on the Central Repository for Reporting and Statistics, it is necessary to amend Regulation (EU) 2019/817 of the European Parliament and of the Council.1a The Central Repository for Reporting and Statistics should provide only statistics based on API data for the implementation and effective supervision of this Regulation. The data that the router automatically transmits to the Central Repository for Reporting and Statistics to that end should not allow for the identification of the passengers concerned. The router should not transmit any data to the Central Repository for Reporting and Statistics for those intra-EU flights that have not been selected by a Member State based on an assessment in compliance with the criteria and methodology for the selection of intra-EU flights set out in this Regulation. / 1a Regulation (EU) 2019/817 of the European Parliament and of the Council of 20 May 2019 on establishing a framework for interoperability between EU information systems in the field of borders and visa and amending Regulations (EC) No 767/2008, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1726 and (EU) 2018/1861 of the European Parliament and of the Council and Council Decisions 2004/512/EC and 2008/633/JHA (OJ L 135, 22.5.2019, p. 27).

Added:Recital 24: (24) In order to adopt measures relating to the technical requirements and operational rules for the automated means for the collection of machine-readable API data, to the common protocols and formats to be used for the transfer of API data by air carriers, to the technical and procedural rules for the transmission of API data from the router and to the PIUs and to the PIU’s and air carriers’ connections to and integration with the router, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of Articles 4, 5, 10 and 11, respectively. It is of particular importance that the Commission carry out appropriate consultations with relevant stakeholders, including air carriers, during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement on Better Law-Making of 13 April 201633. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts. Taking into account the state of the art, those technical requirements and rules might change over time.

Added:Recital 24 a (new): (24a) It is important to collect reliable and useful statistics based on the implementation of this Regulation in order to support its objectives and inform the evaluations under this Regulation. Such statistics should not contain any personally identifiable data. All relevant stakeholders, including relevant Member State authorities, Europol and, where appropriate, air carriers, should have access to those statistics.

Added:Recital 24 b (new): (24b) In order to ensure uniform conditions for the implementation of this Regulation, namely as regards the start of operations of the router, implementing powers should be conferred on the Commission. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council1a. / 1a Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by Member States of the Commission’s exercise of implementing powers (OJ L 55, 28.2.2011, p. 13).

Added:Recital 25: (25) All interested parties, and in particular the air carriers and the PIUs, should be afforded sufficient time to make the necessary preparations to be able to meet their respective obligations under this Regulation, taking into account that some of those preparations, such as those regarding the obligations on the connection to and integration with the router, can only be finalised when the design and development phases of the router have been completed and the router starts operations. Therefore, this Regulation should apply only from an appropriate date after the date at which the router starts operations, as specified by the Commission in accordance with this Regulation and Regulation (EU) [API border management].

Added:Recital 25 a (new): (25a) This Regulation should be subject to regular evaluations to ensure the monitoring of its effective application. In particular, the collection of API data should not be to the detriment of the travel experience of legitimate passengers. Therefore, the Commission should include in its regular evaluation reports on the application of this Regulation an assessment of the impact of this Regulation on the travel experience of legitimate passengers.

Added:Recital 25 b (new): (25b) Given that this Regulation requires additional adjustment and administrative costs by the air carriers, the overall regulatory burden for the aviation sector should be kept under close review. Against this backdrop, the report evaluating the functioning of this Regulation should assess the extent to which the objectives of the Regulation have been met and to which it has impacted the competitiveness of the sector. Therefore, the Commission’s report should also conduct a holistic assessment and refer to the interaction of this Regulation with other relevant EU legislative acts, in particular Regulation (EU) 2017/2226, Regulation (EU) 2018/1240 and Regulation (EC) 767/2008. The report should assess the overall impact of related reporting obligations on air carriers, identifying provisions that could be updated and simplified, where appropriate, to mitigate the burden on air carriers, as well as actions and measures that have been or could be taken to reduce the total cost pressure on the aviation sector.

Added:Article 1 – paragraph 1 – point a: (a) the collection by air carriers of advance passenger information data (‘API data’) on extra EU flights and intra EU flights;

Added:Article 1 – paragraph 1 – point c: (c) the transmission from the router to the Passenger Information Units (‘PIUs’) of the API data and PNR data on extra-EU flights and selected intra-EU flights.

Added:Article 1 – paragraph 1 a (new): This Regulation is without prejudice to Regulation (EU) 2016/679, Regulation (EU) 2018/1725 and Directive (EU) 2016/680.

Added:Article 3 – paragraph 1 – point c: (c) ‘intra-EU flight’ means any flight as defined in Article 3, point (3), of Directive (EU) 2016/681, with the exception of those flights for which neither the Member State from where the flight is scheduled to depart, nor the Member State where the flight is scheduled to land, have notified their decision to apply Directive 2016/681 to intra-EU flights, pursuant to Article 2 of that Directive;

Added:Article 3 – paragraph 1 – point d: (d) ‘scheduled flight’ means a commercial flight as defined in Article 3, point (e), of Regulation (EU) [API border management];

Added:Article 3 – paragraph 1 – point e: (e) ‘non-scheduled flight’ means a commercial flight as defined in Article 3, point (f), of Regulation (EU) [API border management];

Article 3 – paragraph 1 – point g: (g) ‘crew’ means any person as defined in Article 3, point (i), of Regulation (EU) [API border management];

Change 4

Changed:Article 3 – paragraph 1 – point h: (h) ‘traveller’ means any person as defined in Article 3, point (j), of Regulation (EU) [API border management];deleted

Article 3 – paragraph 1 – point i: (i) ‘advance passenger information data’ or ‘API data’ means the data as defined in Article 3, point (k), of Regulation (EU) [API border management];

Article 3 – paragraph 1 – point m: (m) ‘serious crime’ means the offences as defined in Article 3, point (9), of Directive (EU) 2016/681;

Change 5

Changed:Article 3 – paragraph 1 – point n: (n) ‘the router’ means the router as definedreferred to in Article 3, point (m) of Regulation (EU) [API border management];4b;

Change 6

Changed:Article 4 – paragraph 3 – subparagraph 1: 1. Air carriers shall collect the API data referredof topassengers, inconsisting Articleof 4(2),the pointspassenger (a)data toand (d),the offlight Regulationinformation (EU)specified [APIin borderparagraphs management]1a usingand automated1b meansof tothis collectArticle, respectively, on the machine-readableflights datareferred ofto thein travelArticle document2, offor the travellerpurpose concerned.of Theytransferring shallthat doAPI sodata to the router in accordance with paragraph 6. Where the detailedflight technicalis requirementscode-shared andbetween operationalone rulesor referredmore air carriers, the obligation to intransfer paragraphthe 5,API wheredata suchshall rulesbe haveon beenthe adoptedair andcarrier arethat applicable.operates the flight.

Change 7

Removed:Article 4 – paragraph 3 – subparagraph 2: However, where such use of automated means is not possible due to the travel document not containing machine-readable data, or where it is technically impossible to collect the API data referred to in Article 4(2), points (a) to (d), of Regulation (EU) [API border management] using automated means, air carriers shall collect that data manually, in such a manner as to ensure compliance with paragraph 2.

Added:Article 4 – paragraph 1 a (new): 1a. The API data shall consist only of the following passenger data relating to each passenger on the flight: / (a) the surname (family name), first name or names (given names); / (b) the date of birth, sex and nationality; / (c) the type and number of the travel document and the three-letter code of the issuing country of the travel document; / (d) the date of expiry of the validity of the travel document; / (e) the number identifying a passenger name record used by an air carrier to locate a passenger within its information system (PNR record locator); / (f) the number of the seat in the aircraft assigned to a passenger, where the air carrier collects such information; / (g) the number and the weight of checked bags, where the air carrier collects such information.

Removed:Article 5 a (new): Article 5a / Selection of intra-EU flights / 1. Member States that decide to apply Directive (EU) 2016/681 to intra-EU flights shall for the selection of those flights: / (a) take into account only criteria which are relevant for the prevention, detection, investigation and prosecution of terrorist offences and serious crime having an objective link, including an indirect link, with the carriage of passengers by air; and / (b) in the absence of a genuine and present or foreseeable terrorist threat, only target specific routes, travel patterns or airports for which there are indications of suspicious activities that justify the transmission and processing of API data. / 2. The Commission shall facilitate the exchange of views on the choice of selection criteria, as well as, on a voluntary basis, of selected flights.

Added:Article 4 – paragraph 1 b (new): 1b. The API data shall also consist only of the following flight information relating to the flight of each passenger: / (a) the flight identification number or, where the flight is code-shared between one or more air carriers, the flight identification numbers, or, if no such number exists, other clear and suitable means to identify the flight; / (b) where applicable, the border crossing point of entry into the territory of the Member State; / (c) the code of the airport of entry into the territory of the Member State; / (d) the initial point of embarkation; / (e) the local date and estimated time of departure; / (f) the local date and estimated time of arrival.

Change 8

Changed:Article 64 – paragraph 42 – subparagraph 2: However, if those logs are needed for procedures for monitoring or ensuring1 thea security(new): andThe integritycollection of the API data or thein lawfulnessaccordance ofwith the processingfirst operations,subparagraph asshall referrednot toinclude inan paragraphobligation 2,for andair thosecarriers proceduresto havecheck alreadythe beguntravel document at the moment of the expiry of the time period referred to inboarding the first subparagraph, air carriers may keep those logs for asaircraft longor asan necessaryobligation for those procedures.passengers Into thatcarry case,a theytravel shalldocument informwhen thetravelling, Commissionwithout andprejudice immediatelyto deleteacts thoseof logsnational whenlaw theythat are no longer necessarycompatible forwith thoseUnion procedures.law.

Change 9

Removed:Article 8 – paragraph 1: Pursuant to Article 17 of Regulation (EU) [API borders] eu-LISA, PIUs and air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation.

Added:Article 4 – paragraph 3 – subparagraph 1: Air carriers shall collect the API data referred to in paragraph 1a (new) points (a) to (d), using automated means to collect the machine-readable data of the travel document of the passenger concerned. Air carriers shall collect that data during the check-in process, either as part of the online check-in or as part of the check-in at the airport. They shall do so in accordance with the detailed technical requirements and operational rules referred to in paragraph 5, once such rules have been adopted and are applicable and, in particular, by using the most reliable automated means available to collect the machine-readable data of the respective travel document.

Removed:Article 12 – paragraph 1 – subparagraph 1: The funding referred to in Article 7(2)(a) and (b) of Regulation (EU) 2021/1149 of the European Parliament and of the Council 1a may provide support for costs incurred by the Member States in relation to their connections to and integration with the router referred to in Article 10 of this Regulation and the maintenance thereof, in accordance with the eligibility rules and co-financing rates set out in Regulation (EU) 2021/1149. / 1a Regulation (EU) 2021/1149 of the European Parliament and of the Council of 7 July 2021 establishing the Internal Security Fund (OV J 251, 15.7.2021, p. 94).

Added:Article 4 – paragraph 3 – subparagraph 1 a (new): The collection of API data with automated means shall not lead to the collection of any biometric data contained in the travel document.

Removed:Article 12 – paragraph 1 – subparagraph 2: deleted / (deleted) / (deleted) / (deleted) / (deleted)

Added:Article 4 – paragraph 3 – subparagraph 1 b (new): Where air carriers provide an online check-in process, they shall enable passengers to provide the API data referred to in paragraph 1a, points (a) to (d), during the online check-in process, using automated means.

Removed:Article 12 – paragraph 2: deleted

Added:Article 4 – paragraph 3 – subparagraph 2: Where the use of automated means is not possible, air carriers shall collect that data manually, either as part of the online check-in or as part of the check-in at the airport, in such a manner as to ensure compliance with paragraph 2.

Removed:Article 20 – paragraph 1 a (new): 1a. In conducting its evaluation, the Commission shall also pay special attention to the impact of this Regulation on: / (a) passengers, including their travel experience; / (b) air carriers.

Added:Article 4 – paragraph 4: 4. Any automated means used by air carriers to collect API data under this Regulation shall be reliable, secure and up-to-date. Air carriers shall ensure that API data is encrypted during the transmission of the data from the passenger to the air carriers.

Removed:Article 20 – paragraph 1 b (new): 1b. The evaluation referred to in paragraph 1 shall also include a review of the necessity, proportionality and effectiveness of including the mandatory collection and transfer of API data relating to intra-EU flights within the scope of this Regulation.

Added:Article 4 – paragraph 5: 5. The Commission is empowered to adopt delegated acts in accordance with Article 19 to supplement this Regulation by laying down detailed technical requirements and operational rules for the collection of the API data referred to in paragraph 1a, points (a) to (d), using automated means in accordance with paragraphs 3 and 4 of this Article, including on requirements for data security.

Added:Article 4 – paragraph 6: 6. Air carriers shall transfer the encrypted API data to the router, by electronic means. They shall do so in accordance with the detailed rules referred to in paragraph 9, once such rules have been adopted and are applicable.

Added:Article 4 – paragraph 7: 7. Air carriers shall transfer the API data both at the moment of check-in and immediately after flight closure, that is, once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for passengers to board or to leave the aircraft. At the moment of check-in, air carriers shall transfer the API data in accordance with this Regulation and relevant international standards. Air carriers shall receive an acknowledgement of receipt of the transfer of the API data.

Added:Article 4 – paragraph 7 a (new): 7a. The Commission is empowered to adopt delegated acts in accordance with Article 19 to supplement this Regulation by laying down the necessary detailed rules on the common protocols and supported data formats to be used for the encrypted transfers of API data to the router referred to in paragraph 6, including the transfer of API data at the moment of check-in and requirements for data security. Such detailed rules shall ensure that airlines transmit API data using the same structure and content.

Added:Article 4 – paragraph 7 b (new): 7b. The PIUs shall process API data, transferred to them in accordance with this Regulation, solely for the purposes referred to in Article 1. / The PIUs or other competent authorities shall under no circumstances process API data for the purposes of profiling.

Added:Article 4 – paragraph 8 – subparagraph 1 – introductory part: Air carriers shall store, for 24 hours from the moment of departure of the flight, the API data relating to that passenger that they collected pursuant to Article 4. They shall immediately and permanently delete that API data after the expiry of that time period. This is without prejudice to the possibility for air carriers to retain and use the data where necessary for the normal course of their business in compliance with the applicable law and in particular Regulation (EU) 2016/679. / Air carriers shall immediately either correct, complete or update, or permanently delete, the API data concerned in both of the following situations:

Added:Article 4 – paragraph 8 – subparagraph 1 – point a: (a) where they become aware that the API data collected is inaccurate, incomplete or no longer up-to-date;

Added:Article 4 – paragraph 8 a (new): 8a. Air carriers shall immediately and permanently delete API data where they become aware that the API data collected was processed unlawfully or that the data transferred does not constitute API data.

Added:Article 4 – paragraph 8 b (new): 8b. Where the air carriers become aware of the circumstances referred to in point (a) of paragraph 8a or paragraph 8b after having completed the transfer of the data in accordance with paragraph 6, they shall immediately inform the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA). Upon receiving such information, eu-LISA shall immediately inform the PIUs that received the API data transmitted through the router.

Added:Article 4 – paragraph 9: deleted

Added:Article 4 – paragraph 9 a (new): 9a. In accordance with Directive 2016/681, air carriers shall also transfer PNR data to the router, insofar as those data are collected in the normal course of their business, for the transmission of those data from the router to the respective PIUs in accordance with Article 5(4). Air carriers shall not be allowed to transfer PNR data in accordance with Article 8(1) of Directive 2016/681 by any other means.

Added:Article 4 a (new): Article 4a / Fundamental Rights / 1. The collection and processing of personal data in accordance with this Regulation and Regulation (EU) [API Border Management] by air carriers and competent authorities shall not result in discrimination against persons on the grounds of sex and gender, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age or sexual orientation. / 2. This Regulation shall fully respect human dignity and the fundamental rights and principles recognised by the Charter of Fundamental Rights of the European Union, including the right to respect for one’s private life, to asylum, to the protection of personal data, to freedom of movement and to effective legal remedies. / 3. Particular attention shall be paid to children, the elderly, persons with a disability and vulnerable persons. The best interests of the child shall be a primary consideration when implementing this Regulation.

Added:Chapter 2 a (new): CHAPTER 2a (new) / PROVISIONS RELATING TO THE ROUTER / Article 4b / The Router / 1. eu-LISA shall design, develop, host and technically manage, in accordance with Articles 11a and 11b, a router for the purpose of facilitating the transfer of encrypted API and PNR data by the air carriers to the PIUs in accordance with this Regulation. / 2. The router shall be composed of: / (a) a central infrastructure, including a set of technical components enabling the transmission of API and PNR data; / (b) a secure communication channel between the central infrastructure and the PIUs, and a secure communication channel between the central infrastructure and the air carriers, for the transfer of API and PNR data and for any communications relating thereto. / 3. The router shall allow for the reception and transmission of encrypted API data. / 4. The router shall automatically extract and make available the statistics, in accordance with Article 31, to the central repository for reporting and statistics. / 5. Without prejudice to Article 4c of this Regulation, the router shall, where appropriate and to the extent technically possible, share and re-use the technical components, including hardware and software components, of the web service referred to in Article 13 of Regulation (EU) 2017/2226 of the European Parliament and of the Council1a, the carrier gateway referred to in Article 6(2), point (k), of Regulation (EU) 2018/1240, and the carrier gateway referred to in Article 2a, point (h),…

Added:Article 5 – paragraph 1 – subparagraph 1: Upon the verifications referred to in Article 10a, the router shall, immediately and in an automated manner, transmit the API data, transferred to it by air carriers pursuant to Article 4, to the PIUs of the Member State on whose territory the flight will land or depart, or to both in the case of intra-EU-flights. Where a flight has one or more stop-overs at the territory of other Member States than the one from which it departed, the router shall transmit the API data to the PIUs of all the Member States concerned.

Added:Article 5 – paragraph 1 – subparagraph 3: However, for intra-EU flights, the router shall only transmit API data of the flights included in the list referred to in paragraph 2 to the applicable PIUs.

Added:Article 5 – paragraph 1 – subparagraph 4: The router shall transmit the API data in accordance with the detailed rules referred to in paragraph 3, once such rules have been adopted and are applicable.

Added:Article 5 – paragraph 3: 3. The Commission is empowered to adopt delegated acts in accordance with Article 19 to supplement this Regulation by laying down the necessary detailed technical and procedural rules for the transmissions of API data from the router referred to in paragraph 1, including on requirements for data security.

Added:Article 5 – paragraph 3 a (new): 3a. This provision shall apply mutatis mutandis to the transmission of PNR data from the router to the PIUs of the Member States in accordance with Article 8(1) of Directive 2016/681, which shall be the only means for PIUs to receive PNR data from air carriers.

Added:Article 5 a (new): Article 5a / Methodology and criteria for the selection of intra-EU flights / Member States that decide to apply Directive (EU) 2016/681 and consequently this Regulation to intra-EU flights shall for the selection of those flights: / (a) carry out an objective, duly reasoned and non-discriminatory threat assessment in accordance with Article 2 of Directive (EU) 2016/681, the case-law of the Court of Justice of the European Union and the fundamental rights laid down, inter alia, in Articles 7 and 8 of the Charter of Fundamental Rights; / (b) take into account only criteria which are relevant for the prevention, detection, investigation and prosecution of terrorist offences and serious crime having an objective link, including an indirect link, with the carriage of passengers by air and not be purely based on nationality, sex, age, race, colour, ethnic origin, language, religion or belief or membership of a national minority of any passengers or groups of passengers; / (c) in situations of a genuine and present or foreseeable terrorist threat, Member States may apply Directive (EU) 2016/681 to all intra-EU flights arriving at or departing from its territory, in a decision that is limited in time to what is strictly necessary and that is open to effective review. In the absence of such a situation, Member States shall target only specific routes, travel patterns or airports for which there are indications of suspicious activities regarding terrorist offenses and serious crime an…

Added:Article 5 b (new): Article 5b / Deletion of API data from the router / API data, transferred to the router pursuant to this Regulation, shall be stored on the router only insofar as necessary to complete the transmission to the PIUs and shall be deleted from the router, immediately, permanently and in an automated manner, in the following situations: / (a) where the transmission of the API data to the relevant PIUs has been completed; / (b) in cases of technical impossibility of the router to subsequently transmit the API data to the PIU, after 12 hours; / (c) where the API data relates to other intra-EU flights than those included the lists referred to in Article 5(2) of this Regulation. The router shall automatically inform eu-LISA and the PIUs of the immediate deletion of these intra-EU flights for the purposes of the statistics referred to in Article 16a(1).

Added:Article 6 – paragraph -1 (new): -1. eu-LISA shall keep logs of all processing operations relating to the transfer of API data through the router under this Regulation. Those logs shall cover the following: / (a) the air carrier that transferred the API data to the router; / (b) the competent authorities and PIUs to which the API data was transmitted through the router; / (c) the date and time of the transfers referred to in points (a) and (b), and place of transfer; / (d) any access by staff of eu-LISA necessary for the maintenance of the router, as referred to in Article 11b(3); / (e) any other information relating to those processing operations necessary to monitor the security and integrity of the API data and the lawfulness of those processing operations. / Those logs shall not include any personal data, other than the information necessary to identify the relevant member of the staff of eu-LISA, referred to in point (d) of the first subparagraph.

Added:Article 6 – paragraph 1: 1. Air carriers shall create logs of all processing operations under this Regulation undertaken using the automated means referred to in Article 4(3). Those logs shall cover the date, time, and place of transfer of the API data. Those logs shall not contain any personal data, other than the information necessary to identify the relevant member of the staff of the air carrier.

Added:Article 6 – paragraph 3: 3. eu-LISA and air carriers shall take appropriate measures to protect the logs that they created pursuant to paragraph 1 against unauthorised access and other security risks.

Added:Article 6 – paragraph 3 a (new): 3a. The national supervisory authorities referred to in Article 15 and PIUs shall have access to the relevant logs referred to in paragraph 1 where necessary for the purposes referred to in paragraph 2.