Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 4 Jul 2023

LIBE-PR-750253

on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818

To · plenary report· 7 Dec 2023

A-9-2023-0411

on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818

+130 added · −17 removed · 6 changed paragraphs, packaging included.

Part 4 of 4: EXPLANATORY STATEMENT

EXPLANATORY STATEMENT

29 unchanged paragraphs

1. Context of the proposal

The Council Directive 2004/82/EC of 29 April 2004 on the obligation of carriers to communicate passenger data (‘API Directive’) aims at improving border controls and combating illegal immigration. It requires Member States to establish an obligation for air carriers to transmit, at the request of the authorities responsible for carrying out checks on persons at external borders, information concerning the passengers they will carry. The API Directive establishes no obligation for Member States to request the transmission of data. The API Directive contains an open list of data categories that Member States may request. The API Directive is in principle intended as an instrument to enhance border security, but it allows the Member States to use the personal data collected for law enforcement purposes as well.

The Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (‘PNR Directive’) aims to facilitate the prevention, detection, investigation and prosecution of terrorist offences and serious crime and thus enhance the internal security of the Union. The PNR Directive establishes an obligation for Member States to introduce provisions laying down obligations on air carriers operating extra-EU flights to transfer PNR data they collect. The PNR Directive allows Member States to apply the Directive to intra-EU flights. The PNR Directive includes API data in the list of PNR data.

On 21 June 2022, the Court of Justice of the European Union (CJEU) in case C-817/19 confirmed the validity of the PNR Directive. The CJEU also provided clarifications on certain provisions, in particular a number of conditions regarding the selection criteria for flights that Member States must comply with if they apply the PNR Directive to intra-EU flights.

The context of the API and PNR Directives is that in 2019, the EU recorded about 1 billion air passengers, half of which crossed the EU’s external borders. The Schengen Borders Code requires effective and systematic checks of people crossing the EU’s external borders. Advance passenger information is one of the tools for border authorities to anticipate their workload and perform adequate border controls.

The collection and transfer of API is in itself nothing new, nor is it limited to the EU. It is a commitment of all EU Member States since they are all parties to the Chicago Convention of the International Civil Aviation Organisation (ICAO). Furthermore, it is a requirement from many countries of destination, such as the United States, Japan, France, United Kingdom, China, India, Australia, Canada, Mexico and Thailand. API collection is an established practice under the abovementioned API Directive.

2. Content of the proposal

The API and PNR Directives leaves a lot of room for variable implementation. As a result, the API collection practice varies widely among EU Member States. Airlines have to deal with each Member State individually and are confronted with varying requests for data categories, modes of data transfer and safeguards including data security and privacy.

In order to remedy this situation, the Commission has proposed twin Regulations:

 A Regulation on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726 and repealing Council Directive 2004/82/EC (‘API borders’);

 A Regulation on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818 (‘API law enforcement’).

In the Commission’s design, the API borders proposal contains the main elements, including with regards to the technical solution (the router). The API law enforcement proposal has its own legal base and contains the elements relevant to the collection, transfer and processing of API data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime by Member States’ competent authorities.

Taken together, the proposals include the following main changes compared to the API Directive currently in force:

 A closed and exhaustive list of API data elements. Under the current API Directive, the list of data elements is open.

 Automated collection of API data, which should give more reliable data. Under the current API Directive, the collection can be done manually.

 Mandatory API data collection for the purposes of enhancing and facilitating the efficiency of border checks at external borders and of combating illegal immigration on all flights entering the Union. Under the current API Directive, Member States may request this data but are not obliged to do so.

 Mandatory API data collection for law enforcement purposes for all flights to and from the EU, as well as on flights within the EU. Under the current API Directive, Member States may use the personal data for law enforcement purposes, but the mandatory nature of the collection is new.

 Streamlined transmission of API data by air carriers to a new router, which will be developed and managed by the EU Agency for the Operational Management of Large-scale IT Systems (eu-LISA).

 An automatic filter in the router executing the automatic transmission from the router of API data of extra-EU flights and selected intra-EU flights to Member State Passenger Information Units (‘PIUs’) and the automatic deletion of all other API data.

In its Opinion 6/2023 on the Proposals for Regulations on the collection and transfer of advance passenger information (API), the European Data Protection Supervisor (EDPS) assessed the proposal to collect API data from all flights and to have this data automatically filtered by the proposed router on the basis of pre-selected flights positively from a data protection perspective.

3. Rapporteur’s assessment of the proposal

The rapporteur responsible for API law enforcement welcomes the Commission proposal to replace the obsolete API Directive with two new Regulations. The rapporteur agrees with the Commission that it is necessary to remedy the current situation of variable interpretation and application of the API Directive as well as of API elements of the PNR Directive. The rapporteur is of the opinion that API data and PNR data complement each other and that together they can provide more reliable information. This will mean more limited and targeted interventions by law enforcement authorities and less intrusion of travellers’ privacy. By way of example, the rapporteur would like to point out that criminals often book flights (generating PNR data) but without cancellation do not board these flights. The unavailability of API data based on passengers that boarded the flight in such situations leads to unnecessary interventions by law enforcement authorities using limited capacities and sometimes disturbing innocent travellers. Another example is the issue of date of birth, which is often not available to air carriers at the time of booking, but which only becomes available at the time of check in. Date of birth is an extremely important data element, which is crucial in avoiding false hits based on name only.

The rapporteur also supports the collection of API data by air carriers using automated means. Not only does this avoid unnecessary problems due to innocent typos and spelling mistakes. It also stops criminals from playing with such typos, which they currently do enthusiastically to avoid detection. Nevertheless, the rapporteur wants to ensure fair treatment for all passengers in all situations. The rapporteur insists that manual collection of API data remain possible for documents not containing a ‘Machine-Readable Zone’ (MRZ) and for situation of technical impossibility to automatically collect the data. Furthermore, the rapporteur is of the opinion that the Commission should make sure that the obligation to use automated means for the collection of API data does not lead to disproportionate obstacles, such as additional airport check-in fees, for passengers unable to use other means for automated check-in.

The rapporteur strongly supports the inclusion of intra-EU flights in the scope of API law enforcement. With the CJEU, the rapporteur believes that this is proportionate, taking into account the security situation and travel patterns of criminals and terrorists. However, the rapporteur also believes that the selection of intra-EU flights must be strictly limited as indeed demanded by the CJEU. Therefore, the rapporteur introduces some parameters for Member States based on the Court ruling. Furthermore, the rapporteur instructs the Commission to facilitate further steps to increase cohesion among the Member States regarding their selection of intra-EU flights.

The rapporteur believes that the router solution, once operational, could be useful for the transfer of PNR data as well as a secure and reliable and, for the airlines cost-effective, solution. Such a step would be in line with the requirement that Member States take one decision regarding the selection of intra-EU flights for the application of both the PNR Directive and the proposed API Regulations.

The rapporteur insists on stringent data security requirements, which should be embedded in the API borders Regulation.

The rapporteur believes that Member States can use the Internal Security Fund to claim compensation for costs made related to the proposed new technical solution (the router).

The rapporteur believes that delegation of powers to the Commission is appropriate in a number of cases described in the Regulation. The rapporteur insists that this is done via delegated acts, because it gives airline industry representatives more of a voice in technical decisions such regarding the choice of data formats and it places Parliament on an equal footing with the Council.

The rapporteur insists on including in the regular Commission evaluation the impact of this Regulation, also in combination with other legislation applying to passenger air travel, on passengers and on air carriers.