Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 5 Feb 2026
on the draft Council decision on the conclusion, on behalf of the Union, of the Agreement between the European Union and the Kingdom of Norway on the transfer of passenger name record (PNR) data to prevent, detect, investigate and prosecute terrorist offences and serious crime
To · plenary report· 19 Mar 2026
on the draft Council decision on the conclusion, on behalf of the Union, of the Agreement between the European Union and the Kingdom of Norway on the transfer of passenger name record (PNR) data to prevent, detect, investigate and prosecute terrorist offences and serious crime
The two versions differ only in presentation: cover page, numbering, or the parts a report carries that the adopted text does not.
+0 added · −0 removed · 2 changed paragraphs, packaging included.
Part 2 of 2: EXPLANATORY STATEMENT
EXPLANATORY STATEMENT
6 unchanged paragraphs
The proposed Council Decision aims to approve the Agreement between the European Union and the Kingdom of Norway on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (the ‘Agreement’).
Norway and EU Member States that are contracting parties to the Schengen Convention have a shared responsibility to ensure internal security within a common area without internal border controls, including by exchanging relevant information. Passenger Name Record (the ‘PNR’) data is information provided by passengers, collected during airline booking and check-in processes and held in the air carriers´ reservation and departure control systems for their own commercial purposes. Existing agreements on PNR data processing with third countries have demonstrated the potential to enhance security of the Schengen area. Such agreements improve the prevention and detection of terrorism and serious crime offences, including trafficking in drugs, firearms and human beings, at EU external borders, as well as provide for a risk-based data-driven approach that Member States can use as a compensatory measure for the absence of internal border controls within the Schengen area.
Although Norway is not considered a third country under Regulation 2016/679 (the ‘GDPR’), this legal framework does not apply to the processing of personal data, including PNR data, by Norwegian law enforcement authorities for the prevention, investigation, detection or prosecution of criminal offences, or the execution of criminal penalties. At the same time, Norway is bound by the Union acts which constitute a development of the provisions of the Schengen acquis. However, the Directive (EU) 2016/680 (the ‘PNR Directive’) does not constitute a development of the Schengen acquis, hence Norway does participate in the implementation of this legal act.
Under the current framework, Norway may not lawfully receive and process PNR data on flights operated by air carriers between the Union and Norway. Therefore, the Commission recommended to open negotiations of the Agreement on 6 September 2023. On 4 March 2024, the Council provided its authorisation and the negotiations began on 21 March 2024. On 9 April 2025, the negotiations were formally concluded, and the Agreement was adopted by the Council on 22 September 2025. The Agreement was signed by Commissioner Magnus Brunner and State Secretary Joakim Øren in October 2025.
The main purpose of this Agreement is to bridge the security gap existing in the Schengen area and thus enable the air carriers to transfer the PNR data to Norway and vice versa. However, the transfer and processing of personal data, including PNR data, requires strict limitations and effective safeguards. According to the Opinion 16/2025 of the European Data Protection Supervisor from 24 July 2025, the provisions of the Agreement governing the transfer and processing of PNR data proved satisfactory. In this respect, Commission has briefed the rapporteurs on 28 January 2026, confirming that the Agreement sets high standards not only in terms of security, but also in terms of privacy and data protection.
In light of this, the Rapporteur recommends that Parliament endorses the draft Council decision text.