Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2023-0411 → TA-9-2024-0377
- From
- A-9-2023-0411 Plenary report of 7 Dec 2023
- To
- TA-9-2024-0377 Adopted text of 25 Apr 2024
- Changes
- Not comparable
- Paragraphs
- +9 added · −170 removed · 1 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818
- Title (to)
- Advance passenger information: prevention, detection, investigation and prosecution of terrorist offences and serious crime
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 1 of 4: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
RemovedDRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
AddedP9_TA(2024)0377
Changedon the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advanceAdvance passenger information for theinformation: prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818crime
Removed(COM(2022)0731 – C90427/2022 – 2022/0425(COD))
AddedCommittee on Civil Liberties, Justice and Home Affairs
AddedPE750.253
AddedEuropean Parliament legislative resolution of 25 April 2024 on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818 (COM(2022)0731 – C9-0427/2022 – 2022/0425(COD))
5 unchanged paragraphs
(Ordinary legislative procedure: first reading)
The European Parliament,
– having regard to the Commission proposal to Parliament and the Council (COM(2022)0731),
– having regard to Article 294(2) and Articles 82(1) point (d) and 87(2) point (a) of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90427/2022),
– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
Added– having regard to the opinion of the European Economic and Social Committee of 27 April 2023,
Added– having regard to the provisional agreement approved by the committee responsible under Rule 74(4) of its Rules of Procedure and the undertaking given by the Council representative by letter of 13 March 2024 to approve Parliament’s position, in accordance with Article 294(4) of the Treaty on the Functioning of the European Union,
6 unchanged paragraphs
– having regard to Rules 59 of its Rules of Procedure,
– having regard to the opinion of the Committee on Transport and Tourism,
– having regard to the report of the Committee on Civil Liberties, Justice and Home Affairs (A9-0411/2023),
1. Adopts its position at first reading hereinafter set out;
2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Change 1
RemovedRecital 1: (1) The transnational dimension of serious and organised crime and the continuous threat of terrorist attacks on European soil call for action at Union level to adopt appropriate measures to ensure security within an area of freedom, security and justice without internal borders. Information on air passengers, such as Passenger Name Records (PNR) and in particular Advance Passenger Information (API), is essential in order to identify high-risk passengers, including those who are not otherwise known to law enforcement authorities, and to establish links between members of criminal groups, and countering terrorist activities.
AddedP9_TC1-COD(2022)0425
RemovedRecital 2: (2) While Council Directive 2004/82/EC27 establishes a legal framework for the collection and transfer of API data by air carriers with the aims of improving border controls and combating illegal immigration, it also states that Member States may use API data for law enforcement purposes. However, only creating such a possibility leads to several gaps and shortcomings. In particular, it means that, API data is not systematically collected and transferred by air carriers for law enforcement purposes. It also means that, where Member States acted upon the possibility, air carriers are faced with diverging requirements under national law as regards when and how to collect and transfer API data for this purpose. Those divergences lead not only to unnecessary costs and complications for the air carriers, but can also negatively affect the Union’s internal security and complicate effective cooperation between the competent law enforcement authorities of the Member States. Moreover, in view of the different nature of the purposes of facilitating border controls and law enforcement, it is appropriate to establish a distinct legal framework for the collection and transfer of API data for each of those purposes
AddedPosition of the European Parliament adopted at first reading on 25 April 2024 with a view to the adoption of Regulation (EU) 2025/… of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818
RemovedRecital 4: (4) It is therefore necessary to establish clear, harmonised and effective rules at Union level on the collection and transfer of API data for the purpose of preventing, detecting, investigating and prosecuting terrorist offences and serious crime.
Added(As an agreement was reached between Parliament and Council, Parliament's position corresponds to the final legislative act, Regulation (EU) 2025/13.)
RemovedRecital 5: (5) Considering the close relationship between both acts, this Regulation should be understood as complementing the rules provided for in Directive (EU) 2016/681. Therefore, API data is to be collected and transferred in accordance with the specific requirements of this Regulation, including as regards the situations and the manner in which that is to be done. However, the rules of that Directive apply in respect of matters not specifically covered by this Regulation, especially regarding the rules on the subsequent processing of the API data received by the PIUs, exchange of information between Member States, conditions of access by the European Union Agency for Law Enforcement Cooperation (Europol), transfers to third countries, retention and depersonalisation, as well as the protection of personal data. Insofar as those rules apply, the rules of that Directive on penalties and the national supervisory authorities apply as well. This Regulation should leave those rules unaffected.
RemovedRecital 6: (6) The collection and transfer of API data affects the privacy of individuals and entails the processing of their personal data. In order to fully respect their fundamental rights, in particular the right of respect for private life and the right to the protection of personal data, in accordance with the Charter of Fundamental Rights of the European Union (‘Charter’), adequate limits and safeguards should be provided for. In particular, any processing of API data and, in particular, API data constituting personal data, should remain strictly limited to what is necessary for and proportionate to achieving the objectives pursued by this Regulation. In addition, it should be ensured that the processing of any API data collected and transferred under this Regulation do not lead to any form of discrimination precluded by the Charter.
RemovedRecital 7: (7) In view of the complementary nature of this Regulation in relation to Directive (EU) 2016/681, the obligations of commercial air carriers under this Regulation should apply in respect of all flights for which Member States are to require air carriers to transmit PNR data under Directive (EU) 2016/681, namely flights, including both scheduled and non-scheduled flights, both between Member States and third countries (extra-EU flights), and between several Member States (intra-EU flights) insofar as those flights have been selected in accordance with Directive (EU) 2016/681, irrespective of the place of establishment of the air carriers conducting those flights. In accordance with the relevant ICAO classifications, general aviation such as flight schools, military or medical flights, should be exempted from this Regulation.
RemovedRecital 9: (9) In view of the close relationship between the acts of Union law concerned and in the interest of consistency and coherence, the definitions set out in this Regulation should be aligned with, interpreted and applied in the light of, the definitions set out in Directive (EU) 2016/681 and Regulation (EU) [API border management]29 .
RemovedRecital 10: (10) In particular, the items of information that jointly constitute the API data to be collected and subsequently transferred under this Regulation should be the same as those listed clearly and exhaustively in Regulation (EU) API [border management], covering both information relating to each passenger and information on the flight of that passenger. Under this Regulation, such flight information should cover information on the border crossing point of entry into the territory of the Member State concerned only where applicable, that is, not when the API data relate to intra-EU flights
RemovedRecital 11: (11) In order to ensure an approach that is as consistent as possible on the collection and transfer of API data by air carriers, the rules set out in this Regulation should be aligned with those set out in the Regulation (EU) [API border management] where appropriate. That alignment concerns, in particular, the rules on data quality, the precise manner in which they are to transfer the collected API data to the router, the encryption of API data in transit, and the deletion of the API data. Furthermore, and as set out in this Regulation and in the Regulation (EU) [API border management], air carriers should be required to collect the API data using automated means, specifically by reading information from the machine-readable data of the travel document. Where the use of such automated means is however not possible, air carriers should collect the API data manually, either as part of the online check-in process, or as part of the check-in at the airport, in such a manner as to ensure compliance with their obligations under this Regulation.
RemovedRecital 11 a (new): (11a) The collection of API data by automated means should be strictly limited to the alphanumerical data contained in the travel document and should not lead to the collection of any biometric data from it. As the collection of API data is part of the check-in process, either online or at the airport, it should not include an obligation for air carriers to check a travel document of the passenger at the moment of boarding. Compliance with this regulation should not include any obligation for passenger to carry a travel document at the moment of boarding.
RemovedRecital 11 b (new): (11b) The requirements set out by this Regulation and by the corresponding delegated and implementing acts should lead to a uniform implementation by the airlines, thereby minimising the cost of the interconnection of their respective systems. To facilitate a harmonised implementation of those requirements by the airlines, in particular as regards the data structure, format and transmission protocol, the Commission, based on its cooperation with the PIUs, other Member States authorities, air carriers, and relevant Union agencies, should ensure that the practical handbook to be prepared by Commission provides all the necessary guidance and clarifications.
RemovedRecital 11 c (new): (11c) In order to enhance data quality, the router should verify whether the API data transferred to it by the air carriers complies with the supported data formats. Where the router has verified that the data is not compliant with the supported data formats, the router should, immediately and in an automated manner, notify the air carrier concerned thereof.
RemovedRecital 11 d (new): (11d) In order to reduce the impact on air carriers, and with a view to create synergies with other reporting obligations on air carriers in Regulation (EU) 2017/2226, Regulation (EU) 2018/1240 and Regulation (EC) 767/2008 and avoid duplication, air carriers should transfer the API data at the moment of the check-in of each passenger by way of interactive API in accordance with international standards, using the existing carrier gateway. Air carriers should receive an acknowledgement of receipt to the transfer of interactive API, in line with international standards. The use of an interactive API should not lead to an automatic denial of boarding.
RemovedRecital 11 e (new): (11e) The passengers should be enabled to provide certain API data themselves during an online check-in process. Such means could, for example, include a secure app on a passengers’ smartphone, computer or webcam with the capability to read the machine-readable data of the travel document. Where the passengers did not check-in online, air carriers should provide them with the possibility to provide the required machine-readable API data concerned during check-in at the airport with the assistance of a self-service kiosk or of airline staff at the check-in counter. The Commission should ensure that the obligations under this Regulation do not lead to disproportionate obstacles for passengers unable to use online means for automated check-in, such as additional airport check-in fees.
RemovedRecital 11 f (new): (11f) The automatic data collection systems and other processes established under this Regulation should not have a negative impact on the employees in the aviation industry, who should benefit from upskilling and reskilling opportunities that would increase the efficiency and reliability of data collection and transfer as well as the working conditions in the sector.
RemovedRecital 12: (12) In order to ensure the joint processing of API data and PNR data to effectively fight terrorism and serious crime in the Union and at the same time minimise the interference with passengers’ fundamental rights protected under the Charter, the PIUs should be the sole competent authorities in the Member States that are entrusted to receive, and subsequently further process and protect, API data collected and transferred under this Regulation. In the interest of efficiency and to minimise any security risks, the router, as designed, developed, hosted and technically maintained by the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) in accordance with Regulation (EU) [API border management], should transmit the API data, collected and transferred to it by the air carriers under this Regulation, to the relevant PIUs. Given the necessary level of protection of API data constituting personal data, including to ensure the confidentiality of the information concerned, the API data should be transmitted by the router to the relevant PIUs in an automated manner.
RemovedRecital 12 a (new): (12a) With a view to guaranteeing the fulfilment of the rights provided for under the Charter and to ensuring accessible and inclusive travel options, especially for vulnerable groups and persons with disabilities, air carriers, supported by the Member States, should ensure that an offline alternative for the check-in and for the provision of the necessary data by the passengers is possible at all times.
RemovedRecital 13: (13) For extra-EU flights, the PIU of the Member State on whose territory the flight will land and or from where the flight will depart should receive the API data from the router for all those flights, that PNR data is collected for in accordance with Directive (EU) 2016/681. The router should identify the flight and the corresponding PIUs using the information contained in the PNR record locator, a data element common to both the API and PNR data sets allowing for the joint processing of API data and PNR data by the PIUs.
RemovedRecital 14: (14) As regards intra-EU flights, in line with the case law of the Court of Justice of the European Union (CJEU), in order to avoid unduly interfering with passengers’ relevant fundamental rights as protected under the Charter and to ensure compliance with the requirements of Union law on the free movement of persons and the abolition of internal border controls, a selective approach should be provided for. This is with the exception of situations of a genuine and present or foreseeable terrorist threat, where Member States should be able to apply Directive (EU) 2016/681 to all intra-EU flights arriving at or departing from its territory, in a decision that is limited in time to what is strictly necessary and that is open to effective review. In view of the importance of ensuring that API data can be processed together with PNR data, that approach should be aligned with that of Directive (EU) 2016/681. For those reasons, API data on those flights should only be transmitted from the router to the relevant PIUs, where the Member States have selected the flights concerned in application of Article 2 of Directive (EU) 2016/681. As recalled by the CJEU, the selection entails Member States targeting the obligations in question only at, inter alia, certain routes, travel patterns or airports, subject to the regular review of that selection. Furthermore, the selection criteria should be relevant for the prevention, detection, investigation and prosecution of terrorist offences and se…
RemovedRecital 14 a (new): (14a) In order to comply with the requirements of the Court of Justice of the European Union (CJEU), this Regulation should lay down a common methodology for carrying out a threat assessment based on which the Member States should operate a selection of intra-EU flights. That common methodology should also help avoid divergent practices among Member States and allow for effective supervision by the national data protection authorities.
RemovedRecital 15: (15) In order to enable the application of that selective approach under this Regulation in respect of intra-EU flights, the Member States should be required to draw up and submit to eu-LISA the lists of the flights they selected, so that eu-LISA can ensure that only API data for those flights is transmitted from the router to the relevant PIUs and that the API data on other intra-EU flights is immediately and permanently deleted.
RemovedRecital 15 a (new): (15a) In order to increase cohesion among the selective approaches taken by the different Member States, the Commission should facilitate a regular exchange of views on the choice of selection criteria, including the sharing of best practices, as well as, on a voluntary basis, of selected flights.
RemovedRecital 16: (16) In order not to endanger the effectiveness of the system that relies on the collection and transfer of API data set up by this Regulation, and of PNR data under the system set up by Directive (EU) 2016/681, for the purpose of preventing, detecting, investigating and prosecuting terrorist offences and serious crime, in particular by creating the risk of circumvention, information on which intra-EU flights the Member States selected should be treated in a confidential manner. For that reason, such information should not be shared with the air carriers and they should therefore be required to collect API data on all flights covered by this Regulation, including all intra-EU flights, and then transfer it to the router, where the necessary selection should be enacted. Moreover, by collecting API data on all intra-EU flights, passengers are not made aware on which selected intra-EU flights API data, and hence also PNR data, is transmitted to the PIUs in accordance with the assessment of Member States. That approach also ensures that any changes relating to that selection can be implemented swiftly and effectively, without imposing any undue economic and operational burdens on the air carriers. Nonetheless, API data should not be collected and transferred on those flights where neither the Member State of departure nor the Member State of arrival of intra-EU flights have notified the Commission of their decision to apply Directive (EU) 2016/681 to intra-EU flights, pursuant to …
RemovedRecital 16 a (new): (16a) This Regulation does not permit the collection and transfer of API data on intra-EU flights for the purposes of combating illegal immigration, in accordance with Union law and the case law of the Court of Justice of the European Union.
RemovedRecital 17: (17) In the interest of ensuring compliance with the passengers’ fundamental right to the protection of their personal data and in line with Regulation (EU) [API border management], this Regulation should identify the controllers. In the interest of effective monitoring, ensuring adequate protection of personal data and minimising security risks, rules should also be provided for on logging, security of processing and self-monitoring. Where they relate to the processing of personal data, those provisions should be understood as complementing the generally applicable acts of Union law on the protection of personal data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council30 , Directive (EU) 2016/680 of the European Parliament and the Council31 and Regulation (EU) 2018/1725 of the European Parliament and the Council32 . Those acts, which also apply to the processing of personal data under this Regulation in accordance with the provisions thereof, should not be affected by this Regulation.
RemovedRecital 17 a (new): (17a) Taking into account the right of passengers to be informed of the processing of their personal data, Member States should ensure that passengers are provided with accurate information about the collection of API data, the transfer of that data to the PIU and their rights as data subjects that is easily accessible and easy to understand, at the moment of the flight booking and at the moment of check-in. .
RemovedRecital 17 b (new): (17b) In order to ensure compliance with the fundamental right to the protection of personal data, this Regulation should also set out rules on audits. The audits that Member States are responsible for should be carried out by the supervisory authorities referred to in Article 41 of Directive (EU) 2016/680 or by an auditing body entrusted with this task by the supervisory authority.
RemovedRecital 17 c (new): (17c) In order to avoid that air carriers have to establish and maintain multiple connections with PIUs for the transfer of API data and PNR data, and to avoid the related inefficiencies and security risks, provision should be made for a single router, created and operated at the Union level, that should serve as a connection, filter and distribution point for those transfers. In the interest of efficiency and cost effectiveness, the router should, to the extent technically possible and in full respect of the rules of this Regulation and Regulation (EU) [API border management], rely on technical components from other relevant systems created under Union law, in particular the web service referred to in Regulation (EU) 2017/2226, the carrier gateway referred to in Regulation (EU) 2018/1240 and the carrier gateway referred to in Regulation (EC) 767/2008. In order to reduce the impact on air carriers and ensure a harmonised approach towards air carriers, eu-LISA should design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations put on air carriers by Regulation (EU) 2017/2226, Regulation (EU) 2018/1240 and Regulation (EC) 767/2008.
RemovedRecital 17 d (new): (17d) Furthermore, in order to provide for the same level of clarity and certainty, the provisions related to the router, security and support tasks by the eu-LISA should be mirrored in this Regulation and Regulation (EU) [API border management].
RemovedRecital 17 e (new): (17e) The router should serve only to facilitate the transmission of API data from the air carriers to the PIUs in accordance with this Regulation, and should not be a repository of API data. Therefore, and in order to minimise any risk of unauthorised access or other misuse and in accordance with the principle of data minimisation, no storage should take place unless strictly necessary for technical purposes related to the transmission and the API data should be deleted from the router, immediately, permanently and in an automated manner, from the moment that the transmission has been completed.
RemovedRecital 17 f (new): (17f) With a view to ensuring the proper functioning of the transmission of API data from router, the Commission should be empowered to lay down detailed technical and procedural rules on that transmission. Those rules should be such as to ensure that the transmission is secure, effective and swift and impacts passengers’ travel rights and air carriers no more than necessary.
RemovedRecital 18: (18) The router to be created and operated under this Regulation and Regulation (EU) [API border management] should reduce and simplify the technical connections needed to transfer API data and PNR data, limiting them to a single connection per air carrier and per PIU. Therefore, this Regulation provides for the obligation for the PIUs and air carriers to each establish such a connection to, and achieve the required integration with, the router, so as to ensure that the system for transferring API data established by this Regulation can function properly. The design and development of the router by eu-LISA should enable the effective and efficient connection and integration of air carriers’ systems and infrastructure by providing for all relevant standards and technical requirements. To ensure the proper functioning of the system set up by this Regulation, detailed rules should be provided. When designing and developing the router, eu-LISA should ensure that API data transferred by air carriers and transmitted to PIUs is encrypted in transit.
RemovedRecital 19: (19) In view of the Union interests at stake, the costs incurred by the European Data Protection Supervisor and eu-LISA for the performance of its tasks under this Regulation in respect of the router should be borne by the Union budget. The same should go for appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router and costs related to the maintenance of those connections as required under this Regulation, should be borne by the Union budget, in accordance with the applicable legislation and subject to certain exceptions. The costs covered by those exceptions should be borne by each Member State concerned itself. The Union budget should also cover the support, such as training, by eu-LISA to air carriers and PIUs to enable effective transfer and transmission of API data through the router. The costs incurred by the independent national supervisory authorities in relation to the tasks entrusted to them under this Regulation shall also be borne by the respective Member States.
RemovedRecital 20: deleted
RemovedRecital 20 a (new): (20a) In order to allow both the air carriers and the PIUs to make the most efficient use of their connections to the router, to prevent any duplication of passenger data transfers and processing, and to ensure compliance with the CJEU case-law and enhance the related monitoring and supervision, this Regulation should provide for the mandatory use of the router by the air carriers for transferring PNR data, and for the PIUs for receiving such data. The router should constitute the only necessary and available means for the Member States to require air carriers to comply with the obligations related to transfer of PNR data as foreseen by the PNR Directive.
RemovedRecital 21: (21) It cannot be excluded that, due to exceptional circumstances and despite all reasonable measures having been taken in accordance with this Regulation and Regulation (EU) [API border management], the router or the systems or infrastructure connecting the PIUs and the air carriers thereto fail to function properly, thus leading to a technical impossibility to use the router to transmit API data. Given the unavailability of the router and that it will generally not be reasonably possible for air carriers to transfer the API data affected by the failure in a lawful, secure, effective and swift manner through alternative means, the obligation for air carriers to transfer that API data to the router should cease to apply for as long as the technical impossibility persist. In order to minimise the duration and negative consequences thereof, the parties concerned should in such a case immediately inform each other and immediately take all necessary measures to address the technical impossibility. This arrangement should be without prejudice to the obligations under this Regulation of all parties concerned to ensure that the router and their respective systems and infrastructure function properly, as well as the fact that air carriers are subject to penalties when they fail to meet those obligations, including when they seek to rely on this arrangement where such reliance is not justified. In order to deter such abuse and to facilitate supervision and, where necessary, the imposi…
RemovedRecital 23: (23) Effective, proportionate and dissuasive penalties, including financial ones, should be provided for by Member States against those air carriers failing to meet their obligations regarding the collection and transfer of API and PNR data under this Regulation.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 26 September 2026
Cite as
European Parliament (2024). “Changes between A-9-2023-0411 and TA-9-2024-0377”. Text, 25 April 2024. from A-9-2023-0411, to TA-9-2024-0377. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0411/compare/TA-9-2024-0377?all=1 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-25,
author = {{European Parliament}},
title = {{Changes between A-9-2023-0411 and TA-9-2024-0377}},
year = {2024},
date = {2024-04-25},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0411/compare/TA-9-2024-0377?all=1}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0411/compare/TA-9-2024-0377?all=1},
urldate = {2026-09-26},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2023-0411, to TA-9-2024-0377. Data: European Parliament Open Data (CC BY 4.0)}
}