Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
LIBE-PR-750252 → A-9-2023-0409
- From
- LIBE-PR-750252 report parliamentary committee draft of 5 Jul 2023
- To
- A-9-2023-0409 Plenary report of 7 Dec 2023
- Changes
- 31 changes to the text
- Paragraphs
- +96 added · −26 removed · 18 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
Changes that matter, 31
Changes to the text in document order — the ones the change notes describe. Cover page, renumbering and punctuation-only edits are left out (see “Every difference”); changes to citations and references stay in and are marked as formal in the notes.
Change 1
RemovedRecital 2: (2) The use of passenger data and flight information transferred ahead of the arrival of passengers, known as advance passenger information (‘API’) data, contributes to speeding up the process of carrying out the required checks during the border-crossing process. For the purposes of this Regulation that process concerns, more specifically, the crossing of borders between a third country or a Member State not participating in this Regulation, on the one hand, and a Member State participating in this Regulation, on the other hand. Such use strengthens checks at those external borders by providing sufficient time to enable detailed and comprehensive checks to be carried out on all passengers, without having a disproportionate negative effect on persons travelling in good faith. Therefore, in the interest of the effectiveness and efficiency of checks at external borders, an appropriate legal framework should be provided for to ensure that Member States’ competent border authorities at such external border crossing points have access to API data prior to the arrival of passengers.
AddedRecital 1: (1) The carrying-out of checks of persons at the external borders significantly contributes to guaranteeing the long-term security of the Union, Member States and its citizens and, as such, remains an important safeguard, especially in the area without internal border control (‘the Schengen area’). Border checks should be carried out according to in particular, Regulation (EU) 2016/399 of the European Parliament and of the Council32 where applicable, in order to help combat illegal immigration and prevent threats to the Member States’ internal security, public policy, public health and international relations. Such border checks should be carried out in such a way as to fully respect human dignity and be in full compliance with relevant Union law, including the Charter of Fundamental Rights of the European Union (‘the Charter’).
RemovedRecital 7: (7) In order to achieve its objectives, this Regulation should apply to all commercial carriers conducting flights into the Union, as defined in this Regulation, covering both scheduled and non-scheduled flights, irrespective of the place of establishment of the air carriers conducting those flights. General aviation such as flight schools, military or medical flights, should be exempted from this Regulation.
AddedRecital 2: (2) The use of passenger data and flight information transferred ahead of the arrival of passengers, known as advance passenger information (‘API’) data, contributes to speeding up the process of carrying out the required checks during the border-crossing process. For the purposes of this Regulation that process concerns, more specifically, the crossing of borders between a third country or a Member State not participating in this Regulation, and, a Member State participating in this Regulation. Such use strengthens checks at those external borders by providing sufficient time to enable detailed and comprehensive checks to be carried out on all passengers, without having a disproportionate negative effect on persons travelling in good faith. Therefore, in the interest of the effectiveness and efficiency of checks at external borders, an appropriate legal framework should be provided for to ensure that Member States’ competent border authorities at such external border crossing points have access to API data prior to the arrival of passengers.
RemovedRecital 7 a (new): (7a) For transit passengers whose initial point of departure and final destination are outside of the territory of the Member States participating in this Regulation, and who therefore will not cross the external borders, air carriers should not be under the obligation to transfer API data.
AddedRecital 3: (3) The existing legal framework on API data, which consists of Council Directive 2004/82/EC33 and national law transposing that Directive, has proven important in improving border checks, in particular by setting up a framework for Member States to introduce provisions for laying down obligations on air carriers to transfer API data on passengers transported into their territory. However, divergences remain at national level. In particular, API data is not systematically requested from air carriers and air carriers are faced with different requirements regarding the type of information to be collected and the conditions under which the API data needs to be transferred to competent border authorities. Those divergences lead not only to unnecessary costs and complications for the air carriers, but they are also prejudicial to ensuring effective and efficient pre-checks of persons arriving at external borders.
Change 2
ChangedRecital 8:5: (8)(5) In the interest of effectiveness andorder legalto certainty,ensure thea itemsconsistent ofapproach informationat thatboth jointlyunion constituteand theinternational APIlevel dataas tomuch beas collectedpossible and subsequently transferred under this Regulation should bein listedview clearlyof andthe exhaustively,rules coveringon boththe informationcollection relatingof toAPI eachdata passengerapplicable andat informationthat onlevel, the flightupdated oflegal thatframework passenger.established Suchby flightthis informationRegulation should covertake informationinto onaccount the border crossing point of entryrelevant intopractices theinternationally territoryagreed ofwith the Memberair Stateindustry, concernedspecifically in allthe casescontext coveredof bythe thisWorld Regulation,Customs butOrganisation, thatInternational informationAviation shouldTransport beAssociation collectedand onlyInternational whereCivil applicableAviation underOrganisation Regulation(ICAO) (EU)Guidelines [APIon lawAdvance enforcement].Passenger Information.
Change 3
RemovedRecital 10: (10) The passenger should be enabled to provide certain API data themselves during an online check-in process, either manually or by using automated means. Such means could, for example, include a secure app on a passengers’ smartphone, computer or webcam with the capability to read the machine-readable data of the travel document. Where the passenger did not check-in online, air carriers should in practice provide them with the possibility to provide the machine-readable API data concerned during check-in at the airport with the assistance of a self-service kiosk or of airline staff at the counter. This provision of data by the passenger should be made possible at no cost to the passenger.
AddedRecital 6: (6) The collection and transfer of API data affects the privacy of individuals and entails the processing of their personal data. In order to fully respect their fundamental rights, in particular the right of respect for private life and the right to the protection of personal data, in accordance with the Charter, adequate limits and safeguards should be provided for. In particular, any processing of API data and, in particular, API data constituting personal data, should remain strictly limited to what is necessary for and proportionate to achieving the objectives pursued by this Regulation. In addition, it should be ensured that the processing of any API data collected and transferred under this Regulation do not lead to any form of discrimination precluded by the Charter.
RemovedRecital 13: (13) In view of ensuring that the pre-checks carried out in advance by competent border authorities are effective and efficient, the API data transferred to those authorities should contain data of passengers that are effectively set to cross the external borders, that is, of passengers that are effectively on board of the aircraft. Therefore, the air carriers should transfer API data directly after flight closure. Moreover, API data helps the competent border authorities to distinguish legitimate passengers from passengers who may be of interest and therefore may require additional verifications, which would necessitate further coordination and preparation of follow-up measures to be taken upon arrival. That could occur, for example, in cases of unexpected number of passengers of interest whose physical checks at the borders could adversely affect the border checks and waiting times at the borders of other legitimate passengers. To provide the competent border authorities with an opportunity to prepare adequate and proportionate measures at the border, such as temporarily reinforcing or reaffecting staff, particularly for flights where the time between the flight closure and the arrival at the external borders is insufficient to allow the competent border authorities to prepare the most appropriate response, API data should also be transmitted prior to boarding, at the moment of check-in of each passenger. In order to reduce the impact on air carriers, and with a view to cre…
AddedRecital 7: (7) In order to achieve its objectives, this Regulation should apply to all commercial air carriers conducting flights into the Union, as defined in this Regulation, covering both scheduled and non-scheduled flights, irrespective of the place of establishment of the air carriers conducting those flights. In accordance with the relevant ICAO classifications, general aviation such as flight schools, military or medical flights, should be exempted from this Regulation;
RemovedRecital 13 a (new): (13a) In order to enhance data quality, the router should verify whether the API data transferred to it by the air carriers comply with the supported data formats. Where the router has verified that the data are not compliant with the supported data formats, the router should, immediately and in an automated manner, notify the air carrier concerned.
AddedRecital 8: (8) In the interest of effectiveness and legal certainty, the items of information that jointly constitute the API data to be collected and subsequently transferred under this Regulation should be listed clearly and exhaustively, covering both information relating to each passenger and information on the flight taken by that passenger. Such flight information should cover information on the border crossing point of entry into the territory of the Member State concerned in all cases covered by this Regulation.
Show 28 more lines
RemovedRecital 16: (16) To ensure that competent border authorities have sufficient time to carry out pre-checks effectively on all passengers, including passengers on long-haul flights and those travelling on connecting flights, as well as sufficient time to ensure that the API data collected and transferred by the air carriers is complete, accurate and up-to-date, and where necessary to request additional clarifications, corrections or completions from the air carriers, the competent border authorities should store the API data that they received under this Regulation for a fixed time period that remains limited to what is strictly necessary for those purposes. Similarly, to be able to respond to such requests, air carriers should store the API data that they transferred under this Regulation for the same fixed and strictly necessary time period.
AddedRecital 9: (9) In order to allow for flexibility and innovation, it should in principle be left to each air carrier to determine how it meets its obligations regarding the collection of API data set out in this Regulation. However, considering that suitable technological solutions exist that allow collecting certain API data automatically while guaranteeing that the API data concerned is accurate, complete and up-to-date, and having regard the advantages of the use of such technology in terms of effectiveness and efficiency, air carriers should be required to collect the API data using automated means, specifically by reading information from the machine-readable data of the travel document. Where the use of such automated means is however not possible, air carriers should collect the API data manually, either as part of the online check-in process, or as part of the check-in at the airport, in such a manner as to ensure compliance with their obligations under this Regulation.
RemovedRecital 19: (19) The router should serve only to facilitate the transmission of API data from the air carriers to the competent border authorities in accordance with this Regulation and to PIUs in accordance with Regulation (EU) [API law enforcement], and should not be a repository of API data. Therefore, and in order to minimise any risk of unauthorised access or other misuse and in accordance with the principle of data minimisation, any storage of the API data on the router should remain limited to what is strictly necessary for technical purposes related to the transmission and the API data should be deleted from the router, immediately, permanently and in an automated manner, from the moment that the transmission has been completed.
AddedRecital 9 a (new): (9a) The collection of API data by automated means should be limited to the alphanumerical data contained in the travel document and should not lead to the collection of any biometric data from it.
RemovedRecital 23: (23) In view of the Union interests at stake, the costs incurred by the European Data Protection Supervisor and eu-LISA for the performance of its tasks under this Regulation and Regulation (EU) [API law enforcement] should be borne by the Union budget. The same should go for appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router, as required under this Regulation and in accordance with the applicable legislation, subject to certain exceptions. The costs covered by those exceptions should be borne by each Member State concerned itself. The costs incurred by the independent national supervisory authorities in relation to the tasks entrusted to them under this Regulation and Regulation (EU) [API law enforcement] shall be borne by the respective Member States as well.
AddedRecital 9 b (new): (9b) The requirements set out by this Regulation and by the corresponding delegated and implementing acts should lead to a uniform implementation by the airlines, thereby minimizing the cost of the interconnection of their respective systems. To facilitate a harmonized implementation of those requirements by the airlines, in particular as regards the data structure, format and transmission protocol, the Commission, based on its cooperation with the competent border authorities, other Member States authorities, air carriers, and relevant Union agencies, should ensure that the practical handbook to be prepared by the Commission provides all the necessary guidance and clarifications.
AddedRecital 9 c (new): (9c) In order to enhance data quality, the router should verify whether the API data transferred to it by the air carriers comply with the supported data formats. Where the router has verified that the data are not compliant with the supported data formats, the router should, immediately and in an automated manner, notify the air carrier concerned.
AddedRecital 9 d (new): (9d) The automatic data collection systems and other processes established under this Regulation should not negatively impact the employees in the aviation industry, who should benefit from upskilling and reskilling opportunities that would increase the efficiency and reliability of data collection and transfer as well as the working conditions in the sector.
AddedRecital 10: (10) The passenger should be enabled to provide certain API data themselves during an online check-in process, in accordance with Article 5. Such means could, for example, include a secure app on a passengers’ smartphone, computer or webcam with the capability to read the machine-readable data of the travel document. Where the passengers did not check-in online, air carriers should provide them with the possibility to provide the required machine-readable API data concerned during check-in at the airport with the assistance of a self-service kiosk or of airline staff at the counter. The Commission should ensure that the obligations under this Regulation do not lead to disproportionate obstacles for passengers unable to use online means for automated check-in, such as additional airport check-in fees.
AddedRecital 10 a (new): (10a) With a view to guaranteeing the fulfilment of the rights provided for under the Charter and to ensuring accessible and inclusive travel options, especially for vulnerable groups and persons with disabilities, air carriers, supported by the Member States, should ensure that an offline alternative for the check-in and for the provision of the necessary data by the passengers is possible at all times.
AddedRecital 11: (11) The Commission should be empowered to adopt technical requirements and procedural rules that air carriers should to comply with regarding the use of automated means for the collection of machine-readable API data under this Regulation, so as to increase clarity and legal certainty and contribute to ensuring data quality and the responsible use of the automated means.
AddedRecital 13: (13) In view of ensuring that the pre-checks carried out in advance by competent border authorities are effective and efficient, the API data transferred to those authorities should contain data of passengers that are effectively set to cross the external borders, that is, of passengers that are effectively on board of the aircraft. Therefore, the air carriers should transfer API data directly after flight closure. Moreover, API data helps the competent border authorities to distinguish legitimate passengers from passengers who may be of interest and therefore may require additional verifications, which would necessitate further coordination and preparation of follow-up measures to be taken upon arrival. That could occur, for example, in cases of unexpected number of passengers of interest whose physical checks at the borders could adversely affect the border checks and waiting times at the borders of other legitimate passengers. To provide the competent border authorities with an opportunity to prepare adequate and proportionate measures at the border, such as temporarily reinforcing or reaffecting staff, particularly for flights where the time between the flight closure and the arrival at the external borders is insufficient to allow the competent border authorities to prepare the most appropriate response, API data should also be transmitted prior to boarding, at the moment of check-in of each passenger.
AddedRecital 15: (15) In order to avoid any risk of misuse and in line with the principle of purpose limitation, the competent border authorities should be expressly precluded from processing the API data that they receive under this Regulation for any other purpose than those explicitly provided for in this Regulation.
AddedRecital 16: (16) To ensure that competent border authorities have sufficient time to carry out pre-checks effectively on all passengers, including passengers on long-haul flights and those travelling on connecting flights, as well as sufficient time to ensure that the API data collected and transferred by the air carriers is complete, accurate and up-to-date, and where necessary to request additional clarifications, corrections or completions from the air carriers, the competent border authorities should store the API data that they received under this Regulation for a fixed time period that remains limited to what is strictly necessary for those purposes. Similarly, to be able to respond to such requests, air carriers should store the API data that they transferred under this Regulation for the same fixed and strictly necessary time period. Beyond that, and with a view to enhance the travel experience of legitimate passengers, air carriers should be able to retain and use the API data where necessary for the normal course of their business in particular for travel facilitation, in compliance with the applicable law and in particular Regulation (EU) 2016/679.
AddedRecital 17: (17) In order to avoid that air carriers have to establish and maintain multiple connections with the competent border authorities of the Member States’ for the transfer of API data collected under this Regulation and the related inefficiencies and security risks, provision should be made for a single router, created and operated at Union level, that serves as a connection and distribution point for those transfers. In the interest of efficiency and cost effectiveness, the router should, to the extent technically possible and in full respect of the rules of this Regulation and Regulation (EU) [API law enforcement], rely on technical components from other relevant systems created under Union law, in particular the web service referred to in Regulation (EU) 2017/2226, the carrier gateway referred to in Regulation (EU) 2018/1240 and the carrier gateway referred to in Regulation (EC) 767/2008. In order to reduce the impact on air carriers and ensure a harmonised approach towards air carriers, eu-LISA should design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations put on air carriers by Regulation (EU) 2017/2226, Regulation (EU) 2018/1240 and Regulation (EC) 767/2008.
AddedRecital 17 a (new): (17a) In order to provide for the same level of clarity and certainty, the provisions related to the router, security and support tasks by eu-LISA should be mirrored in this Regulation and Regulation (EU) [API law enforcement], as eu-LISA should build and maintain only one router for the purposes of both Regulations.
AddedRecital 19: (19) The router should serve only to facilitate the transmission of API data from the air carriers to the competent border authorities in accordance with this Regulation, and should not be a repository of API data. Therefore, and in order to minimise any risk of unauthorised access or other misuse and in accordance with the principle of data minimisation, no storage should take place unless strictly necessary for technical purposes related to the transmission and the API data should be deleted from the router, immediately, permanently and in an automated manner, from the moment that the transmission has been completed.
AddedRecital 20: (20) With a view to ensuring the proper functioning of the transmission of API data from router, the Commission should be empowered to lay down detailed technical and procedural rules on that transmission. Those rules should be such as to ensure that the transmission is secure, effective and swift and impacts passengers’ travel rights and air carriers no more than necessary.
AddedRecital 22: (22) The router to be created and operated under this Regulation and Regulation (EU) [API Law Enforcement] should reduce and simplify the technical connections needed to transfer API data, limiting them to a single connection per air carrier and per competent border authority. Therefore, this Regulation provides for the obligation for the competent border authorities and air carriers to each establish such a connection to, and achieve the required integration with, the router, so as to ensure that the system for transferring API data established by this Regulation can function properly. The design and development of the router by eu-LISA should enable the effective and efficient connection and integration of air carriers’ systems and infrastructure by providing for all relevant standards and technical requirements. To ensure the proper functioning of the system set up by this Regulation, detailed rules should be provided. When designing and developing the router, eu-LISA should ensure that API data transferred by air carriers and transmitted to competent border authorities is encrypted in transit.
AddedRecital 23: (23) In view of the Union interests at stake, the costs incurred by the European Data Protection Supervisor and eu-LISA for the performance of its tasks under this Regulation in respect of the router should be borne by the Union budget. The same should go for appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router and costs related to the maintenance of those connections, as required under this Regulation and in accordance with the applicable legislation, subject to certain exceptions. The costs covered by those exceptions should be borne by each Member State concerned itself. The Union budget should also cover the support, such as training, by eu-LISA to air carriers and border authorities to enable effective transfer and transmission of API data through the router. The costs incurred by the independent national supervisory authorities in relation to the tasks entrusted to them under this Regulation shall be borne by the respective Member States as well.
AddedRecital 25: (25) In the interest of ensuring compliance with the fundamental right of the passengers to the protection of their personal data, this Regulation should identify the controller and processor and set out rules on audits. In the interest of effective monitoring, ensuring adequate protection of personal data and minimising security risks, rules should also be provided for on logging, security of processing and self-monitoring. Where they relate to the processing of personal data, those provisions should be understood as complementing the generally applicable acts of Union law on the protection of personal data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council34 and Regulation (EU) 2018/1725 of the European Parliament and the Council.35 Those acts, which also apply to the processing of personal data under this Regulation in accordance with the provisions thereof, should not be affected by this Regulation.
AddedRecital 25 a (new): (25a) Taking into account the right of passengers to be informed of the processing of their personal data, Member States should ensure that passengers are provided with accurate information about the collection of API data, the transfer of that data to the competent border authorities and their rights as data subjects that is easily accessible and easy to understand, at the moment of booking and at the moment of check-in .
AddedRecital 28 a (new): (28a) When providing for the penalties applicable to air carriers under this Regulation, Member States should take into account the technical and operational feasibility of ensuring complete data accuracy. Additionally, when penalties are imposed, their application and value should be established taking into consideration the actions undertaken by the air carrier to mitigate the issue as well as its level of cooperation with national authorities.
AddedRecital 30: (30) As the router should be designed, developed, hosted and technically managed by the eu-LISA, established by Regulation (EU) 2018/1726 of the European Parliament and of the Council36 , it is necessary to amend that Regulation by adding that task to the tasks of eu-LISA. In order to store reports and statistics of the router on the Central Repository for Reporting and Statistics it is necessary to amend Regulation (EU) 2019/817 of the European Parliament and of the Council37. The Central Repository for Reporting and Statistics should only provide statistics based on API data for the implementation and effective supervision of this Regulation. The data that the router automatically transmits to the Common Repository for Reporting and Statistics to that end should not allow for the identification of the passengers concerned.
AddedRecital 31: (31) In order to adopt measures relating to the technical requirements and operational rules for the automated means for the collection of machine-readable API data, to the common protocols and formats to be used for the transfer of API data by air carriers, to the technical and procedural rules for the transmission of API data from the router to the competent border authorities and to the PIUs and to the PIU’s and air carriers’ connections to and integration with the router, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of Articles 5, 6, 11, 20 and 21 respectively. It is of particular importance that the Commission carry out appropriate consultations with relevant stakeholders, including air carriers, during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement on Better Law-Making of 13 April 201638 . In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts. Taking into account the state of the art, these technical requirements and rules might change over time.
AddedRecital 31 a (new): (31a) It is important to collect reliable and useful statistics based on the implementation of this Regulation in order to support its objectives and inform the evaluations under this Regulation. Such statistics should not contain any personally identifiable data. All relevant stakeholders, including relevant Member State authorities, Europol and, where appropriate, air carriers, should have access to those statistics.
AddedRecital 34 a (new): (34a) This Regulation should be subject to regular evaluations to ensure the monitoring of its effective application. In particular, the collection of API data should not be to the detriment of the travel experience of legitimate passengers. Therefore, the Commission should include in its regular evaluation reports on the application of this Regulation an assessment of the impact of this Regulation on the travel experience of legitimate passengers.
AddedRecital 34 b (new): (34b) Given that this Regulation requires additional adjustment and administrative costs by the air carriers, the overall regulatory burden for the aviation sector should be kept under close review. Against this backdrop, the report evaluating the functioning of this Regulation should assess the extent to which the objectives of the Regulation have been met and to which extent it has impacted the competitiveness of the sector. Therefore, the Commission’s report should also conduct a holistic assessment and refer to the interaction of this Regulation with other relevant Union legislative acts, in particular Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008. The report should assess the overall impact of related reporting obligations on air carriers, identifying provisions that could be updated and simplified, where appropriate, to mitigate the burden on air carriers, as well as actions and measures that have been or could be taken to reduce the total cost pressure on the aviation sector.
Change 4
RemovedArticle 2 – paragraph 1: This Regulation applies to air carriers conducting scheduled or non-scheduled flights into the Union. General aviation shall be exempted from this Regulation.
AddedArticle 1 – paragraph 1 – subparagraph 1 a (new): This Regulation is without prejudice to Regulations (EU) 2016/679 and (EU) 2018/1725.
RemovedArticle 3 – paragraph 1 – point a: (a) ‘air carrier’ means an air transport undertaking as defined in Article 3, point 1, of Directive (EU) 2016/681, other than air transport undertakings performing general aviation operations;
RemovedArticle 3 – paragraph 1 – point a a (new): (aa) 'general aviation' means all civil aviation operations other than scheduled air services and non-scheduled air transport operations for remuneration or hire as defined in the classification of the International Civil Aviation Organization (ICAO);
Change 5
ChangedArticle 3 – paragraph 1 – point h: (h) (h) ‘passenger’ means any person,excludingperson, excluding members of the crew unless they are off duty, carried or to be carried in an aircraft with the consent of the air carrier, such consent being manifested by that person's registration in the passengers list;
Change 6
AddedArticle 3 – paragraph 1 – point l: (l) ‘Passenger Information Unit’ or ‘PIU’ means the competent authority referred to in Article 3, point k, of Regulation (EU) [API law enforcement];
Change 7
ChangedArticle 4 – paragraph 2 – introductory part: 2. The API data shall consist of only of the following passenger data relating to each passenger on the flight:
Change 8
ChangedArticle 4 – paragraph 3 – point a: (a) the flight identification number or, where the flight is code-shared between one or more air carriers, the,the flightsflight identification numbers, oror, if no such number exists, other clear and suitable means to identify the flight;
Show 23 more changes
Change 9
ChangedArticle 5 – paragraph 21 – subparagraph 1:1 Aira carriers(new): shallThe collectcollection theof API data referred toin Articleaccordance 4(2),with pointsthe (a)first tosubparagraph (d),shall usingnot automatedinclude meansan toobligation collectfor theair machine-readablecarriers datato ofcheck the travel document ofat the passengermoment concerned.of Theyboarding shallthe doaircraft soor inan accordanceobligation withfor thepassengers detailedto technicalcarry requirementsa andtravel operationaldocument ruleswhen referredtravelling, towithout inprejudice paragraphto 4,acts whereof suchnational ruleslaw havethat beenare adoptedcompatible andwith areUnion applicable.law.
Change 10
ChangedArticle 5 – paragraph 2 – subparagraph 11: aAir (new):carriers Whereshall aircollect the API data referred to in Article 4(2), points (a) to (d), using automated means to collect the machine-readable data of the travel document of the passenger concerned. Air carriers provideshall ancollect onlinethat data during the check-in process, theyeither as part of the online check-in or as part of the check-in at the airport. They shall enabledo passengersso toin provideaccordance with the APIdetailed datatechnical requirements and operational rules referred to in Articleparagraph 4(2),4, pointsonce (a)such rules have been adopted and are applicable, and, in particular, by using the most reliable automated means available to (d)collect duringthe machine-readable data of the onlinerespective check-intravel process.document.
Change 11
RemovedArticle 6 – paragraph 1: 1. Air carriers shall transfer the encrypted API data to the router by electronic means. They shall do so in accordance with the detailed rules referred to in paragraph 3, where such rules have been adopted and are applicable.
AddedArticle 5 – paragraph 2 – subparagraph 1 a (new): The collection of API data by automated means shall not lead to the collection of any biometric data from the travel document.
RemovedArticle 6 – paragraph 2: 2. Air carriers shall transfer the API data both at the moment of check-in and immediately after flight closure, that is, once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for passengers to board or to leave the aircraft. At the moment of check-in, air carriers shall transfer the API data by way of interactive API in accordance with international standards. Where an air carrier transfers the API data by way of interactive API, it shall receive a meaningful reply in accordance with Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008.
AddedArticle 5 – paragraph 2 – subparagraph 1 b (new): Where air carriers provide an online check-in process, they shall enable passengers to provide the API data referred to in Article 4(2), points (a) to (d), during the online check-in process, using automated means.
RemovedArticle 6 – paragraph 3: 3. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the common protocols and supported data formats to be used for the encrypted transfers of API data to the router referred to in paragraph 1.
AddedArticle 5 – paragraph 2 – subparagraph 2: However, where such use of automated means is not possible, air carriers shall collect that data manually either as part of the online check-in or as part of the check-in at the airport, in such a manner as to ensure compliance with paragraph 1.
Change 12
ChangedArticle 85 – paragraph 1: 1. Air3: carriers3. shallAny store,automated formeans aused timeby periodair ofcarriers 24to hourscollect fromAPI thedata momentunder ofthis departureRegulation ofshall thebe flight,reliable, thesecure APIand dataup-to-date. relatingAir tocarriers thatshall passengerensure that they collected pursuant to Article 4.API Theydata shallis immediatelyencrypted andduring permanentlythe deletetransmission thatof APIthe data afterfrom the expirypassenger ofto thatthe timeair period.carriers.
Change 13
AddedArticle 5 – paragraph 4: 4. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down detailed technical requirements and operational rules for the collection of the API data referred to in Article 4(2), points (a) to (d), using automated means in accordance with paragraph 2 and 3 of this Article, including on requirements for data security.
AddedArticle 6 – paragraph 1: 1. Air carriers shall transfer the encrypted API data to the router by electronic means. They shall do so in accordance with the detailed rules referred to in paragraph 3, once such rules have been adopted and are applicable.
AddedArticle 6 – paragraph 2: 2. Air carriers shall transfer the API data both at the moment of check-in and immediately after flight closure, that is, once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for passengers to board or to leave the aircraft. At the moment of check-in, air carriers shall transfer the API data in accordance with this Regulation and relevant international standards. Air carriers shall receive an acknowledgement of receipt of the transfer of the API data.
AddedArticle 6 – paragraph 3: 3. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the common protocols and supported data formats to be used for the encrypted transfers of API data to the router referred to in paragraph 1, including the transfer of API data at the moment of check-in, the meaningful reply and requirements for data security. Such detailed rules shall ensure that airlines transmit API data using the same structure and content.
AddedArticle 6 – paragraph 4: deleted
AddedArticle 7 – paragraph 1 a (new): The competent border authorities shall be prohibited from processing API data for the purposes of profiling under any circumstances.
Show 1 more line
AddedArticle 8 – paragraph 1: 1. Air carriers shall store, for a time period of 24 hours from the moment of departure of the flight, the API data relating to that passenger that they collected pursuant to Article 4. They shall immediately and permanently delete that API data after the expiry of that time period. This shall be without prejudice to the possibility for air carriers to retain and use the data where necessary for the normal course of their business, in particular for travel facilitation, in compliance with the applicable law and in particular Regulation (EU) 2016/679.
Change 14
RemovedArticle 8 a (new): Article 8a / Non-discrimination and fundamental rights / Processing of personal data in accordance with this Regulation and Regulation (EU) [API law enforcement] shall not result in discrimination against data subjects on the grounds of sex, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age or sexual orientation. It shall fully respect human dignity and integrity and fundamental rights, including the right to respect for one’s private life and to the protection of personal data. Particular attention shall be paid to children, the elderly and persons with a disability. The best interests of the child shall be a primary consideration.
AddedArticle 8 – paragraph 2 a (new): 2a. Air carriers or competent border authorities shall immediately either correct, complete or update, or permanently delete, the API data concerned in both of the following situations: / (a) where they become aware that the API data collected is inaccurate, incomplete or no longer up-to-date; / (b) where the transfer of the API data in accordance with Article 5(2) has been completed.
RemovedArticle 8 b (new): Article 8b / Legal remedies / Member States shall ensure that the persons affected by the measures provided for under this Regulation have the right to an effective legal remedy in order to uphold their rights.
AddedArticle 8 – paragraph 2 b (new): 2b. Air carriers or competent border authorities shall immediately and permanently delete API data where they become aware that the API data collected was processed unlawfully or that the data transferred does not constitute API data.
RemovedArticle 9 – paragraph 2 – point b: (b) a secure communication channel between the central infrastructure and the competent border authorities and the PIUs, and a secure communication channel between the central infrastructure and the air carriers, for the transfer and transmission of API data and for any communications relating thereto.
AddedArticle 8 – paragraph 2 c (new): 2c. Where the air carriers become aware of the circumstances referred to in point (a) of paragraph 2a or paragraph 2b after having completed the transfer of the data in accordance with Article 6(1), they shall immediately inform the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA). Upon receiving such information, eu-LISA shall immediately inform the competent border authority that received the API data transmitted through the router.
Show 4 more lines
AddedArticle 8 – paragraph 3: deleted
AddedArticle 8 a (new): Article 8a / Fundamental Rights / 1. Collection and processing of personal data in accordance with this Regulation and Regulation (EU) [API law enforcement] by air carriers and competent authorities shall not result in discrimination against persons on the grounds of sex and gender, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age or sexual orientation. / 2. This Regulation shall fully respect human dignity and the fundamental rights and principles recognised by the Charter, including the right to respect for one’s private life, to asylum, to the protection of personal data, to freedom of movement and to effective legal remedies. / 3. Particular attention shall be paid to children, the elderly, persons with a disability and vulnerable persons. The best interests of the child shall be a primary consideration when implementing this Regulation.
AddedArticle 9 – paragraph 1: 1. eu-LISA shall design, develop, host and technically manage, in accordance with Articles 22 and 23, a router for the purpose of facilitating the transfer of encrypted API data by the air carriers to the competent border authorities in accordance with this Regulation.
AddedArticle 9 – paragraph 2 – point b: (b) a secure communication channel between the central infrastructure and the competent border authorities and a secure communication channel between the central infrastructure and the air carriers, for the transfer and transmission of API data and for any communications relating thereto.
Change 15
ChangedArticle 109 – paragraph 1: The router shall only be used by air carriers to transfer2 encryptedb API(new): data2b. andThe byrouter competentshall borderautomatically authoritiesextract and PIUs to receivemake encryptedavailable APIthe data,statistics, in accordance with thisArticle Regulation31, andto Regulationthe (EU)central [APIrepository lawfor enforcement],reporting respectively.and statistics.
Change 16
RemovedArticle 11 – paragraph 1 – subparagraph 1: The router shall, immediately and in an automated manner, transmit the encrypted API data, transferred to it pursuant to Article 6, to the competent border authorities of the Member State referred to in Article 4(3), point (c). It shall do so in accordance with the detailed rules referred to in paragraph 4 of this Article, where such rules have been adopted and are applicable.
AddedArticle 9 – paragraph 3: 3. Without prejudice to Article 10 of this Regulation, the router shall, if appropriate and to the extent technically possible, share and re-use the hardware and software components, of the web service referred to in Article 13 of Regulation (EU) 2017/2226 of the European Parliament and of the Council48 , the carrier gateway referred to in Article 6(2), point (k), of Regulation (EU) 2018/1240, and the carrier gateway referred to in Article 2a, point (h), of Regulation (EC) 767/2008 of the European Parliament and of the Council49 . eu-LISA shall design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations put on air carriers by Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008.
Change 17
ChangedArticle 119 – paragraph 3:3 3.a The(new): Member3a. Stateseu-LISA shall ensuredesign thatand onlydevelop the dulyrouter authorisedin anda trainedway staffthat ofany theAPI competentdata bordertransferred authoritiesfrom havethe accessair carriers to the APIrouter datain transmittedaccordance towith themArticle through6 theand router.any TheyAPI shalldata laytransmitted downfrom the necessary rulesrouter to thatthe effect.competent Thoseborder rulesauthorities shallin includeaccordance ruleswith onArticle 11 and to the creationcentral andrepository regularfor updatereporting ofand astatistics listin ofaccordance thosewith staffArticle and31(2) theirare profiles.encrypted.
Change 18
ChangedArticle 1110 – paragraph 4: 4. The Commission1: isNotwithstanding empoweredthe touse adoptof delegatedthe actsrouter in accordance with Article 37 to4b supplement(new) thisof Regulation by(EU) laying[API downlaw enforcement], the necessaryrouter detailedshall technicalonly andbe proceduralused: rules/ for(a) theby transmissionsair ofcarriers to transfer encrypted API data fromin accordance with this Regulation; / (b) by the routercompetent referredborder authorities to receive encrypted API data in paragraphaccordance 1.with this Regulation.
Change 19
RemovedArticle 12 – paragraph 1 – introductory part: API data, transferred to the router pursuant to this Regulation and Regulation (EU) [API law enforcement], shall be stored on the router only insofar as necessary to complete the transmission to the relevant competent borders authorities or PIUs, as applicable, in accordance with those Regulations and shall be deleted from the router, immediately, permanently and in an automated manner, in the following situations:
AddedArticle 10 a (new): Article 10a / Data format and transfer verifications / 1. The router shall, in an automated manner and based on real-time flight traffic data, verify whether the air carrier transferred the API data in accordance with Article 6(1). / 2. The router shall, immediately and in an automated manner, verify whether the API data transferred to it in accordance with Article 6(1) complies with the detailed rules on the supported data formats, referred to in Article 6(3). / 3. Where the router has verified in accordance with paragraph 1 that the data was not transferred by the air carrier or where the data in question is not compliant with the detailed rules referred to in paragraph 2, the router shall, immediately and in an automated manner, notify the air carrier concerned and the competent border authorities of the Member States to which the data were to be transmitted pursuant to Article 11(1). In this case, the air carrier shall immediately transfer the API data in accordance with Article 6. / 4. The Commission shall adopt implementing acts specifying the necessary detailed technical and procedural rules for the verifications and notifications referred to in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 36(2).
RemovedArticle 12 – paragraph 1 – point a a (new): (aa) in cases of technical impossibility of the router to subsequently transmit the API data to the competent national authorities, after 12 hours;
AddedArticle 11 – paragraph 1 – subparagraph 1: Upon the verifications referred to in Article 10a, the router shall, immediately and in an automated manner, transmit the encrypted API data, transferred to it pursuant to Article 6, to the competent border authorities of the Member State referred to in Article 4(3), point (c). It shall do so in accordance with the detailed rules referred to in paragraph 4 of this Article, once such rules have been adopted and are applicable.
AddedArticle 11 – paragraph 3: 3. The Member States shall ensure that only the duly authorised and trained staff of the competent border authorities, designated in accordance with paragraph 2, have access to the API data transmitted to them through the router. They shall lay down the necessary rules to that effect. Those rules shall include rules on the creation and regular update of a list of those staff and their profiles.
AddedArticle 11 – paragraph 4: 4. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed technical and procedural rules for the transmissions of encrypted API data from the router referred to in paragraph 1, including on requirements for data security.
Show 3 more lines
AddedArticle 12 – paragraph 1 – introductory part: API data, transferred to the router pursuant to this Regulation, shall be stored on the router only insofar as necessary to complete the transmission to the relevant competent borders authorities and shall be deleted from the router, immediately, permanently and in an automated manner, in both of the following situations:
AddedArticle 12 – paragraph 1 – point a: (a) where the transmission of the API data to the relevant competent border authorities has been completed;
AddedArticle 12 – paragraph 1 – point a a (new): (aa) in cases of technical impossibility of the router to subsequently transmit the API data to the competent border authorities, after 12 hours.
Change 20
ChangedArticle 13 – paragraph 1 – subparagraph 1 – introductory part: eu-LISA shall keep logs of all processing operations relating to the transfer of API data through the router under this Regulation and Regulation (EU) [API law enforcement].Regulation. Those logs shall cover:
Change 21
RemovedArticle 13 – paragraph 2: 2. Air carriers shall create logs of all processing operations under this Regulation undertaken by using the automated means referred to in Article 5(2). Those logs shall cover the date, time and place of transfer of the API data. Those logs shall not contain any personal data.
AddedArticle 13 – paragraph 1 – subparagraph 1 – point b: (b) the competent border authorities to which the API data was transmitted through the router;
Change 22
ChangedArticle 13 – paragraph 5 – subparagraph 2: However, if those logs are needed for procedures for2. monitoringAir orcarriers ensuringshall thecreate securitylogs andof integrityall ofprocessing theoperations APIunder datathis orRegulation theundertaken lawfulnessby ofusing the processing operations,automated asmeans referred to in paragraph 2, and these procedures have alreadyArticle begun5(2). atThose thelogs momentshall ofcover the expiry of thedate, time period referred to in theand firstplace subparagraph,of eu-LISAtransfer andof the air carriers shallAPI keepdata. thoseThose logs for as long as necessary for thoseshall proceduresnot aftercontain informingany andpersonal justifyingdata, itother tothan the Commission. In that case, they shallinformation immediatelynecessary deleteto thoseidentify logsthe whenrelevant theymember areof nothe longerstaff necessaryof forthe thoseair procedures.carrier.
Change 23
ChangedArticle 1913 – paragraph 1:3: 1.3. The independent supervisory authoritieslogs referred to in Articleparagraphs 511 ofand Regulation2 (EU)shall 2016/679be shallused carryonly outfor anensuring auditthe ofsecurity processingand operationsintegrity of the API data constituting personaland datathe performedlawfulness byof the competentprocessing, borderin authoritiesparticular foras regards compliance with the purposesrequirements ofset out in this Regulation, inincluding accordanceproceedings withfor relevantpenalties internationalfor auditinginfringements standards,of atthose leastrequirements oncein everyaccordance fourwith years.Articles 29 and 30 of this Regulation.
Change 24
RemovedArticle 19 – paragraph 2: 2. The European Data Protection Supervisor shall carry out an audit of processing operations of API data constituting personal data performed by eu-LISA for the purposes of this Regulation and Regulation (EU) [API law enforcement] in accordance with relevant international auditing standards at least once every year. A report of that audit shall be sent to the European Parliament, to the Council, to the Commission, to the Member States and to eu-LISA. eu-LISA shall be given an opportunity to make comments before the reports are adopted.
AddedArticle 13 – paragraph 4: 4. eu-LISA and air carriers shall take appropriate measures to protect the logs that they created pursuant to paragraphs 1 and 2, respectively, against unauthorised access and other security risks.
AddedArticle 13 – paragraph 4 a (new): 4a. The national supervisory authorities referred to in Article 29 and competent authorities shall have access to the relevant logs referred to in paragraph 1 where necessary for the purposes referred to in paragraph 3.
AddedArticle 13 – paragraph 5 – subparagraph 2: However, if those logs are needed for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations, as referred to in paragraph 2, and these procedures have already begun at the moment of the expiry of the time period referred to in the first subparagraph, eu-LISA and the air carriers may keep those logs for as long as necessary for those procedures, provided that eu-LISA or the air carriers inform the Commission of the need to keep those logs and provide reasons for doing so. In that case, they shall immediately delete those logs when they are no longer necessary for those procedures.
AddedArticle 15 – paragraph 1: The competent border authorities shall be controllers, within the meaning of Article 4, point (7), of Regulation (EU) 2016/679, in relation to the processing of API data constituting personal data through the router, including the transmission of the data from the router to the authorities and the storage for technical reasons of that data in the router, as well as in relation to their processing of API data constituting personal data referred to in Article 7 of this Regulation.
AddedArticle 16 – paragraph 1: eu-LISA shall be the processor on behalf of the competent border authorities within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the processing of API data constituting personal data through the router in accordance with this Regulation.
Show 17 more lines
AddedArticle 16 a (new): Article16a / Information to passengers / In accordance with the right of information in Article 13 of Regulation (EU) 2016/679, air carriers shall provide passengers, on flights covered by this Regulation, with information on the purpose of the collection of their personal data, the type of personal data collected, the recipients of the personal data and the means to exercise the data subject rights. / This information shall be communicated to passengers in writing and in an easily accessible format at the moment of booking and at the moment of check-in, irrespective of the means used to collect the personal data at the moment of check-in in accordance with Article 5.
AddedArticle 17 – paragraph -1 (new): -1. Competent border authorities and air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation.
AddedArticle 17 – paragraph -1 a (new): -1a. Competent border authorities and air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other and with eu-LISA to ensure such security.
AddedArticle 17 – paragraph 1: 1. eu-LISA shall ensure the security and encryption of the API data, in particular API data constituting personal data, that it processes pursuant to this Regulation. The competent border authorities and the air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation. eu-LISA, the competent border authorities and the air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other to ensure such security.
AddedArticle 17 – paragraph 2 – subparagraph 1 – point c: (c) ensure that it is possible to verify and establish to which competent border authorities the API data is transmitted through the router;
AddedArticle 18 – paragraph 1: The air carriers and competent authorities shall monitor their compliance with their respective obligations under this Regulation, in particular as regards their processing of API data constituting personal data, including through frequent verification of the logs in accordance with Article 13.
AddedArticle 19 – paragraph 1: 1. The independent supervisory authorities referred to in Article 51 of Regulation (EU) 2016/679 shall ensure that an audit of processing operations of API data constituting personal data performed by the competent border authorities for the purposes of this Regulation is carried out, in accordance with relevant international auditing standards, at least once every four years.
AddedArticle 19 – paragraph 2: 2. The European Data Protection Supervisor shall carry out an audit of processing operations of API data constituting personal data performed by eu-LISA for the purposes of this Regulation, in accordance with relevant international auditing standards at least once every year. A report of that audit shall be sent to the European Parliament, to the Council, to the Commission, to the Member States and to eu-LISA. eu-LISA shall be given an opportunity to make comments before the reports are adopted.
AddedArticle 20 – paragraph 1 – subparagraph 1: Member States shall ensure that their competent border authorities are connected to the router. They shall ensure that the competent border authorities’ systems and infrastructure for the reception of API data transferred pursuant to this Regulation are integrated with the router.
AddedArticle 20 – paragraph 2: 2. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the connections to and integration with the router referred to in paragraph 1, including on requirements for data security.
AddedArticle 21 – paragraph 2: 2. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the connections to and integration with the router referred to in paragraph 1, including on requirements for data security.
AddedArticle 22 – paragraph 3: 3. eu-LISA shall ensure that the router is designed and developed in such a manner that the router provides the functionalities specified in this Regulation, and that the router starts operations as soon as possible after the adoption by the Commission of the delegated acts provided for in Article 5(4), Article 6(3), Article 11(4), Article 20(2) and Article 21(2) and after the carrying out of a data protection impact assessment in accordance with Article 35 of Regulation (EU) 2016/679.
AddedArticle 22 – paragraph 4: 4. Where eu-LISA considers that the development phase has been completed, it shall, without undue delay, conduct a comprehensive test of the router, in cooperation with the competent border authorities and other relevant Member States’ authorities and air carriers and inform the Commission of the outcome of that test.
AddedArticle 23 – paragraph 2 – subparagraph 1: eu-LISA shall be responsible for the technical management of the router, including its maintenance and technical developments, in such a manner as to ensure that the API data are securely, effectively and swiftly transmitted through the router, in compliance with this Regulation.
AddedArticle 23 – paragraph 2 – subparagraph 2: The technical management of the router shall consist of carrying out all the tasks and enacting all technical solutions necessary for the proper functioning of the router in accordance with this Regulation in an uninterrupted manner, 24 hours a day, 7 days a week. It shall include the maintenance work and technical developments necessary to ensure that the router functions at a satisfactory level of technical quality, in particular as regards availability, accuracy and reliability of the transmission of API data, in accordance with the technical specifications and, as much as possible, in line with the operational needs of the competent border authorities and air carriers.
AddedArticle 24 – paragraph 1: 1. eu-LISA shall, upon their request, provide training to competent border authorities and other relevant Member States’ authorities and air carriers on the technical use of the router and on the connection and integration to the router.
AddedArticle 24 – paragraph 2: 2. eu-LISA shall provide support to the competent border authorities regarding the reception of API data through the router pursuant to this Regulation, in particular as regards the application of Articles 11 and 20.
Change 25
AddedArticle 25 – paragraph 1: 1. Costs incurred by eu-LISA in relation to the design, development, hosting and technical management of the router under this Regulation shall be borne by the general budget of the Union. In view of the Union interests at stake, in relation to its responsibilities for the design, development, hosting and technical management and maintenance of the router, eu-LISA shall be provided with the necessary resources under the Union budget in accordance with the applicable legislation.
AddedArticle 25 – paragraph 2 – subparagraph 1: Costs incurred by eu-LISA and Member States in relation to their connections to and integration with the router referred to in Article 20 shall be borne by the general budget of the Union.
Change 26
ChangedArticle 30 – paragraph 2 a1: (new):1. Member States shall ensurelay thatdown athe systematicrules oron persistentpenalties failureapplicable to comply with the obligations setinfringements inof this Regulation is subjectand toshall financialtake penaltiesall ofmeasures upnecessary to EURensure 10they million,are notwithstandingimplemented. theThe Memberpenalties States’provided rightfor toshall imposebe non-financialeffective, penaltiesproportionate inand addition.dissuasive penalties.
Change 27
RemovedArticle 31 – paragraph 1: 1. Every quarter, eu-LISA shall publish statistics on the functioning of the router, showing in particular the number, the nationality and the country of departure of the passengers, and specifically of the passengers who boarded the aircraft with inaccurate, incomplete or no longer up-to-date API data, with a non-recognised travel document, without a valid visa, without a valid travel authorization, or reported as overstay, the number and nationality of passengers.
AddedArticle 30 – paragraph 1 a (new): 1a. Member States shall ensure that when deciding whether to impose a penalty and when determining the type and level of penalty, the national supervisory authorities take into account relevant circumstances, which may include: / (a) the nature, gravity and duration of the infringement; / (b) the degree of the air carrier's fault; / (c) previous infringements by the air carrier; / (d) the overall level of cooperation of the air carrier with the competent authorities; / (e) the size of the air carrier, such as the annual number of passengers carried; / (f) whether previous penalties have already been applied by other national API supervisory authorities to the same carrier for the same infringement.
RemovedArticle 31 – paragraph 5 – introductory part: 5. eu-LISA shall have the right to access the following API data transmitted through to the router, solely for the purposes of the reporting referred to in Article 38 and for generating statistics in accordance with the present Article, without however such access allowing for the identification of the passengers concerned:
AddedArticle 30 – paragraph 1 b (new): 1b. Member States shall ensure that a systematic or persistent failure to comply with obligations set out in this Regulation is subject to financial penalties of up to 2% of an air carrier's global turnover of the preceding business year.
AddedArticle 31 – paragraph 1: 1. To support the implementation and supervision of this Regulation and based on the statistical information referred to in paragraph 5 of this Article, eu-LISA shall publish every quarter statistics on the functioning of the router, and on compliance by air carriers with the obligations set out in this Regulation. These statistics shall not allow for the identification of individuals. / The statistics shall show in particular: / (a) the number of passengers on which API data is transmitted, / (b) the number of flights for which API data is transmitted, / (c) the number of flights on which API data is not transmitted, / (d) the number of API messages transmitted on time to competent border authorities, / (e) the number of passengers who boarded the aircraft with inaccurate, incomplete or no longer up-to-date API data, with a non-recognised travel document.
AddedArticle 31 – paragraph 2: 2. For the purposes set out in paragraph 1, the router shall automatically transmit the data listed in paragraph 5 to the central repository for reporting and statistics established in Article 39 of Regulation (EU) 2019/817.
Show 3 more lines
AddedArticle 31 – paragraph 3: 3. In order to support the implementation and supervision of this Regulation, at the end of each year, eu-LISA shall compile statistical data in an annual report for that year. It shall publish that annual report and transmit it to the European Parliament, the Council, the Commission, the European Data Protection Supervisor, the European Border and Coast Guard Agency and the national supervisory authorities referred to in Article 29.
AddedArticle 31 – paragraph 4: 4. At the request of the Commission, eu-LISA shall provide it with statistics on specific aspects related to the implementation of this Regulation as well as the statistics pursuant to paragraph 3.
AddedArticle 31 – paragraph 5 – introductory part: 5. The central repository for reporting and statistics shall provide eu-LISA with the statistical information necessary for the reporting referred to in Article 38 and for generating statistics in accordance with the present Article, without however such statistics on API allowing for the identification of the passengers concerned:
Change 28
ChangedArticle 31 – paragraph 5 – point b: (b) the nationality, sex and year of birth of the passenger;deleted
Change 29
RemovedArticle 31 – paragraph 5 – subparagraph 1 a (new): Nothing in this paragraph shall affect the anonymized nature of the statistical data.
AddedArticle 31 – paragraph 6: 6. For the purposes of the reporting referred to in Article 38 and for generating statistics in accordance with the present Article, eu-LISA shall store the data referred to in paragraph 5 of this Article in the central repository for reporting and statistics established by Article 39 of Regulation (EU) 2019/817. It shall store that data for a period of three years in accordance with paragraph 2, without the data allowing for the identification of the passengers concerned. / The central repository for reporting and statistics shall provide duly authorised staff of the competent border authorities and other relevant authorities of the Member States with customisable reports and statistics on API as referred to in paragraph 5 for the implementation and supervision of this Regulation.
Change 30
ChangedArticle 32 a (new): Article 32a / API ContactExpert Group / 1. An API ContactExpert Group shall be established with effect from [one month after the entry into force of this Regulation] in accordance with the horizontal rules on the creation and operation of Commission expert groups. It shall facilitate cooperation and the exchange of information on obligations stemming from and issues relating to this Regulation among Member States, EU institutions and stakeholders. / 2. The API ContactExpert Group shall be composed of representatives of the European Commission, of Member States’ relevant authorities, of the European Parliament and of eu-LISA. Where relevant for the performance of its tasks, the API ContactExpert Group may invite relevant stakeholders, in particular representatives of air carriers, the EDPS and the independent national supervisory authorities, to participate in its work. The Commission’s representative shall chair the API ContactExpert Group.
Change 31
AddedArticle 38 – paragraph 4 – introductory part: 4. By [four years after the date of entry into force of this Regulation ] and every four years thereafter, the Commission shall produce a report containing an overall evaluation of this Regulation, demonstrating the necessity and the added value of the collection of API data, including an assessment of:
AddedArticle 38 – paragraph 4 – point c a (new): (ca) the impact of this Regulation on the travel experience of legitimate passengers.
AddedArticle 38 – paragraph 4 – point c b (new): (cb) the impact of this Regulation on the competitiveness of the aviation sector and the burden incurred by businesses. The Commission’s report shall also address this Regulation’s interaction with other relevant Union legislative acts, in particular Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008, in order to assess the overall impact of related reporting obligations on air carriers, identify provisions that could be updated and simplified, where appropriate, to mitigate the burden on air carriers, and consider actions and measures that could be taken to reduce the total cost pressure on air carriers.
AddedArticle 38 – paragraph 4 a (new): 4a. The evaluation referred to in paragraph 1 shall also include an assessment of the feasibility of including non-commercial business aviation within the scope of this Regulation.
AddedArticle 38 – paragraph 6: 6. The Member States and air carriers shall, upon request, provide eu-LISA and the Commission with the information necessary to draft the reports referred to in paragraphs 2, 3 and 4, including information not constituting personal data related to the results of the pre-checks of Union information systems and national databases at the external borders with API data. In particular, Member States shall provide quantitative and qualitative information on the necessity and added value of the collection of API data from an operational perspective. However, Member States may refrain from providing such information if, and to the extent necessary not to disclose confidential working methods or jeopardise ongoing investigations of the competent border authorities. The Commission shall ensure that any confidential information provided is appropriately protected.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2023). “Changes between LIBE-PR-750252 and A-9-2023-0409”. Text, 7 December 2023. from LIBE-PR-750252, to A-9-2023-0409. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409 (retrieved 25 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-07,
author = {{European Parliament}},
title = {{Changes between LIBE-PR-750252 and A-9-2023-0409}},
year = {2023},
date = {2023-12-07},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409}},
url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. from LIBE-PR-750252, to A-9-2023-0409. Data: European Parliament Open Data (CC BY 4.0)}
}