Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
LIBE-PR-750252 → A-9-2023-0409
- From
- LIBE-PR-750252 report parliamentary committee draft of 5 Jul 2023
- To
- A-9-2023-0409 Plenary report of 7 Dec 2023
- Changes
- 31 changes to the text
- Paragraphs
- +96 added · −26 removed · 18 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 2 of 4: Paragraphs 61–120
RemovedArticle 3 – paragraph 1 – point a a (new): (aa) 'general aviation' means all civil aviation operations other than scheduled air services and non-scheduled air transport operations for remuneration or hire as defined in the classification of the International Civil Aviation Organization (ICAO);
Article 3 – paragraph 1 – point e: (e) ‘scheduled flight’ means a commercial flight that operates according to a fixed timetable, for which tickets can be purchased by the general public;
Article 3 – paragraph 1 – point f: (f) ‘non-scheduled flight’ means a commercial flight that does not operate according to a fixed timetable and that is not necessarily part of a regular or scheduled route;
Change 5
ChangedArticle 3 – paragraph 1 – point h: (h) (h) ‘passenger’ means any person,excludingperson, excluding members of the crew unless they are off duty, carried or to be carried in an aircraft with the consent of the air carrier, such consent being manifested by that person's registration in the passengers list;
Article 3 – paragraph 1 – point j: deleted
Article 3 – paragraph 1 – point k: (k) ‘Advance Passenger Information data’ or ‘API data’ means the passenger data and the flight information referred to in Article 4(2) and (3) respectively;
Change 6
AddedArticle 3 – paragraph 1 – point l: (l) ‘Passenger Information Unit’ or ‘PIU’ means the competent authority referred to in Article 3, point k, of Regulation (EU) [API law enforcement];
Article 4 – paragraph 1: 1. Air carriers shall collect API data of passengers, consisting of the passenger data and the flight information specified in paragraphs 2 and 3 of this Article, respectively, on the flights referred to in Article 2, for the purpose of transferring that API data to the router in accordance with Article 6. Where the flight is code-shared between one or more air carriers, the obligation to transfer the API data shall be on the air carrier that operates the flight.
Change 7
ChangedArticle 4 – paragraph 2 – introductory part: 2. The API data shall consist of only of the following passenger data relating to each passenger on the flight:
4 unchanged paragraphs
Article 4 – paragraph 2 – point e: deleted
Article 4 – paragraph 2 – point g: (g) the number of the seat in the aircraft assigned to a passenger, where the air carrier collects such information;
Article 4 – paragraph 2 – point h: (h) number and the weight of checked bags, where the air carrier collects such information.
Article 4 – paragraph 3 – introductory part: 3. The API data shall also only consist of the following flight information relating to the flight of each passenger:
Change 8
ChangedArticle 4 – paragraph 3 – point a: (a) the flight identification number or, where the flight is code-shared between one or more air carriers, the,the flightsflight identification numbers, oror, if no such number exists, other clear and suitable means to identify the flight;
Change 9
ChangedArticle 5 – paragraph 21 – subparagraph 1:1 Aira carriers(new): shallThe collectcollection theof API data referred toin Articleaccordance 4(2),with pointsthe (a)first tosubparagraph (d),shall usingnot automatedinclude meansan toobligation collectfor theair machine-readablecarriers datato ofcheck the travel document ofat the passengermoment concerned.of Theyboarding shallthe doaircraft soor inan accordanceobligation withfor thepassengers detailedto technicalcarry requirementsa andtravel operationaldocument ruleswhen referredtravelling, towithout inprejudice paragraphto 4,acts whereof suchnational ruleslaw havethat beenare adoptedcompatible andwith areUnion applicable.law.
Change 10
ChangedArticle 5 – paragraph 2 – subparagraph 11: aAir (new):carriers Whereshall aircollect the API data referred to in Article 4(2), points (a) to (d), using automated means to collect the machine-readable data of the travel document of the passenger concerned. Air carriers provideshall ancollect onlinethat data during the check-in process, theyeither as part of the online check-in or as part of the check-in at the airport. They shall enabledo passengersso toin provideaccordance with the APIdetailed datatechnical requirements and operational rules referred to in Articleparagraph 4(2),4, pointsonce (a)such rules have been adopted and are applicable, and, in particular, by using the most reliable automated means available to (d)collect duringthe machine-readable data of the onlinerespective check-intravel process.document.
Change 11
RemovedArticle 6 – paragraph 1: 1. Air carriers shall transfer the encrypted API data to the router by electronic means. They shall do so in accordance with the detailed rules referred to in paragraph 3, where such rules have been adopted and are applicable.
AddedArticle 5 – paragraph 2 – subparagraph 1 a (new): The collection of API data by automated means shall not lead to the collection of any biometric data from the travel document.
RemovedArticle 6 – paragraph 2: 2. Air carriers shall transfer the API data both at the moment of check-in and immediately after flight closure, that is, once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for passengers to board or to leave the aircraft. At the moment of check-in, air carriers shall transfer the API data by way of interactive API in accordance with international standards. Where an air carrier transfers the API data by way of interactive API, it shall receive a meaningful reply in accordance with Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008.
AddedArticle 5 – paragraph 2 – subparagraph 1 b (new): Where air carriers provide an online check-in process, they shall enable passengers to provide the API data referred to in Article 4(2), points (a) to (d), during the online check-in process, using automated means.
RemovedArticle 6 – paragraph 3: 3. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the common protocols and supported data formats to be used for the encrypted transfers of API data to the router referred to in paragraph 1.
AddedArticle 5 – paragraph 2 – subparagraph 2: However, where such use of automated means is not possible, air carriers shall collect that data manually either as part of the online check-in or as part of the check-in at the airport, in such a manner as to ensure compliance with paragraph 1.
Change 12
ChangedArticle 85 – paragraph 1: 1. Air3: carriers3. shallAny store,automated formeans aused timeby periodair ofcarriers 24to hourscollect fromAPI thedata momentunder ofthis departureRegulation ofshall thebe flight,reliable, thesecure APIand dataup-to-date. relatingAir tocarriers thatshall passengerensure that they collected pursuant to Article 4.API Theydata shallis immediatelyencrypted andduring permanentlythe deletetransmission thatof APIthe data afterfrom the expirypassenger ofto thatthe timeair period.carriers.
Change 13
AddedArticle 5 – paragraph 4: 4. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down detailed technical requirements and operational rules for the collection of the API data referred to in Article 4(2), points (a) to (d), using automated means in accordance with paragraph 2 and 3 of this Article, including on requirements for data security.
AddedArticle 6 – paragraph 1: 1. Air carriers shall transfer the encrypted API data to the router by electronic means. They shall do so in accordance with the detailed rules referred to in paragraph 3, once such rules have been adopted and are applicable.
AddedArticle 6 – paragraph 2: 2. Air carriers shall transfer the API data both at the moment of check-in and immediately after flight closure, that is, once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for passengers to board or to leave the aircraft. At the moment of check-in, air carriers shall transfer the API data in accordance with this Regulation and relevant international standards. Air carriers shall receive an acknowledgement of receipt of the transfer of the API data.
AddedArticle 6 – paragraph 3: 3. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the common protocols and supported data formats to be used for the encrypted transfers of API data to the router referred to in paragraph 1, including the transfer of API data at the moment of check-in, the meaningful reply and requirements for data security. Such detailed rules shall ensure that airlines transmit API data using the same structure and content.
AddedArticle 6 – paragraph 4: deleted
AddedArticle 7 – paragraph 1 a (new): The competent border authorities shall be prohibited from processing API data for the purposes of profiling under any circumstances.
AddedArticle 8 – paragraph 1: 1. Air carriers shall store, for a time period of 24 hours from the moment of departure of the flight, the API data relating to that passenger that they collected pursuant to Article 4. They shall immediately and permanently delete that API data after the expiry of that time period. This shall be without prejudice to the possibility for air carriers to retain and use the data where necessary for the normal course of their business, in particular for travel facilitation, in compliance with the applicable law and in particular Regulation (EU) 2016/679.
Article 8 – paragraph 2: 2. The competent border authorities shall store, for a time period of 24 hours from the moment of departure of the flight, the API data relating to that passenger that they received through the router pursuant to Article 11. They shall immediately and permanently delete that API data after the expiry of that time period.
Change 14
RemovedArticle 8 a (new): Article 8a / Non-discrimination and fundamental rights / Processing of personal data in accordance with this Regulation and Regulation (EU) [API law enforcement] shall not result in discrimination against data subjects on the grounds of sex, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age or sexual orientation. It shall fully respect human dignity and integrity and fundamental rights, including the right to respect for one’s private life and to the protection of personal data. Particular attention shall be paid to children, the elderly and persons with a disability. The best interests of the child shall be a primary consideration.
AddedArticle 8 – paragraph 2 a (new): 2a. Air carriers or competent border authorities shall immediately either correct, complete or update, or permanently delete, the API data concerned in both of the following situations: / (a) where they become aware that the API data collected is inaccurate, incomplete or no longer up-to-date; / (b) where the transfer of the API data in accordance with Article 5(2) has been completed.
RemovedArticle 8 b (new): Article 8b / Legal remedies / Member States shall ensure that the persons affected by the measures provided for under this Regulation have the right to an effective legal remedy in order to uphold their rights.
AddedArticle 8 – paragraph 2 b (new): 2b. Air carriers or competent border authorities shall immediately and permanently delete API data where they become aware that the API data collected was processed unlawfully or that the data transferred does not constitute API data.
RemovedArticle 9 – paragraph 2 – point b: (b) a secure communication channel between the central infrastructure and the competent border authorities and the PIUs, and a secure communication channel between the central infrastructure and the air carriers, for the transfer and transmission of API data and for any communications relating thereto.
AddedArticle 8 – paragraph 2 c (new): 2c. Where the air carriers become aware of the circumstances referred to in point (a) of paragraph 2a or paragraph 2b after having completed the transfer of the data in accordance with Article 6(1), they shall immediately inform the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA). Upon receiving such information, eu-LISA shall immediately inform the competent border authority that received the API data transmitted through the router.
AddedArticle 8 – paragraph 3: deleted
AddedArticle 8 a (new): Article 8a / Fundamental Rights / 1. Collection and processing of personal data in accordance with this Regulation and Regulation (EU) [API law enforcement] by air carriers and competent authorities shall not result in discrimination against persons on the grounds of sex and gender, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age or sexual orientation. / 2. This Regulation shall fully respect human dignity and the fundamental rights and principles recognised by the Charter, including the right to respect for one’s private life, to asylum, to the protection of personal data, to freedom of movement and to effective legal remedies. / 3. Particular attention shall be paid to children, the elderly, persons with a disability and vulnerable persons. The best interests of the child shall be a primary consideration when implementing this Regulation.
AddedArticle 9 – paragraph 1: 1. eu-LISA shall design, develop, host and technically manage, in accordance with Articles 22 and 23, a router for the purpose of facilitating the transfer of encrypted API data by the air carriers to the competent border authorities in accordance with this Regulation.
AddedArticle 9 – paragraph 2 – point b: (b) a secure communication channel between the central infrastructure and the competent border authorities and a secure communication channel between the central infrastructure and the air carriers, for the transfer and transmission of API data and for any communications relating thereto.
Article 9 – paragraph 2 a (new): 2a. The router shall allow for the reception and transmission of encrypted API data.
Change 15
ChangedArticle 109 – paragraph 1: The router shall only be used by air carriers to transfer2 encryptedb API(new): data2b. andThe byrouter competentshall borderautomatically authoritiesextract and PIUs to receivemake encryptedavailable APIthe data,statistics, in accordance with thisArticle Regulation31, andto Regulationthe (EU)central [APIrepository lawfor enforcement],reporting respectively.and statistics.
Change 16
RemovedArticle 11 – paragraph 1 – subparagraph 1: The router shall, immediately and in an automated manner, transmit the encrypted API data, transferred to it pursuant to Article 6, to the competent border authorities of the Member State referred to in Article 4(3), point (c). It shall do so in accordance with the detailed rules referred to in paragraph 4 of this Article, where such rules have been adopted and are applicable.
AddedArticle 9 – paragraph 3: 3. Without prejudice to Article 10 of this Regulation, the router shall, if appropriate and to the extent technically possible, share and re-use the hardware and software components, of the web service referred to in Article 13 of Regulation (EU) 2017/2226 of the European Parliament and of the Council48 , the carrier gateway referred to in Article 6(2), point (k), of Regulation (EU) 2018/1240, and the carrier gateway referred to in Article 2a, point (h), of Regulation (EC) 767/2008 of the European Parliament and of the Council49 . eu-LISA shall design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations put on air carriers by Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008.
Change 17
ChangedArticle 119 – paragraph 3:3 3.a The(new): Member3a. Stateseu-LISA shall ensuredesign thatand onlydevelop the dulyrouter authorisedin anda trainedway staffthat ofany theAPI competentdata bordertransferred authoritiesfrom havethe accessair carriers to the APIrouter datain transmittedaccordance towith themArticle through6 theand router.any TheyAPI shalldata laytransmitted downfrom the necessary rulesrouter to thatthe effect.competent Thoseborder rulesauthorities shallin includeaccordance ruleswith onArticle 11 and to the creationcentral andrepository regularfor updatereporting ofand astatistics listin ofaccordance thosewith staffArticle and31(2) theirare profiles.encrypted.
Change 18
ChangedArticle 1110 – paragraph 4: 4. The Commission1: isNotwithstanding empoweredthe touse adoptof delegatedthe actsrouter in accordance with Article 37 to4b supplement(new) thisof Regulation by(EU) laying[API downlaw enforcement], the necessaryrouter detailedshall technicalonly andbe proceduralused: rules/ for(a) theby transmissionsair ofcarriers to transfer encrypted API data fromin accordance with this Regulation; / (b) by the routercompetent referredborder authorities to receive encrypted API data in paragraphaccordance 1.with this Regulation.
Change 19
RemovedArticle 12 – paragraph 1 – introductory part: API data, transferred to the router pursuant to this Regulation and Regulation (EU) [API law enforcement], shall be stored on the router only insofar as necessary to complete the transmission to the relevant competent borders authorities or PIUs, as applicable, in accordance with those Regulations and shall be deleted from the router, immediately, permanently and in an automated manner, in the following situations:
AddedArticle 10 a (new): Article 10a / Data format and transfer verifications / 1. The router shall, in an automated manner and based on real-time flight traffic data, verify whether the air carrier transferred the API data in accordance with Article 6(1). / 2. The router shall, immediately and in an automated manner, verify whether the API data transferred to it in accordance with Article 6(1) complies with the detailed rules on the supported data formats, referred to in Article 6(3). / 3. Where the router has verified in accordance with paragraph 1 that the data was not transferred by the air carrier or where the data in question is not compliant with the detailed rules referred to in paragraph 2, the router shall, immediately and in an automated manner, notify the air carrier concerned and the competent border authorities of the Member States to which the data were to be transmitted pursuant to Article 11(1). In this case, the air carrier shall immediately transfer the API data in accordance with Article 6. / 4. The Commission shall adopt implementing acts specifying the necessary detailed technical and procedural rules for the verifications and notifications referred to in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 36(2).
RemovedArticle 12 – paragraph 1 – point a a (new): (aa) in cases of technical impossibility of the router to subsequently transmit the API data to the competent national authorities, after 12 hours;
AddedArticle 11 – paragraph 1 – subparagraph 1: Upon the verifications referred to in Article 10a, the router shall, immediately and in an automated manner, transmit the encrypted API data, transferred to it pursuant to Article 6, to the competent border authorities of the Member State referred to in Article 4(3), point (c). It shall do so in accordance with the detailed rules referred to in paragraph 4 of this Article, once such rules have been adopted and are applicable.
AddedArticle 11 – paragraph 3: 3. The Member States shall ensure that only the duly authorised and trained staff of the competent border authorities, designated in accordance with paragraph 2, have access to the API data transmitted to them through the router. They shall lay down the necessary rules to that effect. Those rules shall include rules on the creation and regular update of a list of those staff and their profiles.
AddedArticle 11 – paragraph 4: 4. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed technical and procedural rules for the transmissions of encrypted API data from the router referred to in paragraph 1, including on requirements for data security.
AddedArticle 12 – paragraph 1 – introductory part: API data, transferred to the router pursuant to this Regulation, shall be stored on the router only insofar as necessary to complete the transmission to the relevant competent borders authorities and shall be deleted from the router, immediately, permanently and in an automated manner, in both of the following situations:
AddedArticle 12 – paragraph 1 – point a: (a) where the transmission of the API data to the relevant competent border authorities has been completed;
AddedArticle 12 – paragraph 1 – point a a (new): (aa) in cases of technical impossibility of the router to subsequently transmit the API data to the competent border authorities, after 12 hours.
Article 12 – paragraph 1 – point b: deleted
Change 20
ChangedArticle 13 – paragraph 1 – subparagraph 1 – introductory part: eu-LISA shall keep logs of all processing operations relating to the transfer of API data through the router under this Regulation and Regulation (EU) [API law enforcement].Regulation. Those logs shall cover:
Change 21
RemovedArticle 13 – paragraph 2: 2. Air carriers shall create logs of all processing operations under this Regulation undertaken by using the automated means referred to in Article 5(2). Those logs shall cover the date, time and place of transfer of the API data. Those logs shall not contain any personal data.
AddedArticle 13 – paragraph 1 – subparagraph 1 – point b: (b) the competent border authorities to which the API data was transmitted through the router;
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409?all=1&part=2
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 26 September 2026
Cite as
European Parliament (2023). “Changes between LIBE-PR-750252 and A-9-2023-0409”. Text, 7 December 2023. from LIBE-PR-750252, to A-9-2023-0409. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409?all=1&part=2 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-07,
author = {{European Parliament}},
title = {{Changes between LIBE-PR-750252 and A-9-2023-0409}},
year = {2023},
date = {2023-12-07},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409?all=1&part=2}},
url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409?all=1&part=2},
urldate = {2026-09-26},
publisher = {EU Parl Watch Research},
note = {Text. from LIBE-PR-750252, to A-9-2023-0409. Data: European Parliament Open Data (CC BY 4.0)}
}