Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
LIBE-PR-750252 → A-9-2023-0409
- From
- LIBE-PR-750252 report parliamentary committee draft of 5 Jul 2023
- To
- A-9-2023-0409 Plenary report of 7 Dec 2023
- Changes
- 31 changes to the text
- Paragraphs
- +96 added · −26 removed · 18 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 3 of 4: Paragraphs 121–180
Change 22
ChangedArticle 13 – paragraph 5 – subparagraph 2: However, if those logs are needed for procedures for2. monitoringAir orcarriers ensuringshall thecreate securitylogs andof integrityall ofprocessing theoperations APIunder datathis orRegulation theundertaken lawfulnessby ofusing the processing operations,automated asmeans referred to in paragraph 2, and these procedures have alreadyArticle begun5(2). atThose thelogs momentshall ofcover the expiry of thedate, time period referred to in theand firstplace subparagraph,of eu-LISAtransfer andof the air carriers shallAPI keepdata. thoseThose logs for as long as necessary for thoseshall proceduresnot aftercontain informingany andpersonal justifyingdata, itother tothan the Commission. In that case, they shallinformation immediatelynecessary deleteto thoseidentify logsthe whenrelevant theymember areof nothe longerstaff necessaryof forthe thoseair procedures.carrier.
Change 23
ChangedArticle 1913 – paragraph 1:3: 1.3. The independent supervisory authoritieslogs referred to in Articleparagraphs 511 ofand Regulation2 (EU)shall 2016/679be shallused carryonly outfor anensuring auditthe ofsecurity processingand operationsintegrity of the API data constituting personaland datathe performedlawfulness byof the competentprocessing, borderin authoritiesparticular foras regards compliance with the purposesrequirements ofset out in this Regulation, inincluding accordanceproceedings withfor relevantpenalties internationalfor auditinginfringements standards,of atthose leastrequirements oncein everyaccordance fourwith years.Articles 29 and 30 of this Regulation.
Change 24
RemovedArticle 19 – paragraph 2: 2. The European Data Protection Supervisor shall carry out an audit of processing operations of API data constituting personal data performed by eu-LISA for the purposes of this Regulation and Regulation (EU) [API law enforcement] in accordance with relevant international auditing standards at least once every year. A report of that audit shall be sent to the European Parliament, to the Council, to the Commission, to the Member States and to eu-LISA. eu-LISA shall be given an opportunity to make comments before the reports are adopted.
AddedArticle 13 – paragraph 4: 4. eu-LISA and air carriers shall take appropriate measures to protect the logs that they created pursuant to paragraphs 1 and 2, respectively, against unauthorised access and other security risks.
AddedArticle 13 – paragraph 4 a (new): 4a. The national supervisory authorities referred to in Article 29 and competent authorities shall have access to the relevant logs referred to in paragraph 1 where necessary for the purposes referred to in paragraph 3.
AddedArticle 13 – paragraph 5 – subparagraph 2: However, if those logs are needed for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations, as referred to in paragraph 2, and these procedures have already begun at the moment of the expiry of the time period referred to in the first subparagraph, eu-LISA and the air carriers may keep those logs for as long as necessary for those procedures, provided that eu-LISA or the air carriers inform the Commission of the need to keep those logs and provide reasons for doing so. In that case, they shall immediately delete those logs when they are no longer necessary for those procedures.
AddedArticle 15 – paragraph 1: The competent border authorities shall be controllers, within the meaning of Article 4, point (7), of Regulation (EU) 2016/679, in relation to the processing of API data constituting personal data through the router, including the transmission of the data from the router to the authorities and the storage for technical reasons of that data in the router, as well as in relation to their processing of API data constituting personal data referred to in Article 7 of this Regulation.
AddedArticle 16 – paragraph 1: eu-LISA shall be the processor on behalf of the competent border authorities within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the processing of API data constituting personal data through the router in accordance with this Regulation.
AddedArticle 16 a (new): Article16a / Information to passengers / In accordance with the right of information in Article 13 of Regulation (EU) 2016/679, air carriers shall provide passengers, on flights covered by this Regulation, with information on the purpose of the collection of their personal data, the type of personal data collected, the recipients of the personal data and the means to exercise the data subject rights. / This information shall be communicated to passengers in writing and in an easily accessible format at the moment of booking and at the moment of check-in, irrespective of the means used to collect the personal data at the moment of check-in in accordance with Article 5.
AddedArticle 17 – paragraph -1 (new): -1. Competent border authorities and air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation.
AddedArticle 17 – paragraph -1 a (new): -1a. Competent border authorities and air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other and with eu-LISA to ensure such security.
AddedArticle 17 – paragraph 1: 1. eu-LISA shall ensure the security and encryption of the API data, in particular API data constituting personal data, that it processes pursuant to this Regulation. The competent border authorities and the air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation. eu-LISA, the competent border authorities and the air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other to ensure such security.
AddedArticle 17 – paragraph 2 – subparagraph 1 – point c: (c) ensure that it is possible to verify and establish to which competent border authorities the API data is transmitted through the router;
AddedArticle 18 – paragraph 1: The air carriers and competent authorities shall monitor their compliance with their respective obligations under this Regulation, in particular as regards their processing of API data constituting personal data, including through frequent verification of the logs in accordance with Article 13.
AddedArticle 19 – paragraph 1: 1. The independent supervisory authorities referred to in Article 51 of Regulation (EU) 2016/679 shall ensure that an audit of processing operations of API data constituting personal data performed by the competent border authorities for the purposes of this Regulation is carried out, in accordance with relevant international auditing standards, at least once every four years.
AddedArticle 19 – paragraph 2: 2. The European Data Protection Supervisor shall carry out an audit of processing operations of API data constituting personal data performed by eu-LISA for the purposes of this Regulation, in accordance with relevant international auditing standards at least once every year. A report of that audit shall be sent to the European Parliament, to the Council, to the Commission, to the Member States and to eu-LISA. eu-LISA shall be given an opportunity to make comments before the reports are adopted.
AddedArticle 20 – paragraph 1 – subparagraph 1: Member States shall ensure that their competent border authorities are connected to the router. They shall ensure that the competent border authorities’ systems and infrastructure for the reception of API data transferred pursuant to this Regulation are integrated with the router.
AddedArticle 20 – paragraph 2: 2. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the connections to and integration with the router referred to in paragraph 1, including on requirements for data security.
AddedArticle 21 – paragraph 2: 2. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the connections to and integration with the router referred to in paragraph 1, including on requirements for data security.
AddedArticle 22 – paragraph 3: 3. eu-LISA shall ensure that the router is designed and developed in such a manner that the router provides the functionalities specified in this Regulation, and that the router starts operations as soon as possible after the adoption by the Commission of the delegated acts provided for in Article 5(4), Article 6(3), Article 11(4), Article 20(2) and Article 21(2) and after the carrying out of a data protection impact assessment in accordance with Article 35 of Regulation (EU) 2016/679.
AddedArticle 22 – paragraph 4: 4. Where eu-LISA considers that the development phase has been completed, it shall, without undue delay, conduct a comprehensive test of the router, in cooperation with the competent border authorities and other relevant Member States’ authorities and air carriers and inform the Commission of the outcome of that test.
AddedArticle 23 – paragraph 2 – subparagraph 1: eu-LISA shall be responsible for the technical management of the router, including its maintenance and technical developments, in such a manner as to ensure that the API data are securely, effectively and swiftly transmitted through the router, in compliance with this Regulation.
AddedArticle 23 – paragraph 2 – subparagraph 2: The technical management of the router shall consist of carrying out all the tasks and enacting all technical solutions necessary for the proper functioning of the router in accordance with this Regulation in an uninterrupted manner, 24 hours a day, 7 days a week. It shall include the maintenance work and technical developments necessary to ensure that the router functions at a satisfactory level of technical quality, in particular as regards availability, accuracy and reliability of the transmission of API data, in accordance with the technical specifications and, as much as possible, in line with the operational needs of the competent border authorities and air carriers.
AddedArticle 24 – paragraph 1: 1. eu-LISA shall, upon their request, provide training to competent border authorities and other relevant Member States’ authorities and air carriers on the technical use of the router and on the connection and integration to the router.
AddedArticle 24 – paragraph 2: 2. eu-LISA shall provide support to the competent border authorities regarding the reception of API data through the router pursuant to this Regulation, in particular as regards the application of Articles 11 and 20.
Article 25 – title: Costs of eu-LISA, the European Data Protection Supervisor, the national supervisory authorities and of Member States
Change 25
AddedArticle 25 – paragraph 1: 1. Costs incurred by eu-LISA in relation to the design, development, hosting and technical management of the router under this Regulation shall be borne by the general budget of the Union. In view of the Union interests at stake, in relation to its responsibilities for the design, development, hosting and technical management and maintenance of the router, eu-LISA shall be provided with the necessary resources under the Union budget in accordance with the applicable legislation.
AddedArticle 25 – paragraph 2 – subparagraph 1: Costs incurred by eu-LISA and Member States in relation to their connections to and integration with the router referred to in Article 20 shall be borne by the general budget of the Union.
5 unchanged paragraphs
Article 25 – paragraph 2 a (new): 2a. Costs incurred by the European Data Protection Supervisor in relation to the tasks entrusted to it under this Regulation shall be borne by the general budget of the Union.
Article 25 – paragraph 2 b (new): 2b. Costs incurred by independent national supervisory authorities in relation to the tasks entrusted to them under this Regulation shall be borne by the Member States.
Article 28 – title: Voluntary use of the router in application of Directive 2004/82/EC
Article 28 – paragraph 2: 2. Where an air carrier starts using the router in accordance with paragraph 1, it shall continue using the router to transmit such information to the responsible authorities of the Member State concerned until the date of application of this Regulation referred to in Article 39, second subparagraph. However, that use shall be discontinued, from an appropriate date set by that authority, where that authority considers that there are objective reasons that require such discontinuation and has informed the air carrier accordingly.
Article 29 – paragraph 3: 3. Member States shall, by the date of application of this Regulation referred to in Article 39, second subparagraph, notify the Commission of the name and the contact details of the authorities that they designated under paragraph 1 and of the detailed rules that they laid down pursuant to paragraph 2. They shall notify the Commission without delay of any subsequent changes or amendments thereto.
Change 26
ChangedArticle 30 – paragraph 2 a1: (new):1. Member States shall ensurelay thatdown athe systematicrules oron persistentpenalties failureapplicable to comply with the obligations setinfringements inof this Regulation is subjectand toshall financialtake penaltiesall ofmeasures upnecessary to EURensure 10they million,are notwithstandingimplemented. theThe Memberpenalties States’provided rightfor toshall imposebe non-financialeffective, penaltiesproportionate inand addition.dissuasive penalties.
Change 27
RemovedArticle 31 – paragraph 1: 1. Every quarter, eu-LISA shall publish statistics on the functioning of the router, showing in particular the number, the nationality and the country of departure of the passengers, and specifically of the passengers who boarded the aircraft with inaccurate, incomplete or no longer up-to-date API data, with a non-recognised travel document, without a valid visa, without a valid travel authorization, or reported as overstay, the number and nationality of passengers.
AddedArticle 30 – paragraph 1 a (new): 1a. Member States shall ensure that when deciding whether to impose a penalty and when determining the type and level of penalty, the national supervisory authorities take into account relevant circumstances, which may include: / (a) the nature, gravity and duration of the infringement; / (b) the degree of the air carrier's fault; / (c) previous infringements by the air carrier; / (d) the overall level of cooperation of the air carrier with the competent authorities; / (e) the size of the air carrier, such as the annual number of passengers carried; / (f) whether previous penalties have already been applied by other national API supervisory authorities to the same carrier for the same infringement.
RemovedArticle 31 – paragraph 5 – introductory part: 5. eu-LISA shall have the right to access the following API data transmitted through to the router, solely for the purposes of the reporting referred to in Article 38 and for generating statistics in accordance with the present Article, without however such access allowing for the identification of the passengers concerned:
AddedArticle 30 – paragraph 1 b (new): 1b. Member States shall ensure that a systematic or persistent failure to comply with obligations set out in this Regulation is subject to financial penalties of up to 2% of an air carrier's global turnover of the preceding business year.
AddedArticle 31 – paragraph 1: 1. To support the implementation and supervision of this Regulation and based on the statistical information referred to in paragraph 5 of this Article, eu-LISA shall publish every quarter statistics on the functioning of the router, and on compliance by air carriers with the obligations set out in this Regulation. These statistics shall not allow for the identification of individuals. / The statistics shall show in particular: / (a) the number of passengers on which API data is transmitted, / (b) the number of flights for which API data is transmitted, / (c) the number of flights on which API data is not transmitted, / (d) the number of API messages transmitted on time to competent border authorities, / (e) the number of passengers who boarded the aircraft with inaccurate, incomplete or no longer up-to-date API data, with a non-recognised travel document.
AddedArticle 31 – paragraph 2: 2. For the purposes set out in paragraph 1, the router shall automatically transmit the data listed in paragraph 5 to the central repository for reporting and statistics established in Article 39 of Regulation (EU) 2019/817.
AddedArticle 31 – paragraph 3: 3. In order to support the implementation and supervision of this Regulation, at the end of each year, eu-LISA shall compile statistical data in an annual report for that year. It shall publish that annual report and transmit it to the European Parliament, the Council, the Commission, the European Data Protection Supervisor, the European Border and Coast Guard Agency and the national supervisory authorities referred to in Article 29.
AddedArticle 31 – paragraph 4: 4. At the request of the Commission, eu-LISA shall provide it with statistics on specific aspects related to the implementation of this Regulation as well as the statistics pursuant to paragraph 3.
AddedArticle 31 – paragraph 5 – introductory part: 5. The central repository for reporting and statistics shall provide eu-LISA with the statistical information necessary for the reporting referred to in Article 38 and for generating statistics in accordance with the present Article, without however such statistics on API allowing for the identification of the passengers concerned:
Article 31 – paragraph 5 – point a: deleted
Change 28
ChangedArticle 31 – paragraph 5 – point b: (b) the nationality, sex and year of birth of the passenger;deleted
Article 31 – paragraph 5 – point e: (e) the number of passengers checked-in on the same flight;
Article 31 – paragraph 5 – point g: (g) whether the personal data of the passenger is accurate, complete and up-to-date.
Change 29
RemovedArticle 31 – paragraph 5 – subparagraph 1 a (new): Nothing in this paragraph shall affect the anonymized nature of the statistical data.
AddedArticle 31 – paragraph 6: 6. For the purposes of the reporting referred to in Article 38 and for generating statistics in accordance with the present Article, eu-LISA shall store the data referred to in paragraph 5 of this Article in the central repository for reporting and statistics established by Article 39 of Regulation (EU) 2019/817. It shall store that data for a period of three years in accordance with paragraph 2, without the data allowing for the identification of the passengers concerned. / The central repository for reporting and statistics shall provide duly authorised staff of the competent border authorities and other relevant authorities of the Member States with customisable reports and statistics on API as referred to in paragraph 5 for the implementation and supervision of this Regulation.
Article 31 – paragraph 6 a (new): 6a. The use of the data referred to in paragraph 5 of this Article for automated or non-automated risk analysis, profiling or predictive risk assessment shall be prohibited.
Article 32 – paragraph 1: The Commission shall, in close cooperation with the competent border authorities, other relevant Member States’ authorities, the air carriers and relevant Union agencies, in particular the European Data Protection Supervisor and the Fundamental Rights Agency, prepare and make publicly available a practical handbook, containing guidelines, recommendations and best practices for the implementation of this Regulation, including on fundamental rights compliance as well as on penalties in accordance with Article 30.
Change 30
ChangedArticle 32 a (new): Article 32a / API ContactExpert Group / 1. An API ContactExpert Group shall be established with effect from [one month after the entry into force of this Regulation] in accordance with the horizontal rules on the creation and operation of Commission expert groups. It shall facilitate cooperation and the exchange of information on obligations stemming from and issues relating to this Regulation among Member States, EU institutions and stakeholders. / 2. The API ContactExpert Group shall be composed of representatives of the European Commission, of Member States’ relevant authorities, of the European Parliament and of eu-LISA. Where relevant for the performance of its tasks, the API ContactExpert Group may invite relevant stakeholders, in particular representatives of air carriers, the EDPS and the independent national supervisory authorities, to participate in its work. The Commission’s representative shall chair the API ContactExpert Group.
Regulation (EU) 2019/817
Article 35 – paragraph 1, Article 39 – paragraph 2: 2. eu-LISA shall establish, implement and host in its technical sites the CRRS containing the data and statistics referred to in Article 63 of Regulation (EU) 2017/2226, Article 17 of Regulation (EC) No 767/2008, Article 84 of Regulation (EU) 2018/1240, Article 60 of Regulation (EU) 2018/1861 and Article 16 of Regulation (EU) 2018/1860, logically separated by EU information system. eu-LISA shall also collect the data and statistics from the router referred to in Article 31(1) of Regulation (EU) …/… * [this Regulation]. Access to the CRRS shall be granted by means of controlled, secured access and specific user profiles, solely for the purpose of reporting and statistics, to the authorities referred to in Article 63 of Regulation (EU) 2017/2226, Article 17 of Regulation (EC) No 767/2008, Article 84 of Regulation (EU) 2018/1240, Article 60 of Regulation (EU) 2018/1861 and Article 38(2) of Regulation (EU) …/… [this Regulation ]. Especially the use of the CRRS for risk analysis, profiling or predictive risk assessment shall be prohibited.
Article 38 – paragraph 2: 2. By [one year after the date of entry into force of this Regulation] and every year thereafter during the development phase of the router, eu-LISA shall produce a report, and submit it to the European Parliament and to the Council on the state of play of the development of the router. That report shall contain detailed information about the costs incurred and about any risks which may impact the overall costs to be borne by the general budget of the Union in accordance with Article 25. From the date at which the router starts operations and every year thereafter, the Commission shall assess whether the budget under the MFF budget line 4.11.10.02 (“eu-LISA”) covers the needs necessary for good design, development, hosting and technical management of the router and, if appropriate, immediately propose amendment to the budget appropriations.
Change 31
AddedArticle 38 – paragraph 4 – introductory part: 4. By [four years after the date of entry into force of this Regulation ] and every four years thereafter, the Commission shall produce a report containing an overall evaluation of this Regulation, demonstrating the necessity and the added value of the collection of API data, including an assessment of:
AddedArticle 38 – paragraph 4 – point c a (new): (ca) the impact of this Regulation on the travel experience of legitimate passengers.
AddedArticle 38 – paragraph 4 – point c b (new): (cb) the impact of this Regulation on the competitiveness of the aviation sector and the burden incurred by businesses. The Commission’s report shall also address this Regulation’s interaction with other relevant Union legislative acts, in particular Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008, in order to assess the overall impact of related reporting obligations on air carriers, identify provisions that could be updated and simplified, where appropriate, to mitigate the burden on air carriers, and consider actions and measures that could be taken to reduce the total cost pressure on air carriers.
AddedArticle 38 – paragraph 4 a (new): 4a. The evaluation referred to in paragraph 1 shall also include an assessment of the feasibility of including non-commercial business aviation within the scope of this Regulation.
AddedArticle 38 – paragraph 6: 6. The Member States and air carriers shall, upon request, provide eu-LISA and the Commission with the information necessary to draft the reports referred to in paragraphs 2, 3 and 4, including information not constituting personal data related to the results of the pre-checks of Union information systems and national databases at the external borders with API data. In particular, Member States shall provide quantitative and qualitative information on the necessity and added value of the collection of API data from an operational perspective. However, Member States may refrain from providing such information if, and to the extent necessary not to disclose confidential working methods or jeopardise ongoing investigations of the competent border authorities. The Commission shall ensure that any confidential information provided is appropriately protected.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409?all=1&part=3
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 26 September 2026
Cite as
European Parliament (2023). “Changes between LIBE-PR-750252 and A-9-2023-0409”. Text, 7 December 2023. from LIBE-PR-750252, to A-9-2023-0409. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409?all=1&part=3 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-07,
author = {{European Parliament}},
title = {{Changes between LIBE-PR-750252 and A-9-2023-0409}},
year = {2023},
date = {2023-12-07},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409?all=1&part=3}},
url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-750252/compare/A-9-2023-0409?all=1&part=3},
urldate = {2026-09-26},
publisher = {EU Parl Watch Research},
note = {Text. from LIBE-PR-750252, to A-9-2023-0409. Data: European Parliament Open Data (CC BY 4.0)}
}