Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
LIBE-PR-770059 → A-10-2025-0258
- From
- LIBE-PR-770059 report parliamentary committee draft of 2 Apr 2025
- To
- A-10-2025-0258 Plenary report of 10 Dec 2025
- Changes
- 25 changes to the text
- Paragraphs
- +100 added · −29 removed · 16 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council establishing an application for the electronic submission of travel data (“EU Digital Travel application”) and amending Regulations (EU) 2016/399 and (EU) 2018/1726 of the European Parliament and of the Council and Council Regulation (EC) No 2252/2004, as regards the use of digital travel credentials
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council establishing an application for the electronic submission of travel data (“EU Digital Travel application”) and amending Regulations (EU) 2016/399 and (EU) 2018/1726 of the European Parliament and of the Council and Council Regulation (EC) No 2252/2004, as regards the use of digital travel credentials
Changes that matter, 25
Changes to the text in document order — the ones the change notes describe. Cover page, renumbering and punctuation-only edits are left out (see “Every difference”); changes to citations and references stay in and are marked as formal in the notes.
Change 1
ChangedRecital 1: (1) The carrying out of effective and efficient border checks at the external borders contributes to the proper functioning of the area without internal border controls (‘the Schengen area’) and the internal security of the Union. The inclusion in travel documents issued by Member States of a storage medium ('chip'),(the 'chip'), with a facial image of the holder, by Council Regulation (EC) 2252/20041 and Regulation (EU) 2019/11572 , and the entry into force of Regulation (EC) No 562/2006 of the European Parliament and of the Council3 have significantly contributed to high security standards and robust external border management. Border checks are to be carried out in accordance with Regulation (EU) 2016/399 of the European Parliament and of the Council4Council4. ,Such border checks serve the purposes of reliably and securely identifying travellers, preventing threats to the internal security, public policy, and public health and international relations of Member States.
Change 2
ChangedRecital 2: (2) With the current reliance on physical travel documents and physical interactions for the examination of travel documents and the carrying out of border checks, Member States’ border authorities are unable to remotely verify the authenticity and integrity of travel documents and to carry out the relevant checks against databases before travellers arrive at the physical border crossing point, with the exception of air passengers for whom advance passenger information has been transmitted and processed. In light of increasing traveller flows across the external borders of the Schengen area as well as the entry into operation of the Entry/Exit System (EES) established by Regulation (EU) 2017/2226 of the European Parliament and of the Council5 that will require third-country nationals to whom it applies to provide additional data as part of border checks, this Regulation provides the possibility for border authorities to use secure technical solutions to carry out relevant checks before travellers arrive at the border-crossing points.
Change 3
ChangedRecital 3: (3) The existing legal framework on travel documents and border checks, consisting notably of Regulations (EC) No 2252/2004, (EU) XXXX/XXXX6 [COM(2024) 316 final] and (EU) 2016/399, does not allow for the use of data contained in the chip of travel documents for the purpose of carrying out such advance border checks and pre-clearing travellers or using that data for other purposes. Following recent developments at international level, namely in the context of standardisation work carried out by the International Civil Aviation Organization (ICAO), and on the capabilities and reliability of facial recognition, that technologyit is available and respondsappropriate to theexplore callsnew forapproaches facilitatingto facilitate cross-border travel while ensuring high levels of security in full respect of fundamental rights, including the right to privacy and the protection of personal data.
Change 4
ChangedRecital 4: (4) Therefore, the existing legal framework should be updated to ensure that both travellers and border authorities can benefit from more efficient and effective border checks using so-called digital travel credentials, that is, a digital representation of the person’s identity that is derived from the information stored in the chip of the travel document (i.e. passport or EU identity card) and that can be validated,reliably verified, leading ultimately to shorter waiting and processing times at border-crossing points and improving the authorities’ ability to pre-screen travellers, as well as to plan and manage resources andmore focuseffectively, onto higherallow riskfor travellers.a more thorough assessment in cases that exhibit irregularities or require additional verification.
Change 5
ChangedRecital 5: (5) In order to achieve its objectives, this Regulation should cover persons over the age of 18 enjoying the right of free movement under Union law as well as third-country nationals. This Regulation should only apply to persons over the age of 16 who are in possession of a travel document or identity card issued pursuant to Union law, or a travel document containing a chip, that is based on technical specifications and security standards compatible with those provided for by Regulation (EC) No 2252/2004, and that contain reliable technology preventing its cloning.
Change 6
ChangedRecital 5 a (new): (5a) Biometric data are, by their nature, particularly sensitive and merit specific protection as the context of their processing could create significant risks to fundamental rights and freedoms. Children merit specific protection with regard to their personal data, as they maymight be less aware of the risks, consequences and safeguards concerned and of their rights in relation to the processing of personal data.data Furthermore,as facialset recognitionout technologyin mayRegulation not(EU) be2016/679 ableof tothe reliablyEuropean matchParliament and of the facialCouncil1. image/ 1 Regulation (EU) 2016/679 of athe growingEuropean childParliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the imageprocessing storedof personal data and on the chip.free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).
Change 7
ChangedRecital 6: (6) In the interest of achieving a uniform approach at Union level and maximising gains in travel facilitation and economies of scale, a common technical solution for the creation, storage and submission of electronic travel data should be established, as opposed to each Member State developing their own. This application for the electronic submission of travel data (‘the EU Digital Travel application’) should consist of a user-friendly mobile application,application available in at least all official languages of the Union, a backend validation service that can verify the authenticity and integrity of travel documents and match the facial image of the user to the image stored on the travel document’s chip and a technical component for the secure communicationtransmission of travel data from the application to the receiving authority (‘Traveller Router’). In the longer term, the EU Digital(‘Digital Travel application could be developed with new functionalities with a view to establishing a comprehensive one-stopCredential shopRouter’). applicationThe atsource Unioncode levelof tothe increasesoftware easecomponents of travel for the travellersEU andDigital toTravel supportapplication externalshould borderbe management.open-source licensed.
Change 8
ChangedRecital 7: (7) The EU Digital Travel application should allow travellers to create a digital travel credential for single or multiple use and to retrieve of an already created digital travel credential. For reasons of security and for combatting identity fraud, the EU Digital Travel application backend validation service should be able to verify, before the creation of the digital travel credential, the authenticity and integrity of the travel document and verify that the user is the legitimate holder of the travel document by comparing the facial image stored on the chip of the travel document to the user’s live facial image. Digital travel credentials to be used several times should be ableable, based on the user's explicit consent, to be stored in the user’s European Digital Identity Wallet in accordance with Regulation (EU) No 910/2014 of the European Parliament and of the Council7 . Persons who do not havinguse a European Digital Identity Wallet established by that Regulation shouldor bedo ablenot wish to store thetheir digital travel credential in the Wallet should be able to store it locally in the mobile application.
Show 17 more changes
Change 9
RemovedRecital 8: (8) In order to support the carrying out of advance border checks on persons enjoying the right of free movement under Union law when these apply to them and the pre-clearance of third-country nationals, travellers using digital travel credentials should also declare, through the EU Digital Travel application, certain relevant travel data, such as the intended time of crossing the border and the Member State in which the external border is crossed. Such data should be strictly limited to what is necessary for the purpose of carrying out the border check, including for the purposes of supporting the verification of the fulfilment of entry conditions in accordance with Regulation (EU) 2016/399.
AddedRecital 7 a (new): (7a) The EU Digital Travel application should be compatible with EES, European Travel Information and Authorisation System (ETIAS) and advance passenger information system (API).
RemovedRecital 9: (9) The Traveller Router should transmit the travel data submitted by the traveller to the competent border authorities for the advance border check and pre-clearance. Consequently, Member States should be obliged to designate a Single Point of Contact for the border authorities authorised to receive such data.
AddedRecital 7 b (new): (7b) The mobile application should allow carriers to access the digital travel credential for the purposes of Regulations (EU) 2025/121 and (EU) 2025/132 of the European Parliament and of the Council, subject to the explicit consent of the user. Carriers should not be allowed to collect any biometric data in accordance with Regulations (EU) 2025/12 and (EU) 2025/13. / 1 Regulation (EU) 2025/12 of the European Parliament and of the Council of 19 December 2024 on the collection and transfer of advance passenger information for enhancing and facilitating external border checks, amending Regulations (EU) 2018/1726 and (EU) 2019/817, and repealing Council Directive 2004/82/EC (OJ L, 2025/12, 8.1.2025, ELI: http://data.europa.eu/eli/reg/2025/12/oj). / 2 Regulation (EU) 2025/13 of the European Parliament and of the Council of 19 December 2024 on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818 (OJ L, 2025/13, 8.1.2025, ELI: http://data.europa.eu/eli/reg/2025/13/oj).
RemovedRecital 10: (10) The creation, submission and use of digital travel credentials for the purpose of carrying out border checks impacts the right to privacy and the protection of personal data. In order to fully respect the fundamental rights of travellers, adequate limits and safeguards should be in place. Any data that is submitted by travellers to border authorities ahead of travel, and in particular personal data, should be strictly limited to what is necessary and proportionate to the objectives of increasing security, facilitating travel and ensuring the well-functioning of the Schengen area pursued by this Regulation. It should be guaranteed that the processing of data under this Regulation does not lead to any form of discrimination. No personal data should be stored at EU level beyond the stage that is necessary for its submission to the border authority.
AddedRecital 7 c (new): (7c) The EU Digital Travel application should not allow any third party access, including embedded software development kits, plugins, or embedded libraries that allow accessing, processing, transmitting or receiving any personal or technical data.
Show 49 more lines
RemovedRecital 10 a (new): (10a) The competent border authorities should delete the travel data transmitted in accordance with this Regulation, in an automated manner, from the database of the border crossing point immediately after the traveller has crossed the external border. Where the traveller, who has submitted travel data in accordance with this Regulation, does not cross the external border, the competent border authorities should delete, in an automated manner, the travel data transmitted 12 hours after the intended date and time of arrival or departure.
AddedRecital 8: (8) In order to support the carrying out of advance border checks on persons enjoying the right of free movement under Union law when these apply to them and the pre-clearance of third-country nationals, travellers using digital travel credentials should also declare, through the EU Digital Travel application, the intended time of crossing the border and the Member State in which the external border is crossed. Such data should be strictly limited to what is necessary for the purpose of carrying out the border check in accordance with Regulation (EU) 2016/399.
RemovedRecital 13: (13) The European Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) established by Regulation (EU) 2018/1726 of the European Parliament and of the Council10 should be responsible for the development and maintenance of the EU Digital Travel application. Consequently, eu-LISA should put in place the necessary measures for the operational management of the EU Digital Travel application, including for the development, monitoring and reporting of the system. Before the start of operation of the EU Digital Travel application, a test should be carried out in accordance with the technical specifications by eu-LISA in cooperation with the relevant authorities. eu-LISA should also collect statistics on the use of the EU Digital Travel application for the sole purpose of evaluating the effectiveness of this Regulation.
AddedRecital 9: (9) The Digital Travel Credential Router should transmit the end-to-end encrypted travel data submitted by the traveller to the competent border authorities for the advance border check and pre-clearance. Consequently, Member States should be obliged to designate a Single Point of Contact for the border authorities authorised to receive such data.
RemovedRecital 15: (15) In order to increase public awareness of digital travel credentials and to promote the uptake of their use, the Commission should, together with eu-LISA, the European Border and Coast Guard Agency and national border authorities carry out information campaigns on the objectives, use and other important aspects, including on data protection and data security, of the EU Digital Travel application. The information campaigns should also include practical information on the scanning of the chip in the travel document to ensure the correct functioning of the EU Digital Travel application.
AddedRecital 10: (10) The creation, submission and use of digital travel credentials for the purpose of carrying out border checks impacts the right to privacy and the protection of personal data. In order to fully respect the fundamental rights of travellers, adequate limits and safeguards should be in place. Any data that is submitted by travellers to border authorities ahead of travel, and in particular personal data, should be strictly limited to what is necessary and proportionate to the objectives of increasing security, facilitating travel and ensuring the well-functioning of the Schengen area pursued by this Regulation. The creation of the EU Digital Travel application should not, under any circumstances, impact or modify the rules and requirements on the exercise of the right to free movement within the Schengen area. It should be guaranteed that the processing of data under this Regulation does not lead to any form of discrimination, in particular against travellers who choose not to use digital travel credentials. No personal data should be stored at EU level. The Digital Travel Credential Router should transmit the travel data submitted by the traveller to the competent border authority immediately and in an automated manner, without modifying their content.
RemovedRecital 19: (19) In order to establish the Union standard specification for digital travel credentials based on travel documents, it is necessary to amend Regulation (EC) No 2252/2004. To boost the uptake of digital travel credentials, when applying for or renewing a travel document, applicants should be allowed to request that the competent authority issues, together with the physical document, a corresponding digital travel credential. They should also be able to make that request at any point in time. Holders of valid travel documents should also be able to create a digital travel credential based on their existing physical travel document. The digital travel credentials should also be storable in the European Digital Identity Wallet.
AddedRecital 10 a (new): (10a) The competent border authorities should delete the travel data transmitted in accordance with this Regulation, in an automated manner, from the national database of the border crossing point immediately after the traveller has crossed the external border. Where the traveller, who has submitted travel data in accordance with this Regulation, does not cross the external border, the competent border authorities should delete, in an automated manner, from the national database, the travel data transmitted 24 hours after the intended date and time of arrival or departure.
RemovedRecital 23: (23) The Commission should, two years after the start of operations of the EU Digital Travel application, and every four years thereafter, carry out an evaluation of that application and its use and prepare a report, including recommendations, to be submitted to the European Parliament, the Council, the European Data Protection Supervisor and the European Union Agency for Fundamental Rights. The evaluation and report should consider how the objectives of this regulation have been met and how, if at all, fundamental rights have been impacted.
AddedRecital 11: (11) Travellers should be free to choose whether they use a digital travel credential or a physical travel document for the purpose of undergoing border checks. Travellers have to carry a physical travel document in any event, even if they use a digital travel credential. They should be able to withdraw their consent for the processing of their personal data at any time without it affecting the eligibility to cross external borders. Any processing of personal data under this Regulation should be carried out in compliance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council8 and Regulation (EU) 2018/1725 of the European Parliament and of the Council9 , within their respective scope of application.
RemovedRecital 23 a (new): (23a) In order to amend the minimum age for the use of the EU Digital Travel application, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of granting the use of that application for the creation of digital travel credentials to persons under the age of 18, should the necessary technical requirements and any other relevant conditions be fulfilled, in particular as regards the facial image. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement 13 April 2016 on Better Law-Making1a. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts. / 1a OJ L 123, 12.5.2016, p. 1, ELI: http://data.europa.eu/eli/agree_interinstit/2016/512/oj.
AddedRecital 11 a (new): (11a) The application of this Regulation should not result in any form of discrimination against travellers who do not make use of the EU Digital Travel application.
RemovedRecital 25: (25) This Regulation should not affect the possibility to provide, under national law, for the use of digital travel credentials for other purposes than the carrying out of border checks, provided that such national law complies with Union law.
AddedRecital 11 b (new): (11b) In order to respect the voluntary nature of the EU Digital Travel application, travellers who do not wish to use the application, or who choose to withdraw their consent for processing of their personal data, should be able to rely on infrastructure that allows the use of a physical travel document to complete border checks. Member States should ensure the necessary infrastructure at the border crossing points, including manual processing and e-gates, which remain available and deliver comparable access, speed, and quality of service. This is essential to uphold parity and to ensure that consent to digital processing is truly free, informed, and revocable.
RemovedArticle 1 – paragraph 1 – point b: (b) the entry of self-declared travel data, pursuant to Article 5;
AddedRecital 11 c (new): (11c) The application of this Regulation should respect relevant Union law and fundamental rights, as enshrined in the Charter of Fundamental Rights of the European Union (the ‘Charter’), including the right to respect for one’s private life and to the protection of personal data. Particular attention should be paid to vulnerable persons including persons with disabilities, elderly people and persons with limited resources or limited digital skills.
RemovedArticle 2 – paragraph 1 – point a a (new): (aa) ‘border authority’ means the border guard assigned, in accordance with national law, to carry out border checks as defined in Article 2, point (14), of Regulation (EU) 2016/399;
AddedRecital 12: (12) In the interest of ensuring compliance with the fundamental right to privacy and the protection of personal data and to promote legal clarity, the controller and processor should be identified. To ensure adequate safeguards and security, all transmission between the Digital Travel Credential Router and the competent authority should be protected by strong encryption methods so that any potential data breaches would not involve the disclosure of data that can be traced back to a person. For that reason, when designing and developing the router, the European Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) should ensure that any data transmitted by the EU Digital Travel application to competent border authorities is encrypted from end-to-end by design and by default, in order to take account of the sensitivity of the data and to prevent and minimize the impact of security incidents on users and the system as a whole. Member States should also provide adequate training, covering data security and data protection aspects, to the staff of border authorities before they can process data transmitted through the EU Digital Travel application.
RemovedArticle 2 – paragraph 1 – point c a (new): (ca) ‘travel data’ means the data to be submitted by the traveller for the purpose of this Regulation as defined in Article 5.
AddedRecital 13: (13) The European Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) established by Regulation (EU) 2018/1726 of the European Parliament and of the Council10 should be responsible for the development and maintenance of the EU Digital Travel application. Consequently, eu-LISA should put in place the necessary measures for the operational management of the EU Digital Travel application, including for the development, monitoring and reporting of the system. The eu-LISA budget allocated to that purpose should comply with the principles of economy, efficiency and effectiveness. Before the start of operation of the EU Digital Travel application, a test should be carried out in accordance with the technical specifications by eu-LISA in cooperation with the relevant authorities. eu-LISA should also collect statistics on the use of the EU Digital Travel application.
RemovedArticle 2 – paragraph 1 – point d: (d) ‘Traveller Router’ means the technical component referred to in Article 6 enabling the transmission of the travel data submitted by the traveller to the competent border authority.
AddedRecital 13 a (new): (13a) Where the conditions set out in Regulation (EU) 2016/679 require that a data protection impact assessment be carried out, the competent border authorities should carry out that assessment before eu-LISA conducts the test of the EU Digital Travel application.
RemovedArticle 3 – paragraph 1 – point a: (a) a mobile application, enabling the creation and submission of the digital travel credentials for single or multiple use, and the entry and submission of the self-declared travel data;
AddedRecital 13 b (new): (13b) eu-LISA should also collect and publish statistics including on the number of users of the EU Digital Travel application, for the sole purpose of evaluating the usability of the mobile application and the effectiveness of this Regulation, without allowing for the identification of any traveller.
AddedRecital 14: (14) While eu-LISA should be responsible for the overall development, operation and maintenance of the EU Digital Travel application, including the Digital Travel Credential Router that transmits the travel data to the competent authorities, each Member State should be responsible for ensuring, at national level, a secure connection in its national system in order to receive the travel data, including the development, operation and maintenance of that connection. Member States should be responsible for the management and arrangements for access of duly authorised staff of border authorities to the travel data. Member States should ensure the one-to-one verification through e-gates, as defined in Regulation (EU) 2016/399, or through any other infrastructure, between the individual traveller’s identity and their travel document for the purpose of carrying out border checks.
AddedRecital 15: (15) In order to increase public awareness of digital travel credentials and to promote the uptake of their use, the Commission should, together with eu-LISA, the European Border and Coast Guard Agency and national border authorities carry out information campaigns, informing the public, including third country nationals, about the objectives, use and other important aspects, including data protection, right to withdraw consent and data security, of the EU Digital Travel application. Information campaigns should be adapted to the specific circumstances of each Member State taking into account the varying stages of national implementation. The Commission should use a cost-effective approach regarding such campaigns.
AddedRecital 15 a (new): (15a) The information campaigns should also include practical information on how to scan the chip of the travel document in order to ensure the correct use of the EU Digital Travel application. Special attention should be given to ensuring that travellers who are not technologically proficient are clearly informed about the benefits of the application and are provided with accessible, practical guidance on how to use the EU Digital Travel application safely and securely.
AddedRecital 16: (16) In view of the Union interests at stake, the costs incurred by eu-LISA for the performance of its tasks under this Regulation and Regulation (EU) 2018/1726 in respect of the development, operation, maintenance and overall management of the EU Digital Travel application should be borne by the Union budget. Member States should remain liable for the costs incurred at national level for developing, operating and maintaining the secure connection for the reception of the travel data transmitted via the Digital Travel Credential Router.
AddedRecital 19: (19) In order to establish the Union standard specification for digital travel credentials based on travel documents, it is necessary to amend Regulation (EC) No 2252/2004. When applying for or renewing a travel document, the competent authority should automatically issue, together with the physical document, a corresponding digital travel credential. Holders of valid travel documents should also be able to create upon request to the competent authority a digital travel credential based on their existing physical travel document. They should be able to make that request at any point in time. Holders of valid travel documents should also be able to create a digital travel credential based on their existing physical travel document through the EU Digital Travel application. The digital travel credential should also be storable, at the request of the person concerned, in the European Digital Identity Wallet, as qualified electronic attestation of attributes within the meaning of Article 3, point 45, of Regulation (EU) No 910/2014.
AddedRecital 21: (21) While the use of digital travel credentials should be voluntary for travellers, in order to achieve the objectives of increasing security throughout the Schengen area, and to facilitate travel, all Member States should be obliged to allow travellers to use digital travel credentials for the purpose of crossing external borders once the EU Digital Travel application is operational. Before that, Member States may develop national solutions for the use of digital travel credentials, in accordance with the uniform format, for the purpose of border checks.
AddedRecital 22: (22) To further speed up processes and reduce overall time spent at border-crossing points, third-country nationals subject to the Entry/Exit System should be allowed to use the EU Digital Travel application for pre-enrolling certain data required for the border-crossing.
AddedRecital 23: (23) The Commission should, two years after the start of operations of the EU Digital Travel application, and every four years thereafter, carry out an evaluation of that application and its use and prepare a report, including recommendations, to be submitted to the European Parliament, the Council, the European Data Protection Supervisor and the European Union Agency for Fundamental Rights. The evaluation and report should consider how the objectives of this regulation have been met and how, fundamental rights have been impacted.
AddedRecital 23 a (new): (23a) In order to amend the minimum age for the use of the EU Digital Travel application, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of granting the use of that application for the creation of digital travel credentials to persons under the age of 16, should the necessary technical requirements and any other relevant conditions be fulfilled, in particular as regards the facial image. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement 13 April 2016 on Better Law-Making. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.
AddedRecital 24: (24) In order to ensure uniform conditions for the implementation of this Regulation, as regards the technical standard for digital travel credentials, the technical architecture and technical specifications for the EU Digital Travel application and its testing, the collection of statistics, the start of operations of the EU Digital Travel application as well as the standards with regard to technology, methods and procedures to be used for the verification of the authenticity and validity of travel documents and digital travel credentials, implementing powers should be conferred on the Commission. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council11 .
AddedRecital 25: deleted
AddedRecital 26: (26) Since the objectives of this Regulation, notably increasing security and facilitating travel in the context of external border management cannot be sufficiently achieved by the Member States, but can rather, by reason of their inherently cross-border nature, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on the European Union. In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve those objectives.
AddedRecital 28: (28) This Regulation constitutes a development of the provisions of the Schengen acquis in which Ireland does not take part in accordance with Protocol No 19 on the Schengen acquis integrated into the framework of the European Union, annexed to the Treaty on European Union and the Treaty on the Functioning of the European Union, and, subject to the application of Article 4 of that Protocol, Ireland is not bound by it or subject to its application. / (deleted)
AddedRecital 33: (33) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 and delivered an opinion on 4 December 2024 19 ,
AddedArticle 1 – paragraph 1 – point a: (a) the creation of digital travel credentials;
AddedArticle 1 – paragraph 1 – point b: (b) the entry of self-declared data;
AddedArticle 1 – paragraph 1 – point c: (c) the secure submission of digital travel credentials and the self-declared data to the competent authority for the purposes of facilitating travel and of carrying out border checks on persons in accordance with Article 8(2g) and (3), point (j), of Regulation (EU) 2016/399.
AddedArticle 2 – paragraph 1 – point a a (new): (aa) ‘border authority’ means the authority of the Member State that carries out border control as defined in Article 2, point (10), of Regulation (EU) 2016/399 and that is authorised to receive and process travel data for the purposes of this Regulation;
AddedArticle 2 – paragraph 1 – point c a (new): (ca) “digital travel credentials” means the digital representation of a person’s identity as defined in Article 2, point 31, of Regulation (EU) 2016/399;
AddedArticle 2 – paragraph 1 – point c b (new): (cb) “self-declared data” means the data to be submitted by the traveller as set out in Article 5 of this Regulation;
AddedArticle 2 – paragraph 1 – point c c (new): (cc) ‘travel data’ means the data to be submitted by the traveller for the purpose of this Regulation including the digital travel credential and the self-declared data;
AddedArticle 2 – paragraph 1 – point d: (d) ‘Digital Travel Credential Router’ means the technical component referred to in Article 6 enabling the encrypted transmission of the travel data submitted by the traveller to the competent border authority.
AddedArticle 2 – paragraph 1 – point d a (new): (da) ‘e-gate’ means the infrastructure as defined in Article 2, point (24), of Regulation (EU) 2016/399;
AddedArticle 2 – paragraph 1 – point d b (new): (db) 'national database' means a database in a Member State specifically dedicated to the temporary storage of the pre-submitted digital travel credential and the self-declared data sent by the traveller to the competent border authority of that Member State in accordance with and for the purpose of this Regulation;
AddedArticle 3 – paragraph 1 – point a: (a) a mobile application, enabling the creation, storage and submission of the digital travel credential for single or multiple use, and the entry and submission of the self-declared data;
Change 10
ChangedArticle 3 – paragraph 1 – point c: (c) a TravellerDigital Travel Credential Router, which shall ensure secure and end-to-end encrypted transmission of the travel data, pursuant to Article 5, between the mobile application and the receivingcompetent border authority.
Change 11
RemovedArticle 4 – paragraph 1 – introductory part: 1. Persons enjoying the right of free movement under Union law, who are over the age of 18 and in possession of any of the following travel documents, may use the EU Digital Travel application to create a digital travel credential based on that travel document for single or multiple use:
AddedArticle 3 – paragraph 1 a (new): The source code of the software components of the EU Digital Travel application shall be open-source licensed.
Change 12
ChangedArticle 4 – paragraph 4:1 4.– Third-countryintroductory nationalspart: who1. arePersons inenjoying possessionthe ofright aof travelfree documentmovement containingunder aUnion chip,law andwho technologyare preventingover itsthe cloning,age may,of subject16 toand thein availabilitypossession of valid certificates necessaryany forof the checkingfollowing oftravel itsdocuments authenticity,may use the EU Digital Travel application to create a digital travel credential based on that travel document for single or multiple use.use:
Change 13
ChangedArticle 4 – paragraph 5: 5.1 Before– thepoint creationc: of(c) a digital travel credential,document inthat accordancecontains withthe paragraphssame 1data, and 4, the EU Digitala Travelchip applicationcontaining shallreliable verifytechnology thepreventing integrityits andcloning, authenticitythat ofis thebased chipon oftechnical thespecifications travelcompatible documentwith andthose matchprovided thefor facialby imageRegulation of(EC) theNo person2252/2004 seekingand toallowing createfor the digital travel credential against theverification facialof imageits storedauthenticity, onvalidity theand chip.integrity.
Change 14
RemovedArticle 4 – paragraph 6 a (new): 6a. The choice of the traveller not to use the EU Digital Travel application shall not lead to any discrimination against that traveller.
AddedArticle 4 – paragraph 2: 2. The EU Digital Travel application shall provide for the possibility, based on the explicit consent of the user, to store a digital travel credential for multiple use in the mobile application in accordance with Article 7b, and in the European Digital Identity Wallet, as qualified electronic attestation of attributes within the meaning of Article 3, point 45, of Regulation (EU) No 910/2014.
Change 15
ChangedArticle 4 – paragraph 74: a4. (new):Third-country 7a.nationals Thewho Commissionare isover empoweredthe toage adoptof delegated16 actsand who are in accordancepossession withof Articlea 15atravel indocument ordercontaining toa amendchip, thethat minimumis agebased referredon totechnical inspecifications paragraphand 1security ofstandards thiscompatible Article,with those provided thatfor thein necessaryRegulation technical(EC) requirementsNo 2252/2004, and anythat othercontain relevantreliable conditionstechnology forpreventing grantingits digitalcloning, travelshall, credentialssubject to personsthe underavailability of valid certificates necessary for the agechecking of 18,its inauthenticity, particularhave asthe regardspossibility to use the facialEU image,Digital areTravel met.application to create a digital travel credential for single or multiple use.
Change 16
RemovedArticle 5 – paragraph 2 – point a: (a) flight identification number, cruise line registration number, ship identification number;
AddedArticle 4 – paragraph 5: 5. Before the creation of a digital travel credential in accordance with paragraphs 1 and 4, the EU Digital Travel application shall verify the integrity and authenticity of the chip of the travel document and match the facial image of the person seeking to create the digital travel credential against the facial image stored on the chip.
RemovedArticle 5 – paragraph 3 a (new): 3a. The travel data shall be submitted no earlier than 48 hours before the intended arrival or departure.
AddedArticle 4 – paragraph 6: 6. The use of the EU Digital Travel application, the creation and use of digital travel credentials by persons enjoying the right of free movement under Union law and third-country nationals, and the temporary storage of the digital travel credential in the national database shall be voluntary and based on their consent. The use of the EU Digital Travel application is without prejudice to the application of Article 6 of Regulation (EU) 2016/399.
RemovedArticle 6 – paragraph 1: 1. The Traveller Router shall transmit the travel data submitted by the traveller to the competent border authority in accordance with Articles 7b and 7c and the technical specifications adopted in accordance with Article 16(1), point (a).
AddedArticle 4 – paragraph 6 a (new): 6a. The choice of the traveller not to use the EU Digital Travel application shall not lead to any discrimination or practical constraints against that traveller.
Show 24 more lines
RemovedArticle 6 – paragraph 2: 2. Member States shall designate the Single Point of Contact from the competent border authorities authorised to receive the travel data transmitted to them from the Traveller Router in accordance with this Regulation. They shall notify, by [the entry into operation of the EU Digital Travel application], eu-LISA of the name and contact details of the competent border authorities and shall, where necessary, update the notified information.
AddedArticle 4 – paragraph 7 a (new): 7a. The Commission is empowered to adopt delegated acts in accordance with Article 15a in order to amend the minimum age referred to in paragraph 1 and paragraph 4 of this Article, provided that the necessary technical requirements and any other relevant conditions for granting digital travel credentials to persons under the age of 16, in particular as regards the facial image, are met.
RemovedArticle 7 a (new): Article 7a / Deletion of travel data / 1. The competent border authorities shall delete the travel data transmitted in accordance with this Regulation, in an automated manner, from the database of the border crossing point immediately after the traveller has crossed the external border. / 2. Where the traveller, who has submitted travel data in accordance with this Regulation, does not cross the external border, the competent border authorities shall delete, in an automated manner, the travel data transmitted 12 hours after the intended date and time of arrival or departure.
AddedArticle 5 – paragraph 1 – point b: (b) the following self-declared data: / (i) intended date and time of arrival or departure; / (ii) the Member State in which the external border is crossed;
RemovedArticle 7 b (new): Article 7b / Mobile application / 1. The mobile application referred to in Article 3, point (a) shall enable the creation and submission of digital travel credentials for single or multiple use, and the entry and submission of self-declared travel data. / 2. The mobile application shall have privacy and data protection by design, taking into account the state of the art in security and safety of the data it contains. / 3. The mobile application shall be easily accessible to users and free of charge. Specific attention shall be paid to the accessibility of the mobile application for persons with disabilities. / 4. The mobile application shall be available at least in all the official languages of the Member States. / 5. The use of the mobile application shall be subject to high security standards to ensure that any unauthorised access or use is not possible. / 6. The mobile application shall contain practical information regarding the scanning of the chip in the travel document and the purposes of the EU digital travel application. / 7. The technical specifications of the mobile application shall be adopted in accordance with Article 16(1), point (a).
AddedArticle 5 – paragraph 1 – point c: deleted
RemovedArticle 7 c (new): Article 7c / Traveller Router / 1. The Traveller Router referred to in Article 3, point (c), shall ensure secure and encrypted communication between the mobile application and the competent border authority. / 2. Member States shall ensure a secure connection between its national system and the Traveller Router. / 3. eu-LISA shall ensure that the Traveller Router is designed and developed in such a manner that the Traveller Router provides the functionalities specified in this Regulation. / 4. eu-LISA shall host the Traveller router in its technical sites. / 5. eu-LISA shall be responsible for the technical management of the Traveller Router, including its maintenance and technical developments, in such a manner as to ensure that the data are securely, effectively and swiftly transmitted through the Traveller Router, in compliance with this Regulation. / 6. eu-LISA’s staff shall not have access to any of the data that are transmitted through the Traveller Router. However, that prohibition shall not preclude eu-LISA’s staff from having such access insofar as strictly necessary for the maintenance and technical management of the Traveller Router. / 7. eu-LISA shall, upon the request of the relevant Member States’ authorities, provide training to them on the technical use of the router and on their connection to and integration with the Traveller Router. / 8. The technical specifications of the Traveller Router shall be adopted in accordance with Article 16(1), point (a).
AddedArticle 5 – paragraph 2 – introductory part: 2. The self-declared data may also consist, for the purpose of facilitating travel and carrying out border checks, where applicable, of the following information relating to each traveller:
AddedArticle 5 – paragraph 2 – point a: (a) flight identification number, cruise line registration number, ship identification number and border-crossing point;
AddedArticle 5 – paragraph 3: 3. The travel data referred to in paragraph 1 shall be strictly limited to what is necessary for the purpose of carrying out border checks in accordance with Regulation (EU) 2016/399.
AddedArticle 5 – paragraph 3 a (new): 3a. No additional personal data may be processed other than those declared pursuant to paragraphs 1 and 2.
AddedArticle 5 – paragraph 3 b (new): 3b. The travel data shall be submitted no earlier than 48 hours before the intended date and time of arrival or departure.
AddedArticle 6 – paragraph 1: 1. The Digital Travel Credential Router shall transmit the travel data submitted by the traveller to the competent border authority in accordance with Articles 7b and 7c. It shall transmit those data immediately and in an automated manner, without changing their content and in accordance with the technical specifications adopted in accordance with Article 16(1), point (a).
AddedArticle 6 – paragraph 2: 2. Member States shall designate a Single Point of Contact from the competent border authorities authorised to receive the travel data transmitted to them through the Digital Travel Credential Router in accordance with this Regulation. They shall notify, by [the date of entry into operation of the EU Digital Travel application], eu-LISA and the Commission of the name and contact details of the competent border authorities and shall, where necessary, notify them of any updates to that information. The Commission shall, on the basis of those notifications and updates, compile and make publicly available a list of the notified competent border authorities, including their contact details.
AddedArticle 7 – paragraph 1: 1. The competent border authorities shall be data controllers, within the meaning of Article 4, point 7, of Regulation (EU) 2016/679 in relation to the processing of travel data, constituting personal data, received through or stored in the Digital Travel Credential Router, the mobile application and the backend validation service.
AddedArticle 7 – paragraph 2: 2. Each Member State shall designate a competent border authority as data controller and communicate those authorities to the Commission, eu-LISA and the other Member States.
AddedArticle 7 – paragraph 3: 3. eu-LISA shall be the data processor within the meaning of Article 3, point 12, of Regulation (EU) 2018/1725 for the processing of travel data constituting personal data, received through the Digital Travel Credential Router, the mobile application and the backend validation service.
AddedArticle 7 – paragraph 3 a (new): 3a. When acting as a processor in accordance with paragraph 3, eu-LISA shall not engage another processor or transfer any personal data to a third country or an international organisation.
AddedArticle 7 – paragraph 4: 4. No personal data shall be stored on the backend validation service or the Digital Travel Credential Router beyond what is necessary for the creation of the digital travel credential and transmission of the travel data to the competent border authorities.
AddedArticle 7 – paragraph 4 a (new): 4a. The supervisory authorities referred to in Article 51 of Regulation (EU) 2016/679 shall carry out an audit of processing operations of travel data constituting personal data which have been performed by the competent border authorities for the purposes of this Regulation at least once every four years. The European Data Protection Supervisor shall carry out an audit of processing operations of travel data constituting personal data which have been performed by eu-LISA for the purposes of this Regulation, in accordance with relevant international auditing standards at least once every two years.
AddedArticle 7 – paragraph 5: 5. Users of the EU Digital Travel application shall be able to withdraw their consent to process their personal data on the EU Digital Travel application at any time, without detriment to the user. Upon the withdrawal of consent, all personal data, including biometric data provided or processed through the EU Digital Travel application shall be deleted from all the storage locations, including the mobile application, the Digital Traveller Credential Router and the national databases, without undue delay, unless retention is required by law.
AddedArticle 7 a (new): Article 7a / Deletion of travel data / 1. The competent border authorities shall delete the travel data transmitted in accordance with this Regulation, in an automated manner, from the national database of the border-crossing point immediately after the traveller has crossed the external border. / 2. Where the traveller, who has submitted travel data in accordance with this Regulation, does not cross the external border, the competent border authorities shall delete, in an automated manner, from the national database, the travel data transmitted 24 hours after the intended date and time of arrival or departure. / 3. Without prejudice to the powers conferred on the European Data Protection Supervisor by Regulation (EU) 2018/1725, the European Data Protection Supervisor shall have the right to access logs, audit records and system configurations to verify compliance with that Regulation.
AddedArticle 7 b (new): Article 7b / Mobile application / 1. The mobile application referred to in Article 3, point (a) shall enable the creation, submission and storage of digital travel credentials for single or multiple use, and the entry and submission of self-declared data. / 2. The mobile application shall respect privacy and data protection by design and by default, taking into account the state of the art in security and the safety of the data it contains. The mobile application shall be subject to high security standards to ensure that unauthorised access or unauthorised use is not possible. / 3. The mobile application shall allow carriers to access the digital travel credential for the purposes of Regulations (EU) 2025/12 and (EU) 2025/13, subject to the explicit consent of the user. Carriers accessing the digital travel credential shall not be allowed to collect any biometric data in accordance with Regulations (EU) 2025/12 and (EU) 2025/13. / 4. The mobile application shall be easily accessible to users and free of charge. Specific attention shall be paid to the accessibility of the mobile application for vulnerable persons. / 5. The mobile application shall be available at least in all official languages of the European Union. / 6. The use of end-to-end encryption shall be mandatory for every data submission through the application, in order to take account of the sensitivity of the data concerned. / 7. The mobile application shall contain practical information regarding the scanning of…
AddedArticle 7 c (new): Article 7c / Digital Travel Credential Router / 1. The Digital Travel Credential Router referred to in Article 3, point (c), shall ensure secure and end-to-end encrypted transmission of travel data between the mobile application and the competent border authority. / 2. Member States shall ensure a secure connection between their national database and the Digital Travel Credential Router to receive data transmitted through the Digital Travel Credential Router to the competent border authorities; / 3. eu-LISA shall ensure that the Digital Travel Credential Router is designed and developed in such a manner that the Digital Travel Credential Router provides the functionalities specified in this Regulation. The router shall, where appropriate and to the extent technically possible, share and reuse the technical components, including hardware and software components, referred to in Regulation (EU) 2025/12. / 4. eu-LISA shall host the Digital Travel Credential router in its technical sites. / 5. eu-LISA shall be responsible for the technical management of the Digital Travel Credential Router, including its maintenance and technical developments, in such a manner as to ensure that the data are securely, effectively and swiftly transmitted through the Digital Travel Credential Router, in accordance with this Regulation. / 6. eu-LISA’s staff shall not have access to any of the data that are transmitted through the Digital Travel Credential Router. However, that prohibition shall not pr…
Change 17
AddedArticle 8 – paragraph 3: 3. eu-LISA shall ensure the operational management of the EU Digital Travel application as well as its “state of the art” security. The EU Digital Travel application shall be hosted by eu-LISA.
Change 18
ChangedArticle 8 – paragraph 5: 5. Where eu-LISA considers that the development of the EU Digital Travel application has been completed, it shall, withoutno unduelater delay,than one year after the entry into force of this Regulation, conduct a test of the application in cooperation with the competent border authorities and other relevant Member States’ authorities, in accordance with the technical specifications adopted pursuant to Article 16(1), point (c), and inform the European ParliamentParliament, the Council and the Commission of the outcome of that test.
Change 19
RemovedArticle 8 – paragraph 6: 6. eu-LISA shall collect statistics, for the sole purpose of evaluating the effectiveness of this Regulation, on the use of the EU Digital Travel application in accordance with Article 16(1), point (b), without such statistics allowing for the identification of the traveller concerned.
AddedArticle 8 – paragraph 5 a (new): 5a. Where the conditions set out in Article 35 of Regulation (EU) 2016/679 require that a data protection impact assessment be carried out, the competent border authorities referred to in Article 7(1) of this Regulation shall carry out that assessment before eu-LISA conducts the test referred to in paragraph 5.
RemovedArticle 8 a (new): Article 8a / Fundamental rights / Collection and processing of personal data in the context of this Regulation shall not result in discrimination against persons on the grounds listed in Article 21 of the Charter of Fundamental Rights of the European Union (the ‘Charter’). / It shall fully respect relevant Union law and fundamental rights, as enshrined in the Charter, including the right to respect for one’s private life and to the protection of personal data. / Particular attention shall be paid to vulnerable persons. / This Regulation shall respect freedom of movement.
AddedArticle 8 – paragraph 6: 6. eu-LISA shall collect and publish statistics, including on the number of users of the EU Digital Travel application, for the sole purpose of evaluating the usability of the mobile application and the effectiveness of this Regulation, in accordance with Article 16(1), point (b). Such statistics shall not allow for the identification of individual travellers.
Change 20
ChangedArticle 108 – paragraph 16 a (new): The information6a. campaignseu-LISA shall alsoensure includethat practicalthe informationEU onDigital theTravel scanningapplication ofdoes thenot chiptransfer ofor thedisclose travelany documentinformation toregarding ensureits theuse, correctperformance, or functioning ofto theany application.third party, other than those provided for in this Regulation.
Change 21
AddedArticle 8 – paragraph 7: 7. eu-LISA shall perform tasks related to the provision of training of the competent national authorities on the technical use of the EU Digital Travel application.
AddedArticle 8 – paragraph 7 a (new): 7a. eu-LISA shall conduct a penetration test and vulnerability assessment of the EU Digital Travel application within two years after the start of operations of the EU Digital Travel application and every four years thereafter. It shall, in case of a change to the system architecture of the EU Digital Travel application, or a potential or actual breach of that application that could impact data protection, update the data protection impact assessment accordingly.
AddedArticle 8 a (new): Article 8a / Fundamental rights / The application of this Regulation shall fully respect relevant Union law and fundamental rights, as enshrined in the Charter of Fundamental Rights of the European Union (the ‘Charter’), including the right to respect for one’s private life and to the protection of personal data. / Collection and processing of personal data for the purpose of this Regulation shall not result in discrimination against persons on the grounds listed in Article 21 of the Charter. / Particular attention shall be paid to vulnerable persons.
AddedArticle 9 – paragraph 1 – point a: (a) ensuring a secure connection between their national database and the Digital Travel Credential Router to receive data transmitted through the Digital Travel Credential Router to the competent border authorities;
AddedArticle 9 – paragraph 1 – point b a (new): (ba) ensuring the one-to-one verification through e-gates, as defined in Article 2, point (24), of Regulation (EU) 2016/399, or through any other infrastructure, between the individual traveller’s identity and their travel document for the purpose of carrying out border checks;
AddedArticle 9 – paragraph 1 – point c: (c) the management of and arrangements for access of duly authorised staff of border authorities to the data received through the Digital Travel Credential Router for the purpose of carrying out border checks in accordance with Regulation (EU) 2016/399.
Show 11 more lines
AddedArticle 9 – paragraph 2: 2. Each Member State shall provide the staff of border authorities who have a right to access the data transmitted through the Digital Travel Credential Router with appropriate training covering, in particular, data security and data protection rules and applicable fundamental rights before authorising them to process such data.
AddedArticle 9 – paragraph 2 a (new): 2a. Each Member State shall ensure that travellers who do not wish to use the EU Digital Travel application or who withdraw their consent to their data being processed are provided with the necessary infrastructure to complete border checks using a physical travel document. Member States shall also ensure that the use of that infrastructure is not discouraged or made disadvantageous compared to the use of the EU Digital Travel application to complete border checks.
AddedArticle 9 – paragraph 2 b (new): 2b. This Regulation does not replace the existence of physical travel documents or the right to use such documents on their own.
AddedArticle 10 – paragraph 1: The Commission shall, in cooperation with eu-LISA, the European Border and Coast Guard Agency and national border authorities, support the start of operation of the EU Digital Travel application with an information campaign, informing the public, including third-country nationals, about the objectives, purposes, the main processing operations and other data protection and data security aspects, including the right to withdraw consent, and use cases of the EU Digital Travel application. The Commission shall use a cost-effective approach regarding that information campaign.
AddedArticle 10 – paragraph 1 a (new): The information campaign shall also include practical information on how to scan the chip of the travel document in order to ensure the correct use of the application.
AddedArticle 11 – paragraph 1: 1. Costs incurred by eu-LISA in relation to the development, operation, hosting and technical management of the EU Digital Travel application under this Regulation shall be borne by the general budget of the Union. The eu-LISA budget shall comply with the principles of economy, efficiency and effectiveness.
AddedArticle 11 – paragraph 2: 2. Costs incurred by Member States in relation to the development, operation and maintenance of their secure connections to receive data transmitted through the Digital Travel Credential Router shall be borne by Member States.
AddedRegulation (EC) No 2252/2024
AddedArticle 12 – paragraph 1 – point 1, Article 1– paragraph 1a – subparagraph 1 – introductory part: Passports and travel documents newly issued by Member States to their own nationals who are over the age of 16, or upon request from the applicant, passports and travel documents previously issued by Member States to their own nationals who are over the age of 16 shall be accompanied by a digital travel credential, which shall:
AddedRegulation (EC) No 2252/2024
AddedArticle 12 – paragraph 1 – point 1, Article 1 – paragraph 1a – subparagraph 1 – point b: (b) be in a format that enables their storage in the European Digital Identity Wallets, as qualified electronic attestation of attributes, provisions for which are laid down in Regulation (EU) No 910/2014 of the European Parliament and of the Council*;
Change 22
AddedRegulation (EC) No 2252/2024
AddedArticle 12 – paragraph 1 – point 1, Article 1 – paragraph 1a – subparagraph 3 b (new): The Commission is empowered to adopt delegated acts in accordance with Article 15a of Regulation (EU) .../2025 of the European Parliament and of the Council [EU Digital Travel application Regulation] in order to amend the minimum age referred to in paragraph 1 of this Article, provided that the necessary technical requirements and any other relevant conditions for granting digital travel credentials to persons under the age of 16, in particular as regards the facial image, are met.
Change 23
RemovedArticle 12 – paragraph 1 – point 3, Article 4 – paragraph 4: 4. Member States shall allow air carriers, for the purposes of Regulations (EU) 2025/12 and (EU) 2025/13, involved in the process of crossing the external borders, to access the storage medium in passports and travel documents, with the exception of fingerprints, with the consent of the person to whom the passport or travel document has been issued.
AddedArticle 12 – paragraph 1 – point 3, Article 4 – paragraph 4: deleted / (deleted)
RemovedArticle 15 – paragraph 1: 1. The Commission shall determine the date from which the EU Digital Travel application starts operations by means of an implementing act once eu-LISA has informed the European Parliament and the Commission of the successful completion of the test of the application referred to in Article 8(5).
AddedRegulation (EU) 2016/399
AddedArticle 13 – paragraph 1 – point 2 – point d, Article 8 – paragraph 10: 10. The Commission shall adopt implementing acts to establish minimum standards with regard to technology, methods and procedures to be used for the verification of the authenticity and validity of travel documents, and digital travel credentials according to this Article.
AddedRegulation (EU) 2016/399
Show 5 more lines
AddedArticle 13 – paragraph 1 – point 3, Article 8a – paragraph 4a: deleted / (deleted) / (deleted) / (deleted) / (deleted)
AddedArticle 15 – paragraph 1: 1. The Commission shall determine the date from which the EU Digital Travel application starts operations by means of an implementing act once eu-LISA has informed the European Parliament, the Council and the Commission of the successful completion of the test of the application referred to in Article 8(5).
AddedArticle 15 – paragraph 1 a (new): 1a. The successful completion of the test of the EU Digital Travel application by eu-LISA shall be no later than one year after the entry into force of this Regulation.
AddedArticle 15 – paragraph 1 b (new): 1b. The date determined by the implementing act referred to in paragraph 1 shall be no later than 6 months after the successful completion of the test of the EU Digital Travel application.
AddedArticle 15 – paragraph 2: deleted
Change 24
ChangedArticle 16 – paragraph 1 – point b:a: (b)(a) establish the statisticstechnical toarchitecture beof collectedthe byEU eu-LISA,Digital forTravel theapplication soleand purposeestablish ofthe evaluatingtechnical specifications for the effectivenessmobile ofapplication, thisbackend Regulation,services withoutand allowingDigital forTraveller Credential Router, ensuring the identificationhighest standards of anysecurity traveller,and ondata theprotection, useand ofcompatibility thewith EUEES, DigitalETIAS Traveland application;API;
Change 25
RemovedArticle 18 – paragraph 5: 5. By… [two years after the start of operations of the EU Digital Travel application] and every four years thereafter, the Commission shall conduct an overall evaluation of the EU Digital Travel application and its use. The overall evaluation report established on this basis shall include an assessment of the application of this Regulation and an examination of results that have been achieved relative to the objectives that were set and of the impact on fundamental rights. The report shall also include an overall assessment of whether the underlying rationale for operating the EU Digital Travel application continues to hold, of the appropriateness of the technical features of the application, of the security of the application and of any implications for future operations. The evaluation shall include necessary recommendations. The Commission shall transmit the report to the European Parliament, the Council, the European Data Protection Supervisor and the European Union Agency for Fundamental Rights.
AddedArticle 16 – paragraph 1 – point b: (b) establish the statistics to be collected and published by eu-LISA, including on the number of users of the EU Digital Travel application, for the sole purpose of evaluating the usability of the mobile application and effectiveness of this Regulation, without allowing for the identification of any traveller, on the use of the EU Digital Travel application;
AddedArticle 18 – paragraph 1: 1. eu-LISA shall put in place procedures to monitor the development of the EU Digital Travel application in light of the objectives relating to planning and costs and to monitor the functioning of the EU Digital Travel application in light of the objectives relating to the technical output, cost-effectiveness, security and quality of service.
AddedArticle 18 – paragraph 3: 3. The report referred to in paragraph 2 shall include detailed information about the costs incurred and information as to any risks which may impact the overall costs of the EU Digital Travel application to be borne by the general budget of the Union. The report shall also include detailed information about the technical implementation of the project and any technical problems and risks that may impact the security of travel data or the overall development and entry into operations of the EU Digital Travel application.
AddedArticle 18 – paragraph 5: 5. By… [two years from the start of operations of the EU Digital Travel application] and every four years thereafter, the Commission shall conduct an overall evaluation of the EU Digital Travel application and its use. The overall evaluation report established on this basis shall include an assessment of the application of this Regulation and an examination of results that have been achieved relative to the objectives that were set and of the impact on fundamental rights. The report shall also include an overall assessment of whether the underlying rationale for operating the EU Digital Travel application continues to hold, of the appropriateness of the technical features of the application, of the security of the application and of any implications for future operations. The evaluation shall include necessary recommendations. The Commission shall transmit the report to the European Parliament, the Council, the European Data Protection Supervisor and the European Union Agency for Fundamental Rights.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2025). “Changes between LIBE-PR-770059 and A-10-2025-0258”. Text, 10 December 2025. from LIBE-PR-770059, to A-10-2025-0258. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-770059/compare/A-10-2025-0258 (retrieved 25 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2025-12-10,
author = {{European Parliament}},
title = {{Changes between LIBE-PR-770059 and A-10-2025-0258}},
year = {2025},
date = {2025-12-10},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-770059/compare/A-10-2025-0258}},
url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-770059/compare/A-10-2025-0258},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. from LIBE-PR-770059, to A-10-2025-0258. Data: European Parliament Open Data (CC BY 4.0)}
}