Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

LIBE-PR-770059 → A-10-2025-0258

From
LIBE-PR-770059 report parliamentary committee draft of 2 Apr 2025
To
A-10-2025-0258 Plenary report of 10 Dec 2025
Changes
25 changes to the text
Paragraphs
+100 added · −29 removed · 16 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council establishing an application for the electronic submission of travel data (“EU Digital Travel application”) and amending Regulations (EU) 2016/399 and (EU) 2018/1726 of the European Parliament and of the Council and Council Regulation (EC) No 2252/2004, as regards the use of digital travel credentials
Title (to)
on the proposal for a regulation of the European Parliament and of the Council establishing an application for the electronic submission of travel data (“EU Digital Travel application”) and amending Regulations (EU) 2016/399 and (EU) 2018/1726 of the European Parliament and of the Council and Council Regulation (EC) No 2252/2004, as regards the use of digital travel credentials

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 2 of 4: Paragraphs 61–120

AddedRecital 23 a (new): (23a) In order to amend the minimum age for the use of the EU Digital Travel application, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of granting the use of that application for the creation of digital travel credentials to persons under the age of 16, should the necessary technical requirements and any other relevant conditions be fulfilled, in particular as regards the facial image. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement 13 April 2016 on Better Law-Making. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

AddedRecital 24: (24) In order to ensure uniform conditions for the implementation of this Regulation, as regards the technical standard for digital travel credentials, the technical architecture and technical specifications for the EU Digital Travel application and its testing, the collection of statistics, the start of operations of the EU Digital Travel application as well as the standards with regard to technology, methods and procedures to be used for the verification of the authenticity and validity of travel documents and digital travel credentials, implementing powers should be conferred on the Commission. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council11 .

AddedRecital 25: deleted

AddedRecital 26: (26) Since the objectives of this Regulation, notably increasing security and facilitating travel in the context of external border management cannot be sufficiently achieved by the Member States, but can rather, by reason of their inherently cross-border nature, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on the European Union. In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve those objectives.

AddedRecital 28: (28) This Regulation constitutes a development of the provisions of the Schengen acquis in which Ireland does not take part in accordance with Protocol No 19 on the Schengen acquis integrated into the framework of the European Union, annexed to the Treaty on European Union and the Treaty on the Functioning of the European Union, and, subject to the application of Article 4 of that Protocol, Ireland is not bound by it or subject to its application. / (deleted)

AddedRecital 33: (33) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 and delivered an opinion on 4 December 2024 19 ,

AddedArticle 1 – paragraph 1 – point a: (a) the creation of digital travel credentials;

AddedArticle 1 – paragraph 1 – point b: (b) the entry of self-declared data;

AddedArticle 1 – paragraph 1 – point c: (c) the secure submission of digital travel credentials and the self-declared data to the competent authority for the purposes of facilitating travel and of carrying out border checks on persons in accordance with Article 8(2g) and (3), point (j), of Regulation (EU) 2016/399.

AddedArticle 2 – paragraph 1 – point a a (new): (aa) ‘border authority’ means the authority of the Member State that carries out border control as defined in Article 2, point (10), of Regulation (EU) 2016/399 and that is authorised to receive and process travel data for the purposes of this Regulation;

AddedArticle 2 – paragraph 1 – point c a (new): (ca) “digital travel credentials” means the digital representation of a person’s identity as defined in Article 2, point 31, of Regulation (EU) 2016/399;

AddedArticle 2 – paragraph 1 – point c b (new): (cb) “self-declared data” means the data to be submitted by the traveller as set out in Article 5 of this Regulation;

AddedArticle 2 – paragraph 1 – point c c (new): (cc) ‘travel data’ means the data to be submitted by the traveller for the purpose of this Regulation including the digital travel credential and the self-declared data;

AddedArticle 2 – paragraph 1 – point d: (d) ‘Digital Travel Credential Router’ means the technical component referred to in Article 6 enabling the encrypted transmission of the travel data submitted by the traveller to the competent border authority.

AddedArticle 2 – paragraph 1 – point d a (new): (da) ‘e-gate’ means the infrastructure as defined in Article 2, point (24), of Regulation (EU) 2016/399;

AddedArticle 2 – paragraph 1 – point d b (new): (db) 'national database' means a database in a Member State specifically dedicated to the temporary storage of the pre-submitted digital travel credential and the self-declared data sent by the traveller to the competent border authority of that Member State in accordance with and for the purpose of this Regulation;

AddedArticle 3 – paragraph 1 – point a: (a) a mobile application, enabling the creation, storage and submission of the digital travel credential for single or multiple use, and the entry and submission of the self-declared data;

Article 3 – paragraph 1 – point b: (b) a backend validation service, ensuring the confirmation of the authenticity and integrity of the data on the storage medium (the ‘chip’) or the digital travel credential using available certificates and where applicable, the matching of the facial image taken from the user to the travel document or digital travel credential;

Change 10

ChangedArticle 3 – paragraph 1 – point c: (c) a TravellerDigital Travel Credential Router, which shall ensure secure and end-to-end encrypted transmission of the travel data, pursuant to Article 5, between the mobile application and the receivingcompetent border authority.

Change 11

RemovedArticle 4 – paragraph 1 – introductory part: 1. Persons enjoying the right of free movement under Union law, who are over the age of 18 and in possession of any of the following travel documents, may use the EU Digital Travel application to create a digital travel credential based on that travel document for single or multiple use:

AddedArticle 3 – paragraph 1 a (new): The source code of the software components of the EU Digital Travel application shall be open-source licensed.

Change 12

ChangedArticle 4 – paragraph 4:1 4.– Third-countryintroductory nationalspart: who1. arePersons inenjoying possessionthe ofright aof travelfree documentmovement containingunder aUnion chip,law andwho technologyare preventingover itsthe cloning,age may,of subject16 toand thein availabilitypossession of valid certificates necessaryany forof the checkingfollowing oftravel itsdocuments authenticity,may use the EU Digital Travel application to create a digital travel credential based on that travel document for single or multiple use.use:

Change 13

ChangedArticle 4 – paragraph 5: 5.1 Before– thepoint creationc: of(c) a digital travel credential,document inthat accordancecontains withthe paragraphssame 1data, and 4, the EU Digitala Travelchip applicationcontaining shallreliable verifytechnology thepreventing integrityits andcloning, authenticitythat ofis thebased chipon oftechnical thespecifications travelcompatible documentwith andthose matchprovided thefor facialby imageRegulation of(EC) theNo person2252/2004 seekingand toallowing createfor the digital travel credential against theverification facialof imageits storedauthenticity, onvalidity theand chip.integrity.

Change 14

RemovedArticle 4 – paragraph 6 a (new): 6a. The choice of the traveller not to use the EU Digital Travel application shall not lead to any discrimination against that traveller.

AddedArticle 4 – paragraph 2: 2. The EU Digital Travel application shall provide for the possibility, based on the explicit consent of the user, to store a digital travel credential for multiple use in the mobile application in accordance with Article 7b, and in the European Digital Identity Wallet, as qualified electronic attestation of attributes within the meaning of Article 3, point 45, of Regulation (EU) No 910/2014.

Change 15

ChangedArticle 4 – paragraph 74: a4. (new):Third-country 7a.nationals Thewho Commissionare isover empoweredthe toage adoptof delegated16 actsand who are in accordancepossession withof Articlea 15atravel indocument ordercontaining toa amendchip, thethat minimumis agebased referredon totechnical inspecifications paragraphand 1security ofstandards thiscompatible Article,with those provided thatfor thein necessaryRegulation technical(EC) requirementsNo 2252/2004, and anythat othercontain relevantreliable conditionstechnology forpreventing grantingits digitalcloning, travelshall, credentialssubject to personsthe underavailability of valid certificates necessary for the agechecking of 18,its inauthenticity, particularhave asthe regardspossibility to use the facialEU image,Digital areTravel met.application to create a digital travel credential for single or multiple use.

Change 16

RemovedArticle 5 – paragraph 2 – point a: (a) flight identification number, cruise line registration number, ship identification number;

AddedArticle 4 – paragraph 5: 5. Before the creation of a digital travel credential in accordance with paragraphs 1 and 4, the EU Digital Travel application shall verify the integrity and authenticity of the chip of the travel document and match the facial image of the person seeking to create the digital travel credential against the facial image stored on the chip.

RemovedArticle 5 – paragraph 3 a (new): 3a. The travel data shall be submitted no earlier than 48 hours before the intended arrival or departure.

AddedArticle 4 – paragraph 6: 6. The use of the EU Digital Travel application, the creation and use of digital travel credentials by persons enjoying the right of free movement under Union law and third-country nationals, and the temporary storage of the digital travel credential in the national database shall be voluntary and based on their consent. The use of the EU Digital Travel application is without prejudice to the application of Article 6 of Regulation (EU) 2016/399.

RemovedArticle 6 – paragraph 1: 1. The Traveller Router shall transmit the travel data submitted by the traveller to the competent border authority in accordance with Articles 7b and 7c and the technical specifications adopted in accordance with Article 16(1), point (a).

AddedArticle 4 – paragraph 6 a (new): 6a. The choice of the traveller not to use the EU Digital Travel application shall not lead to any discrimination or practical constraints against that traveller.

RemovedArticle 6 – paragraph 2: 2. Member States shall designate the Single Point of Contact from the competent border authorities authorised to receive the travel data transmitted to them from the Traveller Router in accordance with this Regulation. They shall notify, by [the entry into operation of the EU Digital Travel application], eu-LISA of the name and contact details of the competent border authorities and shall, where necessary, update the notified information.

AddedArticle 4 – paragraph 7 a (new): 7a. The Commission is empowered to adopt delegated acts in accordance with Article 15a in order to amend the minimum age referred to in paragraph 1 and paragraph 4 of this Article, provided that the necessary technical requirements and any other relevant conditions for granting digital travel credentials to persons under the age of 16, in particular as regards the facial image, are met.

RemovedArticle 7 a (new): Article 7a / Deletion of travel data / 1. The competent border authorities shall delete the travel data transmitted in accordance with this Regulation, in an automated manner, from the database of the border crossing point immediately after the traveller has crossed the external border. / 2. Where the traveller, who has submitted travel data in accordance with this Regulation, does not cross the external border, the competent border authorities shall delete, in an automated manner, the travel data transmitted 12 hours after the intended date and time of arrival or departure.

AddedArticle 5 – paragraph 1 – point b: (b) the following self-declared data: / (i) intended date and time of arrival or departure; / (ii) the Member State in which the external border is crossed;

RemovedArticle 7 b (new): Article 7b / Mobile application / 1. The mobile application referred to in Article 3, point (a) shall enable the creation and submission of digital travel credentials for single or multiple use, and the entry and submission of self-declared travel data. / 2. The mobile application shall have privacy and data protection by design, taking into account the state of the art in security and safety of the data it contains. / 3. The mobile application shall be easily accessible to users and free of charge. Specific attention shall be paid to the accessibility of the mobile application for persons with disabilities. / 4. The mobile application shall be available at least in all the official languages of the Member States. / 5. The use of the mobile application shall be subject to high security standards to ensure that any unauthorised access or use is not possible. / 6. The mobile application shall contain practical information regarding the scanning of the chip in the travel document and the purposes of the EU digital travel application. / 7. The technical specifications of the mobile application shall be adopted in accordance with Article 16(1), point (a).

AddedArticle 5 – paragraph 1 – point c: deleted

RemovedArticle 7 c (new): Article 7c / Traveller Router / 1. The Traveller Router referred to in Article 3, point (c), shall ensure secure and encrypted communication between the mobile application and the competent border authority. / 2. Member States shall ensure a secure connection between its national system and the Traveller Router. / 3. eu-LISA shall ensure that the Traveller Router is designed and developed in such a manner that the Traveller Router provides the functionalities specified in this Regulation. / 4. eu-LISA shall host the Traveller router in its technical sites. / 5. eu-LISA shall be responsible for the technical management of the Traveller Router, including its maintenance and technical developments, in such a manner as to ensure that the data are securely, effectively and swiftly transmitted through the Traveller Router, in compliance with this Regulation. / 6. eu-LISA’s staff shall not have access to any of the data that are transmitted through the Traveller Router. However, that prohibition shall not preclude eu-LISA’s staff from having such access insofar as strictly necessary for the maintenance and technical management of the Traveller Router. / 7. eu-LISA shall, upon the request of the relevant Member States’ authorities, provide training to them on the technical use of the router and on their connection to and integration with the Traveller Router. / 8. The technical specifications of the Traveller Router shall be adopted in accordance with Article 16(1), point (a).

AddedArticle 5 – paragraph 2 – introductory part: 2. The self-declared data may also consist, for the purpose of facilitating travel and carrying out border checks, where applicable, of the following information relating to each traveller:

AddedArticle 5 – paragraph 2 – point a: (a) flight identification number, cruise line registration number, ship identification number and border-crossing point;

AddedArticle 5 – paragraph 3: 3. The travel data referred to in paragraph 1 shall be strictly limited to what is necessary for the purpose of carrying out border checks in accordance with Regulation (EU) 2016/399.

AddedArticle 5 – paragraph 3 a (new): 3a. No additional personal data may be processed other than those declared pursuant to paragraphs 1 and 2.

AddedArticle 5 – paragraph 3 b (new): 3b. The travel data shall be submitted no earlier than 48 hours before the intended date and time of arrival or departure.

AddedArticle 6 – paragraph 1: 1. The Digital Travel Credential Router shall transmit the travel data submitted by the traveller to the competent border authority in accordance with Articles 7b and 7c. It shall transmit those data immediately and in an automated manner, without changing their content and in accordance with the technical specifications adopted in accordance with Article 16(1), point (a).

AddedArticle 6 – paragraph 2: 2. Member States shall designate a Single Point of Contact from the competent border authorities authorised to receive the travel data transmitted to them through the Digital Travel Credential Router in accordance with this Regulation. They shall notify, by [the date of entry into operation of the EU Digital Travel application], eu-LISA and the Commission of the name and contact details of the competent border authorities and shall, where necessary, notify them of any updates to that information. The Commission shall, on the basis of those notifications and updates, compile and make publicly available a list of the notified competent border authorities, including their contact details.

AddedArticle 7 – paragraph 1: 1. The competent border authorities shall be data controllers, within the meaning of Article 4, point 7, of Regulation (EU) 2016/679 in relation to the processing of travel data, constituting personal data, received through or stored in the Digital Travel Credential Router, the mobile application and the backend validation service.

AddedArticle 7 – paragraph 2: 2. Each Member State shall designate a competent border authority as data controller and communicate those authorities to the Commission, eu-LISA and the other Member States.

AddedArticle 7 – paragraph 3: 3. eu-LISA shall be the data processor within the meaning of Article 3, point 12, of Regulation (EU) 2018/1725 for the processing of travel data constituting personal data, received through the Digital Travel Credential Router, the mobile application and the backend validation service.

AddedArticle 7 – paragraph 3 a (new): 3a. When acting as a processor in accordance with paragraph 3, eu-LISA shall not engage another processor or transfer any personal data to a third country or an international organisation.

AddedArticle 7 – paragraph 4: 4. No personal data shall be stored on the backend validation service or the Digital Travel Credential Router beyond what is necessary for the creation of the digital travel credential and transmission of the travel data to the competent border authorities.

AddedArticle 7 – paragraph 4 a (new): 4a. The supervisory authorities referred to in Article 51 of Regulation (EU) 2016/679 shall carry out an audit of processing operations of travel data constituting personal data which have been performed by the competent border authorities for the purposes of this Regulation at least once every four years. The European Data Protection Supervisor shall carry out an audit of processing operations of travel data constituting personal data which have been performed by eu-LISA for the purposes of this Regulation, in accordance with relevant international auditing standards at least once every two years.

AddedArticle 7 – paragraph 5: 5. Users of the EU Digital Travel application shall be able to withdraw their consent to process their personal data on the EU Digital Travel application at any time, without detriment to the user. Upon the withdrawal of consent, all personal data, including biometric data provided or processed through the EU Digital Travel application shall be deleted from all the storage locations, including the mobile application, the Digital Traveller Credential Router and the national databases, without undue delay, unless retention is required by law.

AddedArticle 7 a (new): Article 7a / Deletion of travel data / 1. The competent border authorities shall delete the travel data transmitted in accordance with this Regulation, in an automated manner, from the national database of the border-crossing point immediately after the traveller has crossed the external border. / 2. Where the traveller, who has submitted travel data in accordance with this Regulation, does not cross the external border, the competent border authorities shall delete, in an automated manner, from the national database, the travel data transmitted 24 hours after the intended date and time of arrival or departure. / 3. Without prejudice to the powers conferred on the European Data Protection Supervisor by Regulation (EU) 2018/1725, the European Data Protection Supervisor shall have the right to access logs, audit records and system configurations to verify compliance with that Regulation.

AddedArticle 7 b (new): Article 7b / Mobile application / 1. The mobile application referred to in Article 3, point (a) shall enable the creation, submission and storage of digital travel credentials for single or multiple use, and the entry and submission of self-declared data. / 2. The mobile application shall respect privacy and data protection by design and by default, taking into account the state of the art in security and the safety of the data it contains. The mobile application shall be subject to high security standards to ensure that unauthorised access or unauthorised use is not possible. / 3. The mobile application shall allow carriers to access the digital travel credential for the purposes of Regulations (EU) 2025/12 and (EU) 2025/13, subject to the explicit consent of the user. Carriers accessing the digital travel credential shall not be allowed to collect any biometric data in accordance with Regulations (EU) 2025/12 and (EU) 2025/13. / 4. The mobile application shall be easily accessible to users and free of charge. Specific attention shall be paid to the accessibility of the mobile application for vulnerable persons. / 5. The mobile application shall be available at least in all official languages of the European Union. / 6. The use of end-to-end encryption shall be mandatory for every data submission through the application, in order to take account of the sensitivity of the data concerned. / 7. The mobile application shall contain practical information regarding the scanning of…

AddedArticle 7 c (new): Article 7c / Digital Travel Credential Router / 1. The Digital Travel Credential Router referred to in Article 3, point (c), shall ensure secure and end-to-end encrypted transmission of travel data between the mobile application and the competent border authority. / 2. Member States shall ensure a secure connection between their national database and the Digital Travel Credential Router to receive data transmitted through the Digital Travel Credential Router to the competent border authorities; / 3. eu-LISA shall ensure that the Digital Travel Credential Router is designed and developed in such a manner that the Digital Travel Credential Router provides the functionalities specified in this Regulation. The router shall, where appropriate and to the extent technically possible, share and reuse the technical components, including hardware and software components, referred to in Regulation (EU) 2025/12. / 4. eu-LISA shall host the Digital Travel Credential router in its technical sites. / 5. eu-LISA shall be responsible for the technical management of the Digital Travel Credential Router, including its maintenance and technical developments, in such a manner as to ensure that the data are securely, effectively and swiftly transmitted through the Digital Travel Credential Router, in accordance with this Regulation. / 6. eu-LISA’s staff shall not have access to any of the data that are transmitted through the Digital Travel Credential Router. However, that prohibition shall not pr…

Article 8 – paragraph 1: 1. eu-LISA shall develop the EU Digital Travel application and its components in accordance with Articles 7b and 7c and the technical specifications adopted pursuant to Article 16(1), point (a).

Change 17

AddedArticle 8 – paragraph 3: 3. eu-LISA shall ensure the operational management of the EU Digital Travel application as well as its “state of the art” security. The EU Digital Travel application shall be hosted by eu-LISA.

Article 8 – paragraph 4: 4. For the purpose of this Regulation, eu-LISA shall ensure that the EU Digital Travel application is interoperable with the European Digital Identity Wallet established under Regulation (EU) No 910/2014.

Change 18

ChangedArticle 8 – paragraph 5: 5. Where eu-LISA considers that the development of the EU Digital Travel application has been completed, it shall, withoutno unduelater delay,than one year after the entry into force of this Regulation, conduct a test of the application in cooperation with the competent border authorities and other relevant Member States’ authorities, in accordance with the technical specifications adopted pursuant to Article 16(1), point (c), and inform the European ParliamentParliament, the Council and the Commission of the outcome of that test.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
26 September 2026

Cite as

European Parliament (2025). “Changes between LIBE-PR-770059 and A-10-2025-0258”. Text, 10 December 2025. from LIBE-PR-770059, to A-10-2025-0258. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-770059/compare/A-10-2025-0258?all=1&part=2 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2025-12-10,
  author = {{European Parliament}},
  title = {{Changes between LIBE-PR-770059 and A-10-2025-0258}},
  year = {2025},
  date = {2025-12-10},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-770059/compare/A-10-2025-0258?all=1&part=2}},
  url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-770059/compare/A-10-2025-0258?all=1&part=2},
  urldate = {2026-09-26},
  publisher = {EU Parl Watch Research},
  note = {Text. from LIBE-PR-770059, to A-10-2025-0258. Data: European Parliament Open Data (CC BY 4.0)}
}