Passenger data
The sharing of passenger data is useful in preventing, detecting and prosecuting terrorist offences and serious crime. The passenger name record directive aims to regulate the transfer of such basic data from the airlines to national authorities, while the advance passenger information regulations sets rules for the collection and transfer of more personal data to national authorities.
What is passenger name record data?
Passenger name record (PNR) data is personal information provided by passengers and collected and held by air carriers. It includes information such as the name of the passenger, travel dates, itineraries, seats, baggage, contact details and means of payment.
The PNR directive regulates the transfer of such data to member states' law enforcement authorities and their processing for the prevention, detection, investigation and prosecution of terrorist offences and serious crime.
The European Parliament and the Council agreed on a compromise text in December 2015. On 14 April 2016, the European Parliament adopted its position. The Council then adopted the directive on 21 April 2016. Member states had two years to bring into force the laws, regulations and administrative provisions necessary to comply with this directive.
What is advance passenger information?
Advance passenger information (API) refers to a passenger's identity, usually obtained from travel documents or passports, such as:
- full name
- date of birth
- nationality
This information is transmitted to government authorities and can be a useful tool for governments' border control or security processing.
In December 2022, the Commission adopted two legislative proposals for regulations to facilitate external border management and to increase internal security. On 1 March 2024, the Council and the European Parliament agreed on the new law.
- Passenger name record data: Council concludes EU-Canada agreement (press release, 14 April 2025)
- Air passenger data: Council and European Parliament reach agreement to increase passenger security and enhance border management (press release, 1 March 2024)
- Air travel data: Council adopts position on EU laws about data collection and processing (press release, 21 June 2023)
EU rules to tackle cross-border crime and terrorism
Organised crime and terrorist activities often involve international travel. As a response to the abolition of internal border controls under the Schengen Convention, the EU provides for the exchange of personal data between law enforcement authorities.
The PNR system complements the already existing tools to cope with cross-border crime. Processing PNR data allows law enforcement authorities to discover persons unsuspected of crime or terrorism before a specific data analysis shows they might be.
Most member states already used PNR data granted under national law to the police or other authorities. The EU PNR system harmonises member states' legal provisions, avoiding legal uncertainty and security gaps, whilst at the same time safeguarding data protection.
The EU has already signed agreements allowing EU carriers to transfer PNR data to the United States and Australia.
In February 2020, the Council adopted a decision authorising the opening of negotiations between the EU and Japan for a PNR agreement.
In April 2025 the Council adopted a decision which formally concludes an agreement between the EU and Canada on the transfer and use of PNR data.
The PNR directive aims to regulate the transfer of PNR data from the airlines to national authorities, as well as their processing of this data. Under the directive, airlines have to provide PNR data for flights entering or departing from the EU. Member states are allowed, but not obliged, to collect PRN data concerning selected intra-EU flights.
The directive establishes that PNR data collected may only be processed for the prevention, detection, investigation and prosecution of terrorist offences and serious crime.
In the context of these activities, PNR data can be used in several ways:
- for a pre-arrival or pre-departure assessment of passengers against defined risk criteria, or in order to identify specific persons
- as input in the development of these risk criteria
- for specific investigations or prosecutions
To protect the fundamental rights to protection of personal data, to privacy and to non-discrimination, the directive includes a series of limitations for the transfer, processing and retention of PNR data:
- the directive prohibits the collection and use of sensitive data
- PNR data can only be kept for a period of 5 years, and must be depersonalised after a period of 6 months so the data subject is no longer immediately identifiable
- member states are required to establish a passenger information unit to handle and protect the data; this unit must include a data protection officer
- member states must ensure that passengers are clearly informed about the collection of PNR data and of their rights
- automated processing of PNR data cannot be the only basis for decisions producing adverse legal effects or seriously affecting a person
- transfer of PNR data to third countries can only take place in very limited circumstances and on a case-by-case basis
Last review: 15 April 2025