Choose the experimental features you want to try

This document is an excerpt from the EUR-Lex website

Document 52026PC0484

Proposal for a COUNCIL DECISION on the signing and provisional application of a Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorisations and visas

COM/2026/484 final

Brussels, 10.9.2026

COM(2026) 484 final

2026/0279(NLE)

Proposal for a

COUNCIL DECISION

on the signing and provisional application of a Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorisations and visas


EXPLANATORY MEMORANDUM

(1)CONTEXT OF THE PROPOSAL

Reasons for and objectives of the proposal

In 2022, the United States of America (US) introduced a new requirement for all countries that have been admitted to or aspire to join the US Visa Waiver Program (VWP). This program enables citizens of participating countries to travel to the US visa-free for a maximum of 90 days for the purposes of tourism or business. The new requirement entails the conclusion of an “Enhanced Border Security Partnership” (EBSP) with the US Department of Homeland Security (DHS) as a condition for admission to, and further participation in, the VWP, as a component of the already existing traveller information exchange requirement.

The VWP partnerships are at the forefront of the US international cooperation on border and immigration security. One of their objectives is to establish robust bilateral exchanges of information to enable authorities to authenticate effectively the identity of travellers from partner countries and determine whether they represent a threat to US security.

As part of its VWP partnerships, the US concluded bilateral agreements with EU Member States, such as the Agreements on Enhancing Cooperation in Preventing and Combating Serious Crime (PCSC Agreements). These agreements established information exchange, including biometric data, on individuals who are suspected or convicted of terrorist offences or serious crime.

Under the EBSP, exchanges concern information, including biometric data, stored in national databases of Member States on individuals travelling or intending to travel to the US. The EBSP agreements are expected to be concluded by 31 December 2026. After this deadline, the DHS will assess each country’s compliance with the EBSP requirement during evaluations for initial and continued participation in the VWP.

The Commission Recommendation for the Council Decision authorising the opening of negotiations on a Framework Agreement between the European Union and the US was adopted on 23 July 2025 1 . The Council adopted the decision to authorise the opening of negotiations on 16 December 2026.

On 16 December 2025, the Council adopted the Decision authorising the opening of negotiations for a framework agreement between the European Union and the United States of America on the reciprocal exchange of information for security screenings and identity verifications relating to border procedures and visa applications 2 . The Commission was appointed as the Union negotiator. The Council Decision also included an addendum with the directives for the negotiation of such agreement (‘negotiation directives’).

The Commission conducted the negotiations in close consultation with the Council’s Working Party on JHA Information Exchange and kept the European Parliament informed of the evolution of the negotiations (LIBE Committee). The negotiations were completed on 23 July 2026.

The Framework Agreement sets the conditions for the reciprocal exchange of information between the competent authorities of the EU Member States and of the US for identity verification, screening and vetting of individuals in the context of border checks and applications for travel authorisations and visas necessary to determine whether the traveller’s entry or stay would pose a serious and genuine risk to public security or public order. The bilateral agreements between Member States and the US will set out the specifics of the information exchange with the US from their national information systems, considering national legal requirements, the set-up of national databases, and other technical requirements or limitations.

One of the key objectives of the Framework Agreement is to ensure reciprocity in the exchange of information with the US, which would help to enhance border protection and security of the Union as a whole. The Framework Agreement establishes rules for a reciprocal exchange of information. It provides for the exchange of information on third country nationals and EU and US citizens. Sharing information on EU citizens is possible under strict reciprocity whereby if the US categorically exempts their nationals, the Member States are entitled to decide on exempting all EU citizens. In line with the principles of necessity and proportionality, the Framework Agreement envisages an automated exchange of information necessary only for the identification of a person. Additional information can be provided upon request, with human oversight, and with the possibility to refuse providing such information.

The Framework Agreement applies to those Member States which enjoy a visa free status with the US or who wish to join the VWP. The Member States are allowed to halt information exchange as provided for in the Framework Agreement in case their status in the VWP changes. As regards bilateral agreements already concluded by Member States with the US prior to the entry into force of this Framework Agreement, the Framework Agreement includes the conditions under which such agreements remain applicable.

The entry into provisional application of the Framework Agreement is a matter of urgency due to the review of the VWP and the deadline set by the US to implement the EBSP requirement by end of 2026. In light of these circumstances, the Commission proposed to apply the Framework Agreement on a provisional basis as soon as possible and until the completion of the Parties’ respective internal procedures for the entry into force of the Framework Agreement.

Consistency with existing policy provisions in the policy area

The Framework Agreement was negotiated taking into account the negotiating directives adopted by the Council 3 . The present Framework Agreement is also consistent with existing Union policies in the area of the common visa policy and its objective for visa reciprocity, as well as with EU’s data protection framework.

This Framework Agreement contributes to fulfilling the objectives of the Union’s common visa policy. The Union has developed a common visa policy for short stays (up to 90 days in any 180-day period) based on Regulation 2018/1806 4 . The Visa Regulation lists the third countries whose nationals must be in possession of visa when crossing the external borders and those whose nationals are exempt from that requirement. Currently, US nationals enjoy visa-free status in the Schengen area. In parallel, the Union has concluded visa waiver and visa facilitation agreements with several third countries 5 .

The principle of reciprocity is one of the foundations of the Union’s visa policy with third countries. Reciprocity means that where the Union has granted to citizens of a third country visa-free access to visit the Schengen area, it expects the third country to reciprocate by allowing Union citizens to travel to that third country without the need for a visa as well. The Union aims to achieve full visa reciprocity with third countries whose nationals are exempted from the visa requirement to enter the Schengen area. Full reciprocity has indeed been achieved with all visa-free third countries, except the US With the exception of Bulgaria, Cyprus and Romania, all Member States participate in the US VWP. Achieving full reciprocity with the US remains a political objective actively pursued by the Union.

This Framework Agreement thus ensures a consistent approach for all Member States participating in the VWP in relation to the EBSP requirement.

Consistency with other Union policies

The Framework Agreement is consistent with the requirements under EU data protection laws to provide safeguards for the transfers of personal information to third countries.

In the EU, the processing of personal data by Member States is governed by Regulation (EU) 2016/679 6 (the ‘GDPR’), except for the processing of data by criminal law enforcement authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties which is covered by Directive (EU) 2016/680 7 . For data transfers between criminal law enforcement authorities for the prevention, investigation, detection or prosecution of criminal offenses, including terrorism, the EU-US ‘Umbrella Agreement’ provides for an international agreement ensuring appropriate safeguards 8 .

Given the different scope and purpose of the information exchange intended by the EBSP, the EU-US ‘Umbrella Agreement’ is not applicable to the transfers envisaged by the US under the EBSP, therefore throughout the Framework Agreement, data protection safeguards have been added.

Part III of the Framework Agreement provides for the necessary safeguards, in line with the GDPR and Article 8 of the Charter of the Fundamental Rights, including provisions ensuring a number of data protection principles and obligations that must be respected by both Parties. These provisions ensure enforceable individual rights, independent supervision and effective administrative and judicial redress for violations of the rights and safeguards recognised in the Framework Agreement resulting from the processing of personal data under this Framework Agreement. The Commission ensured that the Framework Agreement sets out rules for the exchange of personal data while providing for adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of individuals.

(2)LEGAL BASIS, SUBSIDIARITY AND PROPORTIONALITY

·Substantive legal basis 

Given that the main objectives and component of this Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorizations and visas are to provide the conditions and safeguards for the transfer of personal information in the context of border procedures and applications for travel authorisations and visas, the substantive legal bases are Articles 16(2) and 77(2) TFEU.

Given the subject matter of the envisaged Framework Agreement, it is appropriate for the Commission to submit the proposal to the Council.

·Procedural legal basis 

Article 218(5) TFEU provides that, where the agreement envisaged does not relate exclusively or principally to the common foreign and security policy, the Commission shall submit a proposal to the Council. The Council shall adopt a decision authorising the signing of the agreement, and, if necessary, provisional application before entry into force.

The Commission proposes to authorise the signing of the Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorizations and visas, subject to its conclusion at a later date, as well as its provisional application.

The procedural legal basis for the proposed decision to authorise the signing of the envisaged agreement is Article 218(5) TFEU.

·Union competence and proportionality

The Union has competence covering all the provisions of this Framework Agreement. In particular, transfers of personal information by Member States subject to appropriate safeguards provided by a legally binding and enforceable instrument are foreseen by Article 46(2)(a) of the GDPR. In addition, the Union can conclude international agreements concerning checks to which persons crossing external borders are subject as well as common policy on visas (Article 77(2) TFEU). The Union has, thus, competence to conclude this Framework Agreement with the US on the exchange of information in relation to the crossing of the external borders between the EU and the US, including on border procedures and applications for visas and travel authorisations.

A Framework Agreement concluded between the EU and the US is required to ensure the common visa policy objective for visa reciprocity and the safeguards of the EU’s data protection framework. In addition, this Framework Agreement is required to set an adequate level of information exchange between the EU and the US, which should not exceed the level of information sharing among the Member States in a bilateral or EU context, subject also to the principles of proportionality and necessity.

·Choice of the instrument 

This proposal for a Council decision is submitted in accordance with Article 218(5) TFEU, which envisages the adoption by the Council of a decision authorising the signing and the provisional application of the Framework Agreement. There exists no other legal instrument that could be used to achieve the objective expressed in this proposal.

·Fundamental rights

The exchange of information under this Framework Agreement and its processing by the authorities of a third country constitutes an interference with the fundamental rights to privacy and data protection. However, such interference is justified, also because the Framework Agreement pursues legitimate objectives i.e. enhancing border security. The Framework Agreement includes appropriate data protection safeguards to the personal data transferred and processed, in line with EU law, notably Articles 7, 8, 47 and 52 of the Charter of Fundamental Rights of the EU.

(3)OTHER ELEMENTS

·Detailed explanation of the specific provisions of the proposal 

The Framework Agreement sets forth the framework for the exchange of information as well as appropriate safeguards for the protection of personal information when transferred between the US and the Member States in the context of EBSP cooperation relating to border procedures and applications for travel authorisations and visas.

The Framework Agreement consists of five Parts, as follows:

Part 1 on Common Provisions contains the provisions setting out the objective and scope of the Framework Agreement, and the key definitions used in the agreement. This Framework Agreement covers information exchange on individuals crossing the external borders of the US and the Member States or applying for travel authorisation or a visa to enter or stay in the territory of the Member States or of the US. The exchange of information is guided by the principle of reciprocity, which includes, in particular, the similarity regarding maximum volume limits of information exchanged taking into account capacity and technical limitations of the competent authorities. This Part further addresses the relationship between this Framework Agreement and existing EBSPs between the US and some Member States that address matters within the scope of the Framework Agreement. This Framework Agreement will supplement, as appropriate, relevant provisions regarding the protection of personal information in existing EBSPs. The US will adapt existing EBSPs to ensure compliance with this Framework Agreement. The other cooperation channels and information exchanges dealt with in other agreements between the US and the EU and the US and the Member States remain unaffected by this Framework Agreement (e.g. EU-US mutual legal assistance treaty, bilateral mutual legal assistance treaties, bilateral PCSC agreements). It clarifies that this Framework Agreement in and of itself shall not be the legal basis for any transfers of personal information.

Part 2 on Principles and Conditions for the Information Exchange contains provisions setting the necessary conditions for the exchange of information. It stipulates that the information exchange under this Framework Agreement may only take place to the extent authorised and further specified in bilateral agreements between the Member States and the US. Such bilateral agreements must comply with the conditions and safeguards set in the Framework Agreement. Member States could suspend bilateral agreements particularly in cases of suspension of visa-free travel. This Part further sets the rules for an automated exchange of limited personal data needed for the identification of the individual during the assessment of an application for a travel authorisation or visa or during a border check. Where, during such assessment, there is reason to believe that the entry or stay could pose a serious and genuine risk to public security or public order, a query can be submitted in relation to such individual. In cases where there is information of potential interest for EBSP cooperation (i.e. showing that the entry or stay of an individual would pose a serious and genuine risk to public security or public order), such confirmation of risk would be communicated without delay, to the requesting authority following an assessment of all relevant factors, in accordance with national law and consistent with the technical capabilities of the requested authority. Additional information on the same individual may be provided after a human assessment of compliance with the conditions set in the Framework Agreement and the bilateral agreements. The exchange of information is to take place between single points of contact. This Part also provides for grounds for refusal to exchange information that can be used at any stage of the information exchange.

Part 3 on Protection of Personal Information sets out the purpose limitation (i.e. verification of identity, and screening and vetting, of individuals needed to determine whether their entry or stay would pose a serious and genuine risk to public security or public order) for the processing of personal information covered by this Framework Agreement. Further processing of personal information may only take place for purposes that are not incompatible with the original purpose. It distinguishes between onward sharing (within the same country, subject to the data protection safeguards of the Framework Agreement) and onward transfers (to third countries or international organisations, only with prior consent of the requested competent authority, after an assessment of the level of data protection that would be ensured). Both onward sharing and transfers are limited to public authorities. Personal data will only be retained for as long as this is necessary and appropriate, taking into account specific factors listed in the Framework Agreement and subject to at least an annual review of the retention period. This Part provides safeguards for the processing of special categories of data, and includes transparency and information obligations, on individuals’ rights to access and correct their own data. Parties are required to have in place effective administrative and judicial remedies to provide redress for individuals, as well as independent oversight mechanisms.

Part 4 on Institutional Framework includes a single provision establishing a Joint Committee: a joint body of the Parties to the Framework Agreement entrusted with the monitoring of the effective implementation of the Framework Agreement, including by carrying out periodic joint reviews of the implementation of this Framework Agreement.

Part 5 on Final Provisions covers a number of final clauses regarding consultations in case of disputes regarding the way the Framework Agreement is interpreted or applied; the possibility to suspend the Framework Agreement in case of material breach of the agreement by the other party; the territorial application of the Framework Agreement considering the specific situation of Ireland and Denmark; the duration and amendment of the agreement; possibility of each party to terminate the agreement, while it is specified that personal information transferred prior to the termination will continue to be processed in accordance with the rules of this Framework Agreement; the entry into force of the agreement and language clause.

·Signing and the text of the Framework Agreement 

The text of the Framework Agreement is submitted to the Council together with this proposal.

In accordance with the Treaties, it is for the Commission to ensure the signing of the Framework Agreement, subject to its conclusion at a later date.

In accordance with the Treaties, it is also for the Commission to notify the United States of America of the Union’s intention to apply on a provisional basis the Framework Agreement as from the day of its signing, pending its entry into force. Provisional application is proposed due to the review of the VWP and the deadline set by the US to implement the EBSP requirement by end of 2026. Following the start of the provisional application Member States, will be able to start negotiating and concluding bilateral agreements on the EBSP.

2026/0279 (NLE)

Proposal for a

COUNCIL DECISION

on the signing and provisional application of a Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorisations and visas

THE COUNCIL OF THE EUROPEAN UNION,

Having regard to the Treaty on the Functioning of the European Union, and in particular Articles 77(2) and 16(2), in conjunction with Article 218(5) and Article 218(7) thereof,

Having regard to the proposal from the European Commission,

Whereas:

(1)The United States of America have introduced a new requirement for admission to and further participation in the US Visa Waiver Program, which enables citizens of participating countries to travel to the United States visa-free for maximum 90 days for the purpose of tourism or business. The new requirement entails the conclusion of an ‘Enhanced Border Security Partnership’ (EBSP) with the US Department of Homeland Security.

(2)On 16 December 2025, the Council authorised the Commission to open negotiations with the United States of America for a Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for security screenings and identity verifications relating to border procedures and visa applications.

(3)The Commission has negotiated the Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorizations and visas (the ‘Framework Agreement’).

(4)This Framework Agreement sets a common framework for information exchange in the context of the EBSP between the Union and the United States of America.

(5)The Framework Agreement allows for the conclusion of bilateral agreements between the United States of America and the Member States on matters covered by the Framework Agreement. The provisions of such bilateral agreements are to be compatible with those of the Framework Agreement and with Union law.

(6)In addition, in the event that this Framework Agreement is terminated or suspended bilateral agreements between the Member States and the United States of America on matters covered by the Framework Agreement should, in full respect of the principle of sincere cooperation, be terminated or suspended, as the case may be. The Member States should inform the Commission of the termination or suspension of these bilateral agreements.

(7)Given the review of the US Visa Waiver Program and the deadline set by the US to implement the EBSP requirement by end of 2026, the Framework Agreement should be applied on a provisional basis, in accordance with Article 32 thereof, as of its signature, pending the completion of the procedures necessary for its entry into force.

(8)In accordance with Articles 1 and 2 of Protocol No 22 on the Position of Denmark annexed to the Treaty on European Union and to the TFEU, Denmark is not taking part in the adoption of this Recommendation and is not bound by it or subject to its application. Given that this Decision builds upon the Schengen acquis, the Kingdom of Denmark is to, in accordance with Article 4 of that Protocol, decide within a period of six months after the Council has adopted this Decision whether it will implement it in its national law.  

(9)This Decision constitutes a development of the provisions of the Schengen acquis in which Ireland does not take part, in accordance with Council Decision 2002/192/EC 9 ; Ireland is therefore not taking part in its adoption and is not bound by it or subject to its application.

(10)A common understanding was reached during the negotiations on the situation of Denmark and Ireland in relation to the Schengen acquis, as well as of the close relationship between the European Union and Norway, Iceland, Switzerland and Liechtenstein, particularly by virtue of the Agreements of 18 May 1999 and 26 October 2004 concerning the association of those countries with the implementation, application and development of the Schengen acquis. 

(11)The European Data Protection Supervisor was consulted in accordance with Article 42 of Regulation (EU) 2018/1725 of the European Parliament and of the Council 10 and an Opinion [XX] was issued on [XX].

(12)Therefore, the Framework Agreement should be signed.

(13)The Framework Agreement should be applied on a provisional basis, pending its entry into force.

HAS ADOPTED THIS DECISION:

Article 1

The signing of the Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorizations and visas is hereby authorised, subject to the conclusion of the said Framework Agreement 11 .

Article 2 

(1)Any decision of the Union to take measures related to the provision of guidance in accordance with Article 27(4)(c) shall be taken by the European Commission in accordance with the conditions set out in the corresponding provisions of the Framework Agreement.

(2)The Commission shall inform the Council in a timely manner of its intention to adopt the proposed measures set out in paragraph 1 and take into account the possible views expressed. The Commission shall also inform the European Parliament, as appropriate.

Article 3

(1)The Agreement shall be applied on a provisional basis, in accordance with Article 32 thereof, pending its entry into force.

(2)The date from which the Agreement is to be applied on a provisional basis shall be published in the Official Journal of the European Union.

Article 4

This Decision shall enter into force on the day of its adoption.

Done at Brussels,

   For the Council

   The President

(1)    European Commission, Recommendation for a Council Decision authorising the opening of negotiations on a Framework Agreement between the European Union and the United States of America on the exchange of information for security screenings and identity verifications relating to border procedures and applications for visa, COM(2025)447, 23.7.2025.
(2)    Council Decision (EU) 2025/2640 of 16 December 2025 authorising the opening of negotiations for a framework agreement between the European Union and the United States of America on the reciprocal exchange of information for security screenings and identity verifications relating to border procedures and visa applications, OJ L, 19.12.2025.
(3)    Supra, footnote 2.
(4)    Regulation (EU) 2018/1806 of the European Parliament and of the Council of 14 November 2018 listing the third countries whose nationals must be in possession of visas when crossing the external borders and those whose nationals are exempt from that requirement (codification), OJ L 303, 28.11.2018, p. 39.
(5)    The full list of countries is available here: https://home-affairs.ec.europa.eu/policies/schengen/visa-policy_en .
(6)    Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance), OJ L 119, 4.5.2016, p. 1.
(7)    Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA, OJ L 119, 4.5.2016, p. 89.
(8)    Agreement between the United States of America and the European Union on the protection of personal information relating to the prevention, investigation, detection, and prosecution of criminal offences, OJ L 336, 10.12.2016.
(9)    OJ L 64, 7.3.2002.
(10)    OJ L 295, 21.11.2018.
(11)    The text of the Agreement is published in OJ L, …., ELI … .
Top

Brussels, 10.9.2026

COM(2026) 484 final

ANNEX

to the

Proposal for a Council decision

on the signing and provisional application of the Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorisations and visas




Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorisations and visas


Table of Contents

Part 1 – Common Provisions

Article 1 – Objective of the Framework Agreement

Article 2 – Definitions

Article 3 – Scope of the Framework Agreement

Article 4 – Effect of the Framework Agreement

Part 2 – Principles and Conditions for the Information Exchange

Article 5 – Bilateral Agreements

Article 6 – Purpose of the Exchange of Information

Article 7 – Exchange of Information through an Automated Query

Article 8 – Confirmation of Risk

Article 9 – Procedure for Further Exchange of Additional Information

Article 10 – Single Points of Contact

Article 11 – Non-Derogation

Part 3 – Protection of Personal Information

Article 12 – Purpose and Use Limitation

Article 13 – Onward Sharing

Article 14 – Onward Transfers

Article 15 – Quality and Integrity of Information

Article 16 – Information Security

Article 17 – Notification of an Information Security Incident

Article 18 – Record Keeping

Article 19 – Retention Period

Article 20 – Special Categories of Personal Information

Article 21 – Automated Decisions

Article 22 – Access

Article 23 – Rectification

Article 24 – Administrative and Judicial Redress

Article 25 – Transparency

Article 26 – Effective Oversight

Part 4 – Institutional Framework

Article 27 – Joint Committee

Part 5 – Final Provisions

Article 28 – Consultations

Article 29 – Suspension

Article 30 – Territorial Application

Article 31 – Entry into Force, Duration, Amendment, and Termination

Article 32 – Provisional Application

Article 33 – Authentic Text

THE EUROPEAN UNION, hereinafter also referred to as the EU,

and

the UNITED STATES OF AMERICA, hereinafter also referred to as the United States,

together hereinafter referred to as “the Parties”,

SEEKING to encourage and enhance cooperation between the Parties in the spirit of transatlantic partnership;

INTENDING to establish a legal framework to facilitate the reciprocal exchange of information for the purposes of verification of identity, and screening and vetting, of individuals, with a view to preventing individuals who represent a serious and genuine risk to public security or public order, including on terrorism or criminal grounds, the ability to enter or stay in their territories;

HAVING REGARD for United Nations Security Council resolutions 1373 (2001), 1624 (2005), 2178 (2014), 2322 (2016), and, in particular, 2396 (2017) which requires Member States of the United Nations to develop and implement systems to collect biometric data in order to responsibly and properly identify terrorists, in compliance with domestic law and international human rights law, and which encourages Member States of the United Nations to share such information responsibly with each other, as appropriate;

MINDFUL that the United States and the European Union are committed to ensuring a high level of protection of personal information exchanged for the purposes of this Framework Agreement;

NOTING that the United States has in place Enhanced Border Security Partnerships with certain Member States of the EU, and UNDERSTANDING that the United States and those Member States intend to ensure compliance of those Partnerships with this Framework Agreement;

RESOLVED to strengthen, in the context of the bilateral Agreements on Enhancing Border Security through the Exchange of Information between the Member States of the EU and the United States, the exchange of identity information to prevent individuals seeking to cross their respective borders and stay in their territory from posing a risk to public security or public order;

MINDFUL that both Parties are committed to ensuring mutually beneficial exchanges of information needed to ensure the integrity and security of visa-free transatlantic travel through the Enhanced Border Security Partnership, but noting exchanges authorised in the bilateral Agreements on Enhancing Border Security through the Exchange of Information may be temporarily suspended in certain circumstances, including in the event of suspension of the visa-free travel;

RECOGNIZING that this Framework Agreement establishes common principles and safeguards for the reciprocal exchange of information under this Framework Agreement and does not preclude Member States of the EU and the United States from including additional types of information sharing cooperation in the bilateral Agreements on Enhancing Border Security through the Exchange of Information.

RECALLING the European Union’s objective to explore ways to enhance information exchange for law enforcement and border management purposes with strategic partners and recognizing the Parties’ shared objective for future expansion of cooperation in this area;

RECOGNIZING the principles of proportionality and necessity, and relevance and reasonableness, as implemented by the Parties in their respective legal frameworks, and CONSIDERING the level of information exchange between Member States of the EU;

EMPHASIZING that each Party should have in place a legal framework that provides individuals with effective judicial and non-judicial redress to identify and remedy instances where an individual’s personal information has been processed and used in a manner inconsistent with Part 3 of this Framework Agreement, and ACKNOWLEDGING that it is for each Party to determine the type of remedies available, and that it is not required that each type of remedy be available in every instance;

REAFFIRMING the Parties’ longstanding commitment to upholding the shared values and principles of democracy, the rule of law, and respect for human rights and fundamental freedoms, which underpin their domestic and international policies, and further reaffirming respect for the Universal Declaration of Human Rights and international human rights treaties to which the United States and Member States of the EU are parties, including the International Covenant on Civil and Political Rights, done at New York on December 16, 1966, and the Convention against Torture and Other Cruel, Inhuman or Degrading Treatment or Punishment, done at New York on December 10, 1984;

TAKING INTO ACCOUNT the Protocol on the Position of Denmark annexed to the Treaty on European Union and the Treaty on the Functioning of the European Union, and CONFIRMING that this Framework Agreement is not binding upon or applicable in relation to the Kingdom of Denmark;

TAKING INTO ACCOUNT the Protocol on the Schengen acquis integrated into the framework of the European Union, annexed to the Treaty on European Union and the Treaty on the Functioning of the European Union, and CONFIRMING that the provisions of this Framework Agreement are not applicable in relation to Ireland;

HAVE AGREED AS FOLLOWS:

Part 1: Common Provisions

Article 1

Objective of the Framework Agreement

1.The objective of this Framework Agreement is to enhance cooperation between the United States and the Member States of the EU in relation to the exchange of information on individuals crossing their respective external borders or applying for a travel authorisation or a visa to enter or stay in the territory of one of the Member States of the EU or of the United States, while ensuring a high level of protection of personal information.

2.In the pursuit of this objective, this Framework Agreement sets forth the framework for the exchange of information as well as the appropriate safeguards for the protection of personal information when transferred between the United States and the Member States of the EU.

3.This Framework Agreement in and of itself shall not be the legal basis for any transfers of personal information.

4.The exchange of information set out in this Framework Agreement shall be guided by the principle of reciprocity, which includes, in particular, similarity regarding maximum volume limits, type, and quality of information exchanged.

5.The exchange of information under Article 7 shall be based on a maximum volume of individuals to be screened, taking into account the capacity and technical limitations of the Competent Authorities, real volumes of travel, current risks, and reciprocity, to the extent determined in the bilateral Agreements on Enhancing Border Security through the Exchange of Information.

Article 2

Definitions

For the purposes of this Framework Agreement:

1.“Member State” means a Member State of the European Union;

2.“Union citizen” means any person holding the nationality of a Member State;

3.“U.S. national” or “national of the United States” means a citizen or national of the United States;

4.“Personal information” means information relating to an identified or identifiable natural person (an individual). An identifiable person is a person who can be identified, directly or indirectly, by reference to, in particular, an identification number or to one or more factors specific to his or her physical, physiological, mental, economic, cultural, or social identity;

5.“Processing of personal information” means any operation or set of operations involving collection, maintenance, use, alteration, organisation or structuring, disclosure or dissemination, or disposition;

6.“Special categories of personal information” means personal information revealing racial or ethnic origin, political opinions or religious or other beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, and personal information concerning health or sexual life. An individual’s name, date of birth, place of birth, nationality/citizenship, or other basic biographic identity information shall not be deemed to constitute in themselves special categories of personal information;

7.“Competent Authority” means a public authority of the United States or of a Member State responsible for activities covered by this Framework Agreement, consistent with relevant designations in bilateral Agreements on Enhancing Border Security through the Exchange of Information between the Member States and the United States;

8.“Requesting Competent Authority” means the Competent Authority that initiates the query;

9.“Requested Competent Authority” means the Competent Authority that receives the query from the requesting competent authority;

10.“Travel authorisation” means an authorisation to travel and to seek admission to the territory of a Member State or of the United States for short or temporary stays for persons who are not subject to an obligation of being in possession of a visa, as defined in applicable law; and

11.“Visa” means an authorisation to travel or transit and to seek admission to the territory of a Member State or of the United States for short or temporary stays, as defined in applicable law.

Article 3

Scope of the Framework Agreement

1.This Framework Agreement shall apply to personal information of individuals transferred between the Competent Authorities of the United States and the Competent Authorities of the Member States for the purposes set forth in Article 6.

2.The Parties intend for the United States and the Member States to exchange information on U.S. nationals, Union citizens, and third country nationals. Should either the United States or a Member State be unable to categorically exchange information on its respective nationals or citizens, the other side is entitled to decide whether it will reciprocally refrain from exchanging information on all Union citizens or all U.S. nationals respectively.

3.For the purpose of paragraph 2, where a person is a Union citizen or is a U.S. national, or both, the transfer of personal information should be treated as a transfer of information on a citizen of a Member State or a national of the United States, regardless of whether that person holds one or more additional citizenships.

Article 4

Effect on the Framework Agreement

1.This Framework Agreement supplements, as appropriate, provisions regarding the protection of personal information in existing Enhanced Border Security Partnerships between the United States and Member States that address matters within the scope of this Framework Agreement. The United States shall undertake to adapt existing Enhanced Border Security Partnerships to ensure compliance with this Framework Agreement by working with the relevant Member States.

2.The Parties shall take all necessary measures to implement this Framework Agreement, including, in particular, their respective obligations under this Framework Agreement regarding access, rectification, and administrative and judicial redress for individuals provided herein. The protections and remedies set forth in this Framework Agreement shall benefit relevant individuals in the manner implemented in each Party’s respective legal framework. For the United States, its obligations shall apply in a manner consistent with its fundamental principles of federalism.

3.By giving effect to paragraph 2, the processing of personal information by the Competent Authorities, with respect to matters falling within the scope of this Framework Agreement, shall be deemed to comply with their respective data protection legislation restricting or conditioning international transfers of personal information, and no further authorisation under such legislation shall be required.

4.Except as provided in paragraph 1, nothing in this Framework Agreement shall be construed to limit or prejudice the provisions of any treaty, other agreement or arrangement, including mutual legal assistance agreements and agreements on enhancing cooperation in preventing and combatting serious crime, working law enforcement relationships, or domestic law allowing for information sharing between the United States and the Member States.

Part 2: Principles and Conditions for the Information Exchange

Article 5

Bilateral Agreements

The exchange of information under this Framework Agreement may only take place to the extent authorised and further specified in bilateral Agreements on Enhancing Border Security through the Exchange of Information between the Member States and the United States (hereinafter “bilateral agreements”) and only to the extent that those bilateral agreements:

a)include provisions necessary to comply with the conditions for the exchange of information set out in this Framework Agreement;

b)identify specific national information systems that are relevant for the objective described in Article 1 and the purposes described in Article 6, from which information is to be exchanged under this Framework Agreement and in accordance with applicable domestic laws (hereinafter “national information systems”); and

c)include provisions on suspension of the bilateral agreements, for reasons including suspension of visa-free travel.

Article 6

Purpose of the Exchange of Information

Personal information shall only be exchanged under this Framework Agreement for the purposes of verification of identity, and screening and vetting, of individuals needed to determine whether their entry or stay would pose a serious and genuine risk to public security or public order.

Article 7

Exchange of Information through an Automated Query (first step)

1.During the assessment of an application for a travel authorisation or visa or during border checks, the Requesting Competent Authority may submit an automated query in relation to an individual where, during the examination of the individual, there is reason to believe that the entry or stay could pose a serious and genuine risk to public security or public order. This may in particular be the case: where there are indications of identity fraud or misuse of identities; where there are doubts as to the authenticity and validity of the travel documents; where there are indications that an application for a visa contains fraudulent or false information; where there are risk assessments and scenarios identifying risk on the basis of trend analysis of suspicious activity, law enforcement cases, or criminal intelligence; or where information about the concerned individual exists in the national information systems of the Requesting Competent Authority.

2.While carrying out their activities referred to in paragraph 1, the Competent Authorities shall not arbitrarily and unjustifiably discriminate against individuals, in particular, on the grounds of sex, racial or ethnic origin, religion or belief, disability, age or sexual orientation.

3.Subject to the conditions set out in paragraph 1 and 2 above, the Requesting Competent Authority may submit an automated query in relation to an individual where there is a nexus between the individual and the State of the Requested Competent Authority, including where the individual is a citizen/national, is a current or former resident, or has previously stayed or applied to stay on the territory of the State of the Requested Competent Authority.

4.An automated query may only be initiated when the Requesting Competent Authority is also conducting searches against its own national information systems.

5.When submitting an automated query, the Requesting Competent Authority shall include a unique reference number that identifies the individual and/or the query and an indicator of the nature of the Requesting Competent Authority’s encounter with the individual and may use the following personal information:

a)the identity information included in the application or in the travel document, such as the surname (family name), first name or names (given names), the date of birth, national ID number, and/or

b)the fingerprints of an individual.

6.Fingerprint data may only be used for the submission of the automated query if the relevant bilateral agreement requires the Requesting Competent Authority to ensure that the fingerprint data used in the query are of sufficient quality for automated comparison.

7.In case of a positive correspondence (match) with information held in its national information systems, the Requested Competent Authority shall transfer to the Requesting Competent Authority through the automated process:

a)the confirmation of such a match, and

b)alphanumeric data for the identification of an individual, such as first name, last name, and date of birth.

8.In case of a positive correspondence (match) with information held in its national information systems, the Requested Competent Authority may transfer to the Requesting Competent Authority through the automated process, where available and shareable under domestic law, photographs for the identification of an individual. 

9.Under this Article, the Requested Competent Authority may only transfer personal information that is adequate, relevant, and limited to what is needed for the identification of the individual. 

Article 8

Confirmation of Risk

1.Should the procedure described in Article 7 generate a positive correspondence (match), the Requested Competent Authority, to the extent authorised and further specified in the relevant bilateral agreement, shall assess without delay, based on all relevant factors, whether the positive correspondence is related to a risk set forth in Article 6. Such factors may include criminal convictions, terrorist threats or immigration violations, including their nature, seriousness and timing.

2.The Requested Competent Authority shall send without delay a confirmation whether there is information of potential interest related to a risk set forth in Article 6, which may be requested under the procedure of Article 9, and its nature, by indicating the relevant factor or factors referred to in paragraph 1.

3.The sharing of information pursuant to this Article may only take place to the extent that the relevant bilateral agreement establishes the procedures for sharing and the expected content of that communication, in accordance with applicable domestic law and consistent with the technical capabilities of the Requested Competent Authority.

Article 9

Procedure for Further Exchange of Additional Information (second step)

1.Should the procedure described in Article 7 show a positive correspondence (match) and after the procedures described in Article 8 have been completed, the Requesting Competent Authority may request additional information on the same individual for the purposes set forth in Article 6 to the extent authorised in the relevant bilateral agreement.

2.Subject to the safeguards for the protection of personal information set out in Part 3 of this Framework Agreement, the Requested Competent Authority may transfer the additional information requested by the Requesting Competent Authority.

3.The exchange of additional information may only take place to the extent that the relevant bilateral agreement specifies the national information systems from which information may be exchanged, the categories of information that the Requested Competent Authority may transfer, and the procedures for such transfer in accordance with applicable domestic law.

4.With the exception of biometric data for the purpose of uniquely identifying a natural person, special categories of personal information may only be transferred under this Article where particularly relevant to achieve the purposes set forth in Article 6.

5.The exchange of additional information may only take place to the extent that the relevant bilateral agreement establishes conditions for the exchange and only after a human assessment of compliance with those conditions by the Requested Competent Authority, and in accordance with applicable domestic law.

6.In the case of a positive correspondence (match) described in Article 7 and after the procedures described in Article 8 have been completed, the Requested Competent Authority may request available alphanumeric and contextual data on the same individual from the Requesting Competent Authority exclusively for ensuring accuracy and for auditing existing records on the individual concerned. The Requesting Competent Authority shall respond consistent with any relevant procedures provided in the bilateral agreements and in accordance with applicable domestic law.

Article 10

Single Points of Contact

The Competent Authorities shall designate single points of contact for the exchange of personal information under this Framework Agreement.

Article 11

Non-Derogation

The exchange of information under this Framework Agreement shall be without prejudice to the invocation by the Requested Competent Authority of grounds to refuse a request available pursuant to a bilateral agreement or arrangement, such as where the response risks jeopardizing ongoing investigations or would prejudice the State of the Requested Competent Authority’s sovereignty, security, public order, or if the response would conflict with applicable domestic law or international obligations.

Part 3: Protection of Personal Information

Article 12

Purpose and Use Limitation

1.Personal information received under this Framework Agreement shall be processed for the purposes set forth in Article 6.

2.The further processing of personal information under this Framework Agreement shall not be incompatible with the purposes for which it was transferred.

3.Compatible processing includes further processing for purposes of preventing an immediate and serious threat to public security, further processing to report to public oversight authorities such as those listed in Article 26, and where further processing is directly related to the purposes for the exchange of information under this Framework Agreement. All such further processing shall respect the other provisions of this Framework Agreement, in particular its Articles 15 and 19. This paragraph is without prejudice to the application of treaties, agreements, or arrangements mentioned in Article 4, paragraph 4, such as mutual legal assistance agreements.

4.This Article shall not prejudice the ability of the Requested Competent Authority to impose additional conditions in a specific case to the extent the applicable legal framework for transfer permits it to do so. Such conditions shall not include generic data protection conditions, that is, conditions imposed that are unrelated to the specific facts of the case. If the information is subject to such conditions, the Requesting Competent Authority shall comply with them. The Requested Competent Authority may also require the Requesting Competent Authority to give information on the use made of the transferred information.

5.The Parties shall ensure under their respective legal frameworks that personal information is processed in a manner that is directly relevant to and not excessive or overbroad in relation to the purpose of the processing.

Article 13

Onward Sharing

1.All processing of personal information exchanged under this Framework Agreement by other national law enforcement, regulatory, or administrative authorities shall respect the other provisions of Part 3 of this Framework Agreement.

2.The Parties shall have in place measures to promote accountability for processing personal information within the scope of the Framework Agreement by their Competent Authorities, and any of their authorities to which personal information has been transferred. Such measures shall include notification of the safeguards applicable to transfers of personal information under this Framework Agreement, and of the conditions that may have been imposed by the Requested Competent Authority pursuant to Article 12, paragraph 4. Serious misconduct shall be addressed through appropriate and dissuasive criminal, civil, or administrative sanctions. Such measures shall include, as appropriate, discontinuation of transfer of personal information to authorities of constituent territorial entities of the Parties not covered by this Framework Agreement that have not effectively protected personal information, taking into account the purpose of this Framework Agreement, and in particular, the purpose and use limitations and onward transfer provisions of this Framework Agreement.

Article 14

Onward Transfers

1.Personal information received from the Requested Competent Authority pursuant to this Framework Agreement may be transferred to public authorities in third countries or to international organisations only where the prior consent of the Requested Competent Authority has been obtained.

2.When granting its consent to an onward transfer of personal information, the Requested Competent Authority shall take due account of all relevant factors, including the purpose for which the personal information was initially transferred and whether the third country or international organisation with which the information is to be shared ensures an appropriate level of protection of personal information.

Article 15

Quality and Integrity of Information

The Parties shall take reasonable steps to ensure that personal information is maintained with such accuracy, relevance, timeliness, and completeness as is necessary and appropriate for lawful processing of the information. For this purpose, the Competent Authorities shall have in place procedures, the object of which is to ensure the quality and integrity of personal information, including the following:

a)the measures referred to in Article 23;

b)where the Requested Competent Authority becomes aware of significant doubts as to the relevance, timeliness, completeness, or accuracy of such personal information it has transferred, it shall, where feasible, advise the Requesting Competent Authority thereof; and

c)where the Requesting Competent Authority becomes aware of significant doubts as to the relevance, timeliness, completeness, or accuracy of personal information received, it shall, where feasible, advise the Requested Competent Authority thereof.

Article 16

Information Security

1.The Competent Authorities shall ensure that they have in place appropriate technical, security and organisational arrangements for the protection of personal information against all of the following:

a)accidental or unlawful destruction;

b)accidental loss; and

c)unauthorised disclosure, alteration, access, or other processing.

2.Such arrangements shall include appropriate safeguards regarding the authorisation required to access personal information.

Article 17

Notification of an Information Security Incident

1.Upon discovery of an incident involving accidental loss or destruction, or unauthorised access, disclosure, alteration, or other processing of personal information, in which there is a significant risk of damage, the Requesting Competent Authority shall promptly assess the likelihood and scale of damage to individuals and promptly take appropriate action to mitigate any such damage.

2.Action to mitigate damage shall include a notification to the Requested Competent Authority. Such a notification may:

a)include appropriate restrictions as to the further transmission of the notification;

b)be delayed or omitted when it may endanger national security;

c)be delayed when it may endanger public security operations.

3.Action to mitigate damage shall also include notification to the individual, where appropriate, given the circumstances of the incident, unless such notification may endanger:

a)public or national security;

b)official inquiries, investigations or proceedings;

c)the prevention, detection, investigation, or prosecution of criminal offences;

d)rights and freedoms of others, in particular the protection of victims and witnesses.

4.The Competent Authorities involved in the transfer of the personal information may consult each other concerning the incident and the response thereto.

Article 18

Record Keeping

1.The Competent Authorities shall have in place effective methods of demonstrating the lawfulness of processing of personal information, which may include the use of logs containing a clear and specific purpose of each query and the logging of processing operations related to the exchange, as well as other forms of records.

2.The Competent Authorities may use such logs or records for maintaining orderly operations of the national information systems or files concerned, to ensure data integrity and security, conduct auditing activities, and, where necessary, to follow backup procedures.

Article 19

Retention Period

The Parties shall provide in their applicable legal frameworks specific retention periods for records containing personal information, the object of which is to ensure that personal information is not retained for longer than is necessary and appropriate. Such retention periods shall take into account the purposes of processing, the nature of the data and the authority processing it, the impact on relevant rights and interests of affected individuals, and other applicable legal considerations. The Parties shall provide procedures for at least an annual review of the retention period with a view to determining whether changed circumstances require further modification of the applicable period.

Article 20

Special Categories of Personal Information

1.Processing of special categories of personal information shall only take place under appropriate safeguards in accordance with law.

2.The appropriate safeguards referred to in paragraph 1 may include the following protective measures:

a)restricting the purposes for which the information may be processed, such as allowing the processing only on a case-by-case basis;

b)masking, deleting, or blocking the information after effecting the purpose for which it was processed;

c)restricting personnel permitted to access the information;

d)requiring specialised training for personnel who access the information;

e)requiring supervisory approval to access the information.

3.These safeguards shall duly take into account the nature of the personal information, particular sensitivities of the information, and the purpose for which the information is processed.

Article 21

Automated Decisions

Decisions producing significant adverse actions concerning the relevant interests of individuals may not be based solely on the automated processing of personal information without human involvement, unless authorised under the Parties’ respective legal frameworks, and with appropriate safeguards that include the possibility to obtain human intervention.

Article 22

Access

1.The Parties shall ensure that any individual is entitled to seek access to his or her personal information and, subject to the restrictions set forth in paragraph 2, to obtain it. Such access shall be sought and obtained from a Competent Authority in accordance with the applicable legal framework of the State in which relief is sought.

2.The obtaining of personal information in a particular case may be subject to reasonable restrictions provided under domestic law, taking into account legitimate interests of the individual concerned, so as to:

a)protect the rights and freedoms of others, including their privacy;

b)safeguard public and national security;

c)protect law enforcement sensitive information;

d)avoid obstructing official or legal inquiries, investigations, or proceedings;

e)avoid prejudicing the prevention, detection, investigation, or prosecution of criminal offences or the execution of criminal penalties; or

f)otherwise protect interests provided for in legislation regarding freedom of information and public access to documents.

3.Excessive expenses shall not be imposed on the individual as a condition to access his or her personal information.

4.An individual is entitled to authorise, where permitted under domestic law, an oversight authority or other representative to request access on his or her behalf.

5.If access is denied or restricted, the Requested Competent Authority will, without undue delay, provide to the individual, or to his or her duly authorised representative as set forth in paragraph 4, the reasons for the denial or restriction of access.

Article 23

Rectification

1.The Parties shall ensure that any individual is entitled to seek correction or rectification of his or her personal information that he or she asserts is either inaccurate or has been improperly processed. Correction or rectification may include supplementation, erasure, blocking, or other measures or methods for addressing inaccuracies or improper processing. Such correction or rectification shall be sought and obtained from a Competent Authority in accordance with the applicable legal framework of the State in which relief is sought.

2. Where the Requesting Competent Authority concludes following:

a)a request under paragraph 1;

b)notification by the Requested Competent Authority; or

c)its own investigations or inquiries;

that information it has received under this Framework Agreement is inaccurate or has been improperly processed, it shall take measures of supplementation, erasure, blocking, or other methods of correction or rectification, as appropriate.

3.An individual is entitled to authorise, where permitted under domestic law, an oversight authority or other representative to seek correction or rectification on his or her behalf.

4.If correction or rectification is denied or restricted, the Requested Competent Authority will, without undue delay, provide to the individual, or to his or to her duly authorised representative as set forth in paragraph 3, a response setting forth the basis for the denial or restriction of correction or rectification.

Article 24

Administrative and Judicial Redress

The Parties shall have in place effective administrative and judicial remedies to provide redress for individuals whose personal information has been processed and used in a manner inconsistent with Part 3 of this Framework Agreement as set forth under each Party’s respective legal framework and in accordance with Article 4, paragraph 2.

Article 25

Transparency

1.The Parties shall ensure that notice is provided to an individual, as to his or her personal information, which notice may be effected by the Competent Authorities through publication of general notices or through actual notice, in a form and at a time provided for by the law applicable to the authority providing notice, with regard to the:

a)purposes of processing of such information by that authority;

b)purposes for which the information may be shared with other authorities;

c)laws or rules under which such processing takes place;

d)third parties to whom such information is disclosed; and

e)access, correction or rectification, and redress available.

2.Such notice requirement is subject to the reasonable restrictions under domestic law with respect to the matters set forth in Article 22, paragraph 2 (a) through (f).

Article 26

Effective Oversight

1.The Parties shall have in place one or more public oversight authorities that:

a)exercise independent oversight functions and powers, including review, investigation and intervention, where appropriate on their own initiative;

b)have the power to accept and act upon complaints made by individuals relating to the measures implementing Part 3 of this Framework Agreement; and

c)have the power to refer violations of law related to Part 3 of this Framework Agreement for prosecution or disciplinary action when appropriate.

2.The European Union shall provide for oversight under this Article through the data protection authorities of its Member States.

3.The United States shall provide for oversight under this Article cumulatively through more than one authority, which may include inspectors general, chief privacy officers, government accountability offices, privacy and civil liberties oversight boards, and other applicable executive and legislative privacy or civil liberties review bodies.

Part 4: Institutional Framework

Article 27

Joint Committee

1.A Joint Committee consisting of representatives of the Parties shall meet at least once a year to conduct consultations relating to this Framework Agreement and to review its implementation.

2.The Joint Committee shall be co-chaired by a representative of the European Union and a representative of the United States.

3.A Party may also request a meeting to seek to address questions related to the interpretation or application of this Framework Agreement.

4.The Joint Committee shall:

a)Monitor the effective implementation of this Framework Agreement, including by carrying out periodic joint reviews of the implementation of this Framework Agreement no later than three years from the date of the entry into force of this Framework Agreement, and thereafter on a regular basis, to assess the effectiveness, and proportionality or reasonableness, of the volume and reciprocity of the exchange of information in relation to the purposes of the implementation of this Framework Agreement. To this end, the Parties shall ensure that the Joint Committee receives statistics collected by the Member States and the United States including the number and nature of queries, the number and percentage of matches, and the timeliness of responses processed under this Framework Agreement;

b)Hold consultations consistent with Article 28; and

c)Provide guidance regarding how the Framework Agreement should be interpreted and implemented, where appropriate, and facilitate specific aspects of cooperation based on this Framework Agreement.

5.The Joint Committee’s working methods shall be by consensus.

Part 5: Final Provisions

Article 28

Consultations

Any dispute regarding the interpretation and implementation of this Framework Agreement shall be resolved by consultations between the Parties, which may include consultations in the Joint Committee, and shall not be referred to any national or international tribunal or third party for settlement.

Article 29

Suspension

1.In the event of a material breach of this Framework Agreement, either Party may suspend this Framework Agreement in whole or in part by written notification to the other Party through diplomatic channels. Such written notification shall not be made until after the Parties have engaged in a reasonable period of consultation without reaching a resolution; and suspension shall take effect twenty days from the date of receipt of such notification. Such suspension may be lifted by the suspending Party upon written notification to the other Party. The suspension shall be lifted immediately upon receipt of such notification.

2.Notwithstanding any suspension of this Framework Agreement, personal information falling within the scope of this Framework Agreement and transferred prior to its suspension shall continue to be protected in accordance with the safeguards of this Framework Agreement.

3.In the event of suspension of this Framework Agreement, cooperation between the United States and Member States under the bilateral agreements that is dependent on this Framework Agreement is expected to be suspended, consistent with those bilateral agreements. The bilateral agreements are expected to include a suspension provision specifying that elements of the bilateral agreements that fall under this Framework Agreement will be suspended should this Framework Agreement be suspended.

Article 30

Territorial Application

1.Subject to paragraph 2, this Framework Agreement shall apply, of the one part, to the territory in which the Treaty on European Union and the Treaty on the Functioning of the European Union apply and under the conditions laid down in those Treaties, and, of the other part, to the territory of United States.

2.This Framework Agreement shall apply to the territory of Ireland only pursuant to a notification by the European Union to United States to that effect. This Agreement shall not apply to the territory of the Kingdom of Denmark.

Article 31

Entry into Force, Duration, Amendment, and Termination

1.This Framework Agreement shall enter into force on the first day of the month following the date on which the Parties have notified each other in writing of the completion of their respective internal legal procedures for the entry into force of this Framework Agreement.

2.This Framework Agreement shall be in force for an indefinite period.

3.The Parties may agree, in writing, to amend this Framework Agreement.

4.Either Party may terminate this Framework Agreement by written notification to the other Party through diplomatic channels. Such termination shall take effect on the first day of the sixth month following the date of such notification.

5.Notwithstanding any termination of this Framework Agreement, personal information falling within the scope of this Framework Agreement and transferred prior to its termination shall continue to be processed in accordance with this Framework Agreement.

6.In the event of termination of this Framework Agreement, cooperation between the United States and Member States under the bilateral agreements that is dependent on this Framework Agreement is expected to cease, consistent with those bilateral agreements. The bilateral agreements are expected to include a termination provision specifying that elements of the bilateral agreements that fall under this Framework Agreement will be terminated should this Framework Agreement be terminated.

Article 32

Provisional Application

The European Union and the United States may apply this Framework Agreement provisionally, as of the date of signature.

Article 33

Authentic Text

The signed English text of this Framework Agreement shall be the authentic text. This Framework Agreement is drawn up by the European Union also in the Bulgarian, Croatian, Czech, Danish, Dutch, Estonian, Finnish, French, German, Greek, Hungarian, Italian, Irish, Latvian, Lithuanian, Maltese, Polish, Portuguese, Romanian, Slovak, Slovenian, Spanish and Swedish languages.

FOR THE EUROPEAN UNION:



………………………………………

Place: ……………………………….

Date: ………………………………..

FOR THE UNITED STATES OF AMERICA:



………….…………………………………

Place: ………….………………………….

Date: …………….………………………..

Top