Brussels, 24.7.2026

COM(2026) 382 final

2026/0213(NLE)

Proposal for a

COUNCIL DECISION

on the signing of the Agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime


EXPLANATORY MEMORANDUM

The present proposal concerns the signing of the Agreement with the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (‘the Agreement’).

1.CONTEXT OF THE PROPOSAL

Reasons for and objectives of the proposal

Strengthening international cooperation on law enforcement, including on information sharing, is essential to address the threats posed by terrorism and serious transnational crimes. The latest Serious Organised Crime Threat Assessment (SOCTA) report published by Europol 1 illustrates the international dimension of the activities of most serious crime organisations. Additionally, its latest Terrorism Situation and Trend Report (TE-SAT) 2 stresses not only the direct links between transnational travel and the organization of terrorist activities and serious crime, but also the importance of effectively detecting, investigating and prosecuting other serious criminal offences for preventing and detecting terrorist offences.

Passenger name record (PNR) data is information provided by passengers and collected by and held in the air carriers’ reservation and departure control systems for their own commercial purposes. The content of PNR data varies depending on the information given during the booking and check-in process and may include, for example, dates of travel and the complete travel itinerary of the passenger or group of passengers travelling together, contact details like address and phone number, payment information, seat number and baggage information.

The collection and analysis of PNR data can provide the authorities with important elements allowing them to detect suspicious travel patterns and identify associates of criminals and terrorists, in particular those previously unknown to law enforcement authorities. Accordingly, the processing of PNR data has become a widely used law enforcement tool, in the EU and beyond, to detect terrorism and other forms of serious crime, such as drug-related offences, human trafficking and child sexual exploitation, and to prevent such crimes from being committed. It has also proven to constitute an important source of information to support the investigation and prosecution of cases where such illegal activities have been committed 3 .

In 2010, the EU and the Republic of Korea upgraded their broader relationship to a Strategic Partnership, based on shared values and common interests. The EU-Republic of Korea Framework Agreement signed in May 2010 (and entered into force in 2014) provides the basis for cooperation on major political and global issues. The Republic of Korea is a like-minded and strategic partner of the European Union in the fight against terrorism and other serious crime. Within the United Nations, the G20 and other multilateral fora, the European Union and the Republic of Korea work closely together to improve global security frameworks as well as to enhance the security of their citizens.

On 17 December 2021, the Commission adopted an adequacy decision in relation to the transfer of personal data from the EU to the Republic of Korea between commercial operators 4 , concluding that the Republic of Korea ensures an essentially equivalent level of protection to the one guaranteed under the General Data Protection Regulation (GDPR). 5 In this context, the Commission also assessed the conditions and safeguards under which Korean public authorities, including law enforcement, can access data held by those operators. Although the adequacy assessment under this decision does not cover processing of PNR data as such, it nevertheless provides evidence that the foundations for essential data protection safeguards already exist in the legal framework of the Republic of Korea and should therefore also provide the basis for adducing the necessary corresponding safeguards in a PNR Agreement, in particular, enforceable data subject rights, judicial redress and independent oversight.

According to the legislation of the Republic of Korea, air carriers are required to transmit Passenger Name Record (PNR) data to the single window operated by the Korean Customs Service (KCS). This legislation aims at enhancing the security of the Republic of Korea by obtaining PNR data prior to a passenger’s arrival or departure and therefore significantly enhances the ability to conduct efficient and effective advance travel risk assessment of passengers.

In this context, the Republic of Korea has also shared relevant information both as regards the amount of scheduled flights between the EU and the Republic of Korea (approximately 12.000 in 2024) as well as regards the adherence of its legislation to the ICAO Standards on PNR.

To allow for the transfer of PNR data from the EU to the Republic of Korea to effectively fight terrorism and other forms of serious transnational crime, an international agreement is needed, providing the necessary legal basis at EU level. Such type of future agreement should encompass appropriate data protection safeguards within the meaning of Article 46(2)(a) of the General Data Protection Regulation 6 , including a system of independent oversight. A future agreement should respect fundamental rights and observe the principles recognised by the Charter of Fundamental Rights of the European Union, in particular the right to private and family life recognised in Article 7 of the Charter, the right to the protection of personal data recognised in Article 8 of the Charter and the right to effective remedy and fair trial recognised in Article 47 of the Charter.

In light of this, on 15 September 2025, the Commission adopted a Recommendation, proposing that the Council authorises the opening of negotiations of an agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data for preventing, detecting, investigating and prosecuting terrorist offences and serious crime. 7  On 16 December 2025, the Council provided its authorisation to open negotiations and adopted negotiating directives. 8

The purpose of this Agreement is to enable the transfer of PNR data from the Union to the Republic of Korea in recognition of the necessity to use PNR data as an essential tool in the fight against terrorism and other forms of serious crime.

Negotiations with the Republic of Korea began on 17 December 2025. On 4 June 2026, the lead negotiators initialled the agreement text and thus formally concluded negotiations. The Joint Statement pursuant to the EU-Korea Summit held on 10 June 2026 welcomed the conclusion of negotiations and committed to undertake all necessary efforts to ensure its swift entry into force.

The co-legislators have been informed throughout the negotiation process and consulted at all stages of the negotiations, notably through reporting to the Council’s Working Party on Justice and Home Affairs Information Exchange (IXIM) and the European Parliament’s Committee for Civil Liberties, Justice and Home Affairs (LIBE).

Consistency with existing policy provisions in the policy area

In the European Union, in 2016, the European Parliament and the Council of the European Union adopted Directive (EU) 2016/681 on the use of PNR data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (‘PNR Directive’) 9 . This Directive regulates the transfer and processing of PNR data in the European Union and lays down important safeguards for the protection of fundamental rights, in particular the rights to privacy and the protection of personal data. In June 2022, the Court of Justice of the EU (CJEU) confirmed the validity and compliance of this Directive with the Charter of Fundamental Rights of the EU and the Union Treaties, in its Judgment in case C-817/19 10 .

As regards the EU’s external PNR policy, the Commission first set out the broad lines of such policy in a 2003 Communication 11 on the EU approach towards transfers of PNR data from the EU to third countries, which were reviewed in a Communication adopted in 2010 12 . Three international agreements are currently in force between the EU and third countries: with Australia 13 , the United States 14 (2012) and the United Kingdom 15 (2020) which cover the transfer and processing of PNR data from the EU. After negotiations which followed up on Opinion 1/15 of the CJEU of 26 July 2017, 16 a new PNR Agreement with Canada was signed on 4 October 2024 17 . Subsequently, PNR Agreements were also signed with Norway (2025)  18 , Iceland(2025)  19 and Switzerland (2026)  20 .

At international level, an increasing number of third countries have started developing their capabilities to collect PNR data from air carriers. This trend is further prompted by Resolutions adopted by United Nations Security Council (in 2017 and 2019), requiring all States to develop the capability to collect and use PNR data 21 , based on which Standards and Recommended Practices on PNR (SARPs) were adopted by the International Civil Aviation Organization (ICAO) in 2020, by means of Amendment 28 to Annex 9 to the Chicago Convention, which became applicable in February 2021 22 .

The EU position, as established by Council Decision (EU) 2021/121, welcomes the ICAO SARPs on PNR as laying down ambitious safeguards on data protection and therewith allowing significant progress to be made at international level. At the same time, this Council Decision considered by means of requiring Member States to register a difference, that the requirements resulting from Union law (including relevant case-law), are more exacting than certain ICAO Standards, and that transfers from the EU to third countries require a legal basis establishing clear and precise rules and safeguards in relation to the use of PNR data by competent authorities of a third country 23 .

In this context, the negotiation and conclusion of this Agreement constitutes part of a broader effort of the Commission to pursue a consistent and effective approach regarding the transfer of PNR data to third countries, as announced in the Security Union Strategy 2020-2025 24 , building on the ICAO SARPs on PNR, and in line with the Union law and case-law. Such an approach was also requested by the Council with its Conclusions of June 2021 25 .

Herewith, the Commission also seeks to respond to calls from air carriers to ensure more legal clarity and foreseeability on PNR transfers to third countries.

2.LEGAL BASIS, SUBSIDIARITY AND PROPORTIONALITY

Procedural legal basis

Article 218(5) of the Treaty on the Functioning of the European Union (TFEU) provides that, where the agreement envisaged does not relate exclusively or principally to the common foreign and security policy, the Commission shall submit a proposal to the Council. The Council shall adopt a decision authorising the signing of the agreement.

Substantive legal basis

The proposal has two main aims and components, one relating to the necessity of ensuring public security by means of the transfer of PNR data to the Republic of Korea and the other concerning the protection of privacy and other fundamental rights and freedoms of individuals. Thus, the substantive legal basis is Article 16(2) and Article 87(2)(a) of the Treaty on the Functioning of the European Union.

Proportionality

The Union’s objectives with regard to this proposal as set out above can only be achieved by establishing a valid legal basis at Union level to ensure that appropriate protection of fundamental rights is granted to personal data transfers from the Union. The provisions of the agreement are limited to what is necessary to achieve its main objectives and strike a fair balance between the legitimate objective to maintain public security and the right of everyone to enjoy the protection of their personal data and private life.

Choice of the instrument

This proposal for a Council decision is submitted in accordance with paragraph 5 of Article 218 TFEU, which envisages the adoption by the Council of a decision authorising the signing and the provisional application of the agreement. There exists no other legal instrument that could be used in order to achieve the objective expressed in this proposal.

The appropriate safeguards required for the specific processing of PNR data received by the Republic of Korea from air carriers on flights operated by air carriers between the Union and the Republic of Korea must be established by means of a valid legal basis under EU law. The present Agreement constitutes such legal basis enabling PNR data transfers.

   Fundamental rights

The exchange of PNR data and its processing by the authorities of a third country constitutes an interference with the fundamental rights to privacy and data protection. However, such interference is justified, also because the Agreement pursues legitimate objectives i.e. to prevent, detect, investigate and prosecute serious crime and terrorism. The Agreement includes appropriate data protection safeguards to the personal data transferred and processed, in line with EU law, notably Articles 7, 8, 47 and 52 of the Charter of Fundamental Rights of the EU.

3.BUDGETARY IMPLICATIONS

There are no budgetary implications for the Union budget.

4.OTHER ELEMENTS

Detailed explanation of the specific provisions of the proposal

The Agreement, in full alignment with the Charter of Fundamental Rights of the EU, the relevant caselaw of the Court of Justice of the EU and the negotiating directives, provides a legal basis, conditions and safeguards for the transfer to and processing by the Republic of Korea of PNR data received from air carriers from the Union:

Article 1 sets out the scope and objectives the Agreement.

Article 2 includes key definitions of the Agreement, inter alia of the ‘Korean Competent Authority’ as the designated authority responsible for processing PNR data and of the terms ‘serious crime’ and ‘terrorism’, in line with how these concepts have been defined in other relevant EU law instruments.

Article 3 regulates the method and frequency of PNR data transfers by airlines to the Korean Competent Authority with a view to ensuring that PNR data transfers are kept to the minimum necessary and are proportionate to the purpose specified in the Agreement.

Article 4 sets out the purpose limitation – i.e. prevention, detection, investigation and prosecution of terrorist offences and serious crime – in an exhaustive manner for all PNR processing covered by the Agreement.

Article 5 sets out the three specific modalities for the processing of PNR data received under the Agreement by the Korean Competent Authority.

Article 6 provides additional safeguards for carrying out ‘real-time assessment’ and limits automated processing of PNR data.

Article 7 provides for a prohibition to process special categories of PNR data in line with how this concept has been defined in the EU data protection acquis.

Article 8 provides for a high level of security of PNR data received under the Agreement and ensures notifications of data security breaches to the designated Korean overseeing authority.

Article 9 provides for the keeping of logs and documentation of all PNR processing.

Article 10 sets out the maximum retention period of five years, combined with a requirement to delete the data after passengers’ date of departure, unless a risk assessment indicates that there is a connection based on objective elements from which it may be inferred that the PNR data might make an effective contribution to address the purposes of the Agreement, in addition to the requirement for the Republic of Korea to review its assessment every two years and notify the Union of the results of this assessment.

Article 11 requires the Korean Competent Authority to depersonalise PNR data at the latest after six months.

Article 12 includes rules and conditions for the disclosure of PNR data within the Republic of Korea, e.g. by limiting such disclosures to authorities with functions related to the purposes of the Agreement and by requiring prior approval by a judicial authority or another independent body for such disclosures.

Article 13 includes rules and conditions for the disclosure of PNR data outside the Republic of Korea and the EU, e.g. by limiting such disclosures to third countries with which the EU has concluded a comparable agreement or for which the EU has adopted a relevant adequacy decision and by requiring prior approval by a judicial authority or another independent body for such disclosures.

Article 14 fosters police and judicial cooperation through the exchange of PNR data or the results of processing of PNR data between the Korean Competent Authority and the PIUs of Member States of the Union, as well as between the Korean Competent Authority, on the one hand, and Europol within their respective competences, on the other hand.

Article 15 requires the Republic of Korea to appoint an authority required to oversee PNR processing in Korea.

Article 16 includes transparency and information obligations, including a requirement to notify individuals of the disclosure of their PNR data.

Article 17 provides that individuals may access (only) their own PNR data.

Article 18 provides that individuals’ right to correction, redress and information must be ensured.

Article 19 provides that all individuals must be given effective administrative and judicial redress.

Article 20 provides for the obligations by the Republic of Korea to notify the Union with relevant information about the authorities involved in PNR processing, and for the Union to make such information available to the public.

Article 21 provides for the entry into force of the Agreement.

Article 22 provides for dispute settlement and suspension mechanisms.

Article 23 provides for the possibility for either Party to terminate the Agreement at any time.

Article 24 provides for amendments of the Agreement.

Article 25 provides for consultation and evaluation of the implementation of the Agreement.

Article 24 contains a clause regarding the territorial application of the Agreement.

·Signing and the text of the Agreement

The text of the Agreement is submitted to the Council together with this proposal.

In accordance with the Treaties, it is for the Commission to ensure the signing of the Agreement, subject to its conclusion at a later date.

2026/0213 (NLE)

Proposal for a

COUNCIL DECISION

on the signing of the Agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime

THE COUNCIL OF THE EUROPEAN UNION,

Having regard to the Treaty on the Functioning of the European Union, and in particular Articles 16(2), and Article 87(2), point (a), in conjunction with Article 218(5) thereof,

Having regard to the proposal from the European Commission,

Whereas:

(1)On 16 December 2025, the Council authorised the Commission to open negotiations of an Agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data to prevent, detect, investigate and prosecute terrorist offences and serious crime (‘the Agreement’). The negotiations were successfully concluded by the initialling of the Agreement on XXMay / June 2026.

(2)The Agreement enables the transfer of PNR data by air carriers from the Union to the Republic of Korea in full respect of the rights provided in the Charter of Fundamental Rights of the Union, in particular the right to private and family life recognised in Article 7 of the Charter, and the right to the protection of personal data recognised in Article 8 of the Charter. In particular, the Agreement includes appropriate safeguards for the protection of personal data transferred under the Agreement.

(3)The Agreement fosters police and judicial cooperation between the competent authorities of the Republic of Korea and those of the Member States of the Union as well as Europol to contribute to the fight against terrorism and serious crime.

(4)The Agreement should enable the transfer of PNR data from the Union to the Republic of Korea in recognition of the necessity to use PNR data as an essential tool in the fight against terrorism and other forms of serious crime.

(5)The conclusion of this Agreement constitutes part of a broader effort of the Commission to pursue a consistent and effective approach regarding the transfer of PNR data to third countries, as announced in the Security Union Strategy 2020-2025 26 , building on the the International Civil Aviation Organization’s Standards and Recommended Practices (SARPs) on PNR, and in line with the Union law and case-law. Such an approach was also requested by the Council with its Conclusions of June 2021 27 .

(6)[In accordance with Articles 1 and 2 of Protocol No 21 on the position of the United Kingdom and Ireland in respect of the area of freedom, security and justice, annexed to the Treaty on European Union and to the Treaty on the Functioning of the European Union, and without prejudice to Article 4 of that Protocol, Ireland is not taking part in the adoption of this Decision and is not bound by it or subject to its application.] OR [In accordance with Article 3 of Protocol No 21 on the position of the United Kingdom and Ireland in respect of the area of freedom, security and justice, annexed to the Treaty on European Union and to the Treaty on the Functioning of the European Union, Ireland has notified [, by letter of …,] its wish to take part in the adoption and application of this Decision.].

(7)In accordance with Articles 1 and 2 of Protocol No 22 on the position of Denmark, annexed to the Treaty on European Union and to the Treaty on the Functioning of the European Union, Denmark is not taking part in the adoption of this Decision and is not bound by it or subject to its application.

(8)The European Data Protection Supervisor was consulted in accordance with Article 42 of Regulation (EU) 2018/1725 and delivered its Opinion [xxx] on [xx.xx.xxxx].

(9)Therefore, the Agreement should be signed,

HAS ADOPTED THIS DECISION:

Article 1

The signing of the Agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime is hereby authorised, subject to the conclusion of that Agreement 28 .

Article 2

This Decision shall enter into force on the date of its adoption.

Done at Brussels,

   For the Council

   The President

(1)     Serious and Organised Crime Threat Assessment (SOCTA) | Europol
(2)     EU Terrorism Situation & Trend Report (TE-SAT) | Europol
(3)    See also Report from the Commission to the European Parliament and the Council on the review of Directive (EU) 2016/681 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime; COM(2020) 305 final (24.07.2020).
(4)    Commission Implementing Decision (EU) 2022/254 of 17 December 2021 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate protection of personal data by the Republic of Korea under the Personal Information Protection Act (OJ L 44, 24.2.2022, p. 1–90).
(5)    Regulation (EU) 2016/679, OJ L 119, 4.5.2016, p. 1-88.
(6)    OJ L 119, 4.5.2016, p. 1–88.
(7)    COM(2025) 490 final (15.9.2025)
(8)    OJ L, 2025/2641.
(9)    Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (OJ L 119, 4.5.2016, p. 132–149), ), hereinafter referred to as the ‘PNR Directive’ or ‘Directive (EU) 2016/681’.
(10)    Judgment of the Court (Grand Chamber) of 21 June 2022 “Ligue des droits humains ASBL v Conseil des ministres”, C-817/19, EU:C:2022:491. The judgement concerned a request for a preliminary ruling from the Cour Constitutionnelle of Belgium.
(11)    COM(2003) 826 final (16.12.2003).
(12)    COM(2010) 492 final (21.09.2010).
(13)    OJ L 186, 14.7.2012, p. 4–16.
(14)    OJ L 215, 11.8.2012, p. 5–14.
(15)    OJ L 149, 30.4.2021, p. 710 – 735.
(16)    EU:C:2017:592.
(17)    OJ L, 2024/2891.
(18)    Authorised by a Council Decision of 22 September 2025, OJ L, 2025/1964.
(19)    Authorised by a Council Decision of 22 September 2025, OJ L, 2025/1965.
(20)    Authorised by a Council Decision of 23 February 2026, OJ L, 2026/643.
(21)    UNSCR 2396 (2017): “The Security Council: [..] 12. Decides that Member States shall develop the capability to collect, process and analyse, in furtherance of ICAO standards and recommended practices, passenger name record (PNR) data and to ensure PNR data is used by and shared with all their competent national authorities, with full respect for human rights and fundamental freedoms for the purpose of preventing, detecting and investigating terrorist offenses and related travel, [..]”. See also UNSCR 2482 (2019).
(22)    Annex 9, Chapter 9, Section D to the International Convention on Civil Aviation.
(23)    OJ L 37, 3.2.2021, p.6-9.
(24)    Communication from the Commission to the European Parliament, the European Council, the Council, the European Economic and Social Committee and the Committee of the Regions on the EU Security Union Strategy, , COM(2020) 605 final (24.7.2020): [..] as a mid-term action, the Commission will launch a review of the current approach on PNR data transfer to third countries.”.
(25)    Council Conclusions of 7 June 2021 on the transfer of Passenger Name Record (PNR) data to third countries, in particular Australia and the United States, for the purpose of combating terrorism and serious crime, Council Document 9605/21 of 8 June 2021: “Calls on the Commission to pursue a consistent and effective approach regarding the transfer of PNR data to third countries for the purpose of combating terrorism and serious crime, building on the ICAO SARPs, and in line with the relevant requirements established under Union law.”
(26)    Communication from the Commission to the European Parliament, the European Council, the Council, the European Economic and Social Committee and the Committee of the Regions on the EU Security Union Strategy, COM(2020) 605 final (24.7.2020): [..] as a mid-term action, the Commission will launch a review of the current approach on PNR data transfer to third countries.”.
(27)    Council Conclusions of 7 June 2021 on the transfer of Passenger Name Record (PNR) data to third countries, in particular Australia and the United States, for the purpose of combating terrorism and serious crime, Council Document 9605/21 of 8 June 2021: “Calls on the Commission to pursue a consistent and effective approach regarding the transfer of PNR data to third countries for the purpose of combating terrorism and serious crime, building on the ICAO SARPs, and in line with the relevant requirements established under Union law.”
(28)    The text of the Agreement will be published together with the decision on its conclusion. 

Brussels, 24.7.2026

COM(2026) 382 final

ANNEX

to the

Proposal for a COUNCIL DECISION

on the signing of the Agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime


ANNEX

AGREEMENT BETWEEN THE EUROPEAN UNION AND THE REPUBLIC OF KOREA ON THE TRANSFER OF PASSENGER NAME RECORD (PNR) DATA FOR THE PREVENTION, DETECTION, INVESTIGATION AND PROSECUTION OF TERRORIST OFFENCES AND SERIOUS CRIME

THE EUROPEAN UNION, hereinafter also referred to as the "Union" or "EU",

   and

THE REPUBLIC OF KOREA, hereinafter also referred to as ‘Korea’,

hereinafter jointly referred to as "the Parties",

RECOGNISING that preventing, detecting, investigating, and prosecuting terrorist offences, as well as other serious crime, while preserving human rights and fundamental freedoms, in particular rights to privacy and data protection, are objectives of general interest;

RECOGNISING that the Parties share common values with respect to data protection and privacy reflected in their respective laws;

RECOGNISING that information sharing is an essential component of the fight against terrorist offences and other serious crime, and that in this context, the use of Passenger Name Record (PNR) data is a critically important instrument to pursue these goals;

RECOGNISING the importance of sharing PNR data and relevant and appropriate analytical information containing PNR data under this Agreement between the Parties with competent authorities of Korea, Member States of the Union (Member States), Europol and Eurojust as a means to foster international police and judicial cooperation;

SEEKING to enhance and encourage the cooperation between the Parties on PNR through the exchange of information and technical cooperation by national experts from the Member States and Korea, in particular on the development of pre-determined criteria and on other aspects of the processing of PNR;

HAVING REGARD to United Nations Security Council Resolutions 2396 (2017) and 2482 (2019), which call upon all States to develop the capability to collect and process PNR data and to the International Civil Aviation Organization Standards and Recommended Practices for the collection, use, processing and protection of PNR data adopted on 23 June 2020 as Amendment 28 to Annex 9 to the Convention on International Civil Aviation (the Chicago Convention);

HAVING REGARD to the adequacy decision in relation to the transfer of personal data from the EU to the Republic of Korea between commercial operators adopted by the Commission on 17 December 2021, concluding that the Republic of Korea ensures an essentially equivalent level of protection to the one guaranteed under the General Data Protection Regulation (GDPR).

RECOGNISING that this Agreement is not intended to apply to advance passenger information (API) that is collected and transmitted by air carriers to Korea for the purpose of border control;

MINDFUL of the Union's commitments pursuant to Article 6 of the Treaty on European Union on the respect for fundamental rights, the protection of individuals with regard to the processing of personal data pursuant to Article 16 of the Treaty on the Functioning of the European Union, the principles of proportionality and necessity concerning the right to respect for private and family life, the respect for privacy, and the protection of personal data under Articles 7 and 8 of the Charter of Fundamental Rights of the European Union in line with the relevant case-law of the Court of Justice of the European Union, as well as with Article 8 of the European Convention on the Protection of Human Rights and Fundamental Freedoms, Council of Europe Convention No. 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data and its additional Protocol 181;

MINDFUL of Korean commitments under the Constitution of the Republic of Korea, in particular Articles 10 and 17, and the Personal Information Protection Act;

RECOGNISING that under the Customs Act of the Republic of Korea the transfer of PNR data by air carriers to Korea is mandatory;

RECOGNISING that Directive (EU) 2016/681 of the European Parliament and the Council 1 is the basis for the transfers by air carriers of PNR data to the competent authorities of the Member States. Together with Regulation (EU) 2016/679 of the European Parliament and of the Council 2 and Directive (EU) 2016/680 of the European Parliament and of the Council 3 , Directive (EU) 2016/681 ensures a high level of protection of fundamental rights, in particular the rights to privacy and the protection of personal data.

HAVE AGREED AS FOLLOWS:

CHAPTER I

GENERAL PROVISIONS

ARTICLE 1

Objectives and scope

1.    The objective of this Agreement is to enable the transfer of Passenger Name Record (PNR) data by air carriers from the Union to Korea and to lay down rules and conditions subject to which those PNR data may be processed by Korea.

2.    The objective of this Agreement is also to enhance police and judicial cooperation between the Union and Korea in respect of PNR data.

3.    The scope of this Agreement covers air carriers operating passenger flights between the Union and Korea as well as air carriers incorporated, or storing data, in the Union and operating flights to or from Korea.

ARTICLE 2

Definitions

For the purposes of this Agreement, the following definitions apply:

(1)    "air carrier" means an air transport undertaking with a valid operating licence or equivalent permitting it to carry out carriage of passengers by air between the Union and Korea;

(2)    "passenger" means any person, including persons in transfer or transit and excluding members of the crew, carried or to be carried in an aircraft with the consent of the air carrier, such consent being manifested by that person's registration in the passenger list;

(3)    "Korean competent authority" means the Korean authority responsible for receiving and processing PNR data in accordance with Article 5 of this Agreement;

(4)    "passenger name record" or "PNR" means a record of each passenger's travel requirements which contains information necessary to enable reservations to be processed and controlled by the booking and participating air carriers for each journey booked by or on behalf of any person, whether it is contained in reservation systems, departure control systems used to check passengers onto flights, or equivalent systems providing the same functionalities; specifically, as used in this Agreement, PNR data consists of the elements exhaustively listed in the Annex;

(5)    "serious crime" means the offences punishable by a maximum custodial sentence or detention order of at least three years under the national law of Korea which have an objective link, even if only an indirect one, with the carriage of passengers by air;

(6)    "terrorist offence" means:

(a)    an act or omission that is committed for a political, religious or ideological purpose, objective or cause with the intention of intimidating the public with regard to its security, including its economic security, or with the intention of compelling a person, government or domestic or international organisation to do or refrain from doing any act, and that intentionally:

(i)    causes death or serious bodily harm;

(ii)    endangers an individual's life;

(iii)    causes a serious risk to the health or safety of the public;

(iv)    causes substantial property damage likely to result in the harm referred to in points (i), (ii) and (iii); or

(v)    causes serious interference with or serious disruption of an essential service, facility or system, other than as a result of lawful or unlawful advocacy, protest, dissent or stoppage of work, such as a strike, that is not intended to result in the harm referred to in points (i), (ii) and (iii); or

(b)    activities constituting an offence within the scope and as defined in applicable international conventions and protocols relating to terrorism; or

(c)    knowingly participating in or contributing to or instructing a person, a group, or an organisation to carry out any activity for the purpose of enhancing a terrorist entity's ability to facilitate or carry out an act or omission referred to in point (a) or (b); or

(d)    committing an indictable offence where the act or omission constituting the offence is committed for the benefit of, at the direction of, or in association with a terrorist entity; or

(e)    collecting property or inviting a person, a group, or an organisation to provide, providing or making available property or financial or other related services for the purpose of carrying out an act or omission referred to in point (a) or (b) or using or possessing property for the purpose of carrying out an act or omission referred to in point (a) or (b); or

(f)    attempting or threatening to commit an act or omission as referred to in point (a) or (b), conspiring, facilitating, instructing or counselling in relation to an act or omission described in (a) or (b), or being an accessory after the fact, or harbouring or concealing for the purpose of enabling a terrorist entity to facilitate or carry out an act or omission described in (a) or (b); or

(g)    travelling to or from Korea or a Member State for the purpose of committing, or contributing to the commission of a terrorist offence within the meaning of point (a) or (b), or for the purpose of participating in the activities of a terrorist entity within the meaning of paragraph 7 with knowledge of the fact that such participation will contribute to the criminal activities of the terrorist entity.

(7)    "terrorist entity" means:

(i)    a person, a group, or an organisation that has as one of its purposes or activities facilitating or carrying out an act or omission referred to in paragraph 6 point (a) or (b); or

(ii)    a person, a group, or an organisation that knowingly acts on behalf of, at the direction of or in association with such a person, group or organisation referred to in point (i).

CHAPTER II

TRANSFER OF PNR DATA

ARTICLE 3

Method and frequency of transfer

1.    Korea shall ensure that air carriers transfer PNR data to the Korean competent authority exclusively by transmitting the required PNR data into the database of the requesting authority ("push" method), and in accordance with the following procedures to be observed by air carriers:

(a)    by electronic means in compliance with the technical requirements of the Korean competent authority or, in the case of a technical failure, by any other appropriate means ensuring an appropriate level of data security;

(b)    by using a mutually accepted messaging format, and in a secure manner using common protocols as required by the Korean competent authority;

(c)    either directly or through authorised agents, who act on behalf of and under the responsibility of an air carrier, for the purpose of and under the conditions laid down in this Agreement.

2.    Korea shall not require air carriers to provide elements of PNR data which are not already held or collected by air carriers for their reservation purposes or in the air carriers’ normal course of their business.

3.    Korea shall ensure that the Korean competent authority deletes any data element transferred to it by an air carrier pursuant to this Agreement upon receipt of the PNR data, if that data element is not listed in the Annex.

4.    Korea shall ensure that the Korean competent authority requires air carriers to transfer PNR data:

(a)    on a scheduled basis with the earliest point in time being up to 48 hours before the scheduled departure; and

(b)    a maximum of five times, for a particular flight.

5.    Korea shall permit air carriers to limit the transfer referred to in point (b) of paragraph 4 to updates of the PNR data transferred as referred to in point (a) of that paragraph.

6.    Korea shall ensure that the Korean competent authority informs air carriers of the specified times for the transfers.

7.    In specific cases where there is an indication that additional access is necessary to respond to a specific threat related to the purposes set out in Article 4, the Korean competent authority may require an air carrier to provide PNR data prior to, between or after the scheduled transfers. In exercising this discretion, Korea shall act judiciously and proportionately and shall require the use of the method of transfer referred to in paragraph 1 of this Article.

CHAPTER III

PNR PROCESSING AND PROTECTION

ARTICLE 4

Purposes of PNR processing

Korea shall ensure that PNR data received pursuant to this Agreement are processed strictly for the purpose of preventing, detecting, investigating and prosecuting terrorist offences or serious crime.

ARTICLE 5

Modalities of PNR processing

The Korean competent authority may process PNR data exclusively by means of the following specific modalities of processing:

(a)    carrying out an assessment of passengers prior to their scheduled arrival in or departure from Korea to identify persons who require further examination by the competent authorities, in view of the fact that such persons may be involved in a terrorist offence or serious crime in accordance with the real-time assessment carried out under Article 6;

(b)    carrying out a search into the database of retained PNR data with a view to responding, on a case-by-case basis, to a duly reasoned request submitted pursuant to Articles 12 and 13 and, where appropriate, disclosing any relevant PNR data or the results of their processing;

(c)    analysing PNR data for the purpose of updating, testing or creating new criteria to be used in the assessments carried out under Article 6(1)(b), in order to identify any persons who may be involved in a terrorist offence or serious crime;

ARTICLE 6

Real-time assessment

1.    When carrying out an assessment referred to in point (a) of Article 5, the Korean competent authority may:

(a)    compare PNR data only against databases on persons or objects sought or under alert, in accordance with international and national rules applicable to such databases; and

(b)    process PNR data against pre-determined criteria.

2.    Korea shall ensure that the databases referred to in paragraph 1(a) of this Article are non-discriminatory, reliable, up to date and relevant for the purposes set out in Article 4.

3.    Korea shall ensure that any assessment of PNR data as referred to in paragraph 1(b) of this Article is based on non-discriminatory, specific and reliable pre-established models and criteria to enable the Korean competent authority to arrive at results targeting individuals who might be under a reasonable suspicion of involvement or participation in terrorist offences or serious crime. Korea shall ensure that those criteria are in no circumstances based on a person's race or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, health, sexual life or sexual orientation.

4.    Korea shall ensure that any positive match resulting from the real-time processing of PNR data is individually reviewed by the Korean competent authority by non-automated means.

ARTICLE 7

Special categories of data

1.    Any processing of PNR data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, of data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited under this Agreement.

2.    To the extent that the PNR data received under this Agreement by the Korean competent authority include such special categories of personal data, the Korean competent authority shall delete such data immediately.

ARTICLE 8

Data security and integrity

1.    Korea shall ensure that PNR data received under this Agreement are processed in a manner that ensures a high level of data security appropriate for the risks represented by the processing and the nature of PNR data received under this Agreement. In particular, the Korean competent authority shall:

(a)    implement appropriate technical and organisational measures and procedures to ensure such level of security;

(b)    apply encryption, authorisation, and documentation procedures to the PNR data;

(c)    limit access to PNR data to authorised staff; and

(d)    store PNR data in a secure physical environment that is protected with access controls.

2.    Korea shall ensure that any data security breach, in particular leading to accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, or any unlawful forms of processing is subject to effective and dissuasive corrective measures.

3.    Korea shall report any breach of data security to the overseeing authority(ies) referred to in Article 15.

ARTICLE 9

Logging and documenting of PNR data processing

1.    The Korean competent authority shall log and document all processing of PNR data. Korea shall use such a log or documentation only to:

(a)    self-monitor and to verify the lawfulness of data processing;

(b)    ensure proper data integrity or system functionality;

(c)    ensure the security of data processing; and

(d)    ensure oversight and accountability of the public administration.

2.    Logs or documentation kept under paragraph 1 shall be communicated upon request to the overseeing authority(ies) which shall use this information only for the oversight of data protection and for ensuring proper data processing as well as data integrity and security.

CHAPTER IV

STORAGE AND DISCLOSURE OF PNR DATA

ARTICLE 10

Retention periods

1.    Korea shall not retain PNR data for more than five years from the date that it receives the PNR data.

2.    Korea shall review the PNR data retention period every two years and determine whether it remains commensurate with the level of risk of terrorism and serious transnational crime originating from and transiting through the European Union. Korea shall provide a classified report to the European Union outlining the outcome of the review, including the level of risk identified, factors considered in minimising the data retention period, and the related retention decision.

3.    PNR data may be retained under this Agreement beyond the passengers’ date of departure, where Korea considers that there is a connection with the purposes set out in Article 4, based on objective elements from which it may be inferred that the PNR data might make an effective contribution to addressing those purposes.

4.    At the expiry of the appropriate retention period, Korea shall ensure that PNR data are irrevocably deleted in such a manner that the data subjects concerned are no longer identifiable.

5.    By way of derogation from paragraph 1, Korea may allow the retention of PNR data required for review, investigation, enforcement action, judicial proceedings, prosecution, or the enforcement of penalties, until the relevant process is concluded.

ARTICLE 11

Depersonalisation

1.    The Korean competent authority shall depersonalise PNR data at the latest six months after they are received. It shall do so through masking out the following data elements which could serve to identify directly the passenger to whom the PNR data relate:

(a)    name(s), including the names of other passengers on the PNR and number of travelers on the PNR travelling together;

(b)    address and contact information;

(c)    all forms of payment information, including billing address, to the extent that it contains any information which could serve to identify directly the passenger to whom the PNR data relate or any other persons;

(d)    frequent flyer information;

(e)    general remarks to the extent that they contain any information which could serve to identify directly the passenger to whom the PNR data relate; and

(f)    any API data that have been collected.

2.    The Korean competent authority may disclose the data elements referred to in paragraph 1 of this Article only for the purposes of Article 4 and under the conditions of Articles 12 or 13.

ARTICLE 12

Disclosure within Korea

1.    When responding to a duly reasoned request sent by another Korean government authority in accordance with Article 5(b), the Korean competent authority shall disclose, on a case-by-case basis, PNR data or the results of their processing, only where:

(a)    the PNR data is disclosed to government authorities whose functions are directly related to the purposes set out in Article 4 and to the extent that such disclosure is necessary for the achievement of those purposes;

(b)    the minimum amount of PNR data necessary is disclosed;

(c)    the receiving competent authority affords protection equivalent to the safeguards provided for in this Agreement;

(d)    the disclosure is approved by either a judicial authority or another independent body competent under national law to verify whether the conditions for disclosure are met.

2.    By way of derogation from point (d) of paragraph 1, the Korean competent authority may disclose PNR data in cases of duly justified urgency without prior review or approval. In such cases, the review referred to in point (d) of paragraph 1 must take place within a short time.

3.    Korea shall ensure that the receiving government authority does not disclose PNR data to another authority unless the disclosure is explicitly authorised by the Korean competent authority.

ARTICLE 13

Disclosure outside Korea and the EU

1.    When responding to a duly reasoned request sent by a government authority of countries other than the Member States in accordance with Article 5(b), the Korean competent authority shall disclose, on a case-by-case basis, PNR data or the results of their processing, only where:

(a)    such disclosure is necessary to achieve one of the purposes set out in Article 4;

(b)    the minimum amount of PNR data necessary is disclosed;

(c)    the country to the authority of which the PNR data are to be disclosed has either concluded an Agreement with the Union that provides for protection of personal data comparable to this Agreement or is subject to a decision of the European Commission pursuant to Union law, finding that said country ensures an adequate level of data protection within the meaning of Union law; and.

(d)    the disclosure is approved by either a judicial authority or another independent body competent under national law to verify whether the conditions for disclosure are met.

2.    By way of derogation from paragraph 1(c), the Korean competent authority may disclose PNR data to another country if it considers that the disclosure is necessary for the prevention or investigation of a serious and imminent threat to public security, and if that country provides a written assurance, pursuant to an arrangement, agreement or otherwise, that the information will be protected in line with the safeguards set out in this Agreement.

3.    By way of derogation from paragraph 1(d), the Korean competent authority may disclose PNR data in cases of duly justified urgency without prior review and approval. In such cases, the review referred to in point (d) of paragraph 1 must take place within a short time.

ARTICLE 14

Exchange of PNR-related information

1.    The Korean competent authority shall share with Europol or Eurojust, within the scope of their respective mandates, or with the Passenger Information Units of the Member States, PNR data, the results of processing those data, or analytical information based on PNR data, as soon as possible and in specific cases where necessary to prevent, detect, investigate, or prosecute terrorist offences or serious crime. The Korean competent authority shall share such information either on its own initiative or at the request of Europol or Eurojust, within the scope of their respective mandates, or of the Passenger Information Units of the Member States.

2.    The Passenger Information Units of Member States shall share with the Korean competent authority PNR data, the results of processing those data, or analytical information based on PNR data, as soon as possible and in specific cases where necessary to prevent, detect, investigate, or prosecute terrorist offences or serious crime. The Passenger Information Units of Member States shall share such information on their own initiative or at the request of the Korean competent authority.

3.    The Parties shall ensure that the information referred to in paragraphs 1 and 2 is shared in accordance with applicable rules on law enforcement cooperation or information sharing between Korea and Europol or Eurojust, or the relevant Member State. In particular, the exchange of information with Europol under this Article shall take place through a secure communication channel established for the exchange of information.

CHAPTER V

DATA PROTECTION

ARTICLE 15

Oversight

1.    The data protection safeguards for the processing of PNR data under this Agreement shall be subject to oversight by one or more independent public authorities (the ‘overseeing authorities’). Korea shall ensure that the overseeing authorities have effective powers to investigate compliance with the rules related to the collection, use, disclosure, retention, or disposal of PNR data. The overseeing authorities may conduct compliance reviews and investigations, may report findings and may make recommendations to the Korean Competent Authority. Korea shall ensure that the overseeing authorities have the power to refer violations of law related to this Agreement for prosecution or disciplinary action, when appropriate.

2.    Korea shall ensure that the overseeing authorities ensure that complaints relating to non-compliance with this Agreement are received, investigated, responded to, and appropriately redressed.

3. In addition, Korea shall apply this Agreement subject to independent review by other designated public entities that have the mandate to ensure the oversight or accountability of the public administration.

ARTICLE 16

Transparency and information

1.    Korea shall ensure that the Korean competent authority makes the following information available on its website:

(a)    a list of the legislation authorising the transfer of PNR data by air carriers;

(b)    the reason for the collection and storage of PNR data;

(c)    the manner of processing and protecting the PNR data;

(d)    the manner and extent to which the PNR data may be disclosed to other competent authorities; and

(e)    contact information for inquiries.

2.    Korea shall work with interested third parties, such as the aviation and air travel industry, to promote transparency at the time of booking regarding the reasons for the collection and processing of PNR data, and regarding how to request access, rectification and redress to those PNR data.

3.    If PNR data retained in accordance with Article 10 has been disclosed in accordance with Articles 12 or 13, Korea shall inform, taking into account reasonable efforts, the passengers concerned in writing and within a reasonable time once such notification is no longer liable to jeopardise the investigations by the public authorities concerned to the extent the relevant contact information of the passengers is available or can be retrieved. The notification shall include information on how the individual concerned can seek administrative or judicial redress pursuant to Article 19.

ARTICLE 17

Access by individuals to their PNR data

1.    Korea shall ensure that any individual may access their PNR data.

2.    Korea shall ensure that the Korean Competent Authority, within a reasonable time:

(a)    provides the individual with a copy of their PNR data if the individual makes a written request for their PNR data;

(b)    replies in writing to any request;

(c)    provides the individual with access to recorded information confirming that the individual's PNR data has been disclosed, if the individual requests that confirmation;

(d)    sets out the legal or factual reasons for any refusal to allow access to the individual's PNR data; and

(e)    informs the individual that they may make a complaint and of the complaint procedure.

2.    For important reasons of public interest, Korea may make any access to information under this Article subject to reasonable legal requirements and limitations, including any limitations necessary to prevent, detect, investigate, or prosecute criminal offences, or to protect public or national security, with due regard for the legitimate interests of the individual concerned.

ARTICLE 18

Correction or annotation for individuals

1.    Korea shall ensure that any individual may request the correction of their PNR data.

2.    Korea shall ensure that the Korean Competent Authority considers all written requests for correction and shall, within a reasonable time:

(a)    correct the PNR data and notify the individual that the correction has been made; or

(b)    refuse all or part of the correction, (i) attaching a note to the PNR data reflecting any correction requested that was refused and (ii) notifying the individual that the request for correction is refused, and set out the legal or factual reasons for the refusal.

3.    Korea shall inform the requesting individual that they may make a complaint and of the complaint procedure.

ARTICLE 19

Administrative and judicial redress

 

1.    Korea shall ensure that an independent public authority receives, investigates and responds to complaints lodged by an individual concerning their request for access, correction or annotation of their PNR data. Korea shall ensure that the relevant authority notifies the complainant of the means of seeking the judicial redress set out in paragraph 2.

2.    Korea shall ensure that any individual who is of the view that their rights have been infringed by a decision or action in relation to their PNR data may seek effective judicial redress in accordance with Korean law by way of judicial review or such other remedy that may include compensation:

CHAPTER VI

FINAL PROVISIONS

ARTICLE 20

Notifications

1.    Korea shall inform the Union through diplomatic channels in writing of the details of the following authorities:

(a)    the Korean competent authority referred to in Article 2(3);

(b)    the independent overseeing authorities as referred to in Article 15;

(c)    the judicial authority or another independent body competent under national law, as referred to in Articles 12 and 13.

2.    Korea shall notify without delay any changes to the information referred to in paragraph 1.

3.    The Union shall make the information referred to in paragraphs 1 and 2 available to the public.

ARTICLE 21

Entry into force

1.    This Agreement shall be approved by the Parties in accordance with their own internal procedures.

2.    This Agreement shall enter into force on the first day of the month following the date of the receipt of the written information by which Korea has notified the Union of the authorities referred to in Article 20(1) or the written notifications by which the Parties have notified each other through diplomatic channels that the procedures referred to in paragraph 1 of this Article have been completed, whichever is the later.

ARTICLE 22

Dispute resolution and suspension

1.    The Parties shall resolve any dispute regarding the interpretation, application or implementation of this Agreement through consultations with a view to reaching a mutually acceptable resolution, including providing an opportunity for either Party to comply within a reasonable time.

2.    Either Party may suspend in whole or in part the application of this Agreement by notification in writing to the other Party through diplomatic channels. Such written notification shall not be made until after the Parties have engaged in a period of consultation no longer than 2 months. The suspension shall come into effect two months from the date of such notification, unless the Parties jointly decide otherwise.

3.    The Party that has suspended the application of this Agreement shall immediately inform the other Party of the date on which the application of this Agreement will resume, once it considers that the reasons for the suspension no longer apply. The suspending Party shall notify the other Party in writing.

4.    Korea shall continue to apply the terms of this Agreement to all PNR data received before any suspension of this Agreement.

ARTICLE 23

Termination

1.    This Agreement may be terminated at any time by either of the Parties by written notification through diplomatic channels. The termination shall take effect three months after the date of receipt of the written notification.

2.    If either Party gives notice of termination under this Article, the Parties shall, through consultations, decide what measures are needed to ensure that any cooperation initiated under this Agreement is concluded in an appropriate manner.

3.    Korea shall continue to apply the terms of this Agreement to all PNR data received before any termination of this Agreement.

ARTICLE 24

Amendments

1.    This Agreement may be amended at any time by mutual consent between the Parties. The amendments to this Agreement shall be approved by the Parties in accordance with their own internal procedures and shall enter into force on the first day of the month following the date of the receipt of the last written notification by which the Parties have notified each other through diplomatic channels of the completion of their internal procedures necessary for the approval of the Agreement. .

2.    The Annex to this Agreement may be updated, by mutual consent between the Parties expressed by written notification exchanged through diplomatic channels. Such updates shall enter into force on the first day of the month following the date of the receipt of the last written notification.

ARTICLE 25

Consultation and evaluation

1.    The Parties shall enter into consultation with respect to issues related to the monitoring of the implementation of this Agreement. They shall advise each other of any measure that may affect this Agreement.

2.    The Parties shall carry out a joint evaluation of the implementation of this Agreement if requested by either Party and jointly decided. In conducting such an evaluation, the Parties shall pay special attention to the necessity and proportionality of processing PNR data for each of the purposes set out in Article 4. The Parties shall decide in advance on the modalities of such evaluations. Such consultations may lead one or both Parties to propose an amendment to the Agreement. Such proposal shall be submitted in written form and any such amendment shall follow the procedure laid out in Article 24.

ARTICLE 26

Territorial application

1.    This Agreement shall apply to the territory of the Union in accordance with the Treaty on European Union and the Treaty on the Functioning of the European Union and to the territory of Korea.

2.    By the date of entry into force of this Agreement, the Union shall notify Korea of the Member States to the territories of which this Agreement applies. It may subsequently, at any time, notify any changes thereto.

This Agreement shall be drawn up in duplicate in the Bulgarian, Croatian, Czech, Danish, Dutch, English, Estonian, Finnish, French, German, Greek, Hungarian, Irish, Italian, Latvian, Lithuanian, Maltese, Polish, Portuguese, Romanian, Slovak, Slovenian, Spanish, Swedish and Korean languages, each text being equally authentic. In the event of any divergence between the texts of this Agreement, the English text shall prevail.

--

ANNEX

PASSENGER NAME RECORD DATA ELEMENTS

REFERRED TO IN ARTICLE 2(4)

1.    PNR record locator

2.    Date of reservation/issue of ticket

3.    Date(s) of intended travel

4.    Name(s)

5.    Address and contact information, namely telephone number and email address relating to the passengers

6.    Information relating to the payment methods for, and billing of, the air ticket

7.    Complete travel itinerary for specific PNR

8.    Frequent flyer data relating to the passenger(s) (status and frequent flyer number)

9.    Travel agency/travel agent

10.    Travel status of passenger, including confirmations, check-in status, no-show or go-show information



11.    Split/divided PNR information

12.    Information relating to unaccompanied minors under 18 years: name, gender, age, language(s) spoken, name and contact details of guardian on departure and relationship to the minor, name and contact details of guardian on arrival and relationship to the minor, name of departure and arrival agent

13.    Ticketing field information, including ticket number, date of ticket issuance and one-way tickets, automated ticket fare quote fields

14.    Seat number and other seat information

15.    Code share information

16.    All baggage information

17.    Number and other names of travellers on the PNR

18.    Any advance passenger information (API) data elements as far as already collected by carriers

19.    All historical changes to the PNR listed in points 1 to 18

________________

(1)    Directive (EU) 2016/681 of the European Parliament and the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (OJ EU L 119, 4.5.2016, p. 132, ELI: http://data.europa.eu/eli/dir/2016/681/oj).
(2)    Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).
(3)    Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ EU L 119, 4.5.2016, p. 89, ELI: http://data.europa.eu/eli/dir/2016/680/oj).