← Current text · History

Regulation (EU) 2025/13 of the European Parliament and of the Council of 19 December 2024 on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818

Current text a fecha 2025-01-08

CHAPTER 1

GENERAL PROVISIONS

Article 1

Subject matter

For the purpose of preventing, detecting, investigating and prosecuting terrorist offences and serious crime, this Regulation lays down the rules on:

(a) the collection of advance passenger information (API) by air carriers on extra-EU flights and intra-EU flights;

(b) the transfer of API data and other PNR data by air carriers to the router;

(c) the transmission of API data and other PNR data from the router to the passenger information units (PIUs) on extra-EU flights and selected intra-EU flights.

This Regulation is without prejudice to Regulation (EU) 2016/679, Regulation (EU) 2018/1725 and Directive (EU) 2016/680.

Article 2

Scope

This Regulation applies to air carriers conducting:

(a) extra-EU flights;

(b) intra-EU flights that will depart from, arrive in or make a stop-over on the territory of at least one Member State that notified the Commission of its decision to apply Directive (EU) 2016/681 to intra-EU flights in accordance with Article 2(1) of that Directive.

Article 3

Definitions

For the purposes of this Regulation, the following definitions apply:

(1) ‘air carrier’ means an air carrier as defined in Article 3, point (1), of Directive (EU) 2016/681;

(2) ‘extra-EU flight’ means any extra-EU flight as defined in Article 3, point (2), of Directive (EU) 2016/681;

(3) ‘intra-EU flight’ means any intra-EU flight as defined in Article 3, point (3), of Directive (EU) 2016/681;

(4) ‘scheduled flight’ means a scheduled flight as defined in Article 3, point (5), of Regulation (EU) 2025/12;

(5) ‘non-scheduled flight’ means a non-scheduled flight as defined in Article 3, point (6), of Regulation (EU) 2025/12;

(6) ‘passenger’ means a passenger as defined in Article 3, point (4), of Directive (EU) 2016/681;

(7) ‘crew’ means any person on board of an aircraft during the flight, other than a passenger, who works on or operates the aircraft, including flight crew and cabin crew;

(8) ‘advance passenger information’ or ‘API data’ means the data and the flight information referred to in Article 4(2) and (3) respectively;

(9) ‘other passenger name record data’ or ‘other PNR data’ means the passenger name record as defined in Article 3, point (5), of Directive (EU) 2016/681, and as listed in Annex I to that Directive, with the exception of point 18 of that Annex;

(10) ‘passenger information unit’ or ‘PIU’ means the passenger information unit, as contained in the Member States’ notifications to the Commission and modifications thereof published by the Commission pursuant to Article 4(5) of Directive (EU) 2016/681;

(11) ‘terrorist offences’ means terrorist offences as referred to in Articles 3 to 12 of Directive (EU) 2017/541 of the European Parliament and the Council (1);

(12) ‘serious crime’ means serious crime as defined in Article 3, point (9), of Directive (EU) 2016/681;

(13) ‘the router’ means the router referred to in Article 9 of this Regulation and in Article 11 of Regulation (EU) 2025/12;

(14) ‘personal data’ means personal data as defined in Article 3, point (1), of Directive (EU) 2016/680, and Article 4, point 1, of Regulation (EU) 2016/679;

(15) ‘real-time flight traffic data’ means information on the inbound and outbound flight traffic of an airport covered by this Regulation.

CHAPTER 2

COLLECTION, TRANSFER, STORAGE AND DELETION OF API DATA

Article 4

Collection of API data by air carriers

The API data shall consist only of the following data relating to each passenger and crew member on the flight:

(a) the surname (family name), first name or names (given names);

(b) the date of birth, sex and nationality;

(c) the type and number of the travel document and the three-letter code of the issuing country of the travel document;

(d) the date of expiry of the validity of the travel document;

(e) the number identifying a passenger name record used by an air carrier to locate a passenger within its information system (PNR record locator);

(f) the seating information corresponding to the seat in the aircraft assigned to a passenger, where such information is available;

(g) the baggage tag number or numbers and the number and weight of checked bags, where such information is available;

(h) a code indicating the method used to capture and validate the data referred to in points (a) to (d).

The API data shall also consist only of the following flight information relating to the flight of each passenger and crew member:

(a) the flight identification number or, where the flight is code-shared between air carriers, the flight identification numbers, or, if no such number exists, other clear and suitable means to identify the flight;

(b) where applicable, the border crossing point of entry into the territory of the Member State;

(c) the code of the airport of arrival or, where the flight is planned to land in one or several airports within the territories of one or more Member States to which this Regulation applies, the codes of the airports of call on the territories of the Member States concerned;

(d) the code of the airport of departure of the flight;

(e) the code of the airport of the initial point of embarkation, where available;

(f) the local date and time of departure;

(g) the local date and time of arrival;

(h) the contact details of the air carrier;

(i) the format used for the transfer of API data.

Where air carriers provide an online check-in process, they shall enable passengers to provide the API data referred to in paragraph 2, points (a) to (d), by automated means during that online check-in process. For passengers that do not check in online, air carriers shall enable those passengers to provide those API data by automated means during check-in at the airport with the assistance of a self-service kiosk or of air-carriers’ staff at the counter.

Where the use of automated means is not technically possible, air carriers shall exceptionally collect the API data referred to in paragraph 2, points (a) to (d), manually, either as part of the online check-in or as part of the check-in at the airport, in such a manner as to ensure compliance with paragraph 4.

Article 5

Obligations for air carriers regarding transfers of API data and other PNR data

Air carriers shall transfer the API data:

(a) for passengers: (i) per passenger at the moment of check-in, but not earlier than 48 hours prior to the scheduled flight departure time; and (ii) for all boarded passengers immediately after flight closure, namely once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for passengers to board or to leave the aircraft;

(b) for all members of the crew immediately after flight closure, namely once the crew is on board the aircraft in preparation for departure and it is no longer possible for them to leave the aircraft.

Article 6

Storage period and deletion of API data

Air carriers shall store, for a period of 48 hours from the moment of receipt by the router of the API data transferred to it in accordance with Article 5(3), point (a)(ii) and point (b), the API data relating to all passengers and crew that they collected pursuant to Article 4. They shall immediately and permanently delete such API data after the expiry of that period, without prejudice to the possibility for air carriers to retain and use the data where necessary for the normal course of their business in compliance with applicable law, and to Article 16(1) and (3).

Article 7

Correcting, completing and updating API data

Article 8

Fundamental rights

CHAPTER 3

PROVISIONS RELATING TO THE ROUTER

Article 9

The router

The router shall be composed of:

(a) a central infrastructure, including a set of technical components enabling the reception and transmission of encrypted API data and other PNR data;

(b) a secure communication channel between the central infrastructure and the PIUs, and a secure communication channel between the central infrastructure and the air carriers, for the transfer and transmission of API data and other PNR data and for any communications relating thereto, and for the insertion by the Member States of selected flights as referred to in Article 12(4) into the router and any related updates;

(c) a secure channel to receive real-time flight traffic data.

eu-LISA shall design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations for air carriers set out in Regulations (EC) No 767/2008, (EU) 2017/2226 and (EU) 2018/1240.

Article 10

Exclusive use of the router

For the purposes of this Regulation, the router shall be used only:

(a) by air carriers to transfer encrypted API data and other PNR data in accordance with this Regulation;

(b) by PIUs to receive encrypted API data and other PNR data in accordance with this Regulation;

(c) on the basis of international agreements enabling the transfer of PNR data via the router, concluded by the Union with third countries that have concluded an agreement providing for their association with the implementation, application and development of the Schengen acquis.

This Article is without prejudice to Article 12 of Regulation (EU) 2025/12.

Article 11

Data format and transfer verifications

Article 12

Transmission of API data and other PNR data from the router to the PIUs

For the purposes of such transmission, eu-LISA shall establish and keep up to date a table of correspondence between the different airports of origin and destination and the countries to which they belong.

However, for intra-EU flights, the router shall transmit only API data and other PNR data of the flights included in the list referred to in paragraph 4 to the relevant PIUs.

Member States shall, by the relevant date of application of this Regulation referred to in Article 45, second paragraph, insert the selected flights or routes into the router, by automated means through the secure communication channel referred to in Article 9(2)(b), and thereafter provide the router with any updates thereof.

Article 13

Selection of intra-EU flights

The assessment referred to in paragraph 3 shall:

(a) be carried out in an objective, duly reasoned and non-discriminatory way in accordance with Article 2 of Directive (EU) 2016/681;

(b) take into account only criteria which are relevant for the prevention, detection, investigation and prosecution of terrorist offences and serious crime having an objective link, including an indirect link, with the carriage of passengers by air, and not be purely based on the grounds as listed in Article 21 of the Charter of any passengers or groups of passengers;

(c) use only information that can support an objective, duly reasoned and non-discriminatory assessment.

Article 14

Deletion of API data and other PNR data from the router

API data and other PNR data, transferred to the router pursuant to this Regulation shall be stored on the router only insofar as necessary to complete the transmission to the relevant PIUs in accordance with this Regulation and shall be deleted from the router, immediately, permanently and in an automated manner, in both of the following situations:

(a) where it is confirmed, in accordance with Article 12(3), that the transmission of the API data and other PNR data to the relevant PIUs has been completed;

(b) where the API data or other PNR data relate to intra-EU flights other than those included in the lists referred to in Article 12(4).

The router shall automatically inform eu-LISA and the PIUs of the immediate deletion of intra-EU flights as referred to in point (b).

Article 15

Processing of API data and other PNR data by PIUs

API data and other PNR data transmitted to PIUs in accordance with this Regulation shall subsequently be processed by the PIUs in accordance with Directive (EU) 2016/681, in particular as regards the rules on the processing of API data and other PNR data by PIUs, including those set out in Articles 6, 10, 12 and 13 of that Directive, and solely for the purposes of the prevention, detection, investigation and prosecution of terrorist offences and serious crime.

The PIUs or other competent authorities shall under no circumstances process API data and other PNR data for the purposes of profiling, as referred to in Article 11(3) of Directive (EU) 2016/680.

Article 16

Actions where it is technically impossible to use the router

During the period of time between those notifications, Article 5(1) shall not apply, insofar as the technical impossibility prevents the transfer of API data or other PNR data to the router. Air carriers shall store the API data or other PNR data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, air carriers shall transfer the data to the router in accordance with Article 5(1).

Where it is technically impossible to use the router and in exceptional cases related to the objectives of this Regulation that make it necessary for PIUs to immediately receive API data or other PNR data during the technical impossibility to use the router, PIUs may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection, to transfer the API data or other PNR data directly to the PIUs. The PIUs shall process the API data or other PNR data received through any other appropriate means in accordance with the rules and safeguards set out in Directive (EU) 2016/681.

Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 12(3) that the transmission of the API data or other PNR data through the router to the relevant PIU has been completed, the PIU shall immediately delete the API data or other PNR data received by any other appropriate means.

Where it is technically impossible to use the router and in exceptional cases related to the objectives of this Regulation that make it necessary for PIUs to immediately receive API data or other PNR data during the technical impossibility to use the router, PIUs may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection to transfer the API data or other PNR data directly to the PIUs. The PIUs shall process the API data or other PNR data received through any other appropriate means in accordance with the rules and safeguards set out in Directive (EU) 2016/681.

Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 12(3) that the transmission of the API data or other PNR data through the router to the relevant PIU has been completed, the PIU shall immediately delete the API data or other PNR data received by any other appropriate means.

During the period of time between those notifications, Article 5(1) shall not apply, insofar as the technical impossibility prevents the transfer of API data or other PNR data to the router. Air carriers shall store the API data or other PNR data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, air carriers shall transfer the data to the router in accordance with Article 5(1).

Where it is technically impossible to use the router and in exceptional cases related to the objectives of this Regulation that make it necessary for PIUs to immediately receive API data or other PNR data during the technical impossibility to use the router, PIUs may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection, to transfer the API data or other PNR data directly to the PIUs. The PIUs shall process the API data or other PNR data received through any other appropriate means in accordance with the rules and safeguards set out in Directive (EU) 2016/681.

Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 12(3) that the transmission of the API data or other PNR data through the router to the relevant PIU has been completed, the PIU shall immediately delete the API data or other PNR data received by any other appropriate means.

When the technical impossibility has been successfully addressed, the air carrier concerned shall, without delay, submit to the national API supervision authority referred to in Article 37 a report containing all necessary details on the technical impossibility, including the reasons for the technical impossibility, its extent and consequences as well as the measures taken to address it.

CHAPTER 4

SPECIFIC PROVISIONS ON THE PROTECTION OF PERSONAL DATA AND SECURITY

Article 17

Keeping of logs

eu-LISA shall keep logs of all processing operations relating to the transfer and transmission of API data and other PNR data through the router under this Regulation. Those logs shall cover the following:

(a) the air carrier that transferred the API data and other PNR data to the router;

(b) the air carrier that transferred other PNR data to the router;

(c) the PIUs to which the API data were transmitted through the router;

(d) the PIUs to which other PNR data were transmitted through the router;

(e) the date and time of the transfer or transmission referred to in points (a) to (d), and the place of that transfer or transmission;

(f) any access by the staff of eu-LISA necessary for the maintenance of the router, as referred to in Article 26(3);

(g) any other information relating to those processing operations necessary to monitor the security and integrity of the API data and other PNR data and the lawfulness of those processing operations.

Those logs shall not include any personal data, other than the information necessary to identify the relevant member of the staff of eu-LISA, referred to in point (f) of the first subparagraph.

However, if those logs are needed for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations, as referred to in paragraph 3, and those procedures have already begun at the moment of the expiry of the time period referred to in the first subparagraph of this paragraph, air carriers and eu-LISA shall keep those logs for as long as necessary for those procedures. In that case, they shall immediately delete those logs when they are no longer necessary for those procedures.

Article 18

Data protection responsibilities

All the competent authorities designated by Member States shall be joint controllers in accordance with Article 21 of Directive (EU) 2016/680 for the purposes of the processing of personal data in the router.

Article 19

Information for passengers

In accordance with Article 13 of Regulation (EU) 2016/679, air carriers shall provide passengers, on flights covered by this Regulation, with information on the purpose of the collection of their personal data, the type of personal data collected, the recipients of the personal data and the means to exercise their rights as data subjects.

That information shall be communicated to passengers in writing and in an easily accessible format at the moment of booking and at the moment of check-in, irrespective of the means used to collect the personal data at the moment of check-in, in accordance with Article 4.

Article 20

Security

eu-LISA shall take the measures necessary to ensure the security of the router and the API data and other PNR data, in particular data constituting personal data, transmitted through the router, including by establishing, implementing and regularly updating a security plan, a business continuity plan and a disaster recovery plan, in order to:

(a) physically protect the router, including by making contingency plans for the protection of critical components thereof;

(b) prevent any unauthorised processing of the API data or other PNR data, including any unauthorised access thereto and the copying, modification or deletion thereof, both during the transfer of the API data or other PNR data to and from the router and during any storage of the API data or other PNR data on the router where necessary to complete the transmission, in particular by means of appropriate encryption techniques;

(c) ensure that the persons authorised to access the router have access only to the data covered by their access authorisation;

(d) ensure that it is possible to verify and establish to which PIUs the API data or other PNR data are transmitted through the router;

(e) properly report to its Management Board any faults in the functioning of the router;

(f) monitor the effectiveness of the security measures required under this Article and under Regulation (EU) 2018/1725, and assess and update those security measures where necessary in the light of technological or operational developments.

The measures referred to in the first subparagraph of this paragraph shall not affect Article 32 of Regulation (EU) 2016/679, Article 33 of Regulation (EU) 2018/1725 or Article 29 of Directive (EU) 2016/680.

Article 21

Self-monitoring

Air carriers and the PIUs shall monitor their compliance with their respective obligations under this Regulation, in particular as regards their processing of API data constituting personal data. For air carriers the monitoring shall include frequent verification of the logs referred to in Article 17.

Article 22

Personal data protection audits

CHAPTER 5

MATTERS RELATING TO THE ROUTER

Article 23

PIUs’ connections to the router

Member States shall ensure that the connection to the router and integration with it enables their PIUs to receive and further process those API data and other PNR data, as well as to exchange any communications relating thereto, in a lawful, secure, effective and swift manner.

Article 24

Air carriers’ connections to the router

Air carriers shall ensure that the connection to the router and the integration with it enables them to transfer those API data and other PNR data as well as to exchange any communications relating thereto, in a lawful, secure, effective and swift manner. To that end, air carriers shall conduct tests of the transfer of API data and other PNR data to the router in cooperation with eu-LISA in accordance with Article 27(3).

Article 25

eu-LISA’s tasks relating to the design and development of the router

The development of the router shall consist of the elaboration and implementation of the technical specifications, testing and overall project management and coordination of the development phase.

Article 26

eu-LISA’s tasks relating to the hosting and technical management of the router

The technical management of the router shall consist of carrying out all the tasks and enacting all technical solutions necessary for the proper functioning of the router in accordance with this Regulation, in an uninterrupted manner, 24 hours a day, 7 days a week. It shall include the maintenance work and technical developments necessary to ensure that the router functions at a satisfactory level of technical quality, in particular as regards availability, accuracy and reliability of the transmission of API data and other PNR data, in accordance with the technical specifications and, as much as possible, in line with the operational needs of the PIUs and air carriers.

Article 27

eu-LISA’s support tasks relating to the router

CHAPTER 6

GOVERNANCE

Article 28

Programme Management Board

By 28 January 2025, eu-LISA’s Management Board shall establish a Programme Management Board. It shall be composed of 10 members and shall consist of:

(a) seven members appointed by eu-LISA’s Management Board from among its members or its alternates;

(b) the chair of the API-PNR Advisory Group referred to in Article 29;

(c) one member of the eu-LISA staff appointed by its Executive Director; and

(d) one member appointed by the Commission.

As regards point (a), the members appointed by eu-LISA’s Management Board shall be elected only from its members or its alternates from those Member States to which this Regulation applies.

The chairpersonship shall be held by a Member State that is a member of the Programme Management Board.

Upon request of the Programme Management Board, eu-LISA shall provide detailed and updated information on the design and development of the router, including on the resources allocated by eu-LISA.

Article 29

API-PNR Advisory Group

The API-PNR Advisory Group shall exercise the following functions:

(a) provide expertise to eu-LISA and to the Programme Management Board on the design and development of the router in accordance with Article 25;

(b) provide expertise to eu-LISA on the hosting and technical management of the router in accordance with Article 26;

(c) provide its opinion to the Programme Management Board, upon its request, on the progress of the design and development of the router, including on the progress of the technical specifications and compliance test sets referred to in paragraph 2.

Article 30

API-PNR Contact Group

Article 31

API Expert Group

Article 32

Costs incurred by eu-LISA, the European Data Protection Supervisor, the national supervisory authorities and Member States

Article 33

Liability regarding the router

If a failure of a Member State or an air carrier to comply with its obligations under this Regulation causes damage to the router, that Member State or air carrier shall be liable for such damage, as provided for by the applicable Union or national law, unless and insofar as it is demonstrated that eu-LISA, another Member State or another air carrier failed to take reasonable measures to prevent the damage from occurring or to minimise its impact.

Article 34

Start of operations of the router in relation to API data

The Commission shall determine, without undue delay, the date from which the router starts operations in relation to API data by means of an implementing act once eu-LISA has informed the Commission of the successful completion of the comprehensive test of the router referred to in Article 25(5). That implementing act shall be adopted in accordance with the examination procedure referred to in Article 42(2).

The Commission shall set the date referred to in the first paragraph to be no later than 30 days from the date of the adoption of that implementing act.

Article 35

Start of operations of the router in relation to other PNR data

The Commission shall determine, without undue delay, the date from which the router starts operations in relation to other PNR data by means of an implementing act once eu-LISA has informed the Commission of the successful completion of the comprehensive tests of the router referred to in Article 25(6), including on the reliability of the connections of the router with air carriers and PIUs and on the readability of other PNR data transferred by air carriers and transmitted by the router in the necessary standardised format, in accordance with Article 16 of Directive (EU) 2016/681. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 42(2).

The Commission shall set the date referred to in the first paragraph to be no later than 30 days from the date of the adoption of that implementing act.

Article 36

Voluntary use of the router

The Member State concerned shall:

(a) consult eu-LISA before agreeing with the voluntary use of the router in accordance with paragraph 1;

(b) except in situations of duly justified urgency, afford the air carrier concerned an opportunity to comment on its intention to discontinue such use in accordance with paragraph 2 and, where relevant, also consult eu-LISA thereon;

(c) immediately inform eu-LISA and the Commission of any such use to which it agreed and any discontinuation of such use, providing all necessary information, including the date of the start of the use, the date of the discontinuation and the reasons for the discontinuation, as applicable.

CHAPTER 7

SUPERVISION, PENALTIES, STATISTICS AND HANDBOOK

Article 37

National API supervision authority

Article 38

Penalties

Member States shall ensure that the national API supervision authorities, when deciding whether to impose a penalty and when determining the type and level of penalty, take into account relevant circumstances, which may include:

(a) the nature, gravity and duration of the infringement;

(b) the degree of the air carrier’s fault;

(c) previous infringements by the air carrier;

(d) the overall level of cooperation of the air carrier with the competent authorities;

(e) the size of the air carrier, such as the annual number of passengers carried;

(f) whether previous penalties have already been applied by other national API supervision authorities to the same air carrier for the same infringement.

Article 39

Statistics

The CRRS shall provide eu-LISA with the following statistical information necessary for the reporting referred to in Article 44 and for generating statistics in accordance with this Article, without such statistics on API data allowing for the identification of the passengers concerned:

(a) whether the data concern a passenger or a crew member;

(b) the nationality, sex and year of birth of the passenger or crew member;

(c) the date and the initial point of embarkation, the date and airport of departure, and the date and airport of arrival;

(d) the type of travel document, the three-letter code of the issuing country and the date of expiry of the validity of the travel document;

(e) the number of passengers checked-in on the same flight;

(f) the code of the air carrier operating the flight;

(g) whether the flight is a scheduled or a non-scheduled flight;

(h) whether API data were transferred immediately after flight closure;

(i) whether the personal data of the passenger are accurate, complete and up to date;

(j) the technical means used to capture the API data.

The CRRS shall provide eu-LISA with the following statistical information necessary for the reporting referred to in Article 44 and for generating statistics in accordance with this Article, without such statistics on other PNR data allowing for the identification of the passengers concerned:

(a) the date and time the PNR message was received by the router;

(b) flight information contained in the travel itinerary in the specific PNR message;

(c) code share information contained in the specific PNR message.

Article 40

Practical handbook

The Commission shall, in close cooperation with the PIUs, other relevant authorities of the Member States, air carriers and relevant Union bodies and agencies, prepare and make publicly available a practical handbook, containing guidelines, recommendations and best practices for the implementation of this Regulation, including on fundamental rights compliance as well as on penalties in accordance with Article 38.

The practical handbook shall take into account other relevant handbooks.

The Commission shall adopt the practical handbook in the form of a recommendation.

CHAPTER 8

RELATIONSHIP TO OTHER EXISTING INSTRUMENTS

Article 41

Amendment to Regulation (EU) 2019/818

In Article 39 of Regulation (EU) 2019/818, paragraphs 1 and 2 are replaced by the following:

CHAPTER 9

FINAL PROVISIONS

Article 42

Committee procedure

Article 43

Exercise of delegation

As regards a delegated act adopted pursuant to Article 4(11), if an objection under paragraph 6 of this Article has been expressed either by the European Parliament or by the Council, the European Parliament or the Council shall not oppose the tacit extension referred to in the first subparagraph of this paragraph.

Article 44

Monitoring and evaluation

By 29 January 2029, and every four years thereafter, the Commission shall produce a report containing an overall evaluation of this Regulation, including on the necessity and added value of the collection of API data, including an assessment of:

(a) the application of this Regulation;

(b) the extent to which this Regulation achieved its objectives;

(c) the impact of this Regulation on fundamental rights protected under Union law;

(d) the impact of this Regulation on the travel experience of legitimate passengers;

(e) the impact of this Regulation on the competitiveness of the aviation sector and the burden incurred by businesses;

(f) the quality of the data transmitted by the router to the PIUs;

(g) the performance of the router in respect of the PIUs.

For the purposes of point (e) of the first subparagraph, the Commission’s report shall also address this Regulation’s interaction with other relevant Union legislative acts, in particular Regulations (EC) No 767/2008, (EU) 2017/2226 and (EU) 2018/1240 and, in order to assess the overall impact of related reporting obligations on air carriers, identify provisions that could be updated and simplified, where appropriate, to mitigate the burden on air carriers, and consider actions and measures that could be taken to reduce the total cost pressure on air carriers.

Article 45

Entry into force and application

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

It shall apply:

(a) in relation to API data, from the date two years from the date on which the router starts operations, as determined by the Commission in accordance with Article 34; and

(b) in relation to other PNR data, from the date four years from the date on which the router starts operations, as determined by the Commission in accordance with Article 35.

However:

(a) Article 4(12), Article 5(4), Article 7(5), Article 11(5), Article 12(6), Article 18(4), Article 23(2), Article 24(2), Article 25, Article 28, Article 29, Article 32(1), Article 34, Article 35, Article 42 and Article 43 shall apply from 28 January 2025;

(b) Article 6, Article 17(1), (2) and (3), Article 18(1), (2) and (3), Article 19, Article 20, Article 26, Article 27, Article 33 and Article 36 shall apply from the date on which the router starts operations, as determined by the Commission in accordance with Article 34 and Article 35.

This Regulation shall be binding in its entirety and directly applicable in the Member States in accordance with the Treaties.