The router
1. eu-LISA shall design, develop, host and technically manage, in accordance with Articles 25 and 26, a router for the purpose of facilitating the transfer of encrypted API data by air carriers to the competent border authorities in accordance with this Regulation.
2. The router shall be composed of:
(a)
a central infrastructure, including a set of technical components enabling the reception and transmission of encrypted API data;
(b)
a secure communication channel between the central infrastructure and the competent border authorities, and a secure communication channel between the central infrastructure and the air carriers, for the transfer and transmission of API data and for any communications relating thereto;
(c)
a secure channel to receive real-time flight traffic data.
3. Without prejudice to Article 12 of this Regulation, the router shall, where appropriate and to the extent technically possible, share and reuse the technical components, including hardware and software components, of the web service referred to in Article 13 of Regulation (EU) 2017/2226, the carrier gateway referred to in Article 6(2), point (k), of Regulation (EU) 2018/1240 and the carrier gateway referred to in Article 45c, of Regulation (EC) No 767/2008.
eu-LISA shall design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations for air carriers set out in Regulations (EC) No 767/2008, (EU) 2017/2226 and (EU) 2018/1240.
4. The router shall automatically extract and make available the data, in accordance with Article 38 of this Regulation, to the central repository for reporting and statistics (CRRS) established by Article 39 of Regulation (EU) 2019/817.
5. eu-LISA shall design and develop the router in a way that for any transfer of API data from air carriers to the router in accordance with Article 6 and for any transmission of API data from the router to the competent border authorities in accordance with Article 14 and to the CRRS in accordance with Article 38(2) the API data are end-to-end encrypted when in transit.
Exclusive use of the router
For the purposes of this Regulation the router shall be used only by:
(a)
air carriers to transfer encrypted API data in accordance with this Regulation;
(b)
the competent border authorities to receive encrypted API data in accordance with this Regulation.
This Article is without prejudice to Article 10 of Regulation (EU) 2025/13.
Data format and transfer verifications
1. The router shall, in an automated manner and on the basis of real-time flight traffic data, verify whether the air carrier transferred the API data in accordance with Article 6(1).
2. The router shall, immediately and in an automated manner, verify whether the API data transferred to it in accordance with Article 6(1) comply with the detailed rules on the supported data formats referred to in Article 6(3).
3. Where the verification referred to in paragraph 1 of this Article determines that the data were not transferred by the air carrier or where the verification referred to in paragraph 2 of this Article determines that the data are not compliant with the detailed rules on the supported data formats, the router shall, immediately and in an automated manner, notify the air carrier concerned and the competent border authorities of the Member States to which the data were to be transmitted pursuant to Article 14(1). In such cases, the air carrier shall immediately transfer the API data in accordance with Article 6.
4. The Commission shall adopt implementing acts specifying the detailed technical and procedural rules necessary for the verifications and notifications referred to in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 43(2).
Transmission of API data from the router to the competent border authorities
1. Upon the data format and transfer verifications referred to in Article 13, the router shall transmit the encrypted API data transferred to it pursuant to Article 6 or Article 9(3) and (4) to the competent border authorities of the Member State or, where the flight is planned to land in one or several airports within the territories of one or more Member States to which this Regulation applies, to the competent border authorities of the Member States referred to in Article 4(3), point (c). It shall transmit those data immediately and in an automated manner, without changing their content in any way, and in accordance with the detailed rules referred to in paragraph 5 of this Article, once such rules have been adopted and are applicable.
For the purposes of such transmission, eu-LISA shall establish and keep up to date a table of correspondence between the different airports of origin and destination and the countries to which they belong.
2. Member States shall designate competent border authorities authorised to receive the API data transmitted to them from the router in accordance with this Regulation. They shall notify, by the date of application of this Regulation referred to in Article 46, second paragraph, eu-LISA and the Commission of the name and contact details of the competent border authorities and shall, where necessary, notify eu-LISA and the Commission of any updates to that information.
The Commission shall, on the basis of those notifications and updates, compile and make publicly available a list of the notified competent border authorities, including their contact details.
3. Member States shall ensure that their competent border authorities, upon receipt of API data in accordance with paragraph 1, immediately and in an automated manner confirm receipt of such data to the router.
4. Member States shall ensure that only the duly authorised and trained staff of their competent border authorities, designated in accordance with paragraph 2, have access to the API data transmitted to them through the router. They shall lay down the necessary rules to that effect. Those rules shall include rules on the creation and regular update of a list of those staff and their profiles.
5. The Commission shall adopt implementing acts specifying the detailed technical and procedural rules necessary for the transmission of API data from the router referred to in paragraph 1 of this Article, including on requirements for data security. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 43(2).
Deletion of API data from the router
API data transferred to the router pursuant to this Regulation shall be stored on the router only insofar as necessary to complete the transmission to the relevant competent border authorities in accordance with this Regulation and shall be deleted from the router, immediately, permanently and in an automated manner where it is confirmed, in accordance with Article 14(3), that the transmission of the API data to the relevant competent border authorities has been completed.
Actions where it is technically impossible to use the router
1. Where it is technically impossible to use the router to transmit API data because of a failure of the router, eu-LISA shall immediately notify the air carriers and competent border authorities of that technical impossibility in an automated manner. In that case, eu-LISA shall immediately take measures to address the technical impossibility to use the router and shall immediately notify the air carriers and competent border authorities when it has been successfully addressed.
During the period of time between those notifications, Article 6(1) and Article 8(1) shall not apply insofar as the technical impossibility prevents the transfer of API data to the router. Air carriers shall store the API data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, air carriers shall transfer the data to the router in accordance with Article 6(1).
Where the API data are received later than 96 hours after the time of departure as referred to in Article 4(3)(f), the router shall not transmit the API data to the competent border authorities, but instead delete those data.
Where it is technically impossible to use the router, and in exceptional cases related to the objectives of this Regulation that make it necessary for competent border authorities to immediately receive API data during the technical impossibility to use the router, competent border authorities may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection, to transfer the API data directly to the competent border authorities. The competent border authorities shall process the API data received through any other appropriate means in accordance with the rules and safeguards set out in Regulation (EU) 2016/399 and applicable national law.
Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 14(3) that the transmission of the API data through the router to the relevant competent border authority has been completed, the competent border authority shall immediately delete the API data received by any other appropriate means.
2. Where it is technically impossible to use the router to transmit API data because of a failure of the systems or infrastructure referred to in Article 23 of a Member State, the competent border authorities of that Member State shall immediately notify the air carriers, the competent authorities of the other Member States, eu-LISA and the Commission of that technical impossibility in an automated manner. In that case, that Member State shall immediately take measures to address the technical impossibility to use the router and shall immediately notify the air carriers, the competent authorities of the other Member States, eu-LISA and the Commission when it has been successfully addressed. The router shall store the API data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, the router shall transmit the data in accordance with Article 14(1).
During the period of time between those notifications, Article 6(1) and Article 8(1) shall not apply insofar as the technical impossibility prevents the transfer of API data to the router. Air carriers shall store the API data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, air carriers shall transfer the data to the router in accordance with Article 6(1).
Where the API data are received later than 96 hours after the time of departure as referred to in Article 4(3)(f), the router shall not transmit the API data to the competent border authorities, but instead delete those data.
Where it is technically impossible to use the router, and in exceptional cases related to the objectives of this Regulation that make it necessary for competent border authorities to immediately receive API data during the technical impossibility to use the router, competent border authorities may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection, to transfer the API data directly to the competent border authorities. The competent border authorities shall process the API data received through any other appropriate means in accordance with the rules and safeguards set out in Regulation (EU) 2016/399 and applicable national law.
Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 14(3) that the transmission of the API data through the router to the relevant competent border authority has been completed, the competent border authority shall immediately delete the API data received by any other appropriate means.
3. Where it is technically impossible to use the router to transfer API data because of a failure of the systems or infrastructure referred to in Article 24 of an air carrier, that air carrier shall immediately notify the competent border authorities, eu-LISA and the Commission of that technical impossibility in an automated manner. In that case, that air carrier shall immediately take measures to address the technical impossibility to use the router and shall immediately notify eu-LISA and the Commission when it has been successfully addressed.
During the period of time between those notifications, Article 6(1) and Article 8(1) shall not apply insofar as the technical impossibility prevents the transfer of API data to the router. Air carriers shall store the API data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, air carriers shall transfer the data to the router in accordance with Article 6(1). However, the router shall not transmit the API data to the competent border authorities, but instead delete the data, if they are received later than 96 hours after the time of departure as referred to in Article 4(3)(f).
Where it is technically impossible to use the router, and in exceptional cases related to the objectives of this Regulation that make it necessary for competent border authorities to immediately receive API data during the technical impossibility to use the router, competent border authorities may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection, to transfer the API data directly to the competent border authorities. The competent border authorities shall process the API data received through any other appropriate means in accordance with the rules and safeguards set out in Regulation (EU) 2016/399 and applicable national law.
Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 14(3) that the transmission of the API data through the router to the relevant competent border authority has been completed, the competent border authority shall immediately delete the API data received by any other appropriate means.
When the technical impossibility has been successfully addressed, the air carrier concerned shall, without delay, submit to the national API supervision authority referred to in Article 36 a report containing all necessary details on the technical impossibility, including the reasons for the technical impossibility, its extent and consequences as well as the measures taken to address it.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.