Collection of API data by air carriers
Article 4
1. Air carriers shall collect the API data of each passenger and crew member on the flights referred to in Article 2 to be transferred to the router in accordance with Article 5. Where the flight is code-shared between air carriers, the obligation to transfer the API data shall be on the air carrier that operates the flight. 2. The API data shall consist only of the following data relating to each passenger and crew member on the flight: (a) the surname (family name), first name or names (given names); (b) the date of birth, sex and nationality; (c) the type and number of the travel document and the three-letter code of the issuing country of the travel document; (d) the date of expiry of the validity of the travel document; (e) the number identifying a passenger name record used by an air carrier to locate a passenger within its information system (PNR record locator); (f) the seating information corresponding to the seat in the aircraft assigned to a passenger, where such information is available; (g) the baggage tag number or numbers and the number and weight of checked bags, where such information is available; (h) a code indicating the method used to capture and validate the data referred to in points (a) to (d). 3. The API data shall also consist only of the following flight information relating to the flight of each passenger and crew member: (a) the flight identification number or, where the flight is code-shared between air carriers, the flight identification numbers, or, if no such number exists, other clear and suitable means to identify the flight; (b) where applicable, the border crossing point of entry into the territory of the Member State; (c) the code of the airport of arrival or, where the flight is planned to land in one or several airports within the territories of one or more Member States to which this Regulation applies, the codes of the airports of call on the territories of the Member States concerned; (d) the code of the airport of departure of the flight; (e) the code of the airport of the initial point of embarkation, where available; (f) the local date and time of departure; (g) the local date and time of arrival; (h) the contact details of the air carrier; (i) the format used for the transfer of API data. 4. Air carriers shall collect the API data in a manner that ensures that the API data that they transfer in accordance with Article 5 are accurate, complete and up to date. Compliance with this obligation does not require air carriers to check the travel document at the moment of boarding the aircraft, without prejudice to national law that is compatible with Union law. 5. This Regulation does not impose an obligation on passengers to carry a travel document when travelling, without prejudice to other Union legal acts or national law that is compatible with Union law. 6. A Member State may impose an obligation on air carriers to provide the possibility for passengers to voluntarily upload the data referred to in Article 4(2), points (a) to (d), of Regulation (EU) 2025/12 by automated means and to have such data stored by the air carrier with a view to transferring the data for the purpose of future flights in accordance with Article 5 of this Regulation and in a manner compliant with the requirements set out in paragraphs 4, 7 and 8 of this Article. A Member State that imposes such an obligation shall lay down the rules and safeguards on data protection, in accordance with Regulation (EU) 2016/679, including rules on storage period. However, the data shall be deleted where the passenger no longer consents to the storage of the data, or at the latest on the date of expiry of the validity of the travel document. 7. Air carriers shall collect the API data referred to in paragraph 2, points (a) to (d), using automated means to collect the machine-readable data of the travel document of the passenger concerned. They shall do so in accordance with the detailed technical requirements and operational rules referred to in paragraph 12, once such rules have been adopted and are applicable. Where air carriers provide an online check-in process, they shall enable passengers to provide the API data referred to in paragraph 2, points (a) to (d), by automated means during that online check-in process. For passengers that do not check in online, air carriers shall enable those passengers to provide those API data by automated means during check-in at the airport with the assistance of a self-service kiosk or of air-carriers’ staff at the counter. Where the use of automated means is not technically possible, air carriers shall exceptionally collect the API data referred to in paragraph 2, points (a) to (d), manually, either as part of the online check-in or as part of the check-in at the airport, in such a manner as to ensure compliance with paragraph 4. 8. Any automated means used by air carriers to collect API data under this Regulation shall be reliable, secure and up to date. Air carriers shall ensure that API data are encrypted during the transfer of such data from the passenger to the air carrier. 9. During a transitional period, and in addition to the automated means referred to in paragraph 7, air carriers shall make it possible for passengers to provide API data manually as part of the online check-in. In such cases, air carriers shall use data verification techniques to ensure compliance with paragraph 4. 10. The transitional period referred to in paragraph 9 shall not affect the right of air carriers to verify, at the airport prior to the boarding of the aircraft, API data collected as part of the online check-in in order to ensure compliance with paragraph 4, in accordance with the applicable Union law. 11. The Commission is empowered to adopt, as of the date four years after the start of operations of the router in relation to API data referred to in Article 34, and on the basis of an evaluation of the availability and accessibility of automated means to collect API data, a delegated act in accordance with Article 43 to terminate the transitional period referred to in paragraph 9 of this Article. 12. The Commission is empowered to adopt delegated acts in accordance with Article 43 to supplement this Regulation by laying down detailed technical requirements and operational rules for the collection of the API data referred to in paragraph 2, points (a) to (d) of this Article, using automated means in accordance with paragraphs 7 and 8 of this Article, and for the manual collection of API data in exceptional circumstances in accordance with paragraph 7 of this Article and during the transitional period referred to in paragraph 9 of this Article. Those technical requirements and operational rules shall include requirements for data security and for using the most reliable automated means available to collect the machine-readable data of a travel document.