My bookmarksSign up free

Regulation (EU) 2025/13 CHAPTER 2 — COLLECTION, TRANSFER, STORAGE AND DELETION OF API DATA

Article 4–Article 8 · 5 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Collection of API data by air carriers

Article 4

1.   Air carriers shall collect the API data of each passenger and crew member on the flights referred to in Article 2 to be transferred to the router in accordance with Article 5. Where the flight is code-shared between air carriers, the obligation to transfer the API data shall be on the air carrier that operates the flight. 2.   The API data shall consist only of the following data relating to each passenger and crew member on the flight: (a) the surname (family name), first name or names (given names); (b) the date of birth, sex and nationality; (c) the type and number of the travel document and the three-letter code of the issuing country of the travel document; (d) the date of expiry of the validity of the travel document; (e) the number identifying a passenger name record used by an air carrier to locate a passenger within its information system (PNR record locator); (f) the seating information corresponding to the seat in the aircraft assigned to a passenger, where such information is available; (g) the baggage tag number or numbers and the number and weight of checked bags, where such information is available; (h) a code indicating the method used to capture and validate the data referred to in points (a) to (d). 3.   The API data shall also consist only of the following flight information relating to the flight of each passenger and crew member: (a) the flight identification number or, where the flight is code-shared between air carriers, the flight identification numbers, or, if no such number exists, other clear and suitable means to identify the flight; (b) where applicable, the border crossing point of entry into the territory of the Member State; (c) the code of the airport of arrival or, where the flight is planned to land in one or several airports within the territories of one or more Member States to which this Regulation applies, the codes of the airports of call on the territories of the Member States concerned; (d) the code of the airport of departure of the flight; (e) the code of the airport of the initial point of embarkation, where available; (f) the local date and time of departure; (g) the local date and time of arrival; (h) the contact details of the air carrier; (i) the format used for the transfer of API data. 4.   Air carriers shall collect the API data in a manner that ensures that the API data that they transfer in accordance with Article 5 are accurate, complete and up to date. Compliance with this obligation does not require air carriers to check the travel document at the moment of boarding the aircraft, without prejudice to national law that is compatible with Union law. 5.   This Regulation does not impose an obligation on passengers to carry a travel document when travelling, without prejudice to other Union legal acts or national law that is compatible with Union law. 6.   A Member State may impose an obligation on air carriers to provide the possibility for passengers to voluntarily upload the data referred to in Article 4(2), points (a) to (d), of Regulation (EU) 2025/12 by automated means and to have such data stored by the air carrier with a view to transferring the data for the purpose of future flights in accordance with Article 5 of this Regulation and in a manner compliant with the requirements set out in paragraphs 4, 7 and 8 of this Article. A Member State that imposes such an obligation shall lay down the rules and safeguards on data protection, in accordance with Regulation (EU) 2016/679, including rules on storage period. However, the data shall be deleted where the passenger no longer consents to the storage of the data, or at the latest on the date of expiry of the validity of the travel document. 7.   Air carriers shall collect the API data referred to in paragraph 2, points (a) to (d), using automated means to collect the machine-readable data of the travel document of the passenger concerned. They shall do so in accordance with the detailed technical requirements and operational rules referred to in paragraph 12, once such rules have been adopted and are applicable. Where air carriers provide an online check-in process, they shall enable passengers to provide the API data referred to in paragraph 2, points (a) to (d), by automated means during that online check-in process. For passengers that do not check in online, air carriers shall enable those passengers to provide those API data by automated means during check-in at the airport with the assistance of a self-service kiosk or of air-carriers’ staff at the counter. Where the use of automated means is not technically possible, air carriers shall exceptionally collect the API data referred to in paragraph 2, points (a) to (d), manually, either as part of the online check-in or as part of the check-in at the airport, in such a manner as to ensure compliance with paragraph 4. 8.   Any automated means used by air carriers to collect API data under this Regulation shall be reliable, secure and up to date. Air carriers shall ensure that API data are encrypted during the transfer of such data from the passenger to the air carrier. 9.   During a transitional period, and in addition to the automated means referred to in paragraph 7, air carriers shall make it possible for passengers to provide API data manually as part of the online check-in. In such cases, air carriers shall use data verification techniques to ensure compliance with paragraph 4. 10.   The transitional period referred to in paragraph 9 shall not affect the right of air carriers to verify, at the airport prior to the boarding of the aircraft, API data collected as part of the online check-in in order to ensure compliance with paragraph 4, in accordance with the applicable Union law. 11.   The Commission is empowered to adopt, as of the date four years after the start of operations of the router in relation to API data referred to in Article 34, and on the basis of an evaluation of the availability and accessibility of automated means to collect API data, a delegated act in accordance with Article 43 to terminate the transitional period referred to in paragraph 9 of this Article. 12.   The Commission is empowered to adopt delegated acts in accordance with Article 43 to supplement this Regulation by laying down detailed technical requirements and operational rules for the collection of the API data referred to in paragraph 2, points (a) to (d) of this Article, using automated means in accordance with paragraphs 7 and 8 of this Article, and for the manual collection of API data in exceptional circumstances in accordance with paragraph 7 of this Article and during the transitional period referred to in paragraph 9 of this Article. Those technical requirements and operational rules shall include requirements for data security and for using the most reliable automated means available to collect the machine-readable data of a travel document.

Obligations for air carriers regarding transfers of API data and other PNR data

Article 5

1.   Air carriers shall transfer the encrypted API data to the router, by electronic means for the purposes of their transmission to PIUs in accordance with Article 12. Air carriers shall transfer the API data in accordance with the detailed rules referred to in paragraph 4 of this Article, once such rules have been adopted and are applicable. 2.   When adopting measures in accordance with Article 8(1) of Directive (EU) 2016/681, Member States shall require air carriers to transfer any other PNR data they collect in the normal course of their business exclusively to the router, in accordance with the common protocols and data formats set out pursuant to Article 16 of that Directive. 3.   Air carriers shall transfer the API data: (a) for passengers: (i) per passenger at the moment of check-in, but not earlier than 48 hours prior to the scheduled flight departure time; and (ii) for all boarded passengers immediately after flight closure, namely once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for passengers to board or to leave the aircraft; (b) for all members of the crew immediately after flight closure, namely once the crew is on board the aircraft in preparation for departure and it is no longer possible for them to leave the aircraft. 4.   The Commission is empowered to adopt delegated acts in accordance with Article 43 to supplement this Regulation by laying down the necessary detailed rules on the common protocols and supported data formats to be used for the encrypted transfers of API data to the router referred to in paragraph 1 of this Article, including the transfer of API data at the moment of check-in and requirements for data security. Such detailed rules shall ensure that air carriers transfer API data using the same structure and content.

Storage period and deletion of API data

Article 6

Air carriers shall store, for a period of 48 hours from the moment of receipt by the router of the API data transferred to it in accordance with Article 5(3), point (a)(ii) and point (b), the API data relating to all passengers and crew that they collected pursuant to Article 4. They shall immediately and permanently delete such API data after the expiry of that period, without prejudice to the possibility for air carriers to retain and use the data where necessary for the normal course of their business in compliance with applicable law, and to Article 16(1) and (3).

Correcting, completing and updating API data

Article 7

1.   Where an air carrier becomes aware that data that it stores under this Regulation were processed unlawfully, or do not constitute API data, it shall immediately and permanently delete those data. If those data have been transferred to the router, the air carrier shall immediately inform the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA). Upon receiving such information, eu-LISA shall immediately inform the PIU that received the data transmitted through the router. 2.   Where an air carrier becomes aware that the data that it stores under this Regulation are inaccurate, incomplete or no longer up to date, it shall immediately correct, complete or update those data. This is without prejudice to the possibility for air carriers to retain and use the data where necessary for the normal course of their business in compliance with the applicable law. 3.   Where an air carrier becomes aware after the transfer of API data under Article 5(3), point (a)(i), but before the transfer under Article 5(3), point (a)(ii), that the data it has transferred are inaccurate, the air carrier shall immediately transfer the corrected API data to the router. 4.   Where an air carrier becomes aware, after the transfer of API data under Article 5(3), point (a)(ii) or point (b), that the data it has transferred are inaccurate, incomplete or no longer up to date, the air carrier shall immediately transfer the corrected, completed or updated API data to the router. 5.   The Commission is empowered to adopt delegated acts in accordance with Article 43 to supplement this Regulation by laying down the necessary detailed rules on correcting, completing and updating API data within the meaning of this Article.

Fundamental rights

Article 8

1.   The collection and processing of personal data in accordance with this Regulation and Regulation (EU) 2025/12 by air carriers and competent authorities shall not result in discrimination against persons on the grounds listed in Article 21 of the Charter of Fundamental Rights of the European Union (the ‘Charter’). 2.   This Regulation shall fully respect human dignity and the fundamental rights and principles recognised by the Charter, including the right to respect for one’s private life, to asylum, to the protection of personal data, to freedom of movement and to effective legal remedies. 3.   Particular attention shall be paid to children, the elderly, persons with a disability and vulnerable persons. The best interests of the child shall be a primary consideration when implementing this Regulation.

Back to Regulation (EU) 2025/13 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next