The router
1. eu-LISA shall design, develop, host and technically manage, in accordance with Articles 25 and 26, a router for the purpose of facilitating the transfer of encrypted API data and other PNR data by air carriers to the PIUs in accordance with this Regulation.
2. The router shall be composed of:
(a)
a central infrastructure, including a set of technical components enabling the reception and transmission of encrypted API data and other PNR data;
(b)
a secure communication channel between the central infrastructure and the PIUs, and a secure communication channel between the central infrastructure and the air carriers, for the transfer and transmission of API data and other PNR data and for any communications relating thereto, and for the insertion by the Member States of selected flights as referred to in Article 12(4) into the router and any related updates;
(c)
a secure channel to receive real-time flight traffic data.
3. Without prejudice to Article 10 of this Regulation, the router shall, where appropriate and to the extent technically possible, share and reuse the technical components, including hardware and software components, of the web service referred to in Article 13 of Regulation (EU) 2017/2226, the carrier gateway referred to in Article 6(2), point (k), of Regulation (EU) 2018/1240, and the carrier gateway referred to in Article 45c of Regulation (EC) No 767/2008.
eu-LISA shall design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations for air carriers set out in Regulations (EC) No 767/2008, (EU) 2017/2226 and (EU) 2018/1240.
4. The router shall automatically extract and make available the data, in accordance with Article 39 of this Regulation, to the central repository for reporting and statistics (CRRS) established by Article 39 of Regulation (EU) 2019/818.
5. eu-LISA shall design and develop the router in such a way that, for any transfer of API data and other PNR data from the air carriers to the router in accordance with Article 5, and for any transmission of API data and other PNR data from the router to the PIUs in accordance with Article 12 and to the CRRS in accordance with Article 39(2), the API data and other PNR data are end-to-end encrypted during transit.
Exclusive use of the router
For the purposes of this Regulation, the router shall be used only:
(a)
by air carriers to transfer encrypted API data and other PNR data in accordance with this Regulation;
(b)
by PIUs to receive encrypted API data and other PNR data in accordance with this Regulation;
(c)
on the basis of international agreements enabling the transfer of PNR data via the router, concluded by the Union with third countries that have concluded an agreement providing for their association with the implementation, application and development of the Schengen acquis .
This Article is without prejudice to Article 12 of Regulation (EU) 2025/12.
Data format and transfer verifications
1. The router shall, in an automated manner and on the basis of real-time flight traffic data, verify whether the air carrier transferred the API data in accordance with Article 5(1) or other PNR data in accordance with Article 5(2).
2. The router shall, immediately and in an automated manner, verify whether the API data transferred to it in accordance with Article 5(1) comply with the detailed rules on the supported data formats, referred to in Article 5(4).
3. The router shall, immediately and in an automated manner, verify whether the other PNR data transferred to it in accordance with Article 5(2) comply with the rules on the supported data formats, referred to in Article 16 of Directive (EU) 2016/681.
4. Where the verification referred to in paragraph 1 determines that the data were not transferred by the air carrier or where the verification referred to in paragraph 2 or 3 determines that data are not compliant with the detailed rules on the supported data formats, the router shall, immediately and in an automated manner, notify the air carrier concerned and the PIUs of the Member States to which the data were to be transmitted pursuant to Article 12(1). In such cases, the air carrier shall immediately transfer the API data and other PNR data in accordance with Article 5.
5. The Commission shall adopt implementing acts specifying the detailed technical and procedural rules necessary for the verifications and notifications referred to in paragraphs 1 to 4 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 42(2).
Transmission of API data and other PNR data from the router to the PIUs
1. Upon the data format and transfer verifications referred to in Article 11, the router shall transmit the encrypted API data and any other PNR data, transferred to it by air carriers pursuant to Article 5(1) and (2), and where applicable, Article 7(3) and (4), to the PIUs of the Member State on whose territory the flight will land or from whose territory it will depart, or to both in the case of intra-EU flights. It shall transmit those data immediately and in an automated manner, without changing their content in any way. Where a flight has one or more stop-overs at the territory of other Member States than the one from which it departed, the router shall transmit the API data and any other PNR data to the PIUs of all the Member States concerned.
For the purposes of such transmission, eu-LISA shall establish and keep up to date a table of correspondence between the different airports of origin and destination and the countries to which they belong.
However, for intra-EU flights, the router shall transmit only API data and other PNR data of the flights included in the list referred to in paragraph 4 to the relevant PIUs.
2. The router shall transmit the API data and other PNR data in accordance with the detailed rules referred to in paragraph 6, once such rules have been adopted and are applicable.
3. Member States shall ensure that their PIUs, upon receipt of API data and other PNR data in accordance with paragraph 1, immediately and in an automated manner confirm receipt of such data to the router.
4. Member States that decide to apply Directive (EU) 2016/681 to intra-EU flights in accordance with Article 2 of that Directive shall each establish a list of the intra-EU flights or routes selected. Member States may use the code of the airport of departure and the airport of arrival for indicating the selected flights or routes. Those Member States shall, in accordance with Article 2 of that Directive and Article 13 of this Regulation, regularly review and where necessary update those lists. A Member State may select all intra-EU flights or routes when duly justified, in accordance with Directive (EU) 2016/681 and Article 13 of this Regulation.
Member States shall, by the relevant date of application of this Regulation referred to in Article 45, second paragraph, insert the selected flights or routes into the router, by automated means through the secure communication channel referred to in Article 9(2)(b), and thereafter provide the router with any updates thereof.
5. The information inserted by the Member States into the router shall be treated confidentially and access to that information by eu-LISA staff shall be limited to what is strictly necessary for the resolution of technical problems. eu-LISA shall ensure, upon receipt by the router of that information or any updates thereto from a Member State, that the router immediately transmits the API data and other PNR data to the PIU of that Member State in respect of the selected flights or routes, in accordance with paragraph 1.
6. The Commission shall adopt implementing acts specifying the detailed technical and procedural rules necessary for the transmission of API data and other PNR data from the router referred to in paragraph 1 of this Article and for the insertion of information into the router referred to in paragraph 4 of this Article, including on requirements for data security. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 42(2).
Selection of intra-EU flights
1. Member States that decide, in accordance with Article 2 of Directive (EU) 2016/681, to apply that Directive and consequently this Regulation to intra-EU flights shall select such intra-EU flights in accordance with this Article.
2. Member States may apply Directive (EU) 2016/681 and consequently this Regulation to all intra-EU flights arriving at or departing from their territory only in situations of a genuine and present or foreseeable terrorist threat, on the basis of a decision that is based on a threat assessment, limited in time to what is strictly necessary and open to effective review either by a court or by an independent administrative body whose decision is binding.
3. In the absence of a genuine and present or foreseeable terrorist threat, Member States that apply Directive (EU) 2016/681 and consequently this Regulation to intra-EU flights shall select such intra-EU flights according to the outcome of an assessment carried out on the basis of the requirements set out in paragraphs 4 to 7 of this Article.
4. The assessment referred to in paragraph 3 shall:
(a)
be carried out in an objective, duly reasoned and non-discriminatory way in accordance with Article 2 of Directive (EU) 2016/681;
(b)
take into account only criteria which are relevant for the prevention, detection, investigation and prosecution of terrorist offences and serious crime having an objective link, including an indirect link, with the carriage of passengers by air, and not be purely based on the grounds as listed in Article 21 of the Charter of any passengers or groups of passengers;
(c)
use only information that can support an objective, duly reasoned and non-discriminatory assessment.
5. On the basis of the assessment referred to in paragraph 3, Member States shall select only intra-EU flights relating to, inter alia, specific routes, travel patterns or airports for which there are indications of terrorist offenses and serious crime and that justify the processing of API and other PNR data. The selection of intra-EU flights shall be limited to what is strictly necessary for achieving the objectives of Directive (EU) 2016/681 and this Regulation.
6. Member States shall keep all documentation of the assessment referred to in paragraph 3, including where relevant any review thereof, and make it available, in accordance with Directive (EU) 2016/680, to their independent supervisory authorities and national supervisory authorities upon request.
7. Member States shall, in accordance with Article 2 of Directive (EU) 2016/681, review their assessment referred to in paragraph 3 regularly and at least every 12 months, in order to take into account changes in the circumstances that justified the selection of intra-EU flights and for the purpose of ensuring that the selection of intra-EU flights continues to be limited to what is strictly necessary.
8. The Commission shall facilitate a regular exchange of views on the selection criteria for the assessment referred to in paragraph 3, including the sharing of best practices, as well as, on a voluntary basis, the exchange of information on selected flights.
Deletion of API data and other PNR data from the router
API data and other PNR data, transferred to the router pursuant to this Regulation shall be stored on the router only insofar as necessary to complete the transmission to the relevant PIUs in accordance with this Regulation and shall be deleted from the router, immediately, permanently and in an automated manner, in both of the following situations:
(a)
where it is confirmed, in accordance with Article 12(3), that the transmission of the API data and other PNR data to the relevant PIUs has been completed;
(b)
where the API data or other PNR data relate to intra-EU flights other than those included in the lists referred to in Article 12(4).
The router shall automatically inform eu-LISA and the PIUs of the immediate deletion of intra-EU flights as referred to in point (b).
Processing of API data and other PNR data by PIUs
API data and other PNR data transmitted to PIUs in accordance with this Regulation shall subsequently be processed by the PIUs in accordance with Directive (EU) 2016/681, in particular as regards the rules on the processing of API data and other PNR data by PIUs, including those set out in Articles 6, 10, 12 and 13 of that Directive, and solely for the purposes of the prevention, detection, investigation and prosecution of terrorist offences and serious crime.
The PIUs or other competent authorities shall under no circumstances process API data and other PNR data for the purposes of profiling, as referred to in Article 11(3) of Directive (EU) 2016/680.
Actions where it is technically impossible to use the router
1. Where it is technically impossible to use the router to transmit API data or other PNR data because of a failure of the router, eu-LISA shall immediately notify the air carriers and PIUs of that technical impossibility in an automated manner. In that case, eu-LISA shall immediately take measures to address the technical impossibility to use the router and shall immediately notify the air carriers and PIUs when it has been successfully addressed.
During the period of time between those notifications, Article 5(1) shall not apply, insofar as the technical impossibility prevents the transfer of API data or other PNR data to the router. Air carriers shall store the API data or other PNR data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, air carriers shall transfer the data to the router in accordance with Article 5(1).
Where it is technically impossible to use the router and in exceptional cases related to the objectives of this Regulation that make it necessary for PIUs to immediately receive API data or other PNR data during the technical impossibility to use the router, PIUs may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection, to transfer the API data or other PNR data directly to the PIUs. The PIUs shall process the API data or other PNR data received through any other appropriate means in accordance with the rules and safeguards set out in Directive (EU) 2016/681.
Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 12(3) that the transmission of the API data or other PNR data through the router to the relevant PIU has been completed, the PIU shall immediately delete the API data or other PNR data received by any other appropriate means.
2. Where it is technically impossible to use the router to transmit API data or other PNR data because of a failure of the systems or infrastructure referred to in Article 23 of a Member State, the PIU of that Member State shall immediately notify the other PIUs, eu-LISA and the Commission of that technical impossibility in an automated manner. In that case, that Member State shall immediately take measures to address the technical impossibility to use the router and shall immediately notify the other PIUs, eu-LISA and the Commission when it has been successfully addressed. The router shall store the API data or other PNR data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, the router shall transmit the data in accordance with Article 12(1).
Where it is technically impossible to use the router and in exceptional cases related to the objectives of this Regulation that make it necessary for PIUs to immediately receive API data or other PNR data during the technical impossibility to use the router, PIUs may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection to transfer the API data or other PNR data directly to the PIUs. The PIUs shall process the API data or other PNR data received through any other appropriate means in accordance with the rules and safeguards set out in Directive (EU) 2016/681.
Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 12(3) that the transmission of the API data or other PNR data through the router to the relevant PIU has been completed, the PIU shall immediately delete the API data or other PNR data received by any other appropriate means.
3. Where it is technically impossible to use the router to transfer API data or other PNR data because of a failure of the systems or infrastructure referred to in Article 24 of an air carrier, that air carrier shall immediately notify the PIUs, eu-LISA and the Commission of that technical impossibility in an automated manner. In that case, that air carrier shall immediately take measures to address the technical impossibility to use the router and shall immediately notify the PIUs, eu-LISA and the Commission when it has been successfully addressed.
During the period of time between those notifications, Article 5(1) shall not apply, insofar as the technical impossibility prevents the transfer of API data or other PNR data to the router. Air carriers shall store the API data or other PNR data until the technical impossibility has been successfully addressed. As soon as the technical impossibility has been successfully addressed, air carriers shall transfer the data to the router in accordance with Article 5(1).
Where it is technically impossible to use the router and in exceptional cases related to the objectives of this Regulation that make it necessary for PIUs to immediately receive API data or other PNR data during the technical impossibility to use the router, PIUs may request air carriers to use any other appropriate means, ensuring the necessary level of data security, data quality and data protection, to transfer the API data or other PNR data directly to the PIUs. The PIUs shall process the API data or other PNR data received through any other appropriate means in accordance with the rules and safeguards set out in Directive (EU) 2016/681.
Following the notification from eu-LISA that the technical impossibility has been successfully addressed, and where it is confirmed in accordance with Article 12(3) that the transmission of the API data or other PNR data through the router to the relevant PIU has been completed, the PIU shall immediately delete the API data or other PNR data received by any other appropriate means.
When the technical impossibility has been successfully addressed, the air carrier concerned shall, without delay, submit to the national API supervision authority referred to in Article 37 a report containing all necessary details on the technical impossibility, including the reasons for the technical impossibility, its extent and consequences as well as the measures taken to address it.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.