Keeping of logs
1. Air carriers shall create logs of all processing operations related to API data under this Regulation undertaken using the automated means referred to in Article 4(7). Those logs shall cover the date, time, and place of transfer of the API data. Those logs shall not contain any personal data, other than the information necessary to identify the relevant member of the staff of the air carrier.
2. eu-LISA shall keep logs of all processing operations relating to the transfer and transmission of API data and other PNR data through the router under this Regulation. Those logs shall cover the following:
(a)
the air carrier that transferred the API data and other PNR data to the router;
(b)
the air carrier that transferred other PNR data to the router;
(c)
the PIUs to which the API data were transmitted through the router;
(d)
the PIUs to which other PNR data were transmitted through the router;
(e)
the date and time of the transfer or transmission referred to in points (a) to (d), and the place of that transfer or transmission;
(f)
any access by the staff of eu-LISA necessary for the maintenance of the router, as referred to in Article 26(3);
(g)
any other information relating to those processing operations necessary to monitor the security and integrity of the API data and other PNR data and the lawfulness of those processing operations.
Those logs shall not include any personal data, other than the information necessary to identify the relevant member of the staff of eu-LISA, referred to in point (f) of the first subparagraph.
3. The logs referred to in paragraphs 1 and 2 of this Article shall be used only for ensuring the security and integrity of the API data and other PNR data and the lawfulness of the processing, in particular as regards compliance with the requirements set out in this Regulation, including proceedings for penalties for infringements of those requirements in accordance with Articles 37 and 38.
4. Air carriers and eu-LISA shall take appropriate measures to protect the logs that they created pursuant to paragraphs 1 and 2, respectively, against unauthorised access and other security risks.
5. The national API supervision authority referred to in Article 37 and PIUs shall have access to the relevant logs referred to in paragraph 1 of this Article where necessary for the purposes referred to in paragraph 3 of this Article.
6. Air carriers and eu-LISA shall keep the logs that they created pursuant to paragraphs 1 and 2, respectively, for a period of one year from the moment of the creation of those logs. They shall immediately and permanently delete those logs upon the expiry of that period.
However, if those logs are needed for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations, as referred to in paragraph 3, and those procedures have already begun at the moment of the expiry of the time period referred to in the first subparagraph of this paragraph, air carriers and eu-LISA shall keep those logs for as long as necessary for those procedures. In that case, they shall immediately delete those logs when they are no longer necessary for those procedures.
Data protection responsibilities
1. Air carriers shall be controllers, within the meaning of Article 4, point (7), of Regulation (EU) 2016/679, for the processing of API data and other PNR data constituting personal data in relation to the collection of such data and the transfer thereof to the router under this Regulation.
2. Each Member State shall designate a competent authority as controller in accordance with this Article. Member States shall notify the Commission, eu-LISA and the other Member States of those authorities.
All the competent authorities designated by Member States shall be joint controllers in accordance with Article 21 of Directive (EU) 2016/680 for the purposes of the processing of personal data in the router.
3. eu-LISA shall be a processor within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the purposes of the processing of API data and other PNR data constituting personal data under this Regulation through the router, including transmission of the data from the router to the PIUs and storage for technical reasons of those data on the router. eu-LISA shall ensure that the router is operated in accordance with this Regulation.
4. The Commission shall adopt implementing acts establishing the respective responsibilities of the joint controllers, and the respective obligations between the joint controllers and the processor. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 42(2).
Information for passengers
In accordance with Article 13 of Regulation (EU) 2016/679, air carriers shall provide passengers, on flights covered by this Regulation, with information on the purpose of the collection of their personal data, the type of personal data collected, the recipients of the personal data and the means to exercise their rights as data subjects.
That information shall be communicated to passengers in writing and in an easily accessible format at the moment of booking and at the moment of check-in, irrespective of the means used to collect the personal data at the moment of check-in, in accordance with Article 4.
Security
1. eu-LISA shall ensure the security and encryption of the API data and other PNR data, in particular data constituting personal data, that it processes pursuant to this Regulation. PIUs and air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation.eu-LISA, PIUs and air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other to ensure such security.
2. eu-LISA shall ensure the security and the confidentiality of the data related to flights and routes selected by the Member States in accordance with Article 12(4). The PIUs and the air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation. eu-LISA, PIUs and air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other to ensure such security.
3. eu-LISA shall take the measures necessary to ensure the security of the router and the API data and other PNR data, in particular data constituting personal data, transmitted through the router, including by establishing, implementing and regularly updating a security plan, a business continuity plan and a disaster recovery plan, in order to:
(a)
physically protect the router, including by making contingency plans for the protection of critical components thereof;
(b)
prevent any unauthorised processing of the API data or other PNR data, including any unauthorised access thereto and the copying, modification or deletion thereof, both during the transfer of the API data or other PNR data to and from the router and during any storage of the API data or other PNR data on the router where necessary to complete the transmission, in particular by means of appropriate encryption techniques;
(c)
ensure that the persons authorised to access the router have access only to the data covered by their access authorisation;
(d)
ensure that it is possible to verify and establish to which PIUs the API data or other PNR data are transmitted through the router;
(e)
properly report to its Management Board any faults in the functioning of the router;
(f)
monitor the effectiveness of the security measures required under this Article and under Regulation (EU) 2018/1725, and assess and update those security measures where necessary in the light of technological or operational developments.
The measures referred to in the first subparagraph of this paragraph shall not affect Article 32 of Regulation (EU) 2016/679, Article 33 of Regulation (EU) 2018/1725 or Article 29 of Directive (EU) 2016/680.
Self-monitoring
Air carriers and the PIUs shall monitor their compliance with their respective obligations under this Regulation, in particular as regards their processing of API data constituting personal data. For air carriers the monitoring shall include frequent verification of the logs referred to in Article 17.
Personal data protection audits
1. The independent supervisory authorities referred to in Article 41 of Directive (EU) 2016/680 shall carry out an audit of processing operations of API data constituting personal data performed by the PIUs for the purposes of this Regulation at least once every four years. Member States shall ensure that their independent supervisory authorities have sufficient resources and expertise to fulfil the tasks entrusted to them under this Regulation.
2. The European Data Protection Supervisor shall carry out an audit of processing operations of API data and other PNR data constituting personal data performed by eu-LISA for the purposes of this Regulation, in accordance with relevant international auditing standards at least once every year. A report of that audit shall be sent to the European Parliament, to the Council, to the Commission, to the Member States and to eu-LISA. eu-LISA shall be given an opportunity to make comments before the reports are adopted.
3. In relation to the processing operations referred to in paragraph 2, upon request, eu-LISA shall supply information requested by the European Data Protection Supervisor, shall grant the European Data Protection Supervisor access to all the documents it requests and to the logs referred to in Article 17(2), and shall allow the European Data Protection Supervisor access to all eu-LISA’s premises at any time.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.