Sittings · Document

DRAFT OPINION (COM(2022)0731 – C90427/2022 – 2022/0425(COD)) 2023-05-26

On the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818

Committee on Transport and Tourism · Rapporteur: JanChristoph Oetjen

on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, and amending Regulation (EU) 2019/818

SHORT JUSTIFICATION

This Regulation sets new uniform rules on the collection and transfer of Advance Passenger Information (API), which includes a closed list of API data, the means to collect them and a single point for the transfer of these data, for the prevention of, detention, investigation and prosecution of terrorist offences and serious crime.

Serious and organised crime has continued to increase over the last decades and airports are often the transit points for drug trafficking, smuggling of persons or other illicit goods. Therefore, good information on travellers is a key tool for law enforcement authorities in the prevention of, detention, investigation and prosecution of terrorist offences and serious crime.

Advance Passenger Information (API) and Passenger Name Records (PNR) are two types of air passenger data, that, when combined, are particularly useful for identifying high-risk travellers and their travel patterns.

Under the current PNR Directive, air carriers are not obliged and do not have any commercial interest in collecting the full set of API data. Therefore, for the purposes of fighting terrorism and serious crime, this Regulation sets complementary and harmonised rules to collect and transfer API data and extends its application to the same flights, covered by the PNR directive, notably extra-EU flights and selected intra-EU flights.

Overall, the proposal for a regulation introduces:

1. provisions to collect API data by air carriers and streamline the transfer and transmission of API data by air carriers to national authorities through a single router, which will be managed by the EU Agency eu-LISA. It also sets the rules for the transmission of API data to the competent authorities, notably the Passenger Information Units (‘PIUs’), by the router.

2. a requirement to provide better quality API data, as air carriers will have “to collect API data by automated means only" putting an end to the laborious and, more importantly, error-prone experience of passengers who must manually type in travel document information between the purchase of tickets and check-in.

3. provisions on the protection of personal data, as well as security and self-monitoring by air carriers and PIUs.

4. requirements on supervision and possible penalties in case of non-compliance by air carriers.

The regulation also includes budgetary provisions that will finance the establishment and functioning of the router and the costs incurred by the Member States (with some exceptions) in relation to their connections to, and integration with, the router, under the Union budget.

Rapporteur’s position

The Rapporteur welcomes this streamlined and simpler method for air carriers to provide API data, especially through a centralised system. He also shares the view that digitalisation and automation can be an useful tool to mitigate errors and to allow for a better travel experience of legitimate travellers.

The Rapporteur also shares the need to ensure better quality API data for law enforcement, in full respect of personal data protection. However, this Regulation should avoid going to the detriment of the travel experience of the legitimate traveller. It should also allow authorities to estimate in advance the necessary control capacity at airports and should enable air carriers to process the information at the check-in in a more efficient and faster way. The Rapporteur believes that this legislation should facilitate people travelling, with reduced times at disembarkation. Therefore, the Rapporteur introduces a provision in Article 20, which imposes a requirement on the Commission to carry out an assessment on the impact of this Regulation on the travel experience of legitimate travellers.

The Rapporteur understands that in certain cases air carriers may need to keep logs for longer than for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations. However to avoid any missuse or abuse, the air carriers should inform and justify to the Commission the reason for keeping the logs longer.

The Rapporteur believes that the financial appropriation to the functioning of the router will determine its success, therefore the eu-LISA should be provided with the necessary resources. Moreover, eu-LISA should also provide training to air carriers and PIUs to facilitate the correct connection and integration to the router, and to effectively transfer and receive API data. To that effect, eu-LISA should develop the router to enable the air carriers’ systems to connect and transmit API data to the router in accordance with existing standard and technical requirements.

AMENDMENTS

The Committee on Transport and Tourism calls on the Committee on Civil Liberties, Justice and Home Affairs, as the committee responsible, to take the following into account:

Amendment 1

Proposal for a regulation

Recital 6 a (new)

Text proposed by the CommissionAmendment
(6a) This Regulation should be subject to regular evaluations to ensure the monitoring of its effective application. In particular, the collection of API data should not be to the detriment of the travel experience of legitimate travellers. Therefore, the Commission should include in its regular evaluation reports on the application of this Regulation an assessment of the impact of this Regulation on the travel experience of legitimate travellers.

Or. en

Amendment 2

Proposal for a regulation

Recital 15

Text proposed by the CommissionAmendment
(15) In order to enable the application of that selective approach under this Regulation in respect of intra-EU flights, the Member States should be required to draw up and submit to eu-LISA the lists of the flights they selected, so that eu-LISA can ensure that only for those flights API data is transmitted from the router to the relevant PIUs and that the API data on other intra-EU flights is immediately and permanently deleted.(15) In order to enable the application of that selective approach under this Regulation in respect of intra-EU flights, the Member States should be required to draw up and submit to eu-LISA the lists of the flights they selected, insofar as those flights have been selected in accordance with Directive (EU) 2016/681, so that eu-LISA can ensure that only for those flights API data is transmitted from the router to the relevant PIUs and that the API data on other intra-EU flights is immediately and permanently deleted.

Or. en

Amendment 3

Proposal for a regulation

Recital 19

Text proposed by the CommissionAmendment
(19) In view of the Union interests at stake, appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router, as required under this Regulation, should be borne by the Union budget, in accordance with the applicable legislation and subject to certain exceptions. The costs covered by those exceptions should be borne by each Member State concerned itself.(19) In view of the Union interests at stake, appropriate costs incurred by the Member States in relation to their connections to, and integration with, the router, as required under this Regulation, should be borne by the Union budget, in accordance with the applicable legislation and subject to certain exceptions. The costs covered by those exceptions should be borne by each Member State concerned itself. The Union budget should also cover the support, such as training, by eu-LISA to air carriers and PIUs to enable effective transfer and transmission of API data through the router.

Or. en

Amendment 4

Proposal for a regulation

Article 3 – paragraph 1 – point h

Text proposed by the CommissionAmendment
(h) ‘traveller’ means any person as defined in Article 3, point (i), of Regulation (EU) [API border management];(h) ‘traveller’ means any person as defined in Article 3, point (j), of Regulation (EU) [API border management];

Or. en

Amendment 5

Proposal for a regulation

Article 3 – paragraph 1 – point n

Text proposed by the CommissionAmendment
(n) ‘the router’ means the router as defined in Article 3, point (k) of Regulation (EU) [API border management];(n) ‘the router’ means the router as defined in Article 3, point (m) of Regulation (EU) [API border management];

Or. en

Amendment 6

Proposal for a regulation

Article 4 – paragraph 3 – subparagraph 1

Text proposed by the CommissionAmendment
Air carriers shall collect the API data referred to Article 4(2), points (a) to (d), of Regulation (EU) [API border management] using automated means to collect the machine-readable data of the travel document of the traveller concerned. They shall do so in accordance with the detailed technical requirements and operational rules referred paragraph 5, where such rules have been adopted and are applicable.Air carriers shall collect the API data referred to Article 4(2), points (a) to (d), of Regulation (EU) [API border management] using automated means to collect the machine-readable data of the travel document of the traveller concerned. They shall do so in accordance with the detailed technical requirements and operational rules referred to in paragraph 5, where such rules have been adopted and are applicable.

Or. en

Amendment 7

Proposal for a regulation

Article 6 – paragraph 4 – subparagraph 2

Text proposed by the CommissionAmendment
However, if those logs are needed for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations, as referred to in paragraph 2, and those procedures have already begun at the moment of the expiry of the time period referred to in the first subparagraph, air carriers may keep those logs for as long as necessary for those procedures. In that case, they shall immediately delete those logs when they are no longer necessary for those procedures.However, if those logs are needed for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations, as referred to in paragraph 2, and those procedures have already begun at the moment of the expiry of the time period referred to in the first subparagraph, air carriers may keep those logs for as long as necessary for those procedures after informing and justifying it to the Commission. In that case, they shall immediately delete those logs when they are no longer necessary for those procedures.

Or. en

Amendment 8

Proposal for a regulation

Article 11 a (new)

Text proposed by the CommissionAmendment
Article 11a
eu-LISA's support tasks relating to the router
eu-LISA shall, upon their request, provide support to competent border authorities, PIUs and other relevant Member States’ authorities and air carriers on the connection and integration to the router.

Or. en

Amendment 9

Proposal for a regulation

Article 20 – paragraph 1 – point c a (new)

Text proposed by the CommissionAmendment
(ca) the impact of this Regulation on the travel experience of legitimate travellers;

Or. en