lagen.nu
EDPS yttrande 24/2026

EDPS Opinion 24/2026 on the signing and conclusion of an Agreement between the EU and the Republic of Korea on the transfer of Passenger Name Record (PNR) data

Utgivare
Europeiska datatillsynsmannen
Antagen
2026-09-18
Språk
engelska
Ämnesord
PNR
Källa
www.edps.europa.eu
Endast på engelskaEuropeiska datatillsynsmannen har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska datatillsynsmannen.

Opinion 24/2026

on the signing and conclusion of an Agreement between the EU and the Republic of Korea on the transfer of Passenger Name Record (PNR) data

0

The European Data Protection Supervisor (EDPS) is an independent institution of the EU, responsible under Article 52(2) of Regulation 2018/1725 ‘With respect to the processing of personal data… for ensuring that the fundamental rights and freedoms of natural persons, and in particular their right to data protection, are respected by Union institutions and bodies’, and under Article 52(3)‘… for advising Union institutions and bodies and data subjects on all matters concerning the processing of personal data’.

Wojciech Rafał Wiewiórowski was appointed as Supervisor on 5 December 2019 for a term of five years. The selection procedure for a new EDPS mandate for a term of five years is still ongoing.

Under Article 42(1) of Regulation 2018/1725, the Commission shall ‘following the adoption of proposals for a legislative act, of recommendations or of proposals to the Council pursuant to Article 218 TFEU or when preparing delegated acts or implementing acts, consult the EDPS where there is an impact on the protection of individuals’ rights and freedoms with regard to the processing of personal data’.

This Opinion relates to the Proposals for Council Decisions on the signing and on the conclusion, on behalf of the European Union, of the Agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime .

This Opinion does not preclude any future additional comments or recommendations by the EDPS, in particular if further issues are identified or new information becomes available. Furthermore, this Opinion is without prejudice to any future action that may be taken by the EDPS in the exercise of his powers pursuant to Regulation (EU) 2018/1725.

This Opinion is limited to the provisions of the Proposals that are relevant from a data protection perspective.

Executive Summary

On 24 July 2026, the European Commission issued two Proposals for Council Decisions, one on the signing and the other on the conclusion, on behalf of the European Union, of the Agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, along with an Annex containing the Agreement itself.

The objective of the Agreement is to enable the transfer of PNR data by air carriers from the EU to the Republic of Korea and to lay down rules and conditions subject to which those PNR data may be processed by the competent authorities of the Republic of Korea, as well as to enhance police and judicial cooperation between the EU and the Republic of Korea in respect of PNR data.

In the Opinion, the EDPS acknowledges the specific legal situation of the Republic of Korea as regards protection of personal data transferred from the EU. On 17 December 2021, the European Commission adopted an adequacy decision in relation to the transfer of personal data from the EU to the Republic of Korea between commercial operators, concluding that the Republic of Korea ensures an essentially equivalent level of protection to the one guaranteed under the General Data Protection Regulation (GDPR). In this context, the Commission also assessed the conditions and safeguards under which Korean public authorities, including law enforcement, can access data held by those operators.

At the same time, the EDPS recalls that the transfer of PNR data envisaged in the Agreement does not fall under the scope of this adequacy decision. Given that the Agreement aims to enable the transfer of PNR data by air carriers from the EU to the Republic of Korea for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, it must adduce all the appropriate safeguards in line with the applicable EU data protection law, as interpreted by the CJEU.

Following an assessment of the Agreement and the data protection safeguards contained therein, including the implementation of his previous specific recommendations on the negotiating mandate, the EDPS concludes that the Agreement contains the necessary safeguards required in order for it to be compatible with the EU legal framework on data protection.

2

Contents

THE EUROPEAN DATA PROTECTION SUPERVISOR,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (‘EUDPR’) , and in particular Article 42(1) thereof,

HAS ADOPTED THE FOLLOWING OPINION:

1. Introduction

1. On 24 July 2026, the European Commission issued two Proposals for Council Decisions, one on the signing and the other on the conclusion, on behalf of the European Union, of the Agreement between the European Union and the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (‘the Proposals’), along with an Annex containing the Agreement itself.

2. The objective of the Agreement is to to enable the transfer of PNR data by air carriers from the EU to the Republic of Korea and to lay down rules and conditions subject to which those PNR data may be processed by the competent authorities in the Republic of Korea, as well as to enhance police and judicial cooperation between the EU and the Republic of Korea in respect of PNR data .

3. The present Opinion of the EDPS is issued in response to two consultations by the European Commission of 24 July 2026, pursuant to Article 42(1) of EUDPR. Bearing in mind that both consultations concern the same Agreement, the present Opinion covers both Proposals. The EDPS welcomes the reference to this consultation in Recital 8 of the Proposals.

2. General remarks

4. PNR data is information provided by passengers and collected by and held in the air carriers’ reservation and departure control systems for their own commercial purposes. The content of PNR data varies depending on the information given during the booking and check-in process and may include, for example, dates of travel and the complete travel itinerary of the passenger or group of passengers travelling together, contact details such as address and phone number, payment information, seat number and baggage information .

5. While useful for combating terrorism and serious crime, the transfer of PNR data to third countries and the subsequent processing by their authorities constitutes an interference with the fundamental rights enshrined in Articles 7 and 8 of the Charter of Fundamental Rights (‘the Charter’). For this reason, it requires a legal basis under EU law and must be necessary, proportionate and subject to strict limitations and effective safeguards.

6. In addition to the Charter, the applicable legal rules in case of transfer and processing of PNR data, include also the horizontal EU legal framework on data protection, namely 6 7 Regulation (EU) 2016/679 (‘GDPR’) and Directive (EU) 2016/680 (‘LED’) , as well as the specific Directive (EU) 2016/681 (‘EU PNR Directive’) .

7. Furthermore, the Court of Justice of the EU (CJEU) on two occasions interpreted the legal framework on PNR and provided guidance as regards proportionality and necessity of PNR data processing, namely in Opinion 1/15 of 26 July 2017 and Judgment in Case C-817/2019 of 21 June 2022 . The requirements laid down by the CJEU in the cited case law constitute an important point of reference for the assessment of any EU agreement on the transfer of PNR data, including the one at hand.

8. The EDPS also recalls that, in addition to the Union legislation, PNR data is subject to international rules and standards. The United Nations Security Council Resolution 2396 (2017) on threats to international peace and security caused by returning foreign terrorist fighters, adopted on 21 December 2017, and the subsequent UN Security Council Resolution 2482 (2019) of 19 July 2019, called on UN Member States to ‘develop the capability to collect, process and analyse, in furtherance of ICAO standards and recommended practices, passenger name record (PNR) data and to ensure PNR data is used by and shared with all their competent national authorities, with full respect for human rights and fundamental freedoms, which will help security officials make connections between individuals associated to organized crime, whether domestic or transnational, and terrorists, to stop terrorist travel and prosecute terrorism and organized crime, whether domestic or transnational, including by making use of capacity building programmes’.

9. An important legal aspect to be noted, which is also expressly highlighted in the Proposals , is the legal situation of the Republic of Korea. On 17 December 2021, the Commission adopted an adequacy decision in relation to the transfer of personal data from the EU to 5 the Republic of Korea between commercial operators , concluding that the Republic of Korea ensures an essentially equivalent level of protection to the one guaranteed under the General Data Protection Regulation (GDPR) . In this context, the Commission also assessed the conditions and safeguards under which Korean public authorities, including law enforcement, can access data held by those operators. Although the adequacy assessment under this decision does not cover processing of PNR data as such, it nevertheless provides evidence that the foundations for essential data protection safeguards already exist in the legal framework of the Republic of Korea.

10. The EDPS has also previously issued an Opinion on the negotiating mandate for the Agreement between the EU and the Republic of Korea on the transfer of PNR data . In the Opinion, the EDPS made three recommendations: a. to adduce in the future PNR Agreement between the EU and the Republic of Korea the necessary safeguards for the protection of the fundamental rights to privacy and data protection in relation to the processing of PNR data, in line with the applicable Union law, as interpreted by the CJEU; b. to further detail in the future PNR Agreement between the EU and the Republic of Korea the right to information, including the right of individual notification in case of disclosure of PNR data, provided that it would not jeopardise ongoing investigations; c. to consider including in the future PNR Agreement between the EU and the Republic of Korea, the possibility to amend the Agreement, where deemed necessary, through a joint consultation or review mechanism, or another appropriate arrangement.

11. The EDPS notes with satisfaction that these recommendations have been taken into account during the negotiations and are subsequently reflected in the final text of the Agreement .

3. Appropriate safeguards

12. As already noted in paragraph 9 of this Opinion, the Commission adopted an adequacy decision in relation to the transfer of personal data from the EU to the Republic of Korea between commercial operators. The transfer of PNR data envisaged in the Agreement, however, does not fall under the scope of this adequacy decision. Given that the Agreement aims to enable the transfer of PNR data by air carriers from the EU to the Republic of Korea for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, it must adduce all the appropriate safeguards in relation to the processing of PNR data, in line with the applicable EU data protection law, as interpreted by the CJEU.

13. Given the law enforcement context and the potential risks that such transfers of data could pose to data subjects, the safeguards included in this Agreement should satisfactorily address and mitigate these risks to ensure a level of protection of personal data essentially equivalent to that guaranteed within the EU.

14. Using CJEU Opinion 1/15 as the main point of reference for the assessment of Agreement, the EDPS considers that all the appropriate safeguards have been adduced in the Agreement. The EDPS positively notes in particular the specific articles on the prohibition of processing of special categories of personal data , obligation to ensure data security and 17 18 integrity as well as provisions regarding the storage and disclosure of PNR data . Additionally, the EDPS positively notes the provisions aiming to ensure effective and independent oversight as well as those regarding the protection of the specific individual rights of air passengers . Finally, the EDPS welcomes the Annex to the Agreement, defining in a clear a precise manner the PNR data categories to be processed pursuant to the Agreement.

4. Access to PNR data by Europol and Eurojust

15. The EDPS notes that according to Article 14 of the Agreement, the Republic of Korea will share with Europol or Eurojust, within the scope of their respective mandates, the results of processing of PNR data, or analytical information based on PNR data, in specific cases where necessary to prevent, detect, investigate, or prosecute terrorist offences or serious crime. Such exchange may be carried out on its own initiative or at the request of the Union Agencies, within the scope of their respective mandates.

16. In this context, the EDPS reminds that, in as far as the data concerns extra-EU flights between the EU and the Republic of Korea, this information is already processed under the EU PNR Directive by the Member States' Passenger Information Units (PIU). The EU PNR Directive does not foresee direct access to this data for Eurojust and strictly defines the conditions under which Europol is able to access it.

17. In view of the above, it is the understanding of the EDPS that regarding Europol or Eurojust, the condition “within the scope of their respective mandates” refers not only to the tasks and powers of the two Agencies provided for in the EU regulations establishing them but also the specific rules laid down in the EU PNR Directive. Consequently, the EU-Korea PNR Agreement should not lead to situations where Union Agencies request PNR data from the Republic of Korea which they would not be able to request from an EU Member State.

5. Conclusions

18. In light of the above, the EDPS concludes that the Agreement between the European Union and Korea on the transfer of PNR data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime contains the necessary safeguards required in order for it to be compatible with the EU legal framework on data protection. Brussels, 18 September 2026 (e-signed) Wojciech Rafał WIEWIÓROWSKI 8

Fotnoter

  1. 1 COM(2026) 382 final and COM(2026) 383 final. 1
  2. 5 COM(2026) 382 final and COM(2026) 383 final, p. 1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ L 119, 4.5.2016, p. 1. 7 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA, OJ L 119, 4.5.2016, p. 89. 8 Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, OJ L 119, 4.5.2016, p. 132. 9 Opinion 1/15 of the Court of Justice (Grand Chamber) of 26 July 2017, EU:C:2017:592. 10 Judgment of the Court of Justice (Grand Chamber) of 21 June 2022, Ligue des droits humains, C-817/19, EU:C:2022:491. 11 COM(2026) 382 final and COM(2026) 383 final, p. 2.
  3. 12 Commission Implementing Decision (EU) 2022/254 of 17 December 2021 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate protection of personal data by the Republic of Korea under the Personal Information Protection Act (OJ L 44, 24.2.2022, p. 1–90). 13 Regulation (EU) 2016/679, OJ L 119, 4.5.2016, p. 1-88. 14 Opinion 28/2025 on the negotiating mandate for an Agreement between the EU and the Republic of Korea on the transfer of Passenger Name Record data, issued on 6 November 2025. 15 See Articles 16(3) and 25(2) of the Agreement. 6
  4. 16 Article 7 of the Agreement. 17 Article 8 of the Agreement. 18 Chapter IV of the Agreement. 19 Article 15 of the Agreement. 20 Articles 16 to 19 of the Agreement. 7