The Council of the European Union is being asked to authorise the signing of an agreement with the Republic of Korea on the transfer of Passenger Name Record (PNR) data for combating terrorism and serious crime. The proposal for a Council decision, published on 24 July 2026, follows the initialling of the agreement text by lead negotiators on 4 June 2026 and its welcome at the EU-Korea Summit on 10 June 2026.
The agreement covers PNR data from air carriers on flights between the EU and South Korea. Negotiations began on 17 December 2025. The text includes a maximum data retention period of five years, with depersonalisation required after six months. It prohibits processing special categories of PNR data and limits automated processing. Disclosures of data outside South Korea require prior approval by a judicial authority or independent body. South Korea must appoint an independent oversight authority for PNR processing, and individuals are granted rights to access, correction, redress, and effective administrative and judicial remedy.
Policy orientations and trade-offs The agreement balances security needs with data protection, reflecting EU legal standards including the Charter of Fundamental Rights. The retention period of five years, with depersonalisation after six months, represents a compromise between law enforcement requirements and privacy concerns. The prohibition on processing sensitive data and limits on automated processing aim to prevent profiling and discrimination. The requirement for prior judicial approval for onward transfers strengthens data sovereignty but may slow information sharing in urgent cases.
Impact on stakeholders - EU citizens and travellers: Enhanced security through better terrorist and crime prevention, but also increased surveillance and data retention of their travel information. The safeguards provide some privacy protection, though the five-year retention period may raise concerns among civil liberties groups. - Air carriers: Required to transfer PNR data to South Korean authorities, imposing compliance costs and operational adjustments. However, a single agreement replaces potential divergent national requirements, simplifying procedures. - South Korean authorities: Gain access to EU-origin PNR data for law enforcement, but must establish an independent oversight authority and comply with strict data protection rules, including judicial approval for onward transfers. - EU law enforcement agencies: Benefit from reciprocal data sharing that could aid investigations, but the agreement's limitations on automated processing and data retention may reduce the speed and scope of intelligence gathering.
Institutional follow-up If the Council authorises signing, the agreement will be signed by the EU and South Korea, after which the Council will need to decide on its conclusion (ratification). The European Parliament will be consulted before final adoption. The agreement also requires South Korea's domestic ratification procedures. No budgetary implications for the EU budget are foreseen.