The Council of the European Union is considering a proposal to sign an agreement with the Republic of Korea on transferring Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime. The proposal, published on 24 July 2026, sets out detailed data protection rules, retention limits, and oversight requirements for the data-sharing arrangement.
The agreement would cover air carriers operating passenger flights between the EU and Korea, as well as carriers incorporated or storing data in the EU that operate flights to or from Korea. It mandates the use of the "push" method for data transfer, meaning air carriers send data into Korea's database rather than allowing Korean authorities direct access to EU systems. Transfers can begin up to 48 hours before a flight's scheduled departure, with a maximum of five transfers per flight. Korea must delete any data element not listed in the agreement's annex upon receipt.
PNR data retention is capped at five years, with mandatory review every two years. Depersonalisation—masking direct identifiers such as names and addresses—is required within six months of receipt. The agreement explicitly prohibits processing of special categories of data, including race, religion, health, and sexual orientation. Korea must report data security breaches to its overseeing authorities. The agreement does not apply to advance passenger information (API) used for border control.
The proposal represents a formal step toward EU-Korea cooperation on counter-terrorism and serious crime, balancing law enforcement needs with strict privacy safeguards. The Council's decision to sign would follow internal deliberations and could be subject to amendments. Once signed, the agreement would require ratification by both parties before entering into force.
EU air carriers operating flights to Korea would face compliance costs to implement the push system and data deletion protocols. Korean law enforcement gains access to PNR data for investigations but must adhere to EU-level data protection standards. EU passengers benefit from privacy safeguards including retention limits and depersonalisation, though their data would be shared with a non-EU country. EU data protection authorities may scrutinise the agreement's adequacy, particularly regarding oversight and enforcement mechanisms in Korea.