The Council of the European Union has published a proposal for a decision to conclude an agreement with the Republic of Korea on the transfer of Passenger Name Record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime. The proposal, dated 24 July 2026, sets out the terms under which air carriers operating flights between the EU and Korea must transfer PNR data using the 'push' method into Korea's database, starting up to 48 hours before scheduled departure, with a maximum of five transfers per flight. The agreement aims to enhance security cooperation while imposing strict data protection safeguards.

The proposed agreement requires Korea to delete any data elements not listed in the annex upon receipt. PNR data can only be processed for terrorist offences or serious crime, including passenger assessment, database searches, and analysis for updating risk criteria. Korea cannot retain PNR data for more than five years, with mandatory reviews every two years. Data must be depersonalised within six months by masking names, addresses, payment information, frequent flyer data, general remarks, and advance passenger information (API) data. Processing of special categories such as race, religion, health, or sexual orientation is prohibited and must be deleted immediately. Korea must implement encryption, access controls, and report data breaches to overseeing authorities. Disclosure to other Korean authorities requires case-by-case approval by a judicial or independent body, with urgency exceptions.

This is the first major EU PNR agreement with an Asian partner, following similar accords with the United States, Canada, and Australia. The agreement excludes API data from its scope, which is handled separately under EU law. The proposal now requires approval by the European Parliament before the Council can formally adopt the decision. The agreement will affect air carriers operating passenger flights between the EU and Korea, as well as EU-based carriers flying to or from Korea, which must adapt their data transfer systems to comply with the push method and retention limits. Privacy advocates may raise concerns about the five-year retention period and the possibility of data access by Korean authorities for serious crime, while security officials will welcome the enhanced ability to track terrorist suspects. The European Data Protection Supervisor is expected to issue an opinion on the agreement's compliance with EU data protection standards.

← Atlas › News › Home affairs & Migration