Data Protection

ETIAS 2026: new data management rules for transport operators and border authorities

E
Equipo Editorial CambiosLegales
Sep 8, 2026 6 min 63 views

Key data

RegulationCommission Implementing Decision (EU) 2026/1970 of 7 September 2026
Official referenceOJ:L_202601970
Publication8 September 2026
Entry into forceNot specified in the published text
Affected partiesEU border, police and immigration authorities; transport operators
CategoryData Protection
Repealed regulationCommission Implementing Decision (EU) 2021/1028
Legal basisRegulation (EU) 2018/1240 of the European Parliament and of the Council
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

Air, maritime and land transport operators running routes to the EU with passengers from visa-exempt third countries face a new technical obligation. The Commission Implementing Decision (EU) 2026/1970, published on 8 September 2026, updates the framework governing how information stored in the SEIAV central system (internationally known as ETIAS, the European Travel Information and Authorization System) is accessed, modified, deleted and early deleted.

This is not a brand new regulation: it repeals and replaces the Commission Implementing Decision (EU) 2021/1028, updating the technical specifications that were already in force. The change requires a review of internal procedures, system integrations and data protection protocols.

What does this regulation establish?

The Decision regulates four specific operations on data stored in the SEIAV central system:

  • Access: who can consult traveller data and under what technical conditions.
  • Modification: procedures for correcting or updating existing data in the central system.
  • Deletion: removal of data in accordance with regulatory timelines and conditions.
  • Early deletion: removal of data before the ordinary timeline, in specific cases provided for in Regulation (EU) 2018/1240.

All of this is framed within Regulation (EU) 2018/1240, which is the parent regulation of the ETIAS system. The 2026 Decision provides the precise technical and operational specifications that authorities and operators need to implement these operations in practice.

AspectDecision 2021/1028 (repealed)Decision 2026/1970 (in force)
Technical framework for data accessPrevious specificationsNew updated technical specifications
Early deletion proceduresRegulated under previous schemeUpdated with new operational procedures
Data protection guaranteesIn accordance with 2021 standardsStrengthened with new technical measures
StatusRepealedIn force since publication (Sept. 2026)

Economic and operational impact

The direct impact is not a specific fine or fee: it is a cost of technical adaptation and compliance. Affected organizations must assess whether their current ETIAS authorization verification systems and traveller data management are compatible with the new technical specifications.

The main vectors of operational cost are:

  • Update of technical integrations with the SEIAV central system to reflect the new procedures for access, modification and deletion.
  • Review of internal protocols for traveller data protection, especially regarding early deletion.
  • Staff training for border, immigration and transport operations personnel on the new procedures.
  • Compliance audit to verify that current systems are not already operating under the parameters of the repealed Decision 2021/1028.

The risk of inaction is operating with obsolete technical procedures, which can generate data protection incidents or denials of access to the SEIAV central system by the competent authorities.

Who does it affect?

  • Border authorities of EU Member States that use the ETIAS system to control the entry of travellers from visa-exempt third countries.
  • EU police authorities with access to the SEIAV central system within their competencies.
  • Immigration authorities of Member States that manage traveller data in the system.
  • Transport operators (airlines, shipping companies, road transport companies) required to verify that their passengers have a valid ETIAS travel authorization before boarding.

Transport operators are the private business group most directly affected: they have a legal obligation to consult the ETIAS system before allowing passengers from visa-exempt third countries to board, and must do so through technical interfaces that are now being updated.

Practical example

A Spanish airline operating regular flights from Latin America to EU airports currently verifies ETIAS authorizations for its passengers through a technical integration with the SEIAV central system. With the entry into force of Decision 2026/1970, that integration must be adjusted to the new technical specifications for data access.

If the airline continues to operate under the technical parameters of Decision 2021/1028 (already repealed), it risks having its access to the central system denied or verification queries not being processed correctly, which could result in operational delays in boarding or compliance incidents with border authorities.

The immediate action is to contact the technology provider responsible for the ETIAS integration and verify whether they already have an updated version compliant with Decision 2026/1970.

Do you need to track this and other regulations?

Check the full details on CambiosLegales

What should companies do now?

  1. Identify if your company is a transport operator required to verify ETIAS authorizations: airlines, shipping companies and road transport companies with routes to the EU from visa-exempt third countries.
  2. Review the current technical integration with the SEIAV central system and verify whether it is based on the parameters of Decision 2021/1028 (repealed) or already incorporates the new specifications of Decision 2026/1970.
  3. Contact the technology provider responsible for the ETIAS integration to confirm the timeline for updating to the new technical specifications.
  4. Update internal traveller data protection protocols, especially the procedures for deletion and early deletion of data in the central system.
  5. Train operational staff (check-in, boarding, border control) on the procedural changes resulting from the new Decision.
  6. Document the adaptation process to demonstrate compliance in the event of inspections by the competent authorities.

Frequently asked questions

What is the ETIAS system and which transport operators does it affect?

ETIAS (European Travel Information and Authorization System, called SEIAV in Spanish) is the EU system that controls the entry of nationals from visa-exempt third countries. It affects transport operators (airlines, shipping companies and road transport companies) that have a legal obligation to verify that their passengers have a valid travel authorization before boarding, in accordance with Regulation (EU) 2018/1240.

What changes with Decision 2026/1970 compared to the previous regulation?

Commission Implementing Decision (EU) 2026/1970 repeals and replaces Commission Implementing Decision (EU) 2021/1028. It updates the technical specifications and operational procedures for access, modification, deletion and early deletion of data in the SEIAV central system, and strengthens the guarantees for the protection of travellers' personal data.

When does Decision 2026/1970 come into force?

The Decision was published on 8 September 2026. The exact date of entry into force is not specified in the published information. It is recommended to consult the full text in the EU Official Journal to verify the specific date and any transitional period.

What happens if a transport operator does not update its technical integration with ETIAS?

Operating with the technical parameters of Decision 2021/1028 (already repealed) may result in access to the SEIAV central system being denied or verification queries not being processed correctly. This can generate operational delays in boarding and compliance incidents with the border authorities of the Member States.

Do border and police authorities also need to adapt their systems?

Yes. Decision 2026/1970 directly affects the border, police and immigration authorities of EU Member States that use the ETIAS system. They must adapt their technical and operational procedures to the new specifications for access, modification and deletion of data in the SEIAV central system.

Official source

View complete regulation at official source

Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202601970



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts