Key data
| Regulation | EU-Iceland Agreement on PNR data transfer (Passenger Name Record) |
|---|---|
| Official reference | OJ:L_202601919 |
| Publication | August 6, 2026 |
| Entry into force | Not specified in the published text |
| Direct stakeholders | Airlines with routes between the EU and Iceland |
| Category | Data Protection / Public Security |
| Purpose | Prevention, detection, investigation and prosecution of terrorism and serious crimes |
Airlines with EU-Iceland routes have a new compliance obligation: to transmit Passenger Name Record (PNR) data to Icelandic authorities. The international agreement published on August 6, 2026 under reference OJ:L_202601919 establishes the legal framework for this data transfer for public security purposes, including the fight against terrorism and serious crimes.
This is not a recommendation or a voluntary measure: it is a binding obligation for all airlines operating on these routes, with specific technical and legal requirements that must be implemented.
What does this regulation establish?
The agreement regulates the transfer of PNR data from airlines to the competent Icelandic security authorities. The PNR (Passenger Name Record) is the reservation file that each passenger generates when purchasing an airline ticket.
The types of data that must be transmitted include:
- Passenger name
- Flight itinerary (origin, destination, stopovers, dates)
- Payment method used in the reservation
- Baggage information
- Other reservation data included in the PNR file
The agreement also establishes:
- Data retention periods by Icelandic authorities (determined in the agreement text, although the exact periods are not specified in the published summary).
- Data protection guarantees that must be respected in the processing of information.
- Limitation of use: data can only be used for the prevention, detection, investigation and prosecution of terrorism and serious crimes. No other use is permitted under this agreement.
- Technical and legal requirements that airlines must comply with for data transmission.
This type of agreement follows the model already existing between the EU and other third countries (such as Canada, Australia or the United States) regarding PNR data exchange, and now extends that network to Iceland, which although part of the Schengen Area, is not an EU member.
Economic and operational impact
The main impact for airlines is not economic in terms of fees or direct payments, but rather operational and compliance. Affected companies will have to bear adaptation costs in three areas:
| Impact area | Description |
|---|---|
| Data transmission systems | Technical adaptation to send PNR data in the format and protocol required by Icelandic authorities |
| Legal and compliance processes | Review of contracts, privacy policies and internal procedures for processing passenger data |
| Internal training | Update of operations, IT and compliance teams on new obligations |
| Audit and control | Verification that transmitted data complies with permitted types and that no information is shared outside the scope of the agreement |
The risk of non-compliance can result in sanctions from both Icelandic authorities and European data protection authorities, as the agreement incorporates guarantees under the European GDPR framework.
Who does it affect?
- Airlines with direct EU-Iceland routes: these are the main obligated parties. They must transmit PNR data for all passengers on those routes.
- Airlines with connections that include Iceland: depending on the technical interpretation of the agreement, routes with stopovers in Iceland may also be affected.
- IT and reservation systems departments of airlines: responsible for technical adaptation.
- Legal and compliance departments of airlines: responsible for ensuring that data processing complies with the agreement and GDPR.
- Air passengers on EU-Iceland routes: their reservation data will be transmitted to Icelandic authorities, although the agreement establishes data protection guarantees.
- Icelandic security authorities: recipients of the data and responsible for its processing in accordance with the limitations of the agreement.
Practical example
A Spanish airline operating direct flights between Madrid-Barajas and Reykjavik has passengers who book their tickets with different payment methods and different itineraries. With the entry into force of this agreement, the company must transmit to the competent Icelandic authorities, for each flight on that route, the PNR data of all passengers: their full name, exact itinerary (Madrid-Reykjavik, dates and flight number), the payment method used in the reservation and the registered baggage information.
To do this, the airline's IT department must configure a data transmission channel compatible with the technical requirements of the agreement, and the legal department must update the privacy policy informing passengers of this international data transfer. If the airline does not adapt its systems before the effective application date of the agreement, it is exposed to sanctions for non-compliance in both Spain and Iceland.
What should companies do now?
- Identify if you operate EU-Iceland routes: confirm if any of your routes connect an EU airport with Iceland, whether in direct flight or with a stopover.
- Audit your PNR data management systems: review whether your reservation system can generate and transmit the required data (name, itinerary, payment method, baggage) in the format required by Icelandic authorities.
- Consult the full text of the agreement: access the regulation published in the EU Official Journal to learn the exact data retention periods and technical transmission requirements.
- Update your privacy policy: inform passengers of the transfer of their PNR data to Icelandic authorities, in compliance with GDPR.
- Coordinate with the DPO (Data Protection Officer): ensure that data processing under this agreement is documented in the processing activities register.
- Establish a technical adaptation plan with the IT team to implement the data transmission channel before the effective application date of the agreement.
Frequently asked questions
What PNR data must airlines transmit to Iceland?
Airlines must transmit Passenger Name Record data included in the reservation: passenger name, flight itinerary, payment method used and baggage information. The agreement expressly defines these types of data and prohibits the use of information for purposes other than the prevention, detection, investigation and prosecution of terrorism and serious crimes.
When does the EU-Iceland PNR agreement enter into force?
The agreement was published on August 6, 2026, but the exact date of entry into force is not specified in the published text. Airlines must consult the full text of the agreement in the EU Official Journal (reference OJ:L_202601919) to learn the effective application date and plan their adaptation with sufficient advance notice.
Does this agreement only affect airlines with direct flights to Iceland?
The agreement affects airlines operating routes between the EU and Iceland. This includes, at minimum, direct flights between EU airports and Icelandic airports. Airlines with routes that include Iceland as a stopover should review the full text of the agreement to determine if they are also obligated in those cases.
What data protection guarantees does the agreement include?
The agreement establishes data protection guarantees aligned with the European framework, limits the use of PNR data exclusively for public security purposes (terrorism and serious crimes), and sets specific retention periods. The processing of data by Icelandic authorities is subject to these limitations, and airlines must inform their passengers of the transfer in compliance with GDPR.
What happens if an airline does not adapt its systems to transmit PNR data?
Non-compliance with PNR data transmission obligations can result in sanctions from the competent authorities, both in the field of security regulations and in the European GDPR. Airlines must adapt their technical systems and legal processes before the effective application date of the agreement to avoid compliance risks.
Official source
Consult full regulation at official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202601919