European Regulations

EU-Norway PNR Agreement 2026: Real obligations for airlines with routes to Norway

E
Equipo Editorial CambiosLegales
06 Aug 2026 8 min 32 views

Key data

RegulationEU-Norway Agreement on PNR data transfer (Passenger Name Record) for terrorism prevention and serious crimes
Official referenceOJ:L_202601917
PublicationAugust 6, 2026
Entry into forceNot specified in the published text
Main affected partiesAirlines with routes between the EU and Norway, air passengers, security authorities of both parties
CategoryEuropean Regulation
ScopeSecurity, counter-terrorism, data protection in aviation
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

Airlines with routes between the European Union and Norway have had a new mandatory legal framework since August 6, 2026: the EU-Norway Agreement on PNR data transfer (Passenger Name Record), published under reference OJ:L_202601917. This international agreement obliges airlines to transfer their passengers' reservation data to security authorities, with the aim of preventing, detecting, investigating and prosecuting terrorism offences and serious crimes.

Norway is not an EU member, but it is part of the Schengen Area, which makes this type of security cooperation particularly relevant. The agreement strengthens cooperation between law enforcement and counter-terrorism authorities of both parties under strictly regulated conditions.

What does this regulation establish?

The agreement regulates in detail five major blocks of obligations and rights:

BlockMain content
Transmission obligationAirlines with EU-Norway routes must transmit PNR reservation data to the competent authorities designated in both parties
Purpose of processingPrevention, detection, investigation and prosecution of terrorism offences and serious crimes
Retention periodsThe agreement establishes specific periods for data retention (the exact duration is not specified in the published summary)
Data protection safeguardsSpecific safeguards are established for the processing of passengers' personal data
Passenger rightsPassengers have rights recognized in the agreement regarding the processing of their PNR data
Authority accessLaw enforcement and counter-terrorism authorities from the EU and Norway can access and analyze data under strictly regulated conditions

PNR data is the reservation data that passengers provide when purchasing a ticket or checking in: name, itinerary, payment information, contact details, baggage, among others. Its transfer to security authorities is an already established practice in the EU with third countries, and this agreement extends that framework to Norway on a bilateral basis.

Economic and operational impact

For airlines, the impact is fundamentally operational and regulatory compliance. It is not a direct cost in the form of a fee or tariff, but an obligation to adapt systems, processes and contracts that generates indirect costs:

  • Technological adaptation: Reservation and passenger management systems (PNR/DCS) must be configured to extract and transmit data in the format and frequency required by the competent authorities.
  • Data protection protocols: Airlines must update their privacy policies, processing activity records and agreements with reservation system providers to reflect this new data transfer obligation.
  • Internal training: Operations, compliance and customer service teams must understand the passenger rights recognized in the agreement and know how to manage them.
  • Coordination with authorities: It will be necessary to establish communication channels with the competent authorities designated in each EU Member State and in Norway.

The risk of non-compliance is not minor: incorrect, incomplete or late transfer of PNR data may result in legal liability both in the field of security regulations and in the field of personal data protection, which in the EU is regulated by the General Data Protection Regulation (GDPR).

Who does it affect?

  • Airlines with direct EU-Norway routes: Any airline operating flights between an airport in the EU and an airport in Norway, regardless of its country of registration.
  • Low-cost airlines with presence on Nordic routes: Operators such as those connecting European capitals with Oslo, Bergen, Stavanger or other Norwegian cities.
  • Reservation system providers (GDS): Technology platforms that manage PNR data on behalf of airlines may be involved as data processors.
  • Air passengers: Any person traveling on EU-Norway routes will have their reservation data transmitted to security authorities, with the rights that the agreement recognizes for them.
  • Security and law enforcement authorities: The Passenger Information Units (PIU) of the EU Member States and the equivalent authority in Norway are the recipients and managers of this data.
  • Compliance and data protection departments of airlines: DPOs (Data Protection Officers) and legal teams that must adapt existing compliance frameworks.

Practical example

A Spanish airline operating the Madrid-Oslo route with several weekly flights must, upon entry into force of the agreement, transmit the PNR data of each passenger to the designated competent authority. This includes reservation data: full name, flight number, date, payment information, contact details and any other PNR field collected in the purchase or check-in process.

If that same airline uses a reservation system managed by an external provider (GDS), it must review its contract with that provider to ensure that data transmission to the authorities is carried out in compliance with the agreement and the GDPR. Additionally, it must update its privacy policy to inform passengers of this data transfer, the applicable retention periods and the rights they can exercise.

Failure to comply with the transmission obligation, or defective transmission of data, could expose the airline to claims by security authorities and, simultaneously, to sanctions by the data protection authority if the processing does not comply with the safeguards established in the agreement.

Do you need to monitor this and other regulations?

Consult the full details in CambiosLegales

What should companies do now?

  1. Identify if they operate EU-Norway routes: Confirm which company routes fall within the scope of the agreement (any flight between an EU airport and a Norwegian airport).
  2. Review current PNR systems: Check if reservation and passenger management systems are prepared to extract and transmit data in the format required by the competent authorities.
  3. Update contracts with reservation system providers: Ensure that GDS and other technology providers act as data processors in compliance with the GDPR and the agreement.
  4. Review and update privacy policy: Inform passengers of the transfer of their PNR data to security authorities of the EU and Norway, retention periods and their rights.
  5. Identify designated competent authorities: Locate the Passenger Information Units (PIU) of the relevant Member States and the equivalent authority in Norway to establish transmission channels.
  6. Consult with the DPO or specialized legal advisor: Assess the specific impact on processing activity records and data protection impact assessment (DPIA) if one already exists for PNR operations.

Frequently asked questions

Which airlines are obliged by the EU-Norway PNR agreement?

All airlines operating routes between any airport in an EU Member State and any airport in Norway, regardless of their country of registration or headquarters. This includes both flag carriers and low-cost operators covering Nordic routes.

What PNR data must be transmitted to the authorities?

PNR data is the passenger's reservation data: full name, flight itinerary, dates, payment information, contact details, baggage information and other fields collected in the purchase or check-in process. The agreement regulates which specific fields must be transmitted, with what frequency and under what security conditions.

When does the EU-Norway PNR agreement enter into force?

The agreement was published on August 6, 2026 under reference OJ:L_202601917. The exact date of entry into force has not been specified in the published text. Airlines must monitor the publication of the official date to plan their adaptation.

How does this agreement affect the GDPR and passenger data protection?

The agreement establishes specific data protection safeguards compatible with the European framework. Airlines must ensure that PNR data transmission is carried out in compliance with both the agreement and the GDPR: appropriate legal basis, information to passengers in the privacy policy, defined retention periods and access, rectification and deletion rights recognized to passengers.

What happens if an airline does not comply with the obligation to transmit PNR data?

Non-compliance may generate legal liability in the field of security regulations (obligation to cooperate with authorities) and, simultaneously, in the field of data protection if the processing does not comply with the safeguards of the agreement and the GDPR. Airlines must consult with their legal advisor to assess the applicable sanctions regime in each Member State.

Official source

Consult complete regulation in official source

Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202601917



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts