Key data
| Regulation | Council Decision (EU) 2026/2251 of 1 October 2026 |
|---|---|
| CELEX Reference | 32026D2251 |
| Publication | 7 October 2026 |
| Entry into force | Not specified (pending parliamentary ratification) |
| Affected parties | Airlines operating EU-South Korea routes and travelers on those routes |
| Category | European Regulation |
| Reference model | PNR agreements in force with the USA, Canada and Australia |
Airlines with routes between the European Union and South Korea face a new compliance obligation: the systematic transmission of passenger reservation data (PNR) to South Korean authorities. The EU Council authorized the signing of this agreement on 1 October 2026 through Decision (EU) 2026/2251, published on 7 October 2026 in the Official Journal of the EU.
The agreement replicates the model already applied with the United States, Canada and Australia, countries with which the EU maintains similar PNR data exchange agreements for combating terrorism and serious crimes. South Korea now joins that network of international agreements.
What does this regulation establish?
The agreement regulates the transfer of Passenger Name Record (PNR) data, that is, the set of information that passengers provide when booking a flight. This data is collected by airlines and, under this agreement, must be transmitted to the competent authorities of South Korea for an exclusive purpose: the prevention, detection, investigation and prosecution of terrorism and serious crimes.
The types of PNR data covered by the agreement include:
- Passenger's full name
- Flight itinerary (origin, destination, stopovers)
- Baggage information
- Payment method used in the booking
- Other booking data usual in airline systems
The agreement imposes data protection obligations and strict use limitations for South Korean authorities receiving this information. The data cannot be used for purposes other than those expressly provided for in the agreement.
For its full entry into force, the agreement requires parliamentary ratification, so the effective date of application has not yet been determined. The Council decision published on 7 October 2026 only authorizes the signing of the agreement, not its final application.
Economic and operational impact
The main impact of this agreement is operational and regulatory compliance, not directly economic in terms of quantified fees or sanctions in the published text. However, affected airlines will have to bear real costs in several dimensions:
- Adaptation of technological systems: Reservation management systems (PNR/DCS) will need to be configured to transmit data in the format and protocol required by South Korean authorities.
- Review of privacy policies: Airlines will have to update their privacy notices to inform passengers of the transfer of their data to South Korea.
- GDPR compliance: The international transfer of personal data to a third country requires an appropriate legal basis; this agreement acts precisely as that basis, but requires internal implementation.
- Training and internal procedures: Compliance and data protection teams will need to understand and apply the new protocol.
The model followed is the same one already applied by airlines on routes to the USA, Canada and Australia, so companies with experience in those markets have a starting advantage in adaptation.
Who does it affect?
- EU airlines operating direct or connecting flights between any European airport and South Korea.
- Third-country airlines operating EU-South Korea routes with origin or destination in EU territory.
- Data Protection Officers (DPO) of affected airlines, who will need to oversee implementation.
- Technology providers of reservation management systems (GDS, PNR systems) serving airlines on those routes.
- Travelers flying between the EU and South Korea, whose reservation data will be transferred to South Korean authorities.
Practical example
A Spanish airline operating direct flights between Madrid and Seoul collects, at the time of booking, the PNR data of each passenger: name, itinerary, number of checked bags and payment method (for example, credit card). With the agreement in force, this airline will have to transmit this set of data to the competent South Korean authorities before or during the flight, following the agreed technical protocol.
If the airline already transmits PNR data to US authorities on its Madrid-New York routes, the adaptation process for the South Korea route will largely be an extension of the already implemented system: same type of data, same transmission scheme, new recipient and new legal basis agreement. The adaptation effort will be smaller for airlines with experience in previous PNR agreements.
What should companies do now?
- Identify if they operate EU-South Korea routes: The first step is to confirm whether the airline or service provider has flights affected by the scope of the agreement.
- Review current PNR systems: Check whether reservation management systems are already prepared to transmit data in the required format, taking as reference the protocols applied for the USA, Canada or Australia.
- Update data protection documentation: Include South Korea in the records of processing activities and in privacy notices directed to passengers.
- Coordinate with the DPO: The data protection officer must assess the impact of the new international transfer and document the legal basis (the international agreement itself).
- Monitor parliamentary ratification: The agreement does not enter into force until ratification. The legislative process must be followed to determine the effective date of application and plan implementation with sufficient lead time.
- Contact technology providers: If PNR systems are managed by a third party (GDS or other provider), inform them of the new obligation so they can adapt data transmission in time.
Frequently asked questions
What PNR data must airlines transmit to South Korea?
The agreement covers the usual booking data: passenger's full name, flight itinerary (origin, destination and stopovers), baggage information and payment method used in the booking. These are the same types of data already transmitted under PNR agreements with the USA, Canada and Australia.
When does the PNR agreement with South Korea enter into force?
The entry into force date is not specified. The Council Decision of 1 October 2026 only authorizes the signing of the agreement. For its full application, parliamentary ratification is necessary, the deadline for which has not yet been determined. Airlines must monitor the legislative process to prepare in advance.
Which airlines are obliged to comply with this agreement?
All airlines operating routes between the European Union and South Korea, regardless of their nationality. This includes both European airlines and third-country airlines operating flights with origin or destination in EU territory to South Korea.
Can South Korean authorities use PNR data for any purpose?
No. The agreement imposes data protection obligations and strict use limitations for the receiving South Korean authorities. The data can only be used for the prevention, detection, investigation and prosecution of terrorism and serious crimes, which are the only purposes provided for in the agreement.
What is the difference between this agreement and those already in force with the USA, Canada or Australia?
The content and structure are equivalent: same type of PNR data, same purpose (combating terrorism and serious crimes) and same protection obligations for the receiving country. The difference is the recipient: South Korea. Airlines with experience in agreements already in force with the USA, Canada or Australia have a technical and legal basis that facilitates adaptation to this new agreement.
Official source
Consult complete regulation in official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=CELEX:32026D2251