Data Protection

PNR Data for EU-Iceland Flights: Airline Obligations in 2026

E
Equipo Editorial CambiosLegales
06 Aug 2026 7 min 27 views

Key data

RegulationCouncil Decision (EU) 2026/1918, of 4 June 2026
Publication6 August 2026
Entry into force4 June 2026
Affected partiesAirlines operating flights between the EU and Iceland, passengers and security authorities
CategoryData Protection / International Security
Year2026
Official referenceOJ:L_202601918
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

Airlines operating routes between the European Union and Iceland have a new compliance obligation from 4 June 2026: to transfer passenger name record (PNR) data to the competent Icelandic authorities. The Council Decision (EU) 2026/1918, published in the EU Official Journal on 6 August 2026, formalizes the bilateral agreement between the EU and Iceland for the use of this data in the prevention and prosecution of terrorism and serious crimes.

This is not a conceptual novelty: the EU already has PNR agreements in force with the United States, Canada and Australia. Iceland is now joining this international framework for security data exchange. What changes for airlines is the concrete operational obligation on these routes.

What does this regulation establish?

The agreement regulates the transfer of PNR data, that is, the information that airlines collect from passengers at the time of booking a flight. This data is transferred to Icelandic authorities for the following exclusive purposes:

  • Prevention of terrorism and serious crimes
  • Detection of these crimes
  • Investigation of these crimes
  • Prosecution of those responsible

The agreement includes data protection safeguards and establishes strict use limitations: data can only be used for the stated purposes, not for any other security or administrative purpose. This framework of safeguards follows the model of agreements already in force with third countries.

ElementDetail
Data transferredPNR data (Passenger Name Record): information collected by airlines when booking flights
RecipientCompetent authorities of Iceland
Permitted purposePrevention, detection, investigation and prosecution of terrorism and serious crimes
SafeguardsData protection and use limitations established in the agreement
Reference modelPNR agreements with the USA, Canada and Australia
Obligated partiesAirlines operating flights between the EU and Iceland

Economic and operational impact

The direct impact falls on airlines with EU-Iceland routes. The operational implications are concrete:

  • Adaptation of data transmission systems: Airlines must ensure that their technological systems are capable of sending PNR data to Icelandic authorities in the format and timeframes required by the agreement.
  • Update of privacy policies: Passengers must be informed that their PNR data is transferred to Iceland. Airlines' privacy policies and legal notices must reflect this new international data transfer.
  • International regulatory compliance: Airlines already familiar with PNR agreements with the USA, Canada or Australia have a starting point, but must extend their procedures to the Icelandic route specifically.
  • Risk of non-compliance: Failure to transmit PNR data in accordance with the agreement may result in legal liability both within the EU and with Icelandic authorities.

The regulation does not establish direct economic costs (fees, specific fines) in the text of the agreement, but failure to comply with data transfer obligations may activate the enforcement mechanisms of the General Data Protection Regulation (GDPR) and applicable security regulations.

Who is affected?

  • Airlines with direct EU-Iceland routes: They are the main obligated parties. They must transmit PNR data from each flight to Icelandic authorities.
  • Airlines with connections or stops on EU-Iceland routes: They must verify whether their operations fall within the scope of the agreement.
  • Regulatory compliance and data protection departments (DPO): Responsible for adapting internal policies, contracts and data transfer systems.
  • Technology providers of reservation systems (GDS): May be involved in the PNR data transmission chain.
  • Passengers on EU-Iceland flights: Their personal reservation data is subject to this international transfer, with the safeguards established in the agreement.
  • Icelandic security authorities: Recipients of the data and responsible for its use in accordance with the agreed limitations.

Practical example

A Spanish airline operating regular flights between Madrid and Reykjavik must, from 4 June 2026, transmit to the competent Icelandic authorities the PNR data of each passenger boarding on those routes. This data includes information collected at the time of booking: name, itinerary, contact details, payment information and other fields in the passenger name record.

If this airline already had a PNR transmission system in place for its flights to the USA or Canada, the technical process is analogous: it must extend that system to also cover routes to Iceland and update its privacy policy to inform passengers of this new international data transfer. If it did not have any previous PNR system for third countries, it must implement it from scratch for these routes.

Do you need to track this and other regulations?

Check the full details on CambiosLegales

What should companies do now?

  1. Identify if you operate EU-Iceland routes: The first step is to confirm whether the airline has direct flights or connections that fall within the scope of the agreement. If so, the obligation is immediate (in force from 4 June 2026).
  2. Review PNR data transmission systems: Verify whether current systems allow sending PNR data to Icelandic authorities in the required format. If integration with other countries already exists (USA, Canada, Australia), extend it to Iceland.
  3. Update privacy policies and passenger notices: Passengers on EU-Iceland flights must be informed of the transfer of their PNR data to Iceland. Review and update all passenger information documents.
  4. Consult with the Data Protection Officer (DPO): The DPO must validate that the transfer complies with the GDPR and with the safeguards established in the bilateral agreement.
  5. Review contracts with technology providers (GDS): If PNR data transmission is carried out through global distribution systems or external providers, verify that they also comply with the new obligations.
  6. Document compliance: Record the measures adopted to demonstrate compliance in the event of possible inspections or requests from data protection authorities.

Frequently asked questions

What is PNR data and what information does it include?

PNR (Passenger Name Record) data is the information that airlines collect from passengers at the time of making a flight reservation. It includes information such as the passenger's name, itinerary, contact details, payment information and other fields recorded in the reservation system. It is this data that, under the EU-Iceland agreement, must be transferred to the competent Icelandic authorities.

From when are airlines obliged to transfer PNR data to Iceland?

The obligation has been in force since 4 June 2026, the date of entry into force of Council Decision (EU) 2026/1918. Publication in the EU Official Journal took place on 6 August 2026, but the date of application is the earlier date.

What can Iceland use the PNR data received for?

The agreement strictly limits the use of PNR data to four purposes: prevention, detection, investigation and prosecution of terrorism and serious crimes. It cannot be used for any other administrative or security purpose other than those expressly agreed. The agreement includes data protection safeguards and use limitations.

Is this agreement new or does it follow an existing model?

It follows the model of PNR agreements that the EU already has in force with the United States, Canada and Australia. Iceland is joining this international framework for security data exchange. Airlines that already comply with those agreements have a starting point, but must extend their procedures to routes with Iceland.

What happens if an airline does not transmit PNR data to Iceland?

Failure to comply with the data transfer obligations established in the agreement may activate the enforcement mechanisms of the GDPR and applicable security regulations in the EU. Although the agreement does not detail specific penalty amounts, airlines are exposed to legal liability both within the European and Icelandic spheres. It is recommended to consult with the DPO and specialized legal advice.

Official source

Consult the complete regulation in the official source

Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202601918



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts