The EU’s new passenger data router promises deletion but has no technical plan

ATC Intelligence
 ⋅ 

The EU’s new centralized API-PNR router is legally required to erase passenger data immediately, permanently, and automatically once it finishes routing the information to national authorities. But that deletion promise exists only on paper: the router is not yet operational, the tentative start date is 2029, and the technical implementation is still unpublished.

End-to-end encryption is mandatory in transit, yet the published rules do not explain how the router validates encrypted data, handles deletion in caches and backups, or proves to auditors that nothing remains. Passenger data then lives on for years in national systems.

In 2025, the European Union committed to something unusual for border infrastructure: a router that forgets. Regulation (EU) 2025/13, published in the European Union, Official Journal (EUR-Lex), says the new central API-PNR router operated by eu-LISA must not become a repository. It must delete passenger data immediately, permanently, and automatically once transmission is complete — or when no transmission happens at all.

That is the promise. The public technical record behind it is much thinner. Neither eu-LISA nor the European Commission has published a description of how deletion handles the places data hides: caches, logs, backups.

The same regulation requires end-to-end encryption for every hop among carriers, the router, Passenger Information Units, and border authorities. Yet the published documentation does not explain how the router runs automated checks for completeness and correctness while a payload is encrypted.

So a traveler is left with a legally binding privacy claim whose enforcement mechanism remains largely unexplained. That gap is the real story.

A pass-through router with a deletion mandate

Two regulations set the architecture. They entered into force on 28 January 2025, although the router’s operational date is a different matter entirely. The design moves airline-to-government traffic from many bilateral channels to one harmonized interface.

Carriers send API and PNR data once, and the router forwards it to the correct national recipients.

The legal text leaves little room for the router to become a data lake. It excludes analytical capabilities for any API or PNR datasets and permits storage only when strictly necessary for transmission. That means no long-term profiling.

The data protection logic is architectural: the less the router can do, the less it can misuse.

But even a pass-through creates traces. The same regulation requires carriers and eu-LISA to keep processing logs for one year. Those logs must then be deleted immediately and permanently unless an active security or integrity procedure still needs them.

So the claim that the router retains nothing is about passenger data, not about the metadata of handling it.

Flight deals
most people never see

Our AI monitors 150+ airlines for pricing anomalies that traditional search engines miss. Air Traveler Club members save $650 per trip per person on average: see how it works.


Each deal saves 40–80% vs. regular fares:

Superdeals to Asia preview

Encryption, validation, and the audit gap

The router’s validation job is harder to reconcile with the encryption rule. It has to check that each incoming message fits the supported formats and contains the required fields before anything is forwarded.

Here is where the public record goes quiet. A validator normally has to see what it checks. If a payload stays encrypted end to end, the router cannot easily confirm that its content is complete and correct unless carriers validate it beforehand or the system applies a schema check directly to the encrypted container.

The only standard visible in eu-LISA interface material so far is TLS 1.3, which protects the connection but does not by itself explain how application-layer validation works.

That matters because the system’s auditability rests on logs rather than retained passenger records. The one-year log requirement gives an auditor a trail of transfers, but not the contents of what was deleted. Travelers and regulators can point to a transfer record; they cannot inspect the data that supposedly vanished.

Where the data actually lives for five years

The router’s deletion mandate is only the first handoff. Once PNR data reaches a Passenger Information Unit, Directive (EU) 2016/681 — archived by the UK Legislation (The National Archives) — takes over. The directive then obliges every Member State to store PNR data in a Passenger Information Unit database for five years.

After six months, the data is depersonalised by masking names, contact details, payment information, frequent-flyer entries, general remarks, and any API data collected alongside it.

Sensitive categories get special treatment. Data that would reveal a passenger’s race or ethnicity, political or philosophical views, religion, trade-union membership, health, sexual life, or sexual orientation cannot be processed by a Member State. If it arrives, the Member State must delete it immediately.

When the five years run out, the records must be permanently deleted — unless they have already been passed to competent authorities for specific cases, in which case national law takes over. So the router’s automatic erasure does not end the traveler-data lifecycle. It moves the question to national databases across the EU, each with its own rules and practices.

How the routing sequence is supposed to work

In the middle of the pipeline sits a router managed by eu-LISA. Carriers send it API and PNR data over protected links, then automated checks confirm each message fits the shared formats and includes the required fields. From there, the router forwards the encrypted data to Passenger Information Units for law enforcement and to national border authorities for external border checks.

Once a transfer ends — or a flight falls outside the scheme — the passenger record is gone. The router is left with only a temporary log, which itself is later deleted; the storage inside the router is, by design, a temporary by-product rather than a destination.

One oddity stands out: eu-LISA’s 2025–2027 programming document presents the router as the connector between Member States and air carriers, and under the Commission’s tentative planning it lists 2029 as the start date.

For years, then, the deletion-on-arrival promise will sit in the legal text without a system in service to carry it out.

ATC Intelligence

Reporting by

ATC Intelligence

15 years in Asia-Pacific aviation. We monitor 150+ airlines across four continents, track fare anomalies with AI, and verify every deal by hand — from Bali, in the heart of the market we cover.

Questions? Answers.

When will the EU’s centralized API-PNR router begin operating?

eu-LISA’s Single Programming Document 2025–2027 points to 2029 under the Commission’s tentative planning. Regulation (EU) 2025/13 does not apply until a Commission implementing act puts the router into service after comprehensive testing.

Does the new EU router keep passenger data after routing?

No. The regulation requires deletion immediately, permanently, and automatically once transmission is completed or when data are not transmitted. Storage on the router is limited to what is strictly necessary for technical transmission; long-term analytics or profiling are excluded.

How long do national authorities keep PNR data after the router deletes it?

Passenger Information Units must retain PNR data for five years in a database. After six months, identifiers are depersonalised by masking names and other details. At the end of five years, the data must be permanently deleted unless specific records have been transferred to competent authorities and national law applies.

Who oversees data-protection compliance for eu-LISA’s systems?

The European Data Protection Supervisor supervises eu-LISA’s processing of personal data and can obtain relevant information. eu-LISA’s data protection officer must notify the EDPS of high-risk processing operations and respond to requests.