What is happening
The Commission submitted a proposal asking the Council to authorise the agreement’s signature. Negotiations opened on 17 December 2025 after Council authorisation and negotiating instructions, and the lead negotiators initialled the text on 4 June 2026, formally ending the talks. The latest document is a Commission proposal for a Council decision, not the Council decision itself.1
Passenger name record (PNR) dataInformation supplied by passengers and collected and held by airlines in reservation and departure-control systems for commercial purposes. It may include itineraries, contact and payment details, seats and baggage information. is information that passengers provide and airlines keep in booking and departure-control systems for commercial purposes. Depending on what is supplied at booking and check-in, it may include travel dates and itineraries, contact and payment details, seat numbers and baggage information. The draft covers transfers by airlines operating between the EU and the Republic of Korea to the designated Korean authority responsible for processing PNR data.1
The agreement would restrict processing to four actions—preventing, detecting, investigating and prosecuting—concerning terrorist offences and serious crime. Transfer methods and frequency would have to keep the data sent to the minimum necessary. The draft sets a five-year maximum retention period and otherwise requires deletion after departure unless an assessment identifies objective elements showing that the data could contribute effectively to those purposes. The Republic of Korea would review its assessment every two years and notify the EU. Individuals would have access to their own PNR data and rights to correction, information, and administrative and judicial redress.1
Why it matters
The Commission argues that analysing PNR data can reveal suspicious travel patterns and associates of criminals or terrorists who were previously unknown to law enforcement. It presents the agreement as the EU-level legal basis needed for these transfers. The Commission acknowledges that authorities’ use of PNR interferes with privacy and data-protection rights, but says the draft balances those rights with public-security objectives.1
In a 2021 adequacy decisionThe Commission’s 2021 finding that the Republic of Korea provided essentially equivalent protection for covered personal-data transfers from the EU between commercial operators. That decision did not cover PNR processing., the Commission found essentially equivalent protection for covered personal-data transfers from the EU to the Republic of Korea between commercial operators. That finding did not cover PNR processing. The Commission says the earlier assessment nevertheless identified foundations for safeguards including enforceable individual rights, judicial redress and independent oversight. The new draft separately requires a Korean oversight authority and security-breach notifications to that authority.1
What happens next
Under the treaty procedure cited by the Commission, the Council decides whether to authorise signature. In its 24 July proposal, the Commission asked the Council to do so. If the Council gives that authorisation, the Commission says it is responsible for arranging the signing; conclusion of the agreement would come at a later stage.1
