New EU Regulation on API Border Data Processing (Regulation 2025/12)

UK Version of GDPR

The European Union adopted Regulation 2025/12 to standardize how border authorities and airlines process passengers’ Advanced Passenger Information (API). This regulation responds to growing concerns over the security and privacy of large-scale personal data sharing in cross-border travel. Airlines will now have to conduct routine security audits, maintain detailed records of their data flows, and implement strong encryption protocols. In addition, authorities must guarantee robust oversight by Data Protection Officers (DPOs) and submit to reviews by the European Data Protection Supervisor (EDPS). The goal is to strengthen security while upholding fundamental rights under the GDPR, ensuring passengers’ personal data is processed lawfully, transparently, and securely. This regulation is a critical development for sectors dealing with cross-border personal data transfers.
🔗 Official text via EUR-Lex

Picture of Dposphere

Dposphere

Recent Post

The UK’s Information Commissioner’s Office has reprimanded ACRO, the Criminal Records Office, following cybersecurity failures involving

The European cybersecurity certification ecosystem is continuing to develop as organizations face growing pressure to demonstrate

The European Union Agency for Cybersecurity (ENISA) announced that it is expanding its role within the