Kommisjonens gjennomføringsbeslutning (EU) 2026/1970 av 7. september 2026 om tiltak for anvendelse av europaparlaments- og rådsforordning (EU) 2018/1240 med hensyn til tilgang til og endring, sletting og forhåndssletting av data i det sentrale ETIAS-systemet, og om oppheving av Kommisjonens gjennomføringsbeslutning (EU) 2021/1028
Det europeiske system for innreiseinformasjon og -tillatelse: gjennomføringsbestemmelser om tilgang til og endring og sletting av data i det sentrale ETIAS-systemet
Kommisjonsbeslutning publisert i EU-tidende 8.9.2026
Bakgrunn
(fra kommisjonsforordningen)
(1) Regulation (EU) 2018/1240 establishes the European Travel Information and Authorisation System (ETIAS), applicable to visa-exempt third-country nationals seeking to enter the territory of the Member States.
(2) Regulations (EU) 2021/1150 (2), (EU) 2021/1151 (3) and (EU) 2021/1152 (4) of the European Parliament and of the Council introduced conditions for accessing other EU information systems for the purpose of ETIAS. Following the adoption of those Regulations, it is necessary to lay down rules for the implementation of those new provisions.
(3) It is necessary to adopt measures for the technical implementation of ETIAS.
(4) The measures laid down by this Decision should be completed by the Technical Specifications of the ETIAS Information System. Based on the measures laid down by this Decision, the European Union Agency for the Operational Management of Large-Scale IT systems in the Area of Freedom, Security and Justice (eu-LISA) should be able to define the design of the physical architecture of the ETIAS Information System, as well as the technical specifications of the system and to develop the ETIAS Information System.
(5) The technical development and implementation of the ETIAS Central System should cover the way authorities access, amend and erase data in the ETIAS Central System.
(6) As regards access by border authorities for the purposes of obtaining the status of a travel authorisation at borders, access by immigration authorities for the purpose of verifying the conditions of entry or stay on the territory of Member States, access by the central access points for law enforcement purposes, and access by ETIAS National Units for the retrieval of files for the purpose of risk assessment, such access should be granted through a technical interface enabling the connection of national border infrastructures, the central access points, the national systems of the immigration authorities and other EU information systems or national systems, to the ETIAS Central System. The technical specifications developed by eu-LISA should include an interface control document describing the technical interface between the ETIAS Central System and other EU information systems and national systems.
(7) In principle, all searches and results of searches performed by border authorities operating the Entry/Exit System should be conducted via the Entry/Exit System. From the start of operations of the European search portal established pursuant to Article 6 of Regulation (EU) 2019/817 of the European Parliament and of the Council (5), searches by border authorities not performed via the Entry/Exit System, by immigration authorities or by central access points, should take place using the European search portal.
(8) As regards access for the purpose of the manual processing of applications, including for Europol when it provides opinions to ETIAS National Units, as well as access by the ETIAS Central Unit and the ETIAS National Units for the purpose of amending and erasing data, access should be granted through a software designed for that purpose by eu-LISA. That software should also be used by Europol to request access to data in the ETIAS Central System for law enforcement purposes. The means by which the ETIAS Central Unit and the ETIAS National Units and Europol are to authenticate and access that software should be specified.
(9) Duly authorised users from the ETIAS Central Unit, the ETIAS National Units and Europol should log-into the software using user job profiles. The ETIAS Central Unit, the ETIAS National Units and Europol should be able to assign standard permissions, roles and job profiles to users. They should also be able to customise job profiles using pre-established roles and permissions within the software to reflect the way the European Border and Coast Guard Agency and Member States will set up and operate the ETIAS Central Unit and ETIAS National Units respectively, and Europol to reflect the working methods of Europol.
(10) Incompatibilities between pre-established roles and permissions should be pre-determined in the software to prevent users from creating job profiles combining incompatible roles and permissions. To separate duties and avoid users having conflicting responsibilities, permissions associated with the processing of applications should not be combined with permissions associated with amending and deleting data, nor with permissions associated with appeal procedures.
(11) In line with the principles of data protection by design and default, users of the software should be allowed to view only those data which correspond to the permissions assigned to their job profiles. This may result in different user displays depending on the job profile being used.
(12) The software should be developed with general software functionalities supporting the ETIAS Central Unit and the ETIAS National Units in their tasks related to access, amendment and erasure of data.
(13) The software should also provide for a number of specific functionalities to support users in their tasks related to accessing and amending of data, and when manually processing applications which triggered a hit during the automated processing of applications.
(14) One such specific functionality should be the clear displaying to users of the remaining time to comply with their allocated deadlines for the various stages of the examination of the application set out in Regulation (EU) 2018/1240.
(15) Other specific functionalities should support ETIAS National Units during the manual processing of applications when assessing risks. The software should enable extraction of limited data stored in the ETIAS Central System to facilitate consultation by ETIAS National Units of other EU information systems or databases (the Schengen Information system (SIS), the Visa Information System (VIS), the Entry/Exit System or Eurodac) or information in underlying national systems related to the hits triggered during the automated processing of applications. The ETIAS Information System should be developed in such a way as to allow files to be automatically created and available for extraction by ETIAS National Units when manually assessing applications in accordance with Article 26 or Article 28 of Regulation (EU) 2018/1240. It is necessary to identify those functionalities and data elements that should be automatically prepared as part of the files depending on the hit triggered during the automated processing of applications. It is furthermore necessary for the software to have specific functionalities allowing extraction of data in the context of national appeal procedures and allowing uploading of results of the risk assessments as well as recording of data related to national appeal procedures. The specific functionalities of the software for the uploading of results of risk assessments should not allow for the uploading of the reasoning of the decision to issue or refuse a travel authorisation.
(16) eu-LISA should assign credentials to Member States enabling them to arrange one or more roles or user job profiles to the duly authorised staff of central access points, and border and immigration authorities.
(17) In view of their obligations under Regulation (EU) 2018/1725 of the European Parliament and of the Council (6), as well as those laid down in Article 57 of Regulation (EU) 2018/1240, the European Border and Coast Guard Agency, acting as data controller in accordance with Article 3, point (8), of Regulation (EU) 2018/1725, and eu-LISA, acting as controller in relation to information security management of the ETIAS Central System, should carry out an impact assessment of the envisaged processing operations on the protection of personal data pursuant to Article 39 of Regulation (EU) 2018/1725.
(18) Commission Implementing Decision (EU) 2021/1028 (7) established measures for the application of Regulation (EU) 2018/1240 as regards accessing, amending, erasing and advance erasing of data in the ETIAS Central System. The new measures as regards accessing, amending, erasing and advance erasing of data in the ETIAS Central System should be added to those existing in that Decision. Since the new measures to be taken are of substantial number and nature, Implementing Decision (EU) 2021/1028 should, in the interest of clarity, be repealed and replaced by this Decision.
(19) Given that Regulation (EU) 2018/1240 builds upon the Schengen acquis, Denmark notified on 21 December 2018, in accordance with Article 4 of Protocol No 22 on the Position of Denmark, annexed to the Treaty on European Union and to the Treaty on the Functioning of the European Union, its decision to implement Regulation (EU) 2018/1240 in its national law. It is therefore bound by this Decision.
(20) This Decision constitutes a development of the provisions of the Schengen acquis in which Ireland does not take part in accordance with Protocol No 19 on the Schengen acquis integrated into the framework of the European Union, annexed to the Treaty on European Union and the Treaty on the Functioning of the European Union, and, subject to the application of Article 4 of that Protocol, Ireland is not bound by it or subject to its application.
(21) As regards Iceland and Norway, this Decision constitutes a development of the provisions of the Schengen acquis within the meaning of the Agreement concluded by the Council of the European Union and the Republic of Iceland and the Kingdom of Norway concerning association of those two States with the implementation, application and development of the Schengen acquis (8), which fall within the area referred to in Article 1, point A of Council Decision 1999/437/EC (9).
(22) As regards Switzerland, this Decision constitutes a development of the provisions of the Schengen acquis within the meaning of the Agreement between the European Union, the European Community and the Swiss Confederation on the Swiss Confederation’s association with the implementation, application and development of the Schengen acquis (10), which fall within the area referred to in Article 1, point A of Council Decision 1999/437/EC, read in conjunction with Article 3 of Council Decision 2008/146/EC (11).
(23) As regards Liechtenstein, this Decision constitutes a development of the provisions of the Schengen acquis within the meaning of the Protocol between the European Union, the European Community, the Swiss Confederation and the Principality of Liechtenstein on the accession of the Principality of Liechtenstein to the Agreement between the European Union, the European Community and the Swiss Confederation on the Swiss Confederation’s association with the implementation, application and development of the Schengen acquis (12) which fall within the area referred to in Article 1, point A of Council Decision 1999/437/EC read in conjunction with Article 3 of Council Decision 2011/350/EU (13).
(24) As regards Cyprus, this Decision constitutes an act building upon, or otherwise relating to, the Schengen acquis within the meaning of Article 3(1) of the 2003 Act of Accession.
(25) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 and delivered an opinion on 17 March 2026.
(26) The measures provided for in this Decision are in accordance with the opinion of the Smart Borders Committee (ETIAS),