{
  "node_id": "eu-pnr-passenger-name-record-directive-2016-681",
  "title": "Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime",
  "domain": "Data Protection & Privacy",
  "version": "1.0.0",
  "last_updated": "2026-06-23",
  "bluf": "This Directive regulates the transfer by air carriers of passenger name record (PNR) data of extra-EU flights and its processing by Member States for the prevention, detection, investigation and prosecution of terrorist offences and serious crime (Article 1). Each Member State must establish a Passenger Information Unit (Article 4) with a data protection officer (Article 5), process PNR data only for the defined purposes against pre-determined criteria and databases (Article 6), restrict access to designated competent authorities (Article 7), and impose transfer obligations on air carriers (Article 8), with strict retention limits and data-protection safeguards.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-schengen-borders-code-regulation-2016-399",
    "eu-data-governance-act-2022-868"
  ],
  "primary_citations_count": 5
}