| Dokumendiregister | Justiits- ja Digiministeerium |
| Viit | 7-1/7292 |
| Registreeritud | 07.10.2026 |
| Sünkroonitud | 08.10.2026 |
| Liik | Sissetulev kiri |
| Funktsioon | 7 EL otsustusprotsessis osalemine ja rahvusvaheline koostöö |
| Sari | 7-1 EL institutsioonide otsustusprotsessidega seotud dokumendid (eelnõud, töögruppide materjalid, õigustiku ülevõtmise tähtajad) (Arhiiviväärtuslik) |
| Toimik | 7-1/2026 |
| Juurdepääsupiirang | Avalik |
| Adressaat | Riigikantselei |
| Saabumis/saatmisviis | Riigikantselei |
| Vastutaja | Reet Kase (Justiits- ja Digiministeerium, Kantsleri vastutusvaldkond, Üldosakond, Kommunikatsiooni ja väliskoostöö talitus) |
| Originaal | Ava uues aknas |
| Taotle dokumendi eemaldamist või parandamist |
EN EN
EUROPEAN COMMISSION
Brussels, 10.9.2026 COM(2026) 484 final
2026/0279 (NLE)
Proposal for a
COUNCIL DECISION
on the signing and provisional application of a Framework Agreement between the
European Union and the United States of America on the reciprocal exchange of
information for identity verification, and screening and vetting, relating to border
procedures and applications for travel authorisations and visas
EN 1 EN
EXPLANATORY MEMORANDUM
(1) CONTEXT OF THE PROPOSAL
• Reasons for and objectives of the proposal
In 2022, the United States of America (US) introduced a new requirement for all countries
that have been admitted to or aspire to join the US Visa Waiver Program (VWP). This
program enables citizens of participating countries to travel to the US visa-free for a
maximum of 90 days for the purposes of tourism or business. The new requirement entails the
conclusion of an “Enhanced Border Security Partnership” (EBSP) with the US Department of
Homeland Security (DHS) as a condition for admission to, and further participation in, the
VWP, as a component of the already existing traveller information exchange requirement.
The VWP partnerships are at the forefront of the US international cooperation on border and
immigration security. One of their objectives is to establish robust bilateral exchanges of
information to enable authorities to authenticate effectively the identity of travellers from
partner countries and determine whether they represent a threat to US security.
As part of its VWP partnerships, the US concluded bilateral agreements with EU Member
States, such as the Agreements on Enhancing Cooperation in Preventing and Combating
Serious Crime (PCSC Agreements). These agreements established information exchange,
including biometric data, on individuals who are suspected or convicted of terrorist offences
or serious crime.
Under the EBSP, exchanges concern information, including biometric data, stored in national
databases of Member States on individuals travelling or intending to travel to the US. The
EBSP agreements are expected to be concluded by 31 December 2026. After this deadline,
the DHS will assess each country’s compliance with the EBSP requirement during
evaluations for initial and continued participation in the VWP.
The Commission Recommendation for the Council Decision authorising the opening of
negotiations on a Framework Agreement between the European Union and the US was
adopted on 23 July 20251. The Council adopted the decision to authorise the opening of
negotiations on 16 December 2026.
On 16 December 2025, the Council adopted the Decision authorising the opening of
negotiations for a framework agreement between the European Union and the United States of
America on the reciprocal exchange of information for security screenings and identity
verifications relating to border procedures and visa applications2. The Commission was
appointed as the Union negotiator. The Council Decision also included an addendum with the
directives for the negotiation of such agreement (‘negotiation directives’).
The Commission conducted the negotiations in close consultation with the Council’s Working
Party on JHA Information Exchange and kept the European Parliament informed of the
1 European Commission, Recommendation for a Council Decision authorising the opening of
negotiations on a Framework Agreement between the European Union and the United States of
America on the exchange of information for security screenings and identity verifications relating to
border procedures and applications for visa, COM(2025)447, 23.7.2025. 2 Council Decision (EU) 2025/2640 of 16 December 2025 authorising the opening of negotiations for a
framework agreement between the European Union and the United States of America on the reciprocal
exchange of information for security screenings and identity verifications relating to border procedures
and visa applications, OJ L, 19.12.2025.
EN 2 EN
evolution of the negotiations (LIBE Committee). The negotiations were completed on 23 July
2026.
The Framework Agreement sets the conditions for the reciprocal exchange of information
between the competent authorities of the EU Member States and of the US for identity
verification, screening and vetting of individuals in the context of border checks and
applications for travel authorisations and visas necessary to determine whether the traveller’s
entry or stay would pose a serious and genuine risk to public security or public order. The
bilateral agreements between Member States and the US will set out the specifics of the
information exchange with the US from their national information systems, considering
national legal requirements, the set-up of national databases, and other technical requirements
or limitations.
One of the key objectives of the Framework Agreement is to ensure reciprocity in the
exchange of information with the US, which would help to enhance border protection and
security of the Union as a whole. The Framework Agreement establishes rules for a reciprocal
exchange of information. It provides for the exchange of information on third country
nationals and EU and US citizens. Sharing information on EU citizens is possible under strict
reciprocity whereby if the US categorically exempts their nationals, the Member States are
entitled to decide on exempting all EU citizens. In line with the principles of necessity and
proportionality, the Framework Agreement envisages an automated exchange of information
necessary only for the identification of a person. Additional information can be provided upon
request, with human oversight, and with the possibility to refuse providing such information.
The Framework Agreement applies to those Member States which enjoy a visa free status
with the US or who wish to join the VWP. The Member States are allowed to halt information
exchange as provided for in the Framework Agreement in case their status in the VWP
changes. As regards bilateral agreements already concluded by Member States with the US
prior to the entry into force of this Framework Agreement, the Framework Agreement
includes the conditions under which such agreements remain applicable.
The entry into provisional application of the Framework Agreement is a matter of urgency
due to the review of the VWP and the deadline set by the US to implement the EBSP
requirement by end of 2026. In light of these circumstances, the Commission proposed to
apply the Framework Agreement on a provisional basis as soon as possible and until the
completion of the Parties’ respective internal procedures for the entry into force of the
Framework Agreement.
• Consistency with existing policy provisions in the policy area
The Framework Agreement was negotiated taking into account the negotiating directives
adopted by the Council3. The present Framework Agreement is also consistent with existing
Union policies in the area of the common visa policy and its objective for visa reciprocity, as
well as with EU’s data protection framework.
This Framework Agreement contributes to fulfilling the objectives of the Union’s common
visa policy. The Union has developed a common visa policy for short stays (up to 90 days in
any 180-day period) based on Regulation 2018/18064. The Visa Regulation lists the third
3 Supra, footnote 2. 4 Regulation (EU) 2018/1806 of the European Parliament and of the Council of 14 November 2018
listing the third countries whose nationals must be in possession of visas when crossing the external
EN 3 EN
countries whose nationals must be in possession of visa when crossing the external borders
and those whose nationals are exempt from that requirement. Currently, US nationals enjoy
visa-free status in the Schengen area. In parallel, the Union has concluded visa waiver and
visa facilitation agreements with several third countries5.
The principle of reciprocity is one of the foundations of the Union’s visa policy with third
countries. Reciprocity means that where the Union has granted to citizens of a third country
visa-free access to visit the Schengen area, it expects the third country to reciprocate by
allowing Union citizens to travel to that third country without the need for a visa as well. The
Union aims to achieve full visa reciprocity with third countries whose nationals are exempted
from the visa requirement to enter the Schengen area. Full reciprocity has indeed been
achieved with all visa-free third countries, except the US With the exception of Bulgaria,
Cyprus and Romania, all Member States participate in the US VWP. Achieving full
reciprocity with the US remains a political objective actively pursued by the Union.
This Framework Agreement thus ensures a consistent approach for all Member States
participating in the VWP in relation to the EBSP requirement.
• Consistency with other Union policies
The Framework Agreement is consistent with the requirements under EU data protection laws
to provide safeguards for the transfers of personal information to third countries.
In the EU, the processing of personal data by Member States is governed by Regulation (EU)
2016/6796 (the ‘GDPR’), except for the processing of data by criminal law enforcement
authorities for the purposes of prevention, investigation, detection or prosecution of criminal
offences or the execution of criminal penalties which is covered by Directive (EU) 2016/6807.
For data transfers between criminal law enforcement authorities for the prevention,
investigation, detection or prosecution of criminal offenses, including terrorism, the EU-US
‘Umbrella Agreement’provides for an international agreement ensuring appropriate
safeguards8.
Given the different scope and purpose of the information exchange intended by the EBSP, the
EU-US ‘Umbrella Agreement’ is not applicable to the transfers envisaged by the US under
the EBSP, therefore throughout the Framework Agreement, data protection safeguards have
been added.
borders and those whose nationals are exempt from that requirement (codification), OJ L 303,
28.11.2018, p. 39. 5 The full list of countries is available here: https://home-affairs.ec.europa.eu/policies/schengen/visa-
policy_en. 6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the
protection of natural persons with regard to the processing of personal data and on the free movement of
such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA
relevance), OJ L 119, 4.5.2016, p. 1. 7 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the
protection of natural persons with regard to the processing of personal data by competent authorities for
the purposes of the prevention, investigation, detection or prosecution of criminal offences or the
execution of criminal penalties, and on the free movement of such data, and repealing Council
Framework Decision 2008/977/JHA, OJ L 119, 4.5.2016, p. 89. 8 Agreement between the United States of America and the European Union on the protection of personal
information relating to the prevention, investigation, detection, and prosecution of criminal offences, OJ
L 336, 10.12.2016.
EN 4 EN
Part III of the Framework Agreement provides for the necessary safeguards, in line with the
GDPR and Article 8 of the Charter of the Fundamental Rights, including provisions ensuring
a number of data protection principles and obligations that must be respected by both Parties.
These provisions ensure enforceable individual rights, independent supervision and effective
administrative and judicial redress for violations of the rights and safeguards recognised in the
Framework Agreement resulting from the processing of personal data under this Framework
Agreement. The Commission ensured that the Framework Agreement sets out rules for the
exchange of personal data while providing for adequate safeguards with respect to the
protection of privacy and fundamental rights and freedoms of individuals.
(2) LEGAL BASIS, SUBSIDIARITY AND PROPORTIONALITY
• Substantive legal basis
Given that the main objectives and component of this Framework Agreement between the
European Union and the United States of America on the reciprocal exchange of information
for identity verification, and screening and vetting, relating to border procedures and
applications for travel authorizations and visas are to provide the conditions and safeguards
for the transfer of personal information in the context of border procedures and applications
for travel authorisations and visas, the substantive legal bases are Articles 16(2) and 77(2)
TFEU.
Given the subject matter of the envisaged Framework Agreement, it is appropriate for the
Commission to submit the proposal to the Council.
• Procedural legal basis
Article 218(5) TFEU provides that, where the agreement envisaged does not relate
exclusively or principally to the common foreign and security policy, the Commission shall
submit a proposal to the Council. The Council shall adopt a decision authorising the signing
of the agreement, and, if necessary, provisional application before entry into force.
The Commission proposes to authorise the signing of the Framework Agreement between the
European Union and the United States of America on the reciprocal exchange of information
for identity verification, and screening and vetting, relating to border procedures and
applications for travel authorizations and visas, subject to its conclusion at a later date, as well
as its provisional application.
The procedural legal basis for the proposed decision to authorise the signing of the envisaged
agreement is Article 218(5) TFEU.
• Union competence and proportionality
The Union has competence covering all the provisions of this Framework Agreement. In
particular, transfers of personal information by Member States subject to appropriate
safeguards provided by a legally binding and enforceable instrument are foreseen by Article
46(2)(a) of the GDPR. In addition, the Union can conclude international agreements
concerning checks to which persons crossing external borders are subject as well as common
policy on visas (Article 77(2) TFEU). The Union has, thus, competence to conclude this
Framework Agreement with the US on the exchange of information in relation to the crossing
of the external borders between the EU and the US, including on border procedures and
applications for visas and travel authorisations.
EN 5 EN
A Framework Agreement concluded between the EU and the US is required to ensure the
common visa policy objective for visa reciprocity and the safeguards of the EU’s data
protection framework. In addition, this Framework Agreement is required to set an adequate
level of information exchange between the EU and the US, which should not exceed the level
of information sharing among the Member States in a bilateral or EU context, subject also to
the principles of proportionality and necessity.
• Choice of the instrument
This proposal for a Council decision is submitted in accordance with Article 218(5) TFEU,
which envisages the adoption by the Council of a decision authorising the signing and the
provisional application of the Framework Agreement. There exists no other legal instrument
that could be used to achieve the objective expressed in this proposal.
• Fundamental rights
The exchange of information under this Framework Agreement and its processing by the
authorities of a third country constitutes an interference with the fundamental rights to privacy
and data protection. However, such interference is justified, also because the Framework
Agreement pursues legitimate objectives i.e. enhancing border security. The Framework
Agreement includes appropriate data protection safeguards to the personal data transferred
and processed, in line with EU law, notably Articles 7, 8, 47 and 52 of the Charter of
Fundamental Rights of the EU.
(3) OTHER ELEMENTS
• Detailed explanation of the specific provisions of the proposal
The Framework Agreement sets forth the framework for the exchange of information as well
as appropriate safeguards for the protection of personal information when transferred between
the US and the Member States in the context of EBSP cooperation relating to border
procedures and applications for travel authorisations and visas.
The Framework Agreement consists of five Parts, as follows:
Part 1 on Common Provisions contains the provisions setting out the objective and scope of
the Framework Agreement, and the key definitions used in the agreement. This Framework
Agreement covers information exchange on individuals crossing the external borders of the
US and the Member States or applying for travel authorisation or a visa to enter or stay in the
territory of the Member States or of the US. The exchange of information is guided by the
principle of reciprocity, which includes, in particular, the similarity regarding maximum
volume limits of information exchanged taking into account capacity and technical limitations
of the competent authorities. This Part further addresses the relationship between this
Framework Agreement and existing EBSPs between the US and some Member States that
address matters within the scope of the Framework Agreement. This Framework Agreement
will supplement, as appropriate, relevant provisions regarding the protection of personal
information in existing EBSPs. The US will adapt existing EBSPs to ensure compliance with
this Framework Agreement. The other cooperation channels and information exchanges dealt
with in other agreements between the US and the EU and the US and the Member States
remain unaffected by this Framework Agreement (e.g. EU-US mutual legal assistance treaty,
bilateral mutual legal assistance treaties, bilateral PCSC agreements). It clarifies that this
Framework Agreement in and of itself shall not be the legal basis for any transfers of personal
information.
Part 2 on Principles and Conditions for the Information Exchange contains provisions
setting the necessary conditions for the exchange of information. It stipulates that the
EN 6 EN
information exchange under this Framework Agreement may only take place to the extent
authorised and further specified in bilateral agreements between the Member States and the
US. Such bilateral agreements must comply with the conditions and safeguards set in the
Framework Agreement. Member States could suspend bilateral agreements particularly in
cases of suspension of visa-free travel. This Part further sets the rules for an automated
exchange of limited personal data needed for the identification of the individual during the
assessment of an application for a travel authorisation or visa or during a border check.
Where, during such assessment, there is reason to believe that the entry or stay could pose a
serious and genuine risk to public security or public order, a query can be submitted in
relation to such individual. In cases where there is information of potential interest for EBSP
cooperation (i.e. showing that the entry or stay of an individual would pose a serious and
genuine risk to public security or public order), such confirmation of risk would be
communicated without delay, to the requesting authority following an assessment of all
relevant factors, in accordance with national law and consistent with the technical capabilities
of the requested authority. Additional information on the same individual may be provided
after a human assessment of compliance with the conditions set in the Framework Agreement
and the bilateral agreements. The exchange of information is to take place between single
points of contact. This Part also provides for grounds for refusal to exchange information that
can be used at any stage of the information exchange.
Part 3 on Protection of Personal Information sets out the purpose limitation (i.e.
verification of identity, and screening and vetting, of individuals needed to determine whether
their entry or stay would pose a serious and genuine risk to public security or public order) for
the processing of personal information covered by this Framework Agreement. Further
processing of personal information may only take place for purposes that are not incompatible
with the original purpose. It distinguishes between onward sharing (within the same country,
subject to the data protection safeguards of the Framework Agreement) and onward transfers
(to third countries or international organisations, only with prior consent of the requested
competent authority, after an assessment of the level of data protection that would be
ensured). Both onward sharing and transfers are limited to public authorities. Personal data
will only be retained for as long as this is necessary and appropriate, taking into account
specific factors listed in the Framework Agreement and subject to at least an annual review of
the retention period. This Part provides safeguards for the processing of special categories of
data, and includes transparency and information obligations, on individuals’ rights to access
and correct their own data. Parties are required to have in place effective administrative and
judicial remedies to provide redress for individuals, as well as independent oversight
mechanisms.
Part 4 on Institutional Framework includes a single provision establishing a Joint
Committee: a joint body of the Parties to the Framework Agreement entrusted with the
monitoring of the effective implementation of the Framework Agreement, including by
carrying out periodic joint reviews of the implementation of this Framework Agreement.
Part 5 on Final Provisions covers a number of final clauses regarding consultations in case
of disputes regarding the way the Framework Agreement is interpreted or applied; the
possibility to suspend the Framework Agreement in case of material breach of the agreement
by the other party; the territorial application of the Framework Agreement considering the
specific situation of Ireland and Denmark; the duration and amendment of the agreement;
possibility of each party to terminate the agreement, while it is specified that personal
information transferred prior to the termination will continue to be processed in accordance
with the rules of this Framework Agreement; the entry into force of the agreement and
language clause.
EN 7 EN
• Signing and the text of the Framework Agreement
The text of the Framework Agreement is submitted to the Council together with this proposal.
In accordance with the Treaties, it is for the Commission to ensure the signing of the
Framework Agreement, subject to its conclusion at a later date.
In accordance with the Treaties, it is also for the Commission to notify the United States of
America of the Union’s intention to apply on a provisional basis the Framework Agreement
as from the day of its signing, pending its entry into force. Provisional application is proposed
due to the review of the VWP and the deadline set by the US to implement the EBSP
requirement by end of 2026. Following the start of the provisional application Member States,
will be able to start negotiating and concluding bilateral agreements on the EBSP.
EN 8 EN
2026/0279 (NLE)
Proposal for a
COUNCIL DECISION
on the signing and provisional application of a Framework Agreement between the
European Union and the United States of America on the reciprocal exchange of
information for identity verification, and screening and vetting, relating to border
procedures and applications for travel authorisations and visas
THE COUNCIL OF THE EUROPEAN UNION,
Having regard to the Treaty on the Functioning of the European Union, and in particular
Articles 77(2) and 16(2), in conjunction with Article 218(5) and Article 218(7) thereof,
Having regard to the proposal from the European Commission,
Whereas:
(1) The United States of America have introduced a new requirement for admission to and
further participation in the US Visa Waiver Program, which enables citizens of
participating countries to travel to the United States visa-free for maximum 90 days
for the purpose of tourism or business. The new requirement entails the conclusion of
an ‘Enhanced Border Security Partnership’ (EBSP) with the US Department of
Homeland Security.
(2) On 16 December 2025, the Council authorised the Commission to open negotiations
with the United States of America for a Framework Agreement between the European
Union and the United States of America on the reciprocal exchange of information for
security screenings and identity verifications relating to border procedures and visa
applications.
(3) The Commission has negotiated the Framework Agreement between the European
Union and the United States of America on the reciprocal exchange of information for
identity verification, and screening and vetting, relating to border procedures and
applications for travel authorizations and visas (the ‘Framework Agreement’).
(4) This Framework Agreement sets a common framework for information exchange in
the context of the EBSP between the Union and the United States of America.
(5) The Framework Agreement allows for the conclusion of bilateral agreements between
the United States of America and the Member States on matters covered by the
Framework Agreement. The provisions of such bilateral agreements are to be
compatible with those of the Framework Agreement and with Union law.
(6) In addition, in the event that this Framework Agreement is terminated or suspended
bilateral agreements between the Member States and the United States of America on
matters covered by the Framework Agreement should, in full respect of the principle
of sincere cooperation, be terminated or suspended, as the case may be. The Member
States should inform the Commission of the termination or suspension of these
bilateral agreements.
EN 9 EN
(7) Given the review of the US Visa Waiver Program and the deadline set by the US to
implement the EBSP requirement by end of 2026, the Framework Agreement should
be applied on a provisional basis, in accordance with Article 32 thereof, as of its
signature, pending the completion of the procedures necessary for its entry into force.
(8) In accordance with Articles 1 and 2 of Protocol No 22 on the Position of Denmark
annexed to the Treaty on European Union and to the TFEU, Denmark is not taking
part in the adoption of this Recommendation and is not bound by it or subject to its
application. Given that this Decision builds upon the Schengen acquis, the Kingdom
of Denmark is to, in accordance with Article 4 of that Protocol, decide within a period
of six months after the Council has adopted this Decision whether it will implement it
in its national law.
(9) This Decision constitutes a development of the provisions of the Schengen acquis in
which Ireland does not take part, in accordance with Council Decision 2002/192/EC1;
Ireland is therefore not taking part in its adoption and is not bound by it or subject to
its application.
(10) A common understanding was reached during the negotiationson the situation of
Denmark and Ireland in relation to the Schengen acquis, as well as of the close
relationship between the European Union and Norway, Iceland, Switzerland and
Liechtenstein, particularly by virtue of the Agreements of 18 May 1999 and 26
October 2004 concerning the association of those countries with the implementation,
application and development of the Schengen acquis.
(11) The European Data Protection Supervisor was consulted in accordance with Article 42
of Regulation (EU) 2018/1725 of the European Parliament and of the Council2 and an
Opinion [XX] was issued on [XX].
(12) Therefore, the Framework Agreement should be signed.
(13) The Framework Agreement should be applied on a provisional basis, pending its entry
into force.
HAS ADOPTED THIS DECISION:
Article 1
The signing of the Framework Agreement between the European Union and the United States
of America on the reciprocal exchange of information for identity verification, and screening
and vetting, relating to border procedures and applications for travel authorizations and visas
is hereby authorised, subject to the conclusion of the said Framework Agreement3.
Article 2
(1) Any decision of the Union to take measures related to the provision of guidance in
accordance with Article 27(4)(c) shall be taken by the European Commission in
accordance with the conditions set out in the corresponding provisions of the
Framework Agreement.
(2) The Commission shall inform the Council in a timely manner of its intention to adopt
the proposed measures set out in paragraph 1 and take into account the possible
1 OJ L 64, 7.3.2002. 2 OJ L 295, 21.11.2018. 3 The text of the Agreement is published in OJ L, …., ELI … .
EN 10 EN
views expressed. The Commission shall also inform the European Parliament, as
appropriate.
Article 3
(1) The Agreement shall be applied on a provisional basis, in accordance with Article 32
thereof, pending its entry into force.
(2) The date from which the Agreement is to be applied on a provisional basis shall be
published in the Official Journal of the European Union.
Article 4
This Decision shall enter into force on the day of its adoption.
Done at Brussels,
For the Council
The President
EN EN
EUROPEAN COMMISSION
Brussels, 10.9.2026 COM(2026) 484 final
ANNEX
ANNEX
to the
Proposal for a Council decision
on the signing and provisional application of the Framework Agreement between the
European Union and the United States of America on the reciprocal exchange of
information for identity verification, and screening and vetting, relating to border
procedures and applications for travel authorisations and visas
1
Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity
verification, and screening and vetting, relating to border procedures and applications for travel
authorisations and visas
2
Table of Contents
Part 1 – Common Provisions
Article 1 – Objective of the Framework Agreement
Article 2 – Definitions
Article 3 – Scope of the Framework Agreement
Article 4 – Effect of the Framework Agreement
Part 2 – Principles and Conditions for the Information Exchange
Article 5 – Bilateral Agreements
Article 6 – Purpose of the Exchange of Information
Article 7 – Exchange of Information through an Automated Query
Article 8 – Confirmation of Risk
Article 9 – Procedure for Further Exchange of Additional Information
Article 10 – Single Points of Contact
Article 11 – Non-Derogation
Part 3 – Protection of Personal Information
Article 12 – Purpose and Use Limitation
Article 13 – Onward Sharing
Article 14 – Onward Transfers
Article 15 – Quality and Integrity of Information
Article 16 – Information Security
Article 17 – Notification of an Information Security Incident
Article 18 – Record Keeping
Article 19 – Retention Period
Article 20 – Special Categories of Personal Information
Article 21 – Automated Decisions
Article 22 – Access
Article 23 – Rectification
Article 24 – Administrative and Judicial Redress
Article 25 – Transparency
Article 26 – Effective Oversight
Part 4 – Institutional Framework
Article 27 – Joint Committee
Part 5 – Final Provisions
Article 28 – Consultations
Article 29 – Suspension
Article 30 – Territorial Application
Article 31 – Entry into Force, Duration, Amendment, and Termination
Article 32 – Provisional Application
Article 33 – Authentic Text
3
THE EUROPEAN UNION, hereinafter also referred to as the EU,
and
THE UNITED STATES OF AMERICA, hereinafter also referred to as the United States,
together hereinafter referred to as “the Parties”,
SEEKING to encourage and enhance cooperation between the Parties in the spirit of
transatlantic partnership;
INTENDING to establish a legal framework to facilitate the reciprocal exchange of
information for the purposes of verification of identity, and screening and vetting, of
individuals, with a view to preventing individuals who represent a serious and genuine risk to
public security or public order, including on terrorism or criminal grounds, the ability to
enter or stay in their territories;
HAVING REGARD for United Nations Security Council resolutions 1373 (2001), 1624
(2005), 2178 (2014), 2322 (2016), and, in particular, 2396 (2017) which requires Member
States of the United Nations to develop and implement systems to collect biometric data in
order to responsibly and properly identify terrorists, in compliance with domestic law and
international human rights law, and which encourages Member States of the United Nations
to share such information responsibly with each other, as appropriate;
MINDFUL that the United States and the European Union are committed to ensuring a high
level of protection of personal information exchanged for the purposes of this Framework
Agreement;
NOTING that the United States has in place Enhanced Border Security Partnerships with
certain Member States of the EU, and UNDERSTANDING that the United States and those
Member States intend to ensure compliance of those Partnerships with this Framework
Agreement;
RESOLVED to strengthen, in the context of the bilateral Agreements on Enhancing Border
Security through the Exchange of Information between the Member States of the EU and the
United States, the exchange of identity information to prevent individuals seeking to cross
their respective borders and stay in their territory from posing a risk to public security or
public order;
MINDFUL that both Parties are committed to ensuring mutually beneficial exchanges of
information needed to ensure the integrity and security of visa-free transatlantic travel
through the Enhanced Border Security Partnership, but noting exchanges authorised in the
bilateral Agreements on Enhancing Border Security through the Exchange of Information
may be temporarily suspended in certain circumstances, including in the event of suspension
of the visa-free travel;
4
RECOGNIZING that this Framework Agreement establishes common principles and
safeguards for the reciprocal exchange of information under this Framework Agreement and
does not preclude Member States of the EU and the United States from including additional
types of information sharing cooperation in the bilateral Agreements on Enhancing Border
Security through the Exchange of Information.
RECALLING the European Union’s objective to explore ways to enhance information
exchange for law enforcement and border management purposes with strategic partners and
recognizing the Parties’ shared objective for future expansion of cooperation in this area;
RECOGNIZING the principles of proportionality and necessity, and relevance and
reasonableness, as implemented by the Parties in their respective legal frameworks, and
CONSIDERING the level of information exchange between Member States of the EU;
EMPHASIZING that each Party should have in place a legal framework that provides
individuals with effective judicial and non-judicial redress to identify and remedy instances
where an individual’s personal information has been processed and used in a manner
inconsistent with Part 3 of this Framework Agreement, and ACKNOWLEDGING that it is for
each Party to determine the type of remedies available, and that it is not required that each
type of remedy be available in every instance;
REAFFIRMING the Parties’ longstanding commitment to upholding the shared values and
principles of democracy, the rule of law, and respect for human rights and fundamental
freedoms, which underpin their domestic and international policies, and further reaffirming
respect for the Universal Declaration of Human Rights and international human rights
treaties to which the United States and Member States of the EU are parties, including the
International Covenant on Civil and Political Rights, done at New York on December 16,
1966, and the Convention against Torture and Other Cruel, Inhuman or Degrading
Treatment or Punishment, done at New York on December 10, 1984;
TAKING INTO ACCOUNT the Protocol on the Position of Denmark annexed to the Treaty on
European Union and the Treaty on the Functioning of the European Union, and
CONFIRMING that this Framework Agreement is not binding upon or applicable in relation
to the Kingdom of Denmark;
TAKING INTO ACCOUNT the Protocol on the Schengen acquis integrated into the
framework of the European Union, annexed to the Treaty on European Union and the Treaty
on the Functioning of the European Union, and CONFIRMING that the provisions of this
Framework Agreement are not applicable in relation to Ireland;
HAVE AGREED AS FOLLOWS:
5
PART 1: COMMON PROVISIONS
Article 1
Objective of the Framework Agreement
1. The objective of this Framework Agreement is to enhance cooperation between the
United States and the Member States of the EU in relation to the exchange of
information on individuals crossing their respective external borders or applying for a
travel authorisation or a visa to enter or stay in the territory of one of the Member
States of the EU or of the United States, while ensuring a high level of protection of
personal information.
2. In the pursuit of this objective, this Framework Agreement sets forth the framework
for the exchange of information as well as the appropriate safeguards for the
protection of personal information when transferred between the United States and the
Member States of the EU.
3. This Framework Agreement in and of itself shall not be the legal basis for any
transfers of personal information.
4. The exchange of information set out in this Framework Agreement shall be guided by
the principle of reciprocity, which includes, in particular, similarity regarding
maximum volume limits, type, and quality of information exchanged.
5. The exchange of information under Article 7 shall be based on a maximum volume of
individuals to be screened, taking into account the capacity and technical limitations
of the Competent Authorities, real volumes of travel, current risks, and reciprocity, to
the extent determined in the bilateral Agreements on Enhancing Border Security
through the Exchange of Information.
Article 2
Definitions
For the purposes of this Framework Agreement:
1. “Member State” means a Member State of the European Union;
2. “Union citizen” means any person holding the nationality of a Member State;
3. “U.S. national” or “national of the United States” means a citizen or national of the
United States;
4. “Personal information” means information relating to an identified or identifiable
natural person (an individual). An identifiable person is a person who can be
identified, directly or indirectly, by reference to, in particular, an identification number
or to one or more factors specific to his or her physical, physiological, mental,
economic, cultural, or social identity;
6
5. “Processing of personal information” means any operation or set of operations
involving collection, maintenance, use, alteration, organisation or structuring,
disclosure or dissemination, or disposition;
6. “Special categories of personal information” means personal information revealing
racial or ethnic origin, political opinions or religious or other beliefs, trade union
membership, genetic data, biometric data for the purpose of uniquely identifying a
natural person, and personal information concerning health or sexual life. An
individual’s name, date of birth, place of birth, nationality/citizenship, or other basic
biographic identity information shall not be deemed to constitute in themselves
special categories of personal information;
7. “Competent Authority” means a public authority of the United States or of a Member
State responsible for activities covered by this Framework Agreement, consistent with
relevant designations in bilateral Agreements on Enhancing Border Security through
the Exchange of Information between the Member States and the United States;
8. “Requesting Competent Authority” means the Competent Authority that initiates the
query;
9. “Requested Competent Authority” means the Competent Authority that receives the
query from the requesting competent authority;
10. “Travel authorisation” means an authorisation to travel and to seek admission to the
territory of a Member State or of the United States for short or temporary stays for
persons who are not subject to an obligation of being in possession of a visa, as
defined in applicable law; and
11. “Visa”means an authorisation to travel or transit and to seek admission to the territory
of a Member State or of the United States for short or temporary stays, as defined in
applicable law.
Article 3
Scope of the Framework Agreement
1. This Framework Agreement shall apply to personal information of individuals
transferred between the Competent Authorities of the United States and the
Competent Authorities of the Member States for the purposes set forth in Article 6.
2. The Parties intend for the United States and the Member States to exchange
information on U.S. nationals, Union citizens, and third country nationals. Should
either the United States or a Member State be unable to categorically exchange
information on its respective nationals or citizens, the other side is entitled to decide
whether it will reciprocally refrain from exchanging information on all Union citizens
or all U.S. nationals respectively.
3. For the purpose of paragraph 2, where a person is a Union citizen or is a U.S.
national, or both, the transfer of personal information should be treated as a transfer of
information on a citizen of a Member State or a national of the United States,
regardless of whether that person holds one or more additional citizenships.
7
Article 4
Effect on the Framework Agreement
1. This Framework Agreement supplements, as appropriate, provisions regarding the
protection of personal information in existing Enhanced Border Security Partnerships
between the United States and Member States that address matters within the scope of
this Framework Agreement. The United States shall undertake to adapt existing
Enhanced Border Security Partnerships to ensure compliance with this Framework
Agreement by working with the relevant Member States.
2. The Parties shall take all necessary measures to implement this Framework
Agreement, including, in particular, their respective obligations under this Framework
Agreement regarding access, rectification, and administrative and judicial redress for
individuals provided herein. The protections and remedies set forth in this Framework
Agreement shall benefit relevant individuals in the manner implemented in each
Party’s respective legal framework. For the United States, its obligations shall apply
in a manner consistent with its fundamental principles of federalism.
3. By giving effect to paragraph 2, the processing of personal information by the
Competent Authorities, with respect to matters falling within the scope of this
Framework Agreement, shall be deemed to comply with their respective data
protection legislation restricting or conditioning international transfers of personal
information, and no further authorisation under such legislation shall be required.
4. Except as provided in paragraph 1, nothing in this Framework Agreement shall be
construed to limit or prejudice the provisions of any treaty, other agreement or
arrangement, including mutual legal assistance agreements and agreements on
enhancing cooperation in preventing and combatting serious crime, working law
enforcement relationships, or domestic law allowing for information sharing between
the United States and the Member States.
PART 2: PRINCIPLES AND CONDITIONS FOR THE INFORMATION EXCHANGE
Article 5
Bilateral Agreements
The exchange of information under this Framework Agreement may only take place to the
extent authorised and further specified in bilateral Agreements on Enhancing Border Security
through the Exchange of Information between the Member States and the United States
(hereinafter “bilateral agreements”) and only to the extent that those bilateral agreements:
a) include provisions necessary to comply with the conditions for the exchange of
information set out in this Framework Agreement;
b) identify specific national information systems that are relevant for the objective
described in Article 1 and the purposes described in Article 6, from which information
is to be exchanged under this Framework Agreement and in accordance with
applicable domestic laws (hereinafter “national information systems”); and
8
c) include provisions on suspension of the bilateral agreements, for reasons including
suspension of visa-free travel.
Article 6
Purpose of the Exchange of Information
Personal information shall only be exchanged under this Framework Agreement for the
purposes of verification of identity, and screening and vetting, of individuals needed to
determine whether their entry or stay would pose a serious and genuine risk to public security
or public order.
Article 7
Exchange of Information through an Automated Query (first step)
1. During the assessment of an application for a travel authorisation or visa or during
border checks, the Requesting Competent Authority may submit an automated query
in relation to an individual where, during the examination of the individual, there is
reason to believe that the entry or stay could pose a serious and genuine risk to public
security or public order. This may in particular be the case: where there are indications
of identity fraud or misuse of identities; where there are doubts as to the authenticity
and validity of the travel documents; where there are indications that an application
for a visa contains fraudulent or false information; where there are risk assessments
and scenarios identifying risk on the basis of trend analysis of suspicious activity, law
enforcement cases, or criminal intelligence; or where information about the concerned
individual exists in the national information systems of the Requesting Competent
Authority.
2. While carrying out their activities referred to in paragraph 1, the Competent
Authorities shall not arbitrarily and unjustifiably discriminate against individuals, in
particular, on the grounds of sex, racial or ethnic origin, religion or belief, disability,
age or sexual orientation.
3. Subject to the conditions set out in paragraph 1 and 2 above, the Requesting
Competent Authority may submit an automated query in relation to an individual
where there is a nexus between the individual and the State of the Requested
Competent Authority, including where the individual is a citizen/national, is a current
or former resident, or has previously stayed or applied to stay on the territory of the
State of the Requested Competent Authority.
4. An automated query may only be initiated when the Requesting Competent Authority
is also conducting searches against its own national information systems.
5. When submitting an automated query, the Requesting Competent Authority shall
include a unique reference number that identifies the individual and/or the query and
an indicator of the nature of the Requesting Competent Authority’s encounter with the
individual and may use the following personal information:
9
a) the identity information included in the application or in the travel
document, such as the surname (family name), first name or names (given
names), the date of birth, national ID number, and/or
b) the fingerprints of an individual.
6. Fingerprint data may only be used for the submission of the automated query if the
relevant bilateral agreement requires the Requesting Competent Authority to ensure
that the fingerprint data used in the query are of sufficient quality for automated
comparison.
7. In case of a positive correspondence (match) with information held in its national
information systems, the Requested Competent Authority shall transfer to the
Requesting Competent Authority through the automated process:
a) the confirmation of such a match, and
b) alphanumeric data for the identification of an individual, such as first
name, last name, and date of birth.
8. In case of a positive correspondence (match) with information held in its national
information systems, the Requested Competent Authority may transfer to the
Requesting Competent Authority through the automated process, where available and
shareable under domestic law, photographs for the identification of an individual.
9. Under this Article, the Requested Competent Authority may only transfer personal
information that is adequate, relevant, and limited to what is needed for the
identification of the individual.
Article 8
Confirmation of Risk
1. Should the procedure described in Article 7 generate a positive correspondence
(match), the Requested Competent Authority, to the extent authorised and further
specified in the relevant bilateral agreement, shall assess without delay, based on all
relevant factors, whether the positive correspondence is related to a risk set forth in
Article 6. Such factors may include criminal convictions, terrorist threats or
immigration violations, including their nature, seriousness and timing.
2. The Requested Competent Authority shall send without delay a confirmation whether
there is information of potential interest related to a risk set forth in Article 6, which
may be requested under the procedure of Article 9, and its nature, by indicating the
relevant factor or factors referred to in paragraph 1.
3. The sharing of information pursuant to this Article may only take place to the extent
that the relevant bilateral agreement establishes the procedures for sharing and the
expected content of that communication, in accordance with applicable domestic law
and consistent with the technical capabilities of the Requested Competent Authority.
10
Article 9
Procedure for Further Exchange of Additional Information (second step)
1. Should the procedure described in Article 7 show a positive correspondence (match)
and after the procedures described in Article 8 have been completed, the Requesting
Competent Authority may request additional information on the same individual for
the purposes set forth in Article 6 to the extent authorised in the relevant bilateral
agreement.
2. Subject to the safeguards for the protection of personal information set out in Part 3 of
this Framework Agreement, the Requested Competent Authority may transfer the
additional information requested by the Requesting Competent Authority.
3. The exchange of additional information may only take place to the extent that the
relevant bilateral agreement specifies the national information systems from which
information may be exchanged, the categories of information that the Requested
Competent Authority may transfer, and the procedures for such transfer in accordance
with applicable domestic law.
4. With the exception of biometric data for the purpose of uniquely identifying a natural
person, special categories of personal information may only be transferred under this
Article where particularly relevant to achieve the purposes set forth in Article 6.
5. The exchange of additional information may only take place to the extent that the
relevant bilateral agreement establishes conditions for the exchange and only after a
human assessment of compliance with those conditions by the Requested Competent
Authority, and in accordance with applicable domestic law.
6. In the case of a positive correspondence (match) described in Article 7 and after the
procedures described in Article 8 have been completed, the Requested Competent
Authority may request available alphanumeric and contextual data on the same
individual from the Requesting Competent Authority exclusively for ensuring
accuracy and for auditing existing records on the individual concerned. The
Requesting Competent Authority shall respond consistent with any relevant
procedures provided in the bilateral agreements and in accordance with applicable
domestic law.
Article 10
Single Points of Contact
The Competent Authorities shall designate single points of contact for the exchange of
personal information under this Framework Agreement.
Article 11
Non-Derogation
The exchange of information under this Framework Agreement shall be without prejudice to
the invocation by the Requested Competent Authority of grounds to refuse a request available
11
pursuant to a bilateral agreement or arrangement, such as where the response risks
jeopardizing ongoing investigations or would prejudice the State of the Requested Competent
Authority’s sovereignty, security, public order, or if the response would conflict with
applicable domestic law or international obligations.
PART 3: PROTECTION OF PERSONAL INFORMATION
Article 12
Purpose and Use Limitation
1. Personal information received under this Framework Agreement shall be processed
for the purposes set forth in Article 6.
2. The further processing of personal information under this Framework Agreement shall
not be incompatible with the purposes for which it was transferred.
3. Compatible processing includes further processing for purposes of preventing an
immediate and serious threat to public security, further processing to report to public
oversight authorities such as those listed in Article 26, and where further processing is
directly related to the purposes for the exchange of information under this Framework
Agreement. All such further processing shall respect the other provisions of this
Framework Agreement, in particular its Articles 15 and 19. This paragraph is without
prejudice to the application of treaties, agreements, or arrangements mentioned in
Article 4, paragraph 4, such as mutual legal assistance agreements.
4. This Article shall not prejudice the ability of the Requested Competent Authority to
impose additional conditions in a specific case to the extent the applicable legal
framework for transfer permits it to do so. Such conditions shall not include generic
data protection conditions, that is, conditions imposed that are unrelated to the
specific facts of the case. If the information is subject to such conditions, the
Requesting Competent Authority shall comply with them. The Requested Competent
Authority may also require the Requesting Competent Authority to give information
on the use made of the transferred information.
5. The Parties shall ensure under their respective legal frameworks that personal
information is processed in a manner that is directly relevant to and not excessive or
overbroad in relation to the purpose of the processing.
Article 13
Onward Sharing
1. All processing of personal information exchanged under this Framework Agreement
by other national law enforcement, regulatory, or administrative authorities shall
respect the other provisions of Part 3 of this Framework Agreement.
2. The Parties shall have in place measures to promote accountability for processing
personal information within the scope of the Framework Agreement by their
Competent Authorities, and any of their authorities to which personal information has
12
been transferred. Such measures shall include notification of the safeguards applicable
to transfers of personal information under this Framework Agreement, and of the
conditions that may have been imposed by the Requested Competent Authority
pursuant to Article 12, paragraph 4. Serious misconduct shall be addressed through
appropriate and dissuasive criminal, civil, or administrative sanctions. Such measures
shall include, as appropriate, discontinuation of transfer of personal information to
authorities of constituent territorial entities of the Parties not covered by this
Framework Agreement that have not effectively protected personal information,
taking into account the purpose of this Framework Agreement, and in particular, the
purpose and use limitations and onward transfer provisions of this Framework
Agreement.
Article 14
Onward Transfers
1. Personal information received from the Requested Competent Authority pursuant to
this Framework Agreement may be transferred to public authorities in third countries
or to international organisations only where the prior consent of the Requested
Competent Authority has been obtained.
2. When granting its consent to an onward transfer of personal information, the
Requested Competent Authority shall take due account of all relevant factors,
including the purpose for which the personal information was initially transferred and
whether the third country or international organisation with which the information is
to be shared ensures an appropriate level of protection of personal information.
Article 15
Quality and Integrity of Information
The Parties shall take reasonable steps to ensure that personal information is
maintained with such accuracy, relevance, timeliness, and completeness as is
necessary and appropriate for lawful processing of the information. For this purpose,
the Competent Authorities shall have in place procedures, the object of which is to
ensure the quality and integrity of personal information, including the following:
a) the measures referred to in Article 23;
b) where the Requested Competent Authority becomes aware of significant
doubts as to the relevance, timeliness, completeness, or accuracy of such
personal information it has transferred, it shall, where feasible, advise the
Requesting Competent Authority thereof; and
c) where the Requesting Competent Authority becomes aware of significant
doubts as to the relevance, timeliness, completeness, or accuracy of personal
information received, it shall, where feasible, advise the Requested Competent
Authority thereof.
13
Article 16
Information Security
1. The Competent Authorities shall ensure that they have in place appropriate technical,
security and organisational arrangements for the protection of personal information
against all of the following:
a) accidental or unlawful destruction;
b) accidental loss; and
c) unauthorised disclosure, alteration, access, or other processing.
2. Such arrangements shall include appropriate safeguards regarding the authorisation
required to access personal information.
Article 17
Notification of an Information Security Incident
1. Upon discovery of an incident involving accidental loss or destruction, or
unauthorised access, disclosure, alteration, or other processing of personal
information, in which there is a significant risk of damage, the Requesting Competent
Authority shall promptly assess the likelihood and scale of damage to individuals and
promptly take appropriate action to mitigate any such damage.
2. Action to mitigate damage shall include a notification to the Requested Competent
Authority. Such a notification may:
a) include appropriate restrictions as to the further transmission of the
notification;
b) be delayed or omitted when it may endanger national security;
c) be delayed when it may endanger public security operations.
3. Action to mitigate damage shall also include notification to the individual, where
appropriate, given the circumstances of the incident, unless such notification may
endanger:
a) public or national security;
b) official inquiries, investigations or proceedings;
c) the prevention, detection, investigation, or prosecution of criminal offences;
d) rights and freedoms of others, in particular the protection of victims and
witnesses.
4. The Competent Authorities involved in the transfer of the personal information may
consult each other concerning the incident and the response thereto.
14
Article 18
Record Keeping
1. The Competent Authorities shall have in place effective methods of demonstrating the
lawfulness of processing of personal information, which may include the use of logs
containing a clear and specific purpose of each query and the logging of processing
operations related to the exchange, as well as other forms of records.
2. The Competent Authorities may use such logs or records for maintaining orderly
operations of the national information systems or files concerned, to ensure data
integrity and security, conduct auditing activities, and, where necessary, to follow
backup procedures.
Article 19
Retention Period
The Parties shall provide in their applicable legal frameworks specific retention periods for
records containing personal information, the object of which is to ensure that personal
information is not retained for longer than is necessary and appropriate. Such retention
periods shall take into account the purposes of processing, the nature of the data and the
authority processing it, the impact on relevant rights and interests of affected individuals, and
other applicable legal considerations. The Parties shall provide procedures for at least an
annual review of the retention period with a view to determining whether changed
circumstances require further modification of the applicable period.
Article 20
Special Categories of Personal Information
1. Processing of special categories of personal information shall only take place under
appropriate safeguards in accordance with law.
2. The appropriate safeguards referred to in paragraph 1 may include the following
protective measures:
a) restricting the purposes for which the information may be processed, such as
allowing the processing only on a case-by-case basis;
b) masking, deleting, or blocking the information after effecting the purpose for
which it was processed;
c) restricting personnel permitted to access the information;
d) requiring specialised training for personnel who access the information;
e) requiring supervisory approval to access the information.
3. These safeguards shall duly take into account the nature of the personal information,
particular sensitivities of the information, and the purpose for which the information
is processed.
15
Article 21
Automated Decisions
Decisions producing significant adverse actions concerning the relevant interests of
individuals may not be based solely on the automated processing of personal information
without human involvement, unless authorised under the Parties’ respective legal
frameworks, and with appropriate safeguards that include the possibility to obtain human
intervention.
Article 22
Access
1. The Parties shall ensure that any individual is entitled to seek access to his or her
personal information and, subject to the restrictions set forth in paragraph 2, to obtain
it. Such access shall be sought and obtained from a Competent Authority in
accordance with the applicable legal framework of the State in which relief is sought.
2. The obtaining of personal information in a particular case may be subject to
reasonable restrictions provided under domestic law, taking into account legitimate
interests of the individual concerned, so as to:
a) protect the rights and freedoms of others, including their privacy;
b) safeguard public and national security;
c) protect law enforcement sensitive information;
d) avoid obstructing official or legal inquiries, investigations, or proceedings;
e) avoid prejudicing the prevention, detection, investigation, or prosecution of
criminal offences or the execution of criminal penalties; or
f) otherwise protect interests provided for in legislation regarding freedom of
information and public access to documents.
3. Excessive expenses shall not be imposed on the individual as a condition to access his
or her personal information.
4. An individual is entitled to authorise, where permitted under domestic law, an
oversight authority or other representative to request access on his or her behalf.
5. If access is denied or restricted, the Requested Competent Authority will, without
undue delay, provide to the individual, or to his or her duly authorised representative
as set forth in paragraph 4, the reasons for the denial or restriction of access.
Article 23
Rectification
1. The Parties shall ensure that any individual is entitled to seek correction or
rectification of his or her personal information that he or she asserts is either
inaccurate or has been improperly processed. Correction or rectification may include
16
supplementation, erasure, blocking, or other measures or methods for addressing
inaccuracies or improper processing. Such correction or rectification shall be sought
and obtained from a Competent Authority in accordance with the applicable legal
framework of the State in which relief is sought.
2. Where the Requesting Competent Authority concludes following:
a) a request under paragraph 1;
b) notification by the Requested Competent Authority; or
c) its own investigations or inquiries;
that information it has received under this Framework Agreement is inaccurate or has
been improperly processed, it shall take measures of supplementation, erasure,
blocking, or other methods of correction or rectification, as appropriate.
3. An individual is entitled to authorise, where permitted under domestic law, an
oversight authority or other representative to seek correction or rectification on his or
her behalf.
4. If correction or rectification is denied or restricted, the Requested Competent
Authority will, without undue delay, provide to the individual, or to his or to her duly
authorised representative as set forth in paragraph 3, a response setting forth the basis
for the denial or restriction of correction or rectification.
Article 24
Administrative and Judicial Redress
The Parties shall have in place effective administrative and judicial remedies to provide
redress for individuals whose personal information has been processed and used in a manner
inconsistent with Part 3 of this Framework Agreement as set forth under each Party’s
respective legal framework and in accordance with Article 4, paragraph 2.
Article 25
Transparency
1. The Parties shall ensure that notice is provided to an individual, as to his or her personal
information, which notice may be effected by the Competent Authorities through
publication of general notices or through actual notice, in a form and at a time provided
for by the law applicable to the authority providing notice, with regard to the:
a) purposes of processing of such information by that authority;
b) purposes for which the information may be shared with other authorities;
c) laws or rules under which such processing takes place;
d) third parties to whom such information is disclosed; and
e) access, correction or rectification, and redress available.
17
2. Such notice requirement is subject to the reasonable restrictions under domestic law with
respect to the matters set forth in Article 22, paragraph 2 (a) through (f).
Article 26
Effective Oversight
1. The Parties shall have in place one or more public oversight authorities that:
a) exercise independent oversight functions and powers, including review,
investigation and intervention, where appropriate on their own initiative;
b) have the power to accept and act upon complaints made by individuals
relating to the measures implementing Part 3 of this Framework
Agreement; and
c) have the power to refer violations of law related to Part 3 of this
Framework Agreement for prosecution or disciplinary action when
appropriate.
2. The European Union shall provide for oversight under this Article through the data
protection authorities of its Member States.
3. The United States shall provide for oversight under this Article cumulatively through
more than one authority, which may include inspectors general, chief privacy officers,
government accountability offices, privacy and civil liberties oversight boards, and
other applicable executive and legislative privacy or civil liberties review bodies.
PART 4: INSTITUTIONAL FRAMEWORK
Article 27
Joint Committee
1. A Joint Committee consisting of representatives of the Parties shall meet at least once
a year to conduct consultations relating to this Framework Agreement and to review
its implementation.
2. The Joint Committee shall be co-chaired by a representative of the European Union
and a representative of the United States.
3. A Party may also request a meeting to seek to address questions related to the
interpretation or application of this Framework Agreement.
4. The Joint Committee shall:
a) Monitor the effective implementation of this Framework Agreement, including
by carrying out periodic joint reviews of the implementation of this
Framework Agreement no later than three years from the date of the entry into
force of this Framework Agreement, and thereafter on a regular basis, to assess
the effectiveness, and proportionality or reasonableness, of the volume and
reciprocity of the exchange of information in relation to the purposes of the
18
implementation of this Framework Agreement. To this end, the Parties shall
ensure that the Joint Committee receives statistics collected by the Member
States and the United States including the number and nature of queries, the
number and percentage of matches, and the timeliness of responses processed
under this Framework Agreement;
b) Hold consultations consistent with Article 28; and
c) Provide guidance regarding how the Framework Agreement should be
interpreted and implemented, where appropriate, and facilitate specific aspects
of cooperation based on this Framework Agreement.
5. The Joint Committee’s working methods shall be by consensus.
PART 5: FINAL PROVISIONS
Article 28
Consultations
Any dispute regarding the interpretation and implementation of this Framework Agreement
shall be resolved by consultations between the Parties, which may include consultations in
the Joint Committee, and shall not be referred to any national or international tribunal or third
party for settlement.
Article 29
Suspension
1. In the event of a material breach of this Framework Agreement, either Party may
suspend this Framework Agreement in whole or in part by written notification to the
other Party through diplomatic channels. Such written notification shall not be made
until after the Parties have engaged in a reasonable period of consultation without
reaching a resolution; and suspension shall take effect twenty days from the date of
receipt of such notification. Such suspension may be lifted by the suspending Party
upon written notification to the other Party. The suspension shall be lifted
immediately upon receipt of such notification.
2. Notwithstanding any suspension of this Framework Agreement, personal information
falling within the scope of this Framework Agreement and transferred prior to its
suspension shall continue to be protected in accordance with the safeguards of this
Framework Agreement.
3. In the event of suspension of this Framework Agreement, cooperation between the
United States and Member States under the bilateral agreements that is dependent on
this Framework Agreement is expected to be suspended, consistent with those
bilateral agreements. The bilateral agreements are expected to include a suspension
provision specifying that elements of the bilateral agreements that fall under this
Framework Agreement will be suspended should this Framework Agreement be
suspended.
19
Article 30
Territorial Application
1. Subject to paragraph 2, this Framework Agreement shall apply, of the one part, to the
territory in which the Treaty on European Union and the Treaty on the Functioning of
the European Union apply and under the conditions laid down in those Treaties, and,
of the other part, to the territory of United States.
2. This Framework Agreement shall apply to the territory of Ireland only pursuant to a
notification by the European Union to United States to that effect. This Agreement
shall not apply to the territory of the Kingdom of Denmark.
Article 31
Entry into Force, Duration, Amendment, and Termination
1. This Framework Agreement shall enter into force on the first day of the month
following the date on which the Parties have notified each other in writing of the
completion of their respective internal legal procedures for the entry into force of this
Framework Agreement.
2. This Framework Agreement shall be in force for an indefinite period.
3. The Parties may agree, in writing, to amend this Framework Agreement.
4. Either Party may terminate this Framework Agreement by written notification to the
other Party through diplomatic channels. Such termination shall take effect on the first
day of the sixth month following the date of such notification.
5. Notwithstanding any termination of this Framework Agreement, personal information
falling within the scope of this Framework Agreement and transferred prior to its
termination shall continue to be processed in accordance with this Framework
Agreement.
6. In the event of termination of this Framework Agreement, cooperation between the
United States and Member States under the bilateral agreements that is dependent on
this Framework Agreement is expected to cease, consistent with those bilateral
agreements. The bilateral agreements are expected to include a termination provision
specifying that elements of the bilateral agreements that fall under this Framework
Agreement will be terminated should this Framework Agreement be terminated.
Article 32
Provisional Application
The European Union and the United States may apply this Framework Agreement
provisionally, as of the date of signature.
20
Article 33
Authentic Text
The signed English text of this Framework Agreement shall be the authentic text. This
Framework Agreement is drawn up by the European Union also in the Bulgarian, Croatian,
Czech, Danish, Dutch, Estonian, Finnish, French, German, Greek, Hungarian, Italian, Irish,
Latvian, Lithuanian, Maltese, Polish, Portuguese, Romanian, Slovak, Slovenian, Spanish and
Swedish languages.
FOR THE EUROPEAN UNION:
………………………………………
Place: ……………………………….
Date: ………………………………..
FOR THE UNITED STATES OF AMERICA:
………….…………………………………
Place: ………….………………………….
Date: …………….………………………..
Resolutsiooni liik: Riigikantselei resolutsioon Viide: Siseministeerium / / ; Riigikantselei / / 2-5/26-02004
Resolutsiooni teema: ELi ja USA vahelise piiri- ja viisamenetluste alase andmevahetuse raamleping
Adressaat: Siseministeerium Ülesanne: ulenevalt Riigikogu kodu- ja töökorra seaduse § 152` lg 1 p 2 ning Vabariigi Valitsuse reglemendi § 3 lg 4 palun valmistada ette Vabariigi Valitsuse seisukohtade ja otsuste eelnõud järgmiste algatuste kohta, kaasates seejuures olulisi huvigruppe ja osapooli:
- Proposal for a COUNCIL DECISION on the signing and provisional application of a Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorisations and visas, COM(2026)484
- Proposal for a COUNCIL DECISION on the conclusion of Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorizations and visas, COM(026)485
EISi toimiku nr: 26-0413 Tähtaeg: 30.10.2026
Adressaat: Justiits- ja Digiministeerium, Välisministeerium Ülesanne: Palun esitada oma sisend Majandus- ja Kommunikatsiooniministeeriumile seisukohtade kujundamiseks antud eelnõu kohta (eelnõude infosüsteemi (EIS) kaudu). Tähtaeg: 26.10.2026
Lisainfo: Eelnõusid on kavas arutada valitsuse 12.11.2026. aasta istungil ning Vabariigi Valitsuse reglemendi § 6 lg 6 kohaselt sellele eelneval nädalal (04.11.2026) EL koordinatsioonikogus. Esialgsed materjalid EL koordinatsioonikoguks palume esitada hiljemalt 30.10.2026.
Kinnitaja: Nele Grünberg, Euroopa Liidu asjade direktori asetäitja Kinnitamise kuupäev: 07.10.2026 Resolutsiooni koostaja: Sandra Metste [email protected],
.
Eelnõude infosüsteemis (EIS) on antud täitmiseks ülesanne. Eelnõu toimik: 9.1.1/26-0413 - COM(2026) 484 Proposal for a COUNCIL DECISION on the signing and provisional application of a Framework Agreement between the European Union and the United States of America on the reciprocal exchange of information for identity verification, and screening and vetting, relating to border procedures and applications for travel authorisations and visas Arvamuse andmine eelnõu kohta Siseministeeriumile vastavalt Riigikantselei 07.10.2026 resolutsioonile. Osapooled: Justiits- ja Digiministeerium; Välisministeerium Tähtaeg: 26.10.2026 23:59 Link eelnõu toimiku vaatele: https://eelnoud.valitsus.ee/main/mount/docList/257a99ec-a35c-4b31-b490-42806049b8e4 Link menetlusetapile: https://eelnoud.valitsus.ee/main/mount/docList/257a99ec-a35c-4b31-b490-42806049b8e4?activity=2 Eelnõude infosüsteem (EIS) https://eelnoud.valitsus.ee/main