FactBox.

EUR-Lex · 08 Sep 2026 · 1 vistas

EU sets new access rules for ETIAS central system data

Por FactBox Admin

EU sets new access rules for ETIAS central system data

The European Commission has adopted Commission Implementing Decision (EU) 2026/1970, published in the L series of the Official Journal of the European Union on 8 September 2026, setting out the technical rules for how authorities access, amend, erase and advance-erase data in the ETIAS Central System. The decision, signed in Brussels on 7 September 2026 by Commission President Ursula von der Leyen, repeals and replaces the previous Commission Implementing Decision (EU) 2021/1028.

The measure implements Regulation (EU) 2018/1240, which establishes the European Travel Information and Authorisation System (ETIAS) for visa-exempt third-country nationals seeking to enter the Schengen area. It follows the adoption of Regulations (EU) 2021/1150, 2021/1151 and 2021/1152, which set conditions for accessing other EU information systems for ETIAS purposes, and completes the technical specifications of the ETIAS Information System.

Who gets access and how

Access to the ETIAS Central System is channelled through a dedicated software designed by eu-LISA, the EU agency for the operational management of large-scale IT systems. The software governs authentication, roles, job profiles and permissions for all authorised users.

  • ETIAS Central Unit and ETIAS National Units access data for manual processing, amending and erasing records.
  • Europol uses the software to request access to data for law enforcement purposes and to provide opinions to national units.
  • Border authorities consult the system at external borders, mainly via the Entry/Exit System.
  • Immigration authorities verify conditions of entry or stay through the European search portal.
  • Central access points search the system for law enforcement purposes.

Users log in with job profiles built from pre-established roles and permissions. The software prevents the combination of incompatible roles, so that permissions for processing applications cannot be combined with those for amending or deleting data, nor with those linked to appeal procedures. Users may use pseudonyms, which remain traceable to their official identities.

Functionalities and data handling

The software must provide a set of general and specific functionalities to support the daily work of the units. These include automatic saving of data, blocking of hits for limited periods, management dashboards, and clear display of the time remaining to meet the deadlines set out in Regulation (EU) 2018/1240.

For manual risk assessment, the software automatically prepares extraction files containing limited data from the application file — such as surname, first names, date and place of birth, nationality and travel document details — to allow national units to consult other EU systems such as the Schengen Information System (SIS), the Visa Information System (VIS), the Entry/Exit System or Eurodac. It also supports national and Union appeal procedures and the recording of their outcomes.

Searches for amending or erasing data under Article 55 of the regulation may be run on fields including surname, first names, travel document number, application number, nationality, date of birth, sex and period of time. Before any change is recorded, the software requires the user to confirm the amendment or erasure by entering their credentials.

Law enforcement and safeguards

Europol requests for access under Article 53 of the regulation are submitted through the software, with a specialised unit assessing whether the request fulfils all conditions. The ETIAS Central System automatically prevents access to certain sensitive data, and central access points may process urgent requests in exceptional cases where there is an imminent danger to life, with verification carried out ex post.

The European Data Protection Supervisor was consulted and delivered an opinion on 17 March 2026, and the Smart Borders Committee (ETIAS) gave its opinion. The decision builds on the Schengen acquis: Denmark is bound by it, while Ireland does not take part; Iceland, Norway, Switzerland, Liechtenstein and Cyprus are associated with its application.

The decision enters into force on the twentieth day following its publication in the Official Journal. For the millions of visa-exempt travellers and the border and immigration authorities of the Schengen area, it defines the operational backbone of ETIAS, ensuring that personal data are accessed, amended and erased under strict, auditable rules.


Source: Official Journal of the European Union, L series, 8.9.2026 (official reference: CELEX L_202601970).