Germany has inserted a new Section 19e "Digitale Fluggastabfertigung" into the Luftverkehrsgesetz (LuftVG, Aviation Act), authorizing airlines, airport operators and ground handlers to run automated, biometric-assisted passenger processing at check-in, baggage drop and boarding. The provision, published on the official BMJV legal-text portal gesetze-im-internet.de on August 5, 2026, lets processors read the machine-readable zone and chip of a passenger's passport, including the stored photograph, and match it against a live image taken at the airport. It is the first federal statute to set a dedicated data-protection frame for biometric airport processing in Germany.
The new paragraph conditions every processing step on three cumulative requirements: the processing must be necessary for digital passenger processing, the passenger must have expressly consented, and the processing must take place exclusively within European Union territory. Airlines cannot make the digital path mandatory: Section 19e(7) requires them to keep a non-digital, equivalent procedure available for every passenger and every sub-process.
Who must comply, and what can they now read?
Section 19e(1) names the three touchpoints where automated systems may be used: check-in, baggage drop (Gepäckaufgabe) and boarding control. The right to read passport data extends under Section 19e(8) to airport operators (Flugplatzbetreiber) and ground handling service providers as defined in Annex 1 No. 2 of the Bodenabfertigungsdienst-Verordnung, and airport operators may also deploy it at the security screening control under Section 8(1) of the Luftsicherheitsgesetz. Section 19e(9) extends the same regime to the German Personalausweis (ID card).
For each passenger, processors may read the passport's machine-readable zone and chip data, including the facial image stored on the chip, the holder's family and given names, the card access file, the public chip authentication key, the card security object and the document security object. The chip photo is matched once against a live image captured at the airport to verify that passenger and passport holder are identical. That live image must be converted immediately into a biometric template; the name data must be converted into an encrypted file.
How fast must biometric data be deleted?
Section 19e(5) sets a hard deletion ladder. Chip security objects and machine-readable-zone data used for authenticity checks are deleted immediately after the chip read and the creation of the encrypted file. The live image is deleted immediately once the biometric template is created. The name data, the biometric template and the encrypted file must be deleted as soon as they are no longer needed, and at the latest three hours after the passenger's departure. Data kept for the purpose of Section 18(4) of the Passgesetz remains subject to that provision's own deletion deadline.
| Obligation | Trigger | Deadline |
|---|---|---|
| Delete chip security objects and MRZ authenticity data | After chip read and encrypted file creation | Immediately |
| Delete live airport image | After biometric template creation | Immediately |
| Delete name data, biometric template, encrypted file | When no longer needed | At latest 3 hours after departure |
| Keep non-digital equivalent procedure available | All passengers, all sub-processes | Continuous |
What technical standards apply?
Section 19e(6) fixes the benchmark at the state of the art, which is presumed to be laid down in the Technical Guidelines of the Bundesamt für Sicherheit in der Informationstechnik (BSI). Where those guidelines provide a certification scheme, fundamental compliance with guidelines TR-03121 (biometrics for human verification) and TR-03135 (biometric templates) must be confirmed by BSI. Airlines, airports and their vendors must therefore procure certified matching systems, not merely GDPR-compliant ones, and chip authenticity checks must track the current state of the art.
What should affected operators do now?
The official text carries no explicit entry-into-force date, which under Article 82(2) of the Grundgesetz generally means the statute takes effect on the 14th day after its promulgation in the Bundesgesetzblatt; operators should track the BGBl. publication to pin the exact date. German airlines such as Lufthansa and Condor, airport operators including Fraport, Munich and Berlin-Brandenburg, their ground handlers and biometric-identity vendors should now audit consent-capture flows for explicit opt-in at every touchpoint, confirm that all processing stays on EU infrastructure, and verify that their matching systems carry or are pursuing BSI TR-03121 and TR-03135 certification. Deletion pipelines must be engineered to the three-hour post-departure ceiling, and the non-digital equivalent path must remain genuinely equivalent, not degraded.
Continuous, per-jurisdiction real-time monitoring surfaces this kind of statutory insertion the moment it publishes on the official gazette portal.
Take advantage of this real-time watch
Next steps: confirm whether your operations touch German territory, brief your data-protection officer and airport-IT leads on the Section 19e(5) deletion ladder, and schedule a BSI certification readiness review for any biometric matching component already deployed.


