The Schengen Information System (SIS) is one of Europe’s largest and most important databases. It was created with the aim of strengthening security and police cooperation among the Schengen Area States, and it affects millions of people every year — from travelers crossing borders to residents, asylum seekers, or individuals subject to a judicial or administrative order. However, while personal data can be entered into this system, every person has the right to access, rectify, or request the deletion of inaccurate, outdated, or unlawfully processed data.
Do you suspect that your personal data is being shared among European authorities? As a law firm specialized in European Union Law and data protection, we explain how the Schengen Information System (SIS) works and what steps to take to protect your rights and request the removal of your personal data.
What is the Schengen Information System (SIS)?
The Schengen Information System, known as SIS, is a European database shared by the Schengen Area Member States, created to ensure cooperation in matters of security, justice, immigration, and border control.
The current legal framework of the SIS is governed by Regulations (EU) 2018/1861 and 2018/1862, which set out the rules applicable to the system’s operation in the areas of borders, police cooperation, and judicial cooperation.
Since 2023, the third-generation SIS (SIS III) has been in force — a modernized version that replaces the previous SIS II. This new version expands the types of alerts that can be registered, improves interoperability with other European systems (such as EES or ETIAS), and strengthens personal data protection, in line with Regulation (EU) 2016/679 (GDPR) and Directive (EU) 2016/680 on data protection in the criminal field.
In short, the SIS is a shared IT platform that allows national authorities — such as police, customs, border guards, judges, and prosecutors — to access real-time information about persons or objects subject to an alert in any Schengen State.
💡 What types of alerts does the Schengen Information System contain?
The Schengen Information System can include different categories of alerts, such as:
- Persons wanted for arrest or surrender under a European Arrest Warrant.
- Missing persons, including minors or vulnerable individuals who must be protected.
- Persons not authorized to enter or reside in the Schengen Area (for example, following an expulsion or entry ban).
- Vehicles, firearms, documents, or license plates that have been stolen, lost, or misappropriated.
- Judicial or police orders related to investigations, discreet surveillance, or specific checks.
Each alert in the SIS contains basic information (name, date of birth, nationality, reason for the alert, and measures to be taken) and is immediately communicated to all competent authorities of the Schengen States.
What personal data does the Schengen Information System (SIS) contain?
The Schengen Information System (SIS) stores a wide range of personal and judicial data related to persons or objects subject to an alert. These data are recorded by the national authorities of the Member State issuing the alert (called the issuing State) in accordance with the rules established by Regulation (EU) 2018/1861 and the applicable national legislation. For natural persons, the SIS may contain the following information:
- Identity data: first and last names, gender, date and place of birth, nationality, and any known aliases.
- Physical characteristics: photographs, fingerprints, or other biometric identifiers.
- Contact or identification data: passport number, identity card, or residence permits.
- Reason for the alert: for example, arrest warrant, entry ban, location of a missing person, or discreet control for police or judicial reasons.
- Decisions or measures taken: references to judicial, administrative, or police resolutions justifying the person’s inclusion in the system.
Concerning objects (vehicles, weapons, documents, identity papers, or license plates), the SIS records technical data such as serial numbers, license plates, or country of issuance, along with the reason for the search or seizure.
💡 Warning: Even if the person concerned resides in another EU Member State, the data included in the SIS remain accessible to all authorities across the Schengen Area. This means that a person listed in an alert issued, for example, in Italy or Belgium, can be identified or controlled in any other participating country — from Spain to Finland.
For this reason, as we will see next, it is essential to know your rights of access, rectification, and deletion of personal data in the SIS, and to understand how to exercise them.
Who has access to the SIS and for what purpose?
Access to the Schengen Information System (SIS) is strictly regulated. Only certain competent authorities can consult and use the data recorded, and always for legitimate and proportionate purposes. The main authorities with access to the SIS include:
- Police forces and gendarmerie, responsible for the prevention and detection of crimes.
- Border guards and customs authorities, in charge of controlling entry and exit at the external borders of the Schengen Area.
- Immigration and foreign affairs authorities, managing visas, residence permits, and return or expulsion decisions.
- Judges, prosecutors, and courts, when the information is necessary for judicial proceedings or criminal cooperation.
- Europol, for tasks related to analysis and combating serious crime and terrorism.
- Frontex, the European Border and Coast Guard Agency, in the context of border control and joint operations management.
This access is regulated by the principle of purpose limitation, as established in both Regulation (EU) 2018/1861 and the General Data Protection Regulation (GDPR). In other words, SIS data can only be used for the specific purposes for which they were entered (for example, to arrest a wanted person or prevent entry of an unauthorized individual) and cannot be reused for other administrative or commercial purposes. Furthermore, the use of SIS must respect the principle of proportionality, ensuring that measures taken are appropriate and not excessive in relation to the intended objective.
From a technical perspective, at the European level, the management and supervision of the SIS is coordinated by eu-LISA, the agency responsible for operational functionality, IT security, and interoperability of the system among different Member States. Nevertheless, each State retains responsibility for the accuracy and legality of the data it enters into its national section of the system (N.SIS).
Rights regarding the Schengen Information System (SIS)
Few European citizens are aware that the Schengen Information System (SIS) also recognizes individual data protection rights. This means that if your data appear in a SIS alert, you have the right to know, correct inaccurate information, or even request its deletion, pursuant to Regulation (EU) 2018/1861 and the General Data Protection Regulation (GDPR). Below, we clearly explain the main rights concerning the SIS and how to exercise them effectively.
Right to information
The right to information (Article 52 of Regulation (EU) 2018/1861) guarantees that any person whose data are processed in the SIS is informed, in a clear and understandable manner, about the existence of such processing, the purposes for which their data are used, and the rights they can exercise (access, rectification, deletion, and judicial remedies).
The Member State may restrict this communication to safeguard national security, defense, public safety, or for the prevention, detection, investigation, and prosecution of crimes. However, it must justify such restriction and lift it once the reasons for it no longer apply.
Right of access: how to find out if your data are in the SIS
The right of access allows you to request information on whether your personal data are registered in the SIS and, if so, to know which specific data are processed, the reason for the alert, and which authority entered them. This right is recognized in Article 53 of Regulation (EU) 2018/1861 and Articles 14 and 15 of the GDPR.
To exercise it, you must submit a written request to the competent authority of the Member State that issued the alert (for example, a national police station, Ministry of Interior, or immigration authority). Authorities are obliged to respond within a reasonable time, unless there are security or confidentiality reasons limiting access. In such cases, the State must provide a written justification for the refusal.
Right to rectification or deletion: how to correct or remove data in the SIS
If the data are inaccurate, incomplete, or should no longer appear in the system, you can exercise your right to rectification or deletion, also recognized by Article 53 of Regulation (EU) 2018/1861 and Article 16 of the GDPR. These rights allow you to:
- Correct erroneous data, e.g., if your name or nationality was registered incorrectly.
- Update information, if the circumstances that led to the alert have changed.
- Request full deletion, when the legal basis justifying the alert has disappeared or was unlawful from the outset.
💡 Practical example: In cases of alerts for non-admission to the Schengen Area (Regulation 2018/1861), a person can request the deletion of the alert if they subsequently obtain a valid residence permit or a favorable judicial decision. In such cases, the issuing State is obliged to review and delete the alert to avoid violating the right to free movement and residence.
To request rectification or deletion, you must submit a motivated application to the issuing State, attaching documents that prove your situation (judicial decision, residence permit, updated passport, etc.). If the State does not respond or rejects your request, you can file a complaint with the national Data Protection Authority (DPA) or appeal the decision before the competent courts, as explained below. For more specific information, review our article about the right to be forgotten in Belgium.
Right to effective judicial remedy: appealing a decision or seeking accountability
If your rights regarding the SIS have been violated, you can exercise your right to an effective judicial remedy, guaranteed by Articles 54 and 58 (compensation) of Regulation (EU) 2018/1861. This right allows you to:
- Appeal a decision before the national courts of the issuing State or the competent judicial authority of your country of residence.
- Request judicial review of a refusal to rectify or delete your data.
- Claim compensation if you have suffered material or moral damages as a result of unlawful or negligent processing of your data in the SIS.
Additionally, if the dispute involves EU law interpretation, national courts may refer a preliminary question to the Court of Justice of the European Union (CJEU), if the conditions are met. It is also important to note that data processed in the SIS and related supplementary information will not be transmitted to or made available to third countries or international organizations (article 50 of Regulation 2018/1861).
Summary table: rights in data protection and SIS
| Right | Legal basis | Where to exercise | Practical advice |
|---|---|---|---|
| Information | Art. 52 Regulation (EU) 2018/1861 | National authority of the issuing State or DPA | Request to be informed about the inclusion of your data in the SIS, the purposes of processing, and your derived rights. |
| Access | Art. 53 Regulation (EU) 2018/1861 & Arts. 14-15 GDPR | National authority of the issuing State | Request written confirmation of whether your data are in the SIS. |
| Rectification / Deletion | Art. 53 Regulation (EU) 2018/1861 | Authority of the issuing State or DPA | Provide documents proving the error or change of circumstances. |
| Effective judicial remedy | Art. 54 Regulation (EU) 2018/1861 | National courts / CJEU | Appeal negative decisions or request compensation for damages. |

How to delete data from the SIS: step-by-step procedure
If your personal data appear in the Schengen Information System (SIS), it is important to know that you have the right to request their deletion or rectification. In this section, we explain, clearly and practically, how to delete data from the SIS step by step, with concrete examples and applicable legal references.
Step 1 | Identify the State that issued the alert
The first step to delete your data from the SIS is to identify which Member State entered the alert (also called the issuing State). That country has the competence to modify or delete the registered information, in accordance with Article 34 of Regulation (EU) 2018/1861. Once the responsible State is identified, you must submit your request to its competent authorities.
Step 2 | Submit a request for access or deletion
The second step consists of submitting a formal request for access or deletion of your data in the SIS. Each Member State has its own application form and national procedure to process such requests, although the principles and deadlines established by European law must be respected. In the request, you must include any document that justifies the deletion, such as:
- A court ruling, administrative resolution, or valid residence permit
- Identifying data (full name, date of birth, nationality)
- A copy of your identity document or passport
- A clear description of the reason for your request, whether it is access, rectification, or deletion
Practical examples by country
- In France, requests are submitted to the Commission Nationale de l’Informatique et des Libertés (CNIL).
- In Belgium, requests are submitted to the Autorité de protection des données (APD), formerly the Commission de la protection de la vie privée.
- In Spain, you should address your request to the Agencia Española de Protección de Datos (AEPD), which acts as an intermediary between the citizen and police or immigration authorities.
- In Portugal, the competent authority is the Comissão Nacional de Proteção de Dados (CNPD), based in Lisbon, which coordinates directly with the Serviço de Estrangeiros e Fronteiras (SEF) and other national authorities.
- In Germany, requests are processed by the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) — the Federal Commissioner for Data Protection and Freedom of Information — which cooperates with the Bundespolizei and the Bundeskriminalamt (BKA), responsible for maintaining the SIS nationally.
Step 3 | Review by the issuing authority
Once the request is submitted, the issuing State must verify whether the alert is still necessary and proportionate. Article 34 of Regulation (EU) 2018/1861 establishes that all entries in the SIS must have a valid legal basis and be maintained only as long as necessary.
The responsible authority will review whether the reasons for the alert persist, for example an active court order or entry ban, and will check that the information is accurate and up-to-date, ensuring that maintaining the alert respects the principle of proportionality. If the alert is unjustified, the State must delete the data from the SIS and communicate the decision to the other Schengen countries.
Step 4 | Judicial or administrative appeal
If the issuing authority does not respond, rejects the request, or maintains the alert unjustifiably, you may appeal through an administrative or judicial remedy. The administrative appeal should be submitted to the issuing State’s data protection authority. The judicial appeal before the national courts of the issuing State allows you to request deletion or correction of the data under the national procedure of each Member State, as well as any compensation for damages.
Regarding the interpretation of EU law, national courts may submit a preliminary question to the Court of Justice of the European Union (CJEU) if they have doubts about how to apply European regulations. During these procedures, it is advisable to be assisted by a specialized lawyer to receive guidance and monitor the progress of your case.
Alerts for objects in the SIS, practical and administrative implications
Alerts for objects registered in the Schengen Information System (SIS) have a direct impact on administrative procedures and commercial activities. For example, a vehicle, vessel, or aircraft that has been stolen or seized in one Member State may be detained during customs inspections or border controls, even if it is in transit to another Schengen country. Through the SIS, prosecutors, courts, and competent authorities can coordinate criminal investigations and prevent the objects from being resold or used illegally.
Similarly, alerts regarding lost or stolen identity documents or passports enable immigration authorities and airports to block fraudulent use, protecting third parties and preventing identity theft crimes. In this context, the proper request for information, updating, and deletion of data by a specialized lawyer becomes essential.
Relevant case law and practical examples
The Schengen Information System (SIS) has been the subject of multiple judicial decisions, both at the level of the European Union and in national courts, which have established principles regarding proportionality, data accuracy, and the protection of fundamental rights.
Case C-505/19 WS v. Federal Republic of Germany (2021)
In this case, the Court of Justice of the European Union (CJEU) examined the proportionality of including personal data in the SIS. The applicant challenged his registration in the system following the issuance of a police alert in Germany.
According to the CJEU, the inclusion of data in the SIS must respect the principles of necessity and proportionality, taking into account the nature of the alert and the specific circumstances of the individual concerned. If the alert has disproportionate effects on a citizen’s rights — such as restricting freedom of movement or access to public services — the issuing State must modify or delete the data. This judgment reinforces the obligation of Member States to periodically review the validity and relevance of alerts in order to prevent undue interference with fundamental rights.
Case C-625/19 PPU – XD (2019)
In this case, the CJEU addressed the interpretation of EU rules on pre-trial detention and the execution of European arrest warrants. The Court emphasized the importance of safeguarding fundamental rights, including the protection of personal data, within the framework of judicial cooperation in criminal matters. Although not directly related to the SIS, it establishes principles applicable to data protection in the broader European context.
Case C-71/17 – Melnyk (2019)
This case focused on data exchange within cross-border police cooperation, establishing that Member States must ensure that the shared data are relevant and proportionate. Moreover, the Court highlighted the obligation to periodically review alerts and to provide effective redress mechanisms for individuals affected by incorrect or disproportionate data.
Data protection and cooperation between Schengen authorities
The Schengen Information System (SIS) enables cooperation in the areas of security, border control, and migration within the European Union. However, strict compliance with data protection rules depends on constant coordination between national and European authorities.
Cooperation Between Member States and eu-LISA (SIS)
The proper functioning of the SIS relies on effective Schengen cooperation. Each Member State has a national contact point (N.SIS) responsible for entering, updating, and verifying alerts in the shared database. These contact points work closely with eu-LISA, the agency in charge of the technical maintenance and cybersecurity of the SIS. eu-LISA ensures that national systems remain interconnected and coordinates technical and cybersecurity audits to make sure every State complies with the common EU data protection standards.
Supervision by the European Data Protection Supervisor (EDPS)
The European Data Protection Supervisor (EDPS) is responsible for supervising the SIS (Article 56 of Regulation (EU) 2018/1861). Together with the national data protection authorities — such as the AEPD in Spain, the APD in Belgium, the CNIL in France, and the Garante per la Protezione dei Dati Personali in Italy — the EDPS carries out joint periodic audits to verify that Member States comply with EU rules on privacy and data security.
These audits help detect potential duplications, unauthorized access, or unlawful data processing, and propose corrective measures to improve the system’s reliability. The cooperation between national and European authorities ensures that the SIS operates in a consistent, lawful, and transparent manner throughout the Schengen area.
Exercise your rights today and protect your privacy from misuse
Knowledge is important to exercising your rights. If you suspect that your personal data has been entered into the Schengen Information System (SIS) without your consent or in an incorrect manner, you have the full right to request access, rectification, or deletion. Our team will assist you in exercising these rights before the competent national authority or data protection authority. In cases of refusal or lack of response, we can bring the matter before national courts or the Court of Justice of the European Union to seek effective protection.
Acting in an informed way not only allows you to regain control over your personal information, but also strengthens transparency and accountability within public institutions. The responsible exercise of these rights is essential to ensure that European security is not built at the expense of individual privacy, but in full respect of the rule of law and human dignity. At Arthur & Marin, we have a team of experts in data protection and fundamental rights.
Contact us at +32 465 345 345 or info@arthurmarin.com for a personalized evaluation of your case and to receive comprehensive legal assistance.
💡 We guide and support you throughout the entire process to ensure the full protection of your rights
FAQ on the Schengen Information System (SIS)
1. What does it mean to be listed in the Schengen Information System (SIS)?
Being listed in the SIS means that your personal data — or data relating to an object such as a vehicle, document, or weapon — appears in an alert shared among the Schengen Area Member States. These alerts may include arrest warrants, entry bans, missing person searches, or stolen vehicle records. They are accessible to police, customs authorities, migration services, and Europol, among others.
2. Who can access my data in the SIS?
Access is granted to police and security forces, migration and border authorities, judges and prosecutors in judicial proceedings, as well as Europol and Frontex. Access is strictly limited to legitimate purposes and must comply with the principles of proportionality and necessity.
3. How long do data remain in the SIS?
The retention period depends on the type of alert and the applicable legal framework. Member States are required to periodically review the validity of each record to ensure that the data processing remains proportionate and lawful.
4. How can I find out if I have an SIS alert?
To verify whether your data appear in the SIS, you can exercise your right of access before the competent authority of the issuing State or before the national data protection authority, depending on the country.
5. Can I have my data deleted from the SIS if the reason for the alert no longer exists?
Yes. You have the right to request the rectification or deletion of your personal data in the SIS. For example, if you obtain a residence permit that nullifies the reason for a non-admission alert, you may request that the issuing State delete your data. In case of refusal, you can lodge a complaint with the national data protection authority or bring the matter before the courts.
6. What are the consequences of being in the SIS?
Having an SIS alert can affect your freedom of movement, your ability to enter or reside in other Schengen States, and your access to certain public services. Even if you live in a different country from the one that issued the alert, all Schengen authorities can consult it.
7. What is the difference between SIS II and the new SIS III?
SIS III, in force since 2023, is the latest version of the Schengen Information System. It enhances interoperability with other EU databases and introduces new types of alerts, such as those concerning at-risk minors or vulnerable persons. It also strengthens personal data protection and cooperation among Member States.
8. Can I have an SIS alert without having committed a crime?
Yes. Not all SIS alerts are linked to criminal offences. Some entries concern administrative decisions, objects, or even the search for missing persons. However, all alerts must comply with Regulation (EU) 2018/1861.
9. What happens if my country of origin is not part of the Schengen Area?
If you are a national of a country outside the Schengen Area, an SIS alert may prevent you from entering or moving freely within it. Nevertheless, you still retain your rights of access, rectification, and deletion of data.
10. What safeguards does EU law provide to protect my data in the SIS?
Regulation (EU) 2018/1861 and the GDPR establish strict safeguards regarding purpose limitation, accuracy, and the constant updating of records. They also guarantee the rights of access, rectification, deletion, and judicial remedy, as well as oversight by independent national data protection authorities and by the European Data Protection Supervisor (EDPS).