PNR data can only be kept for a period of 5 years, and must be depersonalised after a period of 6 months so the data subject is no longer immediately identifiable. member states are required to establish a passenger information unit to handle and protect the data; this unit must include a data protection officer.