The reservation is made in seconds. The file lives for years. Somewhere between the seat map and the boarding gate, a traveler’s record starts collecting details most people barely notice when they book: a meal code, a wheelchair request, a phone number, a split itinerary, a free-text remark. In airline jargon, those fragments sit in fields like OSI, SSI, and SSR. In the language of surveillance, they look different. They look like a dossier hiding inside customer service.
The Case For
PNR fields were never just about names and flight numbers
The official paper trail is unusually clear. U.S. Customs and Border Protection’s 2013 Passenger Name Record Privacy Policy says the data it receives can include “General remarks including Other Service Indicated (OSI), Special Service Indicated (SSI) and Supplemental Service Request (SSR) information.” Those fields sit far beyond the narrow idea most travelers have of a manifest.
Industry guidance confirms the same thing from the airline side. IATA’s Guidelines on Passenger Name Record (PNR) Data notes that PNRs may contain requested seating, special meals, medical requirements, free text, and general remarks, and explicitly lists OSI, SSI, and SSR among the fields states may seek. In plain English, the record can capture not just where someone is going, but hints about their body, beliefs, routines, and vulnerabilities.
The privacy alarm was sounding early
European regulators saw the danger long before today’s AI-and-data-state debate made it fashionable. In 2004, the Article 29 Data Protection Working Party warned in Opinion 6/2004 that the “pull” method gave authorities all data first and left them to filter afterward. The opinion specifically said airlines should move to “push” as soon as possible and that filtering software had to sort out both non-listed fields and sensitive data stored inside permitted fields. That is not a minor procedural complaint. It is an admission that the system could ingest more than governments were publicly comfortable defending.
The European Commission’s own 2010 PNR explainer made the issue even plainer. It said PNR can contain sensitive information, including clues about health or religion, and used meal preferences and medical conditions as concrete examples. Officials insisted such information should not be used except in tightly limited circumstances. But that assurance carried a quiet confession inside it: the data was there to begin with.
The architecture kept the sensitive material close at hand
The realist case gets sharper when you look at retention and access. CBP’s privacy policy says PNR in ATS-P is generally accessible for five years, then moved to dormant status, with personal identifiers masked after six months and the file retained for an additional ten years. Fifteen years is a long afterlife for a booking record that may include service requests and open-text remarks. Even if the agency says masking and supervisory approval limit later access, the state still keeps the structure intact for a decade and a half.
That is the broader pattern behind the 2011 EU-US PNR deal and the push-versus-pull fight: once passenger data becomes intelligence infrastructure, the real battle shifts to who filters it and how long the state keeps it.
The Realist’s Eye
Potential sensitivity is not the same as proven misuse
This is where the darker theory needs stress-testing. The documents show that PNR systems can contain sensitive clues. They do not automatically prove that authorities routinely exploited every meal code or medical note. Official EU and U.S. documents say those fields were supposed to be filtered, deleted, or masked. A system with weak safeguards is not identical to a system with documented abuse in every case.
Much of this information began as ordinary airline operations data: accessibility, seating, medical support, child assistance, baggage coordination, and meal delivery. The concern is not that every service field was created for surveillance. It is that security systems later inherited the full record because it offered a richer behavioral picture around travel.
The ambiguity lives in the free-text edges
Still, that inheritance problem is exactly why the concern refuses to die. OSI, SSI, and SSR fields were controversial not because every entry was scandalous, but because they could carry information that bled beyond a clean list of approved data categories. A meal code can hint at religion. An assistance request can hint at disability or illness. A note added by an agent can reveal more than the passenger realizes.
That leaves a tension modern privacy law still has not resolved. Is a system genuinely privacy-protective if it collects the risky field, stores it inside the broader file, and then promises to ignore or mask it later? Or is that just administrative minimization after the state has already secured the advantage of possession?
The deeper story is mission creep by data inheritance
Maybe the unsettling part is not a secret order to profile passengers by meal request. Maybe it is something more ordinary. Security agencies inherited airline reservation systems built for commerce, then treated the resulting data exhaust as raw material for risk analysis. That is less cinematic than a black-budget plot. It is also how modern surveillance usually expands: not by inventing a database from scratch, but by repurposing one that already exists.
If that sounds familiar, it should. Across the Government Secrets archive, the same logic keeps surfacing. Administrative systems become intelligence assets. Temporary access becomes permanent workflow. The remarkable thing is not that the records existed. It is how normal it became to argue that because the data was already there, the state should keep it too.
What We Know For Certain
- CBP’s published PNR privacy policy says U.S. authorities may receive OSI, SSI, and SSR information inside passenger reservation data.
- IATA guidance says PNR records may include special meals, medical requirements, free text, and general remarks.
- European privacy regulators warned in 2004 that pull-based access exposed authorities to more data than they should automatically receive.
- Official EU explanations acknowledged that PNR may contain sensitive clues, including information suggestive of health or religion.
- CBP says PNR records can remain in ATS-P for up to fifteen years, with masking after six months and tighter controls after five years.
The Unanswered Questions
- How often did sensitive clues in OSI, SSI, or SSR fields trigger additional scrutiny in practice?
- How effective were automated filters at catching sensitive information embedded in free-text remarks?
- What oversight could truly verify that prohibited fields were ignored rather than merely retained?
- How many travelers understood that service requests for comfort, health, or religion could enter long-term state databases?
- At what point does inherited customer-service data become de facto intelligence profiling?
The Closer — You Decide
A boarding pass feels disposable. A reservation record does not. It can outlive the trip by years, carrying the small personal disclosures people make for comfort, necessity, faith, or health. Governments insist the filters matter. Privacy regulators insisted the architecture mattered more. Both arguments still sit in the file. Whether those fields were a narrow operational byproduct or a quiet doorway into far more intimate passenger intelligence depends on how much trust you place in systems that collect first and minimize later. The evidence is on the table. You decide.




