A Romanian IT contractor discovered in January 2025 that a fraudulent passport application flagged her in SIS II. Within hours, Europol had processed the alert and cross-referenced it with Interpol’s databases. By the time she learned of the entry, three border agencies had already logged hits against her name.
Three interconnected systems—Europol, Interpol and SIS II—allow law enforcement across Europe to exchange alerts, biometric records and criminal intelligence in near real-time. When you’re flagged in one, the others know within hours. Europol accesses all SIS II data classes and can propose Member States to enter new alerts. Crucially, SIS II alerts take legal priority over Interpol notices when both systems flag the same individual. Your data-protection rights extend across all three systems, but each operates under distinct legal frameworks: Regulation (EU) 2016/794 for Europol, Interpol’s Rules on Processing Data for Red Notices, and Regulation (EU) 2018/1862 for SIS II.
Schengen Information System (SIS II) – the largest law enforcement database in Europe, containing over 90 million alerts for wanted persons, stolen documents and objects, operated by EU Member States and accessible to Europol and certain national authorities under Regulation (EU) 2018/1862.
Europol – the European Union Agency for Law Enforcement Cooperation, established under Regulation (EU) 2016/794, which supports Member States in preventing and combating terrorism, cybercrime and serious organised crime through data analysis and operational coordination.
Interpol – an international organisation that facilitates police cooperation among 196 member countries through a global system of colour-coded notices, including Red Notices for wanted persons, governed by its Constitution and Rules on the Processing of Data.
Key Takeaways
- Article 37a of Regulation (EU) 2018/1862 grants Europol the power to propose Member States enter SIS II alerts when there is factual indication of terrorist offences or serious crime. Proposals still require Member State approval.
- SIS II alerts always have priority over Interpol notices when both systems flag the same person—a rule embedded in Article 1.8.1 of the Sirene Manual (Decision 2013/115/EU). This means detention in the Schengen area follows SIS II procedure first.
- The new SIS II legal framework entered into force on 27 December 2018, with full application required by 28 December 2021. Any alerts created before this date should have been reviewed and revalidated under the new rules.
- Europol has unrestricted read access to all SIS II data classes and can exchange information directly with Member States’ Sirene offices. EUROJUST, by contrast, has limited access privileges.
- Data subjects can access their SIS II records under Article 41 of Regulation (EC) 1987/2006, and Europol processing under Regulation (EU) 2016/794. Getting a complete picture requires separate requests to both the alert-issuing Member State and Europol’s Data Protection Officer.
How does Europol access and use SIS II data in criminal investigations?
Europol holds unrestricted read access to all SIS II alerts. Most national law enforcement agencies cannot claim this privilege. The agency’s analysts can query wanted persons, missing persons, judicial proceedings targets, and alerts on stolen vehicles, identity documents and firearms without routing requests through individual Member States.
Under Article 37a of Regulation (EU) 2018/1862, Europol can propose that a Member State enter an alert when its analysis reveals factual indication that a person intends to commit or is committing a terrorist offence or serious crime within Europol’s mandate. The Member State retains final decision-making authority, but Europol’s proposal triggers a formal assessment process. This power emerged from the 2018 legislative reform, designed to address contemporary threats: foreign terrorist fighters, cross-border organised crime networks, and individuals flagged by multiple intelligence sources.
Direct communication channels connect Europol to national Sirene bureaux—the specialised offices that manage supplementary information tied to SIS II alerts. When a Greek border guard hits an alert created by German authorities, the Greek Sirene office contacts its German counterpart within minutes to obtain arrest instructions and warrant details. Europol can access these exchanges and contribute additional intelligence from its own case files.
The operational advantage surfaces in counter-terrorism work. French authorities investigating suspected jihadist recruitment can use Europol’s Counter-Terrorism Centre to check SIS II instantly, cross-reference Interpol databases, and identify parallel investigations across Member States. Intelligence that once took weeks is assembled in hours.
What is the legal relationship between Interpol notices and SIS II alerts?
SIS II alerts trump Interpol notices. Article 1.8.1 of the Sirene Manual (Commission Decision 2013/115/EU) is explicit: when conflicting information exists, the SIS II alert takes priority. A Polish border officer who encounters both an Interpol Red Notice and a SIS II alert for the same person must act on the SIS II alert first and follow instructions from the issuing Sirene bureau, regardless of which notice was filed more recently.
Why this hierarchy exists matters. SIS II alerts rest on EU law, creating binding obligations between Member States and Schengen-associated countries. They include mandatory data quality checks, time limits for alert duration, and enforceable data-protection rights. Interpol notices operate under international law and do not create automatic arrest obligations.
Many cases populate both systems simultaneously. Belgium issues an arrest warrant for suspected fraud, enters a SIS II alert, and requests an Interpol Red Notice. SIS II circulates within 31 Schengen countries. The Red Notice reaches 196 countries globally. Detained in Switzerland—SIS II procedure applies. Detained in Dubai—Interpol rules govern. The geographic scope determines which legal framework controls your case.
Europol cannot issue Interpol Red Notices. Only national authorities can request them through their Interpol National Central Bureaux. That said, Europol can facilitate information exchange leading a Member State to request a Red Notice. When Europol identifies a high-value target during joint investigation, it typically recommends the case-leading Member State enter both a SIS II alert and, if the suspect may travel outside Europe, request an Interpol diffusion or Red Notice.
| System | Geographic Scope | Legal Basis | Who Can Issue | Priority in EU |
|---|---|---|---|---|
| SIS II | Schengen Area (31 countries) | Regulation (EU) 2018/1862 | Member State authorities; Europol can propose | Priority over Interpol |
| Interpol Red Notice | Global (196 countries) | Interpol Constitution & Rules on Processing Data | National Central Bureaux | Secondary to SIS II in Schengen |
| Europol Data Systems | EU Member States + partners | Regulation (EU) 2016/794 | Europol and Member States | Analytical support; no direct arrest authority |
Takeaway: Flagged in both systems? Detention within the Schengen area will be processed under SIS II first. Challenging the SIS II entry requires action in the Member State that issued it; contesting an Interpol Red Notice requires submission to the Commission for the Control of Interpol’s Files in Lyon. Each process operates independently, with no automatic coordination between them.
Can Europol create alerts in SIS II without Member State approval?
No. Europol cannot unilaterally create or delete SIS II alerts. Article 37a of Regulation (EU) 2018/1862 grants Europol the power to propose that a Member State enter an alert—not to create one. Final decision-making remains exclusively with national authorities. This safeguard reflects a core principle: SIS II alerts must be issued under national law, and Member States retain sovereignty over their criminal justice systems.
When Europol identifies a person presenting serious security risk, it submits a formal proposal to the Member State with jurisdiction—usually where the suspected offence occurred or the person resides. The proposal must include specific factual indications: intelligence reports, intercepts, financial analysis. The Member State then applies its own legal standards to determine whether evidence meets the threshold for issuing a national arrest warrant or administrative decision justifying a SIS II entry.
This gatekeeping function is intentional. If Europol could create alerts unilaterally, individuals would face movement restrictions based solely on agency assessment, without judicial oversight. Requiring Member State approval ensures every SIS II alert is backed by a judicial decision or administrative act issued under national law—decisions that can be challenged in national courts.
What are your data-protection rights when Europol processes your information?
Regulation (EU) 2016/794 gives you real rights: access, rectification, deletion, and processing restrictions. Article 41 requires Europol to respond within three months—extendable to six if your request is genuinely complex. Submit requests in writing to Europol’s Data Protection Officer in The Hague. Plan accordingly. A three-month window means filing in January gets you an answer by April, at earliest.
Access isn’t unlimited. Europol refuses or restricts disclosure when it would compromise an ongoing investigation, endanger witnesses or informants, or threaten national security. If refused, they must explain why—unless the explanation itself would defeat the purpose. Disagree? Lodge a complaint with the European Data Protection Supervisor.
Found errors in Europol’s records about you? Article 42 mandates correction without delay. Here’s the catch: when a Member State provided the data, Europol must notify that state so its national database gets updated too. Correcting your Europol record alone doesn’t fix what’s in your country’s criminal intelligence system or SIS II. You may need to push for correction on both sides.
Deletion is trickier. Europol must erase data once it’s no longer needed and within retention limits specified in its data retention policy. Operational data tied to active investigations typically stays for up to three years after closure, subject to periodic review. Never convicted, never charged, or charges dropped? You have stronger grounds for early deletion.
Can’t get results through Europol’s Data Protection Officer? Direct action exists under Article 263 TFEU if you can show you’re directly and individually affected by a Europol decision on your data rights. More practically, escalate to the European Data Protection Supervisor, which investigates Europol and issues binding corrective orders. Get specialist legal advice for data access requests or EDPS complaints.
How do Member State Sirene offices use Interpol data alongside SIS II?
Sirene offices run parallel systems. A single suspect might trigger both a SIS II alert and an Interpol notice—and they handle them simultaneously using different rules. When Italy issues a SIS II alert for extradition, its Sirene bureau enters the alert into SIS and uploads supplementary material: arrest warrant copies, translations, photographs accessible to other Sirene offices. If the suspect may leave the Schengen zone, Italy also requests an Interpol Red Notice.
Border officer makes a hit? The foreign Sirene office contacts its Italian counterpart for instructions—typically within one to two hours. Instructions differ by system. A SIS II hit specifies arrest for extradition, identity checks, or reporting back. An Interpol Red Notice hit outside Schengen triggers a call from the local NCB to Interpol Lyon to Interpol Rome to the Italian NCB. That chain adds hours.
Article 1.8.1 of the Sirene Manual settles conflicts: SIS II always wins. A Portuguese office discovering both a SIS II alert and an Interpol Red Notice for the same Czech citizen processes only SIS II. If SIS II says European Arrest Warrant but Interpol says third-country extradition, Portugal executes the EAW and notifies the third country that intra-EU surrender takes precedence.
Sirene also cross-checks Interpol’s Stolen and Lost Travel Documents database against SIS II alerts on fraudulent passports. A fake Bulgarian passport used at Frankfurt Airport gets queried against both SIS II and SLTD simultaneously. Hit on both? The German Sirene office coordinates with Bulgaria to map whether the document links to a broader fraud network and whether the person is wanted for other offences.
What recourse do you have if you believe you are wrongly flagged in SIS II or by Europol?
First, identify which Member State created the SIS II alert. Article 58 of the SIS II Decision (now Regulation (EU) 2018/1862) requires you to exercise rights in the state that entered the alert—or your own state if that can’t be determined. Submit an access request to the national Sirene office or data-protection authority. Expect responses within timelines set by national law implementing the Regulation.
Alert based on a national arrest warrant or court order? You must challenge the underlying legal act itself in the issuing Member State’s courts. A Greek court order doesn’t vanish from SIS II just because it inconveniences you. The warrant itself must be withdrawn or annulled—often requiring specialist representation in that jurisdiction, especially if the underlying case is dormant or based on evidence you dispute.
For Europol, file a complaint with the European Data Protection Supervisor if Europol refuses access, fails to correct errors, or processes your data unlawfully. The EDPS investigates, orders corrective action, and can impose fines. Submit written complaints with copies of all Europol correspondence, details of the contested processing, and evidence that it violates Regulation (EU) 2016/794.
Subject to an Interpol Red Notice? Request correction or deletion from the Commission for the Control of Interpol’s Files, an independent body at Interpol Lyon. The CCF checks whether the notice complies with Interpol’s Constitution and Rules, especially Article 2, which bars processing for political, military, religious or racial offences. Processing takes months. For cases spanning both Interpol and SIS II, challenge both systems simultaneously—otherwise one stays live while the other is corrected.
“Article 1.8.1 of the Sirene Manual mandates that SIS II alerts always have priority over Interpol alerts—a hierarchy that directly shapes how border agencies across 31 countries respond to conflicting flags.”
How does the 2018 SIS II reform affect data-sharing with Europol and Interpol?
Regulations (EU) 2018/1861 and 2018/1862 overhauled the SIS II framework. They entered force 27 December 2018; Member States had until 28 December 2021 to fully implement. The changes expanded alert categories, added biometric data fields, and tightened data protection.
Most significant: Article 37a formally codified Europol’s right to propose alerts. This power didn’t exist before 2018. Under the old framework, Europol accessed SIS II data and provided analysis but couldn’t recommend alert creation. The new provision emerged from 2015–2016 failures—the Paris and Brussels attacks exposed coordination gaps between national authorities and Europol.
The reform imposed stricter data quality rules. Member States must now review and update SIS II alerts regularly to confirm they remain accurate, relevant and necessary. Alerts unreviewed beyond specified limits auto-delete. This addressed a persistent problem: alerts staying active years after cases closed, warrants withdrew, or persons were arrested.
For individuals flagged in SIS II, the reform cuts both ways. Expanded data fields mean fingerprints, facial images, DNA profiles now live in SIS II and spread across Member States—raising identification odds. Simultaneously, strengthened data protections give you clearer rights: access, challenge, correction. By 2026, most Member States completed technical and legislative upgrades, though rollout continues.
⚠️ Time is critical — every day matters
Get a free case assessment
Our team specialises in cases with an international element. We review applicable treaties, assess risks, and prepare an action plan.
This article is published by an independent law firm for informational purposes only and does not represent or claim affiliation with any government body, international organisation, or official authority.
Frequently Asked Questions
Can Europol access Interpol databases directly?
No. Europol has no direct technical access to Interpol’s central databases, including the I-24/7 system. Instead, information flows through formal cooperation channels, memoranda of understanding, and liaison officers stationed at each organization. When Europol needs data held by Interpol, it submits a request through designated contact points. Interpol then responds—or doesn’t—based on whether the request meets its data-sharing criteria. This indirect process can add days or weeks to time-sensitive investigations.
How long do SIS II alerts remain active?
An alert stays live until the Member State that created it withdraws it or until national law expires the retention period, whichever comes first. Regulation (EU) 2018/1862 mandates periodic reviews; alerts deemed unnecessary must be deleted. Alerts tied to arrest warrants typically outlive the warrant itself—staying active until the warrant is either executed or formally withdrawn.
Think you’re wrongly flagged? You’ll need to contact the Member State that issued the alert and request deletion directly. Don’t expect a fast answer. Some states process these requests in weeks; others take months.
Does Interpol notify you when a Red Notice is issued?
Interpol will not tell you. Red Notices exist to locate and arrest people, and alerting the subject would defeat that purpose. Most individuals discover they’re on a Red Notice only when stopped at a border or when an employer runs a background check. There’s no courtesy letter, no email warning. Just the shock of being flagged.
Your only proactive option: submit an access request to the Commission for the Control of Interpol’s Files and ask whether a Red Notice exists in your name. The response takes time, but at least you’ll know.
What happens if a SIS II alert and an Interpol notice contain conflicting information?
SIS II wins—but only inside the Schengen area. Article 1.8.1 of the Sirene Manual makes this clear: when the two systems contradict each other, the border or police officer follows the SIS II instruction and ignores Interpol. Outside Schengen, Interpol takes precedence.
Fixing the conflict means correcting data in both systems simultaneously, which almost always requires separate legal challenges in different jurisdictions. It’s messy and slow.
Can I appeal a Europol decision to process my data?
Yes, but the path is narrow and formal. File a complaint with the European Data Protection Supervisor, which can investigate and order Europol to stop or correct its actions. If the EDPS rules against you and you still disagree, you can sue in the Court of Justice of the European Union under Article 263 TFEU—provided you can prove the decision injured you directly and individually. That’s a high bar. Hiring a lawyer who understands EU data law isn’t optional; it’s essential.
Related services & guides
Third-Country Transfer
Challenge transfers of your data to non-EU countries.
Preventive Data Check
Check proactively whether Europol holds data on you.
Europol Lawyers (hub)
Overview of every route to enforce your data-protection rights against Europol.