Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

ADR.OR.D.007 Management of aeronautical data and aeronautical information

ANNEX III — Organisation Requirements (Part-ADR.OR) · Regulation (EU) No 139/2014 · EAR revision 13 Mar 2026

IRImplementing rule

ADR.OR.D.007Management of aeronautical data and aeronautical information

(a)As part of its management system, the aerodrome operator shall implement and maintain a quality management system covering the following activities:

(1)its aeronautical data activities;

(2)its aeronautical information provision activities.

(b)As part of its management system, the aerodrome operator shall establish a security management system to ensure the security of operational data it receives, or produces, or otherwise employs, so that access to that operational data is restricted only to those authorised.

(c)The security management system shall define the following elements:

(1)the procedures relating to data security risk assessment and mitigation, security monitoring and improvement, security reviews and lesson dissemination;

(2)the means designed to detect security breaches and to alert personnel with appropriate security warnings;

(3)the means of controlling the effects of security breaches and of identifying recovery action and mitigation procedures to prevent reoccurrence.

(d)The aerodrome operator shall ensure the security clearance of its personnel with respect to aeronautical data security.

(e)The aspects related to information security shall be managed in accordance with point ADR.OR.D.005A.

IR · ADR.OR.D.007 — Regulation (EU) No 139/2014 · Delegated Regulation (EU) 2022/1645 · Aerodromes Easy Access Rules · EAR revision 13 Mar 2026

GMGuidance material

GM1 ADR.OR.D.007(a)Management of aeronautical data and aeronautical information

Show the text

QUALITY MANAGEMENT SYSTEM FOR AERONAUTICAL DATA AND AERONAUTICAL INFORMATION PROVISION ACTIVITIES An aerodrome operator does not need to duplicate functions and activities in order to discharge the responsibilities related to the management of aeronautical data and aeronautical information provision activities. In this respect, the compliance monitoring may be used for the purposes of ensuring compliance with the relevant requirements for management of aeronautical data and aeronautical information provision activities.

GM · GM1 ADR.OR.D.007(a) — Regulation (EU) No 139/2014 · ED Decision 2014/012/R · Aerodromes Easy Access Rules · EAR revision 13 Mar 2026

AMCAcceptable means of compliance

AMC1 ADR.OR.D.007(b)Management of aeronautical data and aeronautical information

Show the text

SECURITY MANAGEMENT FOR AERONAUTICAL DATA AND AERONAUTICAL INFORMATION PROVISION ACTIVITIES

(a)The security management objectives should be:

(1)to ensure the security of aeronautical data and aeronautical information received, produced, or otherwise employed so that it is protected from interference, and access to it is restricted only to those authorised; and

(2)to ensure that the security management measures meet appropriate national, EU, or international requirements for critical infrastructure and business continuity, and international standards for security management, including:

(i)ISO/IEC 17799:2005 — Information technology — Security techniques — Code of practice for information security management;

(ii)ISO 28000:2007: — Specification for security management systems for the supply chain.

(b)Regarding the ISO standards, the relevant certificates issued by an appropriately accredited organisation, are considered as an Acceptable Means of Compliance.

AMC · AMC1 ADR.OR.D.007(b) — Regulation (EU) No 139/2014 · ED Decision 2014/012/R · Aerodromes Easy Access Rules · EAR revision 13 Mar 2026

GMGuidance material

GM1 ADR.OR.D.007(b)Management of aeronautical data and aeronautical information

Show the text

INFORMATION SECURITY THREAT Information security threat may be any circumstance or event with the potential to adversely impact the operation, systems and/or constituents due to human action (accidental, casual or purposeful, intentional or unintentional, mistaken) resulting from unauthorised access, use, disclosure, denial, disruption, modification, or destruction of information and/or information system interfaces. This includes malware and the effects of external systems on dependent systems but does not include physical threats.

GM · GM1 ADR.OR.D.007(b) — Regulation (EU) No 139/2014 · ED Decision 2021/003/R · Aerodromes Easy Access Rules · EAR revision 13 Mar 2026

All rules in SUBPART D — MANAGEMENT — AERODROME OPERATORS (ADR.OR.D)

Consolidated from the EASA Easy Access Rules (revision 13 Mar 2026, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about ADR.OR.D.007 →

Metis opens with Avioverse in October 2026 · request early access.