Showing posts with label EU-US relations. Show all posts
Showing posts with label EU-US relations. Show all posts

Friday, 10 January 2014

European Parliament wants to question Snowden

The European Parliament's LIBE Committee's Inquiry into the Electronic Mass Surveillance of European Citizens is not due to be published in March, and the Committee has voted to question the whistle-blower Edward Snowden via video-link. However The Guardian has ran a story on the draft of the report in which the Inquiry says the actions of the NSA and the UK's GCHQ "appear illegal".

The draft report states (PDF; main findings start at p.16):

"[The Inquiry] Condemns in the strongest possible terms the vast, systemic, blanket collection of the  personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of the press, thought and speech, as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding the extra-territoriality of national laws

[...]

[The Inquiry] Stresses that, despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities."

(Points 9,and 60 of the main findings).

Along with calling for the US and EU Member States to prohibit blanket mass surveillance activities and demanding that the UK, France, the Netherlands, Sweden and Germany revise their national intelligence laws in line with the European Convention on Human Rights, the rapporteur, S&D MEP Claude Moraes (UK),  called for the SWIFT Agreement with the US to be put on ice.

The SWIFT Agreement allows for the transfer of financial transaction data to the US, and has come in for a lot of criticism. The first attempt at agreement failed, but the European Parliament voted through a second renegotiated SWIFT deal earlier during this parliament.

Tagesschau reports that the inquiry may show that French and German intelligence agencies have also been carrying out similar surveillance programmes. This is probably widely suspected anyway, but for a parliamentary inquiry to finger France and Germany after the outrage expressed by those two countries would be very embarrassing. It would be particularly uncomfortable for Merkel, who is seen to have reacted to the NSA Affair slowly, and due to the controversial nature of the EU's own data retention laws in the country.

The European Parliament report won't have any binding effect, but the Inquiry is a strong political statement. As well as being a fundamental issue that needs investigation, this is a ticket to the central political stage. Questioning Snowden would be a major coup and turn the Inquiry into an international event. Though the Inquiry overwhelmingly wants to question Snowden (only 2 UK Conservatives on the Committee voted against the proposal), it is depending on Snowden wanting to use the platform - something that the US Congress fears and has warned against. It's hard to see why Snowden wouldn't take this opportunity to state his case personally and publicly.


EDIT: Ralf Grahn drew my attention to the draft report online, so I've changed the blog to include links and some extracts to it.

Tuesday, 12 November 2013

The European Cloud - Europe's Response to the NSA Scandal?

Negotiations over the EU-US trade deal reopened yesterday, demonstrating that the NSA affair has not halted progress here despite the calls from the European Parliament for talks to be suspended. At the same time the Parliament's Civil Liberties, Justice and Home Affairs Committee (LIBE) continues to hold sessions on its inquiry into the spying allegations. Neelie Kroes, the Commissioner that heads the Digital Agenda policy, has said that while the spying revelations are shocking and unacceptable, the spying will probably continue - "Let's not be naive". Instead Kroes argues that Europe should focus on building its digital infrastructure and single market in the internet.

In the EU the spying scandal does not look like it will produce any sharp changes in policy direction, but rather an acceleration of existing policies as the Commission and others capitalise on the political fallout from the affair. For the Data Protection Regulation this has already meant a reversal of the bill's dilution that had been brought about under the influence of lobbyists, and for Kroes it means pushing the European Cloud.

The European Cloud Strategy was adopted by the Commission last year, aiming to boost European cloud computing by sorting through problems of technical standards, data portability, clear cloud computing contracts and user trust. The policy is mostly economically focused, noting that cloud computing can generate jobs and economic growth while providing opportunities for cost-cutting for small and medium businesses. However, cloud computing concerns issues of data protection as well as copyright issues. As the EU works through its data protection reforms, the fact that 85% of cloud computing services are US based will surely raise concerns not only over how much the EU needs to do to catch up in this market, but also over how effective European privacy rules will be in practice.

With European expert groups meeting on how to approach cloud computing contracts and a European Cloud Partnership mulling commercial strategy, the technical discussions seem removed from the headlines in the media, but the Commission probably does see this as part of the solution (as well as using the crisis to promote its policies). First, the Commission's strongest in the single market, so boosting European internet businesses so European consumers (and others) have an alternative to the US-based cloud is one of the few things they can actually do, so they would be naturally inclined to favour this policy. Second, the best way for Brussels to exert its regulatory power in an area (and one of the few ways it can exert any power) is to have a strong market in that area and then come up with high standards for it, setting the pace in the global marketplace.

In a sense, Kroes makes a good point. It is hard to imagine that the Franco-German push to put transatlantic spying on a "legal footing" will do much, if anything, to reduce actual levels of spying. Improving the market position of the EU would help provide an alternative and allow the EU to stamp its data protection philosophy on to the global economy more effectively - and the political impetus behind such an economic policy is unlikely to fizzle out as quickly as the focus on spying may do.

However, this isn't enough - we should and need to push more forcefully to ensure that security services here and in the US are more politically accountable. It is not enough that what they do is legal: after all, it would hardly solve the problem to provide that legal backing wherever it's currently lacking. Rather we need to have a more critical approach to the demands of security for ever more information and resources, and to have a real debate over how we balance safety and security and civil liberties.

Because while we can never have total security, we can run out of privacy.

Friday, 25 October 2013

EU reaction to the NSA Affair

The fallout from the NSA Affair and Snowden's leaks continue, with revelations that Angela Merkel's mobile phone was hacked causing worldwide headlines (though there's been some criticism of Merkel for taking so long over these allegations, and indications that the NSA has been spying on German citizens, seriously, as Der Standard pointedly notes with the headline "Und ploetzlich ist es ein Problem" ["And suddenly it is a problem"]). The Guardian is reporting that the number of tapped heads of government is probably much higher, and the European Council has finally been roused too - it turns out that prime ministers don't like to be spied on. Now everything from the halting of data-sharing agreements to cancelling the free trade talks is on the table (after all, it's much harder to negotiate if you're being spied on).

The European Parliament has also signalled its displeasure, voting for a motion calling for the end of the SWIFT agreement. It's not binding, and the Commission has responded by stating that there is no indication of wrong-doing under the SWIFT Agreement (or "Terrorist Financial Tracking Programme" - PDF). Parliament's issues with SWIFT aren't new to the NSA revelations, however. After a troubled birth (the Parliament voted down the first agreement before passing the second after lobbying from Vice-President Joe Biden), last year the report before Parliament on the implementation of the safeguards in the agreement caused disquiet - it turned out that the full report wasn't even made available to MEPs to review. (Notably, the European Data Protection Supervisor had criticised some of the key provisions of the draft SWIFT Agreement).

The Commission has said that the agreement has effective safeguards, and that it's waiting on the response to a request for reassurances from the US. It's not planning to suspend the agreement.

Martin Schulz, the President of the European Parliament has also said that the free trade talks with the US should be suspended in the light of the spying affair.

The most notable moves, though, probably come over the draft Data Protection Regulation. The European Parliament has adopted its position on the law this week, which has hardened. The subject of intense lobbying, the biggest impact of the Snowden-leak was to reverse the watering down of the proposed law, with the security of citizens' data in the hands of US companies a key concern. The bill still has a long way to go, and it has to be agreed with the Council before it can be signed into law.

But what does this all add up to? At the end of this week the EU still transfers the same kind of data to the US as at the start, and there is little coherence in the EU's position. Most demands amount to the suspension of agreements or negotiations, and it will take a while to see what actually comes out of this. If we are ever going to see better data protection standards and a more regulated approach to intelligence and police work, we have to have clear standards and guidelines on how we shape these laws. When it comes to the EU, a proper regard for the necessity and proportionality of proposed security laws within the EU and agreements with third countries has to be stressed. And the Commission must drop its deference of the security services if it is to enforce and monitor agreements - or even draw up laws.

Wednesday, 15 August 2012

A European SWIFT?: the Commission outlines available options

Just after the Lisbon Treaty came into force, the European Parliament used its new power to block the SWIFT Treaty with the US, which would give the US Department of Homeland Security access to financial transaction data for anti-terrorism purposes. The problem was there was no way of targeting suspected individuals and no judicial oversight: financial transaction information would be handed over in bulk (based on search categories) to the US government to search through.

After some changes (Europol gained the role of verifying the compliance of US requests under the treaty for data) and heavy lobbying that included a vice-presidential visit to the European Parliament, the EP voted through a re-negotiated treaty. Since then it turns out that the negotiated safeguards are wholly inadequate, with general data covering a global area for an essentially unlimited time being provided to the US DHS.

Part of SWIFT II was that the US would help the EU establish its own system (Article 11), and the Commission has published a communication on the options on setting up a European Terrorist Financial Tracking System (PDF). A more targeted approach to data collection is one of the aims of a European system, so that these systems are less intrusive into the privacy of citizens.

The Communication doesn't pick a particular option, and there will be an Impact Assessment based on a study the Commission contracted out in 2010. The Communication also promises that the Impact Assessment will pay particular attention to the necessity and proportionality of a European system and its impact on fundamental rights - given the poor use of statistics in the PNR proposals, I can't say I've much confidence in the quality of impact assessments in the area of justice and home affairs.


Goals:

Two main goals have been identified:

"• the system must provide an effective contribution to the fight against terrorism and its financing within the European Union;

• the system must contribute to limiting the amount of personal data transferred to third countries. The system should provide for the processing of the data required to run it on EU territory, subject to EU data protection principles and legislation."

A European TFTS could provide a useful extra tool in the fight against terrorism, and given the European basis of SWIFT (it's based in Belgium), designing a system that respects civil liberties and fundamental rights would have a positive knock-on effect in the EU's security relations with the US and other countries when it comes to finance tracking by ensuring that any transfers of data also comply with fundamental rights.

More specifically the system will cover:

"• preparing and issuing (legally valid) requests to the designated provider(s) of financial messaging services for the raw data to be provided to an authorised recipient or recipients. This involves determining the message categories to be requested, how often such messages should be sent, and maintaining contacts with the providers on these issues;

• monitoring and authorising requests to the designated provider(s) for such raw data. This involves verifying whether the request for the raw data have been prepared in accordance with the applicable limitations;

• receiving and storing (processing) the raw data from the designated provider(s), including the implementation of an adequate system of physical and electronic data security;

• running the actual searches on the data provided, in line with the applicable legal framework; on the basis of requests for such searches from authorities of the Member States, the U.S. or other third States on the basis of clearly defined conditions and safeguards, or on the own initiative of the authority (or authorities) entrusted with processing the data;

• monitoring and authorising the running of searches on the data provided;

• analysing the results of the searches, through combining these results with other available information or intelligence;

• distributing the results of the searches (without further analysis) or the results of the analyses to authorised recipients;

• implementing an appropriate data protection regime, including applicable retention times, logging obligations, handling requests for access, correction and deletion, etc."

Options (from page 9 onwards):

The Communication makes it clear that a hybrid solution is preferable to an exclusively national or exclusively centralised approach, so all of the options are designed along hybrid lines with differing degrees of (de)centralisation.

Option 1: A central EU TFTS unit as a coordination and analytical unit cooperating with national law enforcement authorities. Under this system most of the data work would be done at the European level with national requests to the central unit. Europol or Eurojust are possibilities for performing the central unit's role.

Option 2: EU TFTS extraction service option. This would be the same as option 1, but the central unit would not carry out analysis based on the extracted data for national requests (only for EU or third country requests), and requests would be verified at the national level.

Option 3: A Financial Intelligence Unit: there would be a European FIU platform which would request data from SWIFT and/or other data providers on the basis of national FIU needs. National FIUs would carry out the analysis, etc., for their Member State. The FIU Platform could deal with third country requests and for EU institutions.

The FIU model bears a striking resemblance to the Passenger Information Units envisaged by the current proposed Passenger Name Record Directive (PDF), so I'm guessing that something close to option three will be what we see in the draft law. going with this model will bring up a lot of issues regarding safeguards and oversight, and how data analysis is used, as well as what scope the FIU Platform will have for transfering data on to third countries. Some of these issues will also remain for the other options, but at first glance it looks like option 2 provides a system with clearer lines of responsibility that also ensures that the information is delivered to national experts who can then get on with the job.


Two key aspects for a European TFTS.

A European TFTS has to be a system of individualised searches. The processing of bulk data is essentially casting a wide net, with government rummaging through everything that's been dredged up, whether or not the data belongs to non-suspects. Developing a system capable of delivering individualised searches is necessary if the system is to be equipped with sufficient safeguards to protect civil liberties.

The second key aspect for a European TFTS is that searches need to be subject to judicial oversight in the Member States - law authorities should not be able to issue searches whenever they want, but they should have to get judicial permission (or an equivalent process in national law) for a search based on specific legal grounds. This would help prevent data mining (or similar practices such as what goes on under the current treaty) and ensure that there are strong safeguards. These aren't the only safeguards necessary - retention periods and how far analysis shifts into profiling are other issues that need to be considered when the studies and the legislative proposal come out - but they are necessary. If these basic elements are missing from any TFTS, then it should be rejected. (The Communication mentions that Europol as a possibility for a role in verifying requests for data under the system, despite not being a judicial authority by any stretch of the imagination).

The contracted study should be finished by the end of the year and I assume the impact assessment and proposal will be published in 2013.

Tuesday, 17 July 2012

“I feel that we’ve been had!” – Report on the SWIFT Agreement


Blow to civil liberties as PNR deal passes

 BY CC greenefa.

In 2010 the EU ratified an agreement with the US called the SWIFT Agreement (or more technically: the “Terrorist Financial Tracking Programme” – PDF), after the first agreement was vetoed by the Parliament, and despite privacy concerns remaining for the second agreement. The SWIFT Agreement permits the transfer of financial transaction information to the US government for the purpose of counter-terrorism. The problem is that you can’t ask for someone’s transaction information, but data is transferred in bulk to the US, where they search through the information to see if they can find out anything relevant to counter-terrorism. As a check, the second agreement stipulates that Europol must check that requests for transfers are in compliance with the agreement. Given that Europol could gain from any leads from the information, it’s not exactly the impartial check of a judicial body.

The LIBE Committee debated the Second Report on the role of Europol by the Joint Supervisory Body on 21/6/2012 (you can watch it here). The first report (PDF) found some serious failings, including:

- Due to the abstract nature of transfer requests, proper verification of whether the requests are in line with the conditions of the Agreement is impossible.
 - Information provided orally to Europol affects their decision making, but cannot be reviewed by the JSB. Whether the deficiency in information in the requests is remedied by oral information is impossible to verify.
- Significant involvement of oral information renders proper internal and external audit impossible.

Recommendations:

- Inform the JSB on the results of the review in policies and procedures for Europol’s role. - Ensure the ability of the Europol Data Protection Officer to carry out his role.
- Ensure hard-deletion of Article 4 data (data to the US where Europol has to verify their requests), which where inputted into some of Europol’s information processing systems before the upgrading of the security level.
- Contact the US Treasury Department and ensure that adequate information is provided with requests.
- Ensure verifications by Europol are made based on written requests, along with any supplemental documents, in order to allow for proper internal and external audit.

The Second Report notes that all US data requests to date have been approved and that some of the reasons are too generic. Many of the request applications included “copy and paste” texts and the information provided was out-of-date and already in the public domain, and oral information is still being provided to Europol in order for it to make decisions. Also, there is no geographic limitation to these requests (data concerning the whole world is requested), and the requests submitted on a monthly basis for a month in duration (so effectively data transfer is ongoing all year round with little limitation).

The JSB concluded that 2 of its recommendations from its previous report have been implemented, while progress is ongoing for the other 3. The EU and US have signed an agreement for a second person to be posted from the EU to the US Treasury Department to oversee the operation of the agreement. The Overseer currently in place has been involved in intensive on-the-job training, and has been in US Treasury briefings. Clearly continuous information is being provided on generic and incomplete information with little restriction, so it’s hard to see how the current system provides adequate safeguards.

The full report however is not publically available or even available to the MEPs on the LIBE Committee – when the Committee requested access to the report, the JSB said it had no objections, and that there was nothing sensitive in the report that would prevent it from being disclosed. However, Europol stated that disclosure would threaten operational interests, so the report has not been disclosed. You can find the JSB’s public statement here: PDF.

Sophie in’t Veld and Jan Albrecht weren’t impressed (Veld: “I feel that we’ve been had!”). Veld highlighted that the EP was assured that there would be no data mining, but that the current procedure – of continuous and almost unlimited access – is much worse and goes further than what Parliament had expected. Veld objected to the secrecy of the report, saying that the Committee cannot fulfil its role of scrutinising Europol and the Agreement properly on the basis of a “3 page summary”. Albrecht said that the demands of MEPs have not been met after 2 years of the agreement, adding that if we have a functional fundamental rights jurisdiction, we could get this taken down in court.

While the role of the Europol Data Protection Officer seems to have been strengthened, it hardly seems like there are any safeguards on the flow of financial transaction data to the US. Without a sunset clause on the agreement, the European Parliament is in a fairly weak position to act against the treaty or to demand amendments. We seen the trend of PNR treaties on passenger information lead to a bad proposal for EU PNR, and soon the Commission will propose a TFTS for the EU. We need to make sure that we don’t throw away our civil liberties for little or no security gain simply because law enforcement authorities want our information and data.