Showing posts with label LIBE Committee. Show all posts
Showing posts with label LIBE Committee. Show all posts

Friday, 10 January 2014

European Parliament wants to question Snowden

The European Parliament's LIBE Committee's Inquiry into the Electronic Mass Surveillance of European Citizens is not due to be published in March, and the Committee has voted to question the whistle-blower Edward Snowden via video-link. However The Guardian has ran a story on the draft of the report in which the Inquiry says the actions of the NSA and the UK's GCHQ "appear illegal".

The draft report states (PDF; main findings start at p.16):

"[The Inquiry] Condemns in the strongest possible terms the vast, systemic, blanket collection of the  personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of the press, thought and speech, as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding the extra-territoriality of national laws

[...]

[The Inquiry] Stresses that, despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities."

(Points 9,and 60 of the main findings).

Along with calling for the US and EU Member States to prohibit blanket mass surveillance activities and demanding that the UK, France, the Netherlands, Sweden and Germany revise their national intelligence laws in line with the European Convention on Human Rights, the rapporteur, S&D MEP Claude Moraes (UK),  called for the SWIFT Agreement with the US to be put on ice.

The SWIFT Agreement allows for the transfer of financial transaction data to the US, and has come in for a lot of criticism. The first attempt at agreement failed, but the European Parliament voted through a second renegotiated SWIFT deal earlier during this parliament.

Tagesschau reports that the inquiry may show that French and German intelligence agencies have also been carrying out similar surveillance programmes. This is probably widely suspected anyway, but for a parliamentary inquiry to finger France and Germany after the outrage expressed by those two countries would be very embarrassing. It would be particularly uncomfortable for Merkel, who is seen to have reacted to the NSA Affair slowly, and due to the controversial nature of the EU's own data retention laws in the country.

The European Parliament report won't have any binding effect, but the Inquiry is a strong political statement. As well as being a fundamental issue that needs investigation, this is a ticket to the central political stage. Questioning Snowden would be a major coup and turn the Inquiry into an international event. Though the Inquiry overwhelmingly wants to question Snowden (only 2 UK Conservatives on the Committee voted against the proposal), it is depending on Snowden wanting to use the platform - something that the US Congress fears and has warned against. It's hard to see why Snowden wouldn't take this opportunity to state his case personally and publicly.


EDIT: Ralf Grahn drew my attention to the draft report online, so I've changed the blog to include links and some extracts to it.

Tuesday, 12 November 2013

The European Cloud - Europe's Response to the NSA Scandal?

Negotiations over the EU-US trade deal reopened yesterday, demonstrating that the NSA affair has not halted progress here despite the calls from the European Parliament for talks to be suspended. At the same time the Parliament's Civil Liberties, Justice and Home Affairs Committee (LIBE) continues to hold sessions on its inquiry into the spying allegations. Neelie Kroes, the Commissioner that heads the Digital Agenda policy, has said that while the spying revelations are shocking and unacceptable, the spying will probably continue - "Let's not be naive". Instead Kroes argues that Europe should focus on building its digital infrastructure and single market in the internet.

In the EU the spying scandal does not look like it will produce any sharp changes in policy direction, but rather an acceleration of existing policies as the Commission and others capitalise on the political fallout from the affair. For the Data Protection Regulation this has already meant a reversal of the bill's dilution that had been brought about under the influence of lobbyists, and for Kroes it means pushing the European Cloud.

The European Cloud Strategy was adopted by the Commission last year, aiming to boost European cloud computing by sorting through problems of technical standards, data portability, clear cloud computing contracts and user trust. The policy is mostly economically focused, noting that cloud computing can generate jobs and economic growth while providing opportunities for cost-cutting for small and medium businesses. However, cloud computing concerns issues of data protection as well as copyright issues. As the EU works through its data protection reforms, the fact that 85% of cloud computing services are US based will surely raise concerns not only over how much the EU needs to do to catch up in this market, but also over how effective European privacy rules will be in practice.

With European expert groups meeting on how to approach cloud computing contracts and a European Cloud Partnership mulling commercial strategy, the technical discussions seem removed from the headlines in the media, but the Commission probably does see this as part of the solution (as well as using the crisis to promote its policies). First, the Commission's strongest in the single market, so boosting European internet businesses so European consumers (and others) have an alternative to the US-based cloud is one of the few things they can actually do, so they would be naturally inclined to favour this policy. Second, the best way for Brussels to exert its regulatory power in an area (and one of the few ways it can exert any power) is to have a strong market in that area and then come up with high standards for it, setting the pace in the global marketplace.

In a sense, Kroes makes a good point. It is hard to imagine that the Franco-German push to put transatlantic spying on a "legal footing" will do much, if anything, to reduce actual levels of spying. Improving the market position of the EU would help provide an alternative and allow the EU to stamp its data protection philosophy on to the global economy more effectively - and the political impetus behind such an economic policy is unlikely to fizzle out as quickly as the focus on spying may do.

However, this isn't enough - we should and need to push more forcefully to ensure that security services here and in the US are more politically accountable. It is not enough that what they do is legal: after all, it would hardly solve the problem to provide that legal backing wherever it's currently lacking. Rather we need to have a more critical approach to the demands of security for ever more information and resources, and to have a real debate over how we balance safety and security and civil liberties.

Because while we can never have total security, we can run out of privacy.

Thursday, 25 April 2013

Draft EU PNR Directive voted down at Committee Stage

The LIBE Committee of the European Parliament has shot down the draft Passenger Name Record Directive by a vote of 30-25, with the Liberal, Green and left wing groups voting against and the conservative groups for the draft law. The Directive concerned the collection of the information passengers give to airlines when booking a flight by law enforcement authorities (in the form of national "Passenger Information Units (PIUs)" that would analyse the data and pass on information to other law enforcement authorities). The data would be collected to fight terrorism and serious crime, and is a key plank of the Commission's counter-terrorism strategy.

I wrote about the PNR Directive at length last year. The information gathered covers everything from the flight to the food you order, so the authorities would be casting a wide net. There would be some rights for people to have their data corrected or deleted, but:

"However the purposes for gathering and processing the data is so wide that it’s debatable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

[...]

 There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF)."

While the draft parliamentary report (by LIBE rapporteur Timothy Kirkhope [ECR Group]) clarified some issues with the original text, it did little to address the scope of both the data gathered and the purposes that it could be used for (without further restricting and defining these, it would be very difficult for the system to be held to account in that most uses for the data would be lawful and citizens would have little substance to their data rights).

The draft Directive could still go to the EP plenary, where the full European Parliament could still pass the law.

Tuesday, 25 September 2012

Reports of US breaching EU PNR Agreement

The transfer of Passenger Name Record Data - the information you hand over to airlines when you book a flight - from EU airlines to the US government has been a controversial issue in Brussels, with the transfers taking place for a decade on one basis or another without a satisfactory agreement in place to regulate it.

Earlier this year the European Parliament ratified an agreement with the US to regulate - and make legal in the EU - the transfer of this personal data to the US government for anti-terrorism and crime fighting purposes. I was against this agreement because it is spectacularly disproportionate and infringed privacy rights: data can be held for far too long (over a decade) for practically any purpose whatsoever. Sadly Sophie In't Veld's report advising rejection of the agreement was voted down in Committee and the Parliament ratified the agreement in plenary.

However it seems that the US hasn't been satisfied with even this gift of a treaty, with reports that the US government has been collecting data on people on flights that do not take off or land in the US, in contravention of the agreement. The S&D Group in the European Parliament has called on the Justice Commissioner Malmstrom to account for this before the LIBE Committee in Parliament:

"S&D spokesperson on civil liberties, justice and home affairs, Claude Moraes MEP, said:
 
"The media reports show that the US may be requesting data which falls outside the scope of the EU-US PNR agreement. We signed up to the agreement on strict conditions and we need clear answers if EU citizens' data is being collected contrary to spirit of the agreement.
 
"If our citizens' data is being collected for flights simply going through US airspace, then this could be against EU data protection laws. We are taking this matter very seriously and that is why the S&Ds have requested that Commissioner Malmström comes to the civil liberties committee to give MEPs a full picture of the situation regarding US collection of EU citizens' PNR data.""

It would not be the first time the Parliament has been disappointed by poor results from bad treaties.