Showing posts with label PNR. Show all posts
Showing posts with label PNR. Show all posts

Thursday, 25 April 2013

Draft EU PNR Directive voted down at Committee Stage

The LIBE Committee of the European Parliament has shot down the draft Passenger Name Record Directive by a vote of 30-25, with the Liberal, Green and left wing groups voting against and the conservative groups for the draft law. The Directive concerned the collection of the information passengers give to airlines when booking a flight by law enforcement authorities (in the form of national "Passenger Information Units (PIUs)" that would analyse the data and pass on information to other law enforcement authorities). The data would be collected to fight terrorism and serious crime, and is a key plank of the Commission's counter-terrorism strategy.

I wrote about the PNR Directive at length last year. The information gathered covers everything from the flight to the food you order, so the authorities would be casting a wide net. There would be some rights for people to have their data corrected or deleted, but:

"However the purposes for gathering and processing the data is so wide that it’s debatable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

[...]

 There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF)."

While the draft parliamentary report (by LIBE rapporteur Timothy Kirkhope [ECR Group]) clarified some issues with the original text, it did little to address the scope of both the data gathered and the purposes that it could be used for (without further restricting and defining these, it would be very difficult for the system to be held to account in that most uses for the data would be lawful and citizens would have little substance to their data rights).

The draft Directive could still go to the EP plenary, where the full European Parliament could still pass the law.

Tuesday, 25 September 2012

Reports of US breaching EU PNR Agreement

The transfer of Passenger Name Record Data - the information you hand over to airlines when you book a flight - from EU airlines to the US government has been a controversial issue in Brussels, with the transfers taking place for a decade on one basis or another without a satisfactory agreement in place to regulate it.

Earlier this year the European Parliament ratified an agreement with the US to regulate - and make legal in the EU - the transfer of this personal data to the US government for anti-terrorism and crime fighting purposes. I was against this agreement because it is spectacularly disproportionate and infringed privacy rights: data can be held for far too long (over a decade) for practically any purpose whatsoever. Sadly Sophie In't Veld's report advising rejection of the agreement was voted down in Committee and the Parliament ratified the agreement in plenary.

However it seems that the US hasn't been satisfied with even this gift of a treaty, with reports that the US government has been collecting data on people on flights that do not take off or land in the US, in contravention of the agreement. The S&D Group in the European Parliament has called on the Justice Commissioner Malmstrom to account for this before the LIBE Committee in Parliament:

"S&D spokesperson on civil liberties, justice and home affairs, Claude Moraes MEP, said:
 
"The media reports show that the US may be requesting data which falls outside the scope of the EU-US PNR agreement. We signed up to the agreement on strict conditions and we need clear answers if EU citizens' data is being collected contrary to spirit of the agreement.
 
"If our citizens' data is being collected for flights simply going through US airspace, then this could be against EU data protection laws. We are taking this matter very seriously and that is why the S&Ds have requested that Commissioner Malmström comes to the civil liberties committee to give MEPs a full picture of the situation regarding US collection of EU citizens' PNR data.""

It would not be the first time the Parliament has been disappointed by poor results from bad treaties.

Tuesday, 17 July 2012

“I feel that we’ve been had!” – Report on the SWIFT Agreement


Blow to civil liberties as PNR deal passes

 BY CC greenefa.

In 2010 the EU ratified an agreement with the US called the SWIFT Agreement (or more technically: the “Terrorist Financial Tracking Programme” – PDF), after the first agreement was vetoed by the Parliament, and despite privacy concerns remaining for the second agreement. The SWIFT Agreement permits the transfer of financial transaction information to the US government for the purpose of counter-terrorism. The problem is that you can’t ask for someone’s transaction information, but data is transferred in bulk to the US, where they search through the information to see if they can find out anything relevant to counter-terrorism. As a check, the second agreement stipulates that Europol must check that requests for transfers are in compliance with the agreement. Given that Europol could gain from any leads from the information, it’s not exactly the impartial check of a judicial body.

The LIBE Committee debated the Second Report on the role of Europol by the Joint Supervisory Body on 21/6/2012 (you can watch it here). The first report (PDF) found some serious failings, including:

- Due to the abstract nature of transfer requests, proper verification of whether the requests are in line with the conditions of the Agreement is impossible.
 - Information provided orally to Europol affects their decision making, but cannot be reviewed by the JSB. Whether the deficiency in information in the requests is remedied by oral information is impossible to verify.
- Significant involvement of oral information renders proper internal and external audit impossible.

Recommendations:

- Inform the JSB on the results of the review in policies and procedures for Europol’s role. - Ensure the ability of the Europol Data Protection Officer to carry out his role.
- Ensure hard-deletion of Article 4 data (data to the US where Europol has to verify their requests), which where inputted into some of Europol’s information processing systems before the upgrading of the security level.
- Contact the US Treasury Department and ensure that adequate information is provided with requests.
- Ensure verifications by Europol are made based on written requests, along with any supplemental documents, in order to allow for proper internal and external audit.

The Second Report notes that all US data requests to date have been approved and that some of the reasons are too generic. Many of the request applications included “copy and paste” texts and the information provided was out-of-date and already in the public domain, and oral information is still being provided to Europol in order for it to make decisions. Also, there is no geographic limitation to these requests (data concerning the whole world is requested), and the requests submitted on a monthly basis for a month in duration (so effectively data transfer is ongoing all year round with little limitation).

The JSB concluded that 2 of its recommendations from its previous report have been implemented, while progress is ongoing for the other 3. The EU and US have signed an agreement for a second person to be posted from the EU to the US Treasury Department to oversee the operation of the agreement. The Overseer currently in place has been involved in intensive on-the-job training, and has been in US Treasury briefings. Clearly continuous information is being provided on generic and incomplete information with little restriction, so it’s hard to see how the current system provides adequate safeguards.

The full report however is not publically available or even available to the MEPs on the LIBE Committee – when the Committee requested access to the report, the JSB said it had no objections, and that there was nothing sensitive in the report that would prevent it from being disclosed. However, Europol stated that disclosure would threaten operational interests, so the report has not been disclosed. You can find the JSB’s public statement here: PDF.

Sophie in’t Veld and Jan Albrecht weren’t impressed (Veld: “I feel that we’ve been had!”). Veld highlighted that the EP was assured that there would be no data mining, but that the current procedure – of continuous and almost unlimited access – is much worse and goes further than what Parliament had expected. Veld objected to the secrecy of the report, saying that the Committee cannot fulfil its role of scrutinising Europol and the Agreement properly on the basis of a “3 page summary”. Albrecht said that the demands of MEPs have not been met after 2 years of the agreement, adding that if we have a functional fundamental rights jurisdiction, we could get this taken down in court.

While the role of the Europol Data Protection Officer seems to have been strengthened, it hardly seems like there are any safeguards on the flow of financial transaction data to the US. Without a sunset clause on the agreement, the European Parliament is in a fairly weak position to act against the treaty or to demand amendments. We seen the trend of PNR treaties on passenger information lead to a bad proposal for EU PNR, and soon the Commission will propose a TFTS for the EU. We need to make sure that we don’t throw away our civil liberties for little or no security gain simply because law enforcement authorities want our information and data.

Wednesday, 2 May 2012

Member States v the Commission: the contradiction behind the EU budget

Member States reacted with shock that the Commission proposed a 6.8% increase for the EU budget, and the Commission argued it is necessary for the EU to be able to meet the commitments it has already made.

Really, it seems there's a contradiction between how the Member States act in the Council, and how they act outside it. In the Council they're open to all sorts of ideas and are trying to secure funding for themselves (the fight to retain structural funds and CAP money will begin in earnest if it hasn't already - Irish MEPs have already started to voice concerns over CAP).

Lately this kind of attitude can be seen in the UK's approach to the proposed EU PNR Directive, which will require the collection of data on all passengers flying into and out of the EU for the purposes of fighting crime and terrorism. The UK Minister for Immigration said to the House of Commons European Scrutiny Committee that they managed to get agreement in the Council for the proposal to permit Member States to collect PNR data for intra-EU flights and for other modes of transport if they wanted. On the question of depersonalising data gathered that has been stored for other 2 years (to limit the data the government holds on people), the Committee reports:

"Whilst UK experience suggests most requests for access to full PNR data will be made within the initial two year period, the Minister recognises that the requirement to mask data (rather than to archive it in accordance with existing practice in the UK) will have operational and cost implications for which the UK may seek EU funding. [Emphasis mine]."

The UK is a major supporter and player behind EU security legislation, and if it feels that it could summit applications for EU funding over these issues, the question has to be: where does the money come from? There are far more Member States which do not have any PNR system in place at all and would have to create their own if this Directive passes - should they get funding as well? This application might not yet have been made, but if Member States are caught in a culture where commitments - and funding applications - are easily made, but little thought is given to how they will be paid for, then perhaps its better to turn to a system of own resources, where the EU raises its own funds, within limits and subject to the consent of the Council and EP.

The more the institutions have responsibility for raising funding as well as spending money - and the more we can hold them directly accountable for it - the more pressure there will be to rationalise what the money will be used for.

Friday, 27 April 2012

US PNR Deal passes

After the European Parliament consented to the US PNR Agreement by 409 to 226 votes (strangely the EUObserver thinks this is "half-hearted" support; I call it a pretty solid majority), the Council has also passed the Agreement.

The treaty will probably come into force on 1st June 2012 (PDF).

The Parliament is also currently debating the EU's own PNR system, which monitors passengers on flights into and out of the EU (though it may be extended to cover flights within the EU if the proposal is amended) by collecting the flight information of all passengers. The LIBE Committee's draft report has been published (PDF), and there are over 400 proposed amendments to the proposed Directive (PDF 1 and 2).

Thursday, 19 April 2012

EU-US PNR vote today

The European Parliament is going to vote in plenary today on the EU-US PNR Agreement (you can watch the debate here - it's on now), which will permit the transfer of passenger data (including credit card, luggage and meal choice details) from airlines to US authorities when flying to the US. Rapporteur Sophie in 't Veld's report recommended that the agreement be rejected due to a lack of guarantees that US authorities won't use the data for purposes other than the fight against terrorism and serious transnational crime, and because EU citizens will not have sufficient access to legal redress under the agreement.

However the LIBE Committee rejected this report and the EP is likely to accept the agreement, though the BBC reports that it may be by a thin majority. It seems that worries over the US bypassing the EU and making bilateral agreements with national governments and a sense that the EP has already made at least some display of strength over forcing a renegotiation have fed into the desire to vote for the agreement.

Wednesday, 28 March 2012

Report on EU-US PNR Treaty rejected in Committee

Sophie in ‘t Veld’s (ALDE) report to the LIBE (Civil liberities, justice and home affairs) Committee was rejected yesterday. The report to reject the EU-US treaty failed in a vote of 23 votes for, 31 against, and 1 abstention.

The PNR treaty will confirm the transfer of passenger data on flights to the US to the Department of Homeland Security. In ‘t Veld had urged rejection of the treaty for several reasons, but chief among them was the loopholes which permitted the data to be used for unspecified purposes outside the treaty’s aim of fighting terrorism and serious transborder crime.

It’s likely that the EP will assent to the treaty in plenary now, avoiding a clash with the US similar to over the SWIFT I treaty.

Wednesday, 29 February 2012

The EU's PNR Directive in Parliament

As well as Sophie in ‘t Veld reporting on the proposed EU-US PNR Agreement on Monday, Timothy Kirkhope (ECR) presented his draft report on the EU’s own Passenger Name Record regime. The PNR Directive is technical, but it involves a huge amount of data collection on people not suspected of a crime, and the processing of data to create models used to identify unknown criminals. The law poses major questions on data protection, and there are also issues of how necessary and effective the system is, and how much of the costs airlines (and therefore consumers) will bear to pay for the system. I’ll divide this post into outlining and discussing the proposed directive and briefly looking at Kirkhope’s report to the Committee on civil liberties, justice and home affairs.

The PNR Directive.

The proposed PNR Directive (PDF) would introduce a system where a wide range of data gathered by airlines on passengers on flights into and out of the EU would be processed for the purposes of fighting terrorism and serious transnational crime. The data gathered includes the information on passports, flight arrival and departure times and destination, check in status, payment details, address and contact information, frequent flyer information, travel agent, travel itinerary, general remarks (including information on unaccompanied minors and their guardian’s contact details and relationship to the minor), seat number, baggage information, code share information, ticketing field information, and date of reservation/issue of ticket. This data would be collected from everyone on flights into and out of the EU regardless of whether or not they’re suspected of a crime and without distinction to how susceptible an air route is judged to be to use for terrorism of serious transnational crime (also the UK has suggested an amendment for the latter). This raises questions of proportionality.

PNR data is to be used in three different ways: re-actively, in real time, and pro-actively. The re-active use of PNR data is the use of data in the investigation or prosecution of a crime which has already taken place; use of PNR data in real time entails the use of data to arrest or place an individual under surveillance for a crime being committed or about to be committed; and the pro-active use of PNR data is using PNR data to build up criteria against to identify persons worthy of further surveillance or action. “Serious transnational crime” isn’t really harmonised by the Directive – it uses the list of crimes in the European Arrest Warrant, but Member States can decide to exclude some of these crimes from their transposing legislation if they think one is too “minor” – so the Directive can’t even decide what’s a “serious crime”!

The data is transferred by airlines to “Passenger Information Units” (PIUs) that will be set up to process and analyse the data, and alert national law enforcement agencies if necessary. PIUs can be national, or countries can set up joint PIUs if they want to share the costs. (The vast majority of EU Member States don’t have a PNR regime, so this PNR Directive will effectively introduce PNR systems into most Member States for the first time). The data will be retained for 30 days, after which it will be “depersonalised” (identifying data removed, but not deleted so it can still be restored and used) and retained in this masked state for a further 5 years. Data can be kept for longer if it’s used in criminal investigations or prosecutions. 5 years seems disproportionate if the data isn’t being used in an investigation or prosecution – and even the Council’s own legal service has suggested a maximum retention period of 2 years ("Draft Agreement on the Use of Passenger Name Records (PNR), Note for the Attention of Mr Stefano Manservisi Director General, DG Home, European Commission Legal Service, SJ.f(2011)603245, 18/5/2011").

Data subjects (people who own data that is being stored or processed) have rights of access, rectification and erasure, and the National Supervisory Authorities set up under EU data protection legislation (Framework Decision on Data Protection) monitor the PIUs’ use of data and assist data subjects with their requests to exercise their rights. However the purposes for gathering and processing the data is so wide that it’s debateable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF).

So PNR faces a lot of questions on several fronts: is it necessary, does it work, are there cheaper and less invasive alternatives? So how does the draft report in the Committee deal with this?


Timothy Kirkhope’s report.

The draft report (PDF) has contains a long list of proposed amendments to the directive (it should be noted that the report is open to amendments from the Committee before it votes on the report as a whole).

Some of these amendments would clarify the scope of the Directive – by stating that it applies to airlines incorporated in the EU and that store data in the EU, and expanding the Directive to include intra-EU flights as well as flights entering and leaving the EU. By including intra-EU flights, there would obviously be a much, much greater amount of data gathered on people. In Committee it was explained that the Commission wanted the Directive to avoid including intra-EU flights so it could test the system out first (the Directive includes provision for a review in 5 years on whether to include intra-EU flights), while Kirkhope countered that gradual introductions of schemes rarely work in his experience. The costs of transferring data to the PIUs would be borne by the airlines, while Member States would pay for the PIUs and their work. Kirkhope said that the estimated costs that would be passed on to consumers in ticket prices would be between 10 to 18 cents.

The report’s amendments insert provisions regulating the transfer of data between Member States to ensure that safeguard standards are maintained and that data is only shared in certain circumstances. There are also new provisions to more extensively regulate the transfer of data to third countries, though the assessment is still left to Member States so there isn’t a common decision on the adequacy of a third country’s data protection standards like there is for internal market matters.

The amendments would also clarify the state of data after the initial 30 day period – the Directive uses the phrases “masked” and “anonymised”. Unfortunately, the draft report decides to simply change the phrasing to a more unified “masked” terminology rather than changing the procedure so identifying data will be deleted after 30 days. Some amendments do aim to strengthen data protection by setting down punishment for data breaches such as demotion, denial of system access, formal reprimands, and removal form duty, as well as an obligation to inform data subjects that might be affected by a data breach. National Supervisory Authorities would be given powers to take disciplinary action against persons responsible for a privacy breach, increasing their powers of independent oversight.

Kirkthorpe believes that the use of a PNR regime is necessary and proportional. While the necessity of the Directive is probably best debated by the Committee and whole Parliament, there are still questions over how proportional the Directive would be even with the report’s amendments, particularly over the targeting (or lack of targeting) of air routes, the oversight of creating and use of objective assessment criteria, and the length of the retention period. It does provide some good improvements to people’s rights to access, rectify and erase their data and makes it easier and more effective to exercise these rights (though the problem of the content of these rights given the wide use of data remains).

I’m very sceptical of the necessity for a PNR system – a lot of the analysis backing up the proposal seems to be based on numbers on the increase of crime together with rhetoric on fighting crime and anecdotal examples of how PNR could be used, rather than an analysis of the benefits of PNR versus the existing EU databases. It seems that we are being asked to accept the creation of a massive information gathering system on trust, and I’m not convinced.

Monday, 27 February 2012

In 't Veld to propose EP rejection of EU-US PNR Agreement

Sophie in 't Veld (ALDE), rapporteur on the EU-US Passenger Name Record Agreement (Text) will present her report to the committee on civil liberties, justice and home affairs today. The PNR agreement will permit the transfer of Passenger Name Record data for passengers on flights from the EU to the US to fight terrorism and serious crime. PNR data is all the data from the machine-readable part of the passport (name, etc.) plus the times of departure and arrival, place of departure and arrival, check in time/status, payment details, luggage details, and other general information.

If the Parliament does vote for rejection, it will be a big blow to the US and those in the EU who have been trying to set the rules for this data transfer. In fact, the PNR saga has been going on for about a decade now, since the US adopted its PNR regime in the wake of the September 11 attacks, setting penalties for airlines that refused to transfer the PNR data they collect (airlines collect PNR data for commercial purposes). This left EU airlines in the position where they would be punished by the US if they didn't hand over the data, and by EU data protection laws if they did. An agreement in 2004 fell foul of an ECJ judgment over the legal base used, and an agreement in 2007 was never assented to by the EP (as required under the Lisbon Treaty after December 2009), so it only applied provisionally. The European Parliament called for new agreements with the US (and Canada and Australia) to bring them more into line with data protection rights (the Committee voted to assent to the new Australian agreement in October).

There have been several concerns raised over the agreement, mainly on data protection grounds. In her report, in 't Veld highlights that the necessity and proportionality of PNR systems haven't been satisfactorily established - in fact, with the EU's own proposed PNR Directive, this is also the case (PDF) - when information gathering could be done on a smaller scale (e.g. via an API system that just covers passport and flight departure/arrival data); that the agreement does not limit the use of data to fighting terrorism and serious crime; that data does not have to be destroyed, but can be held indefinitely: despite its use being restricted over time, it could still be accessed and used. It is also pointed out that the agreement does not provide a sufficient protection against the use of sensitive data by the US Department of Homeland Security (data indicating race, religion, sexual orientation, etc); that there aren't sufficient guarantees that data will be equally well protected if it's transferred to another country from the US; and that the agreement might not provide EU citizens with adequate means of judicial address.

She says (PDF):

"The call for a coherent approach and a single set of principles to govern international agreements on the transfer of PNR data was an approach embraced by the Commission and the Council. However, the Agreement with the US differs fundamentally from this approach as well as from the Agreement with Australia, concluded on 13 December 2011. This Agreement was considered to be sufficiently consistent with the criteria set out by Parliament, while the Agreement with the US departs from the approach that had been agreed by the European Parliament, the Commission and the Council in 2010. Additionally, compared to the first EU US PNR Agreement of 2004, this 2011 Agreement even represents a deterioration on many points. Having in mind that the European Parliament sought annulment of the 2004 Agreement before the Court of Justice, your Rapporteur will recommend the European Parliament to decline to consent to the conclusion of the Agreement."


I hope the Committee votes for this report - the case for PNR regimes is quite shaky, with high levels of data collection from people who aren't suspected of any crime, for no proven gains in effectiveness over less invasive and data protection-compliant alternatives. Rejecting the PNR Agreement would be the second time this parliament that the EP has blocked an US-EU Agreement - the first being over SWIFT I (which prompted heavy lobbying by the US). Blocking this agreement would not only put an end to invasive data gathering, but also raise the profile of the EP and of the importance of data protection rights in the US's security dealings with the EU.

The report will be presented to the Committee at 15:00 CET. The Committee will vote on the report on March 20th, and the plenary will vote on the agreement in April.