Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Friday, 10 January 2014

European Parliament wants to question Snowden

The European Parliament's LIBE Committee's Inquiry into the Electronic Mass Surveillance of European Citizens is not due to be published in March, and the Committee has voted to question the whistle-blower Edward Snowden via video-link. However The Guardian has ran a story on the draft of the report in which the Inquiry says the actions of the NSA and the UK's GCHQ "appear illegal".

The draft report states (PDF; main findings start at p.16):

"[The Inquiry] Condemns in the strongest possible terms the vast, systemic, blanket collection of the  personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of the press, thought and speech, as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding the extra-territoriality of national laws

[...]

[The Inquiry] Stresses that, despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities."

(Points 9,and 60 of the main findings).

Along with calling for the US and EU Member States to prohibit blanket mass surveillance activities and demanding that the UK, France, the Netherlands, Sweden and Germany revise their national intelligence laws in line with the European Convention on Human Rights, the rapporteur, S&D MEP Claude Moraes (UK),  called for the SWIFT Agreement with the US to be put on ice.

The SWIFT Agreement allows for the transfer of financial transaction data to the US, and has come in for a lot of criticism. The first attempt at agreement failed, but the European Parliament voted through a second renegotiated SWIFT deal earlier during this parliament.

Tagesschau reports that the inquiry may show that French and German intelligence agencies have also been carrying out similar surveillance programmes. This is probably widely suspected anyway, but for a parliamentary inquiry to finger France and Germany after the outrage expressed by those two countries would be very embarrassing. It would be particularly uncomfortable for Merkel, who is seen to have reacted to the NSA Affair slowly, and due to the controversial nature of the EU's own data retention laws in the country.

The European Parliament report won't have any binding effect, but the Inquiry is a strong political statement. As well as being a fundamental issue that needs investigation, this is a ticket to the central political stage. Questioning Snowden would be a major coup and turn the Inquiry into an international event. Though the Inquiry overwhelmingly wants to question Snowden (only 2 UK Conservatives on the Committee voted against the proposal), it is depending on Snowden wanting to use the platform - something that the US Congress fears and has warned against. It's hard to see why Snowden wouldn't take this opportunity to state his case personally and publicly.


EDIT: Ralf Grahn drew my attention to the draft report online, so I've changed the blog to include links and some extracts to it.

Tuesday, 12 November 2013

The European Cloud - Europe's Response to the NSA Scandal?

Negotiations over the EU-US trade deal reopened yesterday, demonstrating that the NSA affair has not halted progress here despite the calls from the European Parliament for talks to be suspended. At the same time the Parliament's Civil Liberties, Justice and Home Affairs Committee (LIBE) continues to hold sessions on its inquiry into the spying allegations. Neelie Kroes, the Commissioner that heads the Digital Agenda policy, has said that while the spying revelations are shocking and unacceptable, the spying will probably continue - "Let's not be naive". Instead Kroes argues that Europe should focus on building its digital infrastructure and single market in the internet.

In the EU the spying scandal does not look like it will produce any sharp changes in policy direction, but rather an acceleration of existing policies as the Commission and others capitalise on the political fallout from the affair. For the Data Protection Regulation this has already meant a reversal of the bill's dilution that had been brought about under the influence of lobbyists, and for Kroes it means pushing the European Cloud.

The European Cloud Strategy was adopted by the Commission last year, aiming to boost European cloud computing by sorting through problems of technical standards, data portability, clear cloud computing contracts and user trust. The policy is mostly economically focused, noting that cloud computing can generate jobs and economic growth while providing opportunities for cost-cutting for small and medium businesses. However, cloud computing concerns issues of data protection as well as copyright issues. As the EU works through its data protection reforms, the fact that 85% of cloud computing services are US based will surely raise concerns not only over how much the EU needs to do to catch up in this market, but also over how effective European privacy rules will be in practice.

With European expert groups meeting on how to approach cloud computing contracts and a European Cloud Partnership mulling commercial strategy, the technical discussions seem removed from the headlines in the media, but the Commission probably does see this as part of the solution (as well as using the crisis to promote its policies). First, the Commission's strongest in the single market, so boosting European internet businesses so European consumers (and others) have an alternative to the US-based cloud is one of the few things they can actually do, so they would be naturally inclined to favour this policy. Second, the best way for Brussels to exert its regulatory power in an area (and one of the few ways it can exert any power) is to have a strong market in that area and then come up with high standards for it, setting the pace in the global marketplace.

In a sense, Kroes makes a good point. It is hard to imagine that the Franco-German push to put transatlantic spying on a "legal footing" will do much, if anything, to reduce actual levels of spying. Improving the market position of the EU would help provide an alternative and allow the EU to stamp its data protection philosophy on to the global economy more effectively - and the political impetus behind such an economic policy is unlikely to fizzle out as quickly as the focus on spying may do.

However, this isn't enough - we should and need to push more forcefully to ensure that security services here and in the US are more politically accountable. It is not enough that what they do is legal: after all, it would hardly solve the problem to provide that legal backing wherever it's currently lacking. Rather we need to have a more critical approach to the demands of security for ever more information and resources, and to have a real debate over how we balance safety and security and civil liberties.

Because while we can never have total security, we can run out of privacy.

Friday, 25 October 2013

EU reaction to the NSA Affair

The fallout from the NSA Affair and Snowden's leaks continue, with revelations that Angela Merkel's mobile phone was hacked causing worldwide headlines (though there's been some criticism of Merkel for taking so long over these allegations, and indications that the NSA has been spying on German citizens, seriously, as Der Standard pointedly notes with the headline "Und ploetzlich ist es ein Problem" ["And suddenly it is a problem"]). The Guardian is reporting that the number of tapped heads of government is probably much higher, and the European Council has finally been roused too - it turns out that prime ministers don't like to be spied on. Now everything from the halting of data-sharing agreements to cancelling the free trade talks is on the table (after all, it's much harder to negotiate if you're being spied on).

The European Parliament has also signalled its displeasure, voting for a motion calling for the end of the SWIFT agreement. It's not binding, and the Commission has responded by stating that there is no indication of wrong-doing under the SWIFT Agreement (or "Terrorist Financial Tracking Programme" - PDF). Parliament's issues with SWIFT aren't new to the NSA revelations, however. After a troubled birth (the Parliament voted down the first agreement before passing the second after lobbying from Vice-President Joe Biden), last year the report before Parliament on the implementation of the safeguards in the agreement caused disquiet - it turned out that the full report wasn't even made available to MEPs to review. (Notably, the European Data Protection Supervisor had criticised some of the key provisions of the draft SWIFT Agreement).

The Commission has said that the agreement has effective safeguards, and that it's waiting on the response to a request for reassurances from the US. It's not planning to suspend the agreement.

Martin Schulz, the President of the European Parliament has also said that the free trade talks with the US should be suspended in the light of the spying affair.

The most notable moves, though, probably come over the draft Data Protection Regulation. The European Parliament has adopted its position on the law this week, which has hardened. The subject of intense lobbying, the biggest impact of the Snowden-leak was to reverse the watering down of the proposed law, with the security of citizens' data in the hands of US companies a key concern. The bill still has a long way to go, and it has to be agreed with the Council before it can be signed into law.

But what does this all add up to? At the end of this week the EU still transfers the same kind of data to the US as at the start, and there is little coherence in the EU's position. Most demands amount to the suspension of agreements or negotiations, and it will take a while to see what actually comes out of this. If we are ever going to see better data protection standards and a more regulated approach to intelligence and police work, we have to have clear standards and guidelines on how we shape these laws. When it comes to the EU, a proper regard for the necessity and proportionality of proposed security laws within the EU and agreements with third countries has to be stressed. And the Commission must drop its deference of the security services if it is to enforce and monitor agreements - or even draw up laws.

Thursday, 25 April 2013

Draft EU PNR Directive voted down at Committee Stage

The LIBE Committee of the European Parliament has shot down the draft Passenger Name Record Directive by a vote of 30-25, with the Liberal, Green and left wing groups voting against and the conservative groups for the draft law. The Directive concerned the collection of the information passengers give to airlines when booking a flight by law enforcement authorities (in the form of national "Passenger Information Units (PIUs)" that would analyse the data and pass on information to other law enforcement authorities). The data would be collected to fight terrorism and serious crime, and is a key plank of the Commission's counter-terrorism strategy.

I wrote about the PNR Directive at length last year. The information gathered covers everything from the flight to the food you order, so the authorities would be casting a wide net. There would be some rights for people to have their data corrected or deleted, but:

"However the purposes for gathering and processing the data is so wide that it’s debatable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

[...]

 There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF)."

While the draft parliamentary report (by LIBE rapporteur Timothy Kirkhope [ECR Group]) clarified some issues with the original text, it did little to address the scope of both the data gathered and the purposes that it could be used for (without further restricting and defining these, it would be very difficult for the system to be held to account in that most uses for the data would be lawful and citizens would have little substance to their data rights).

The draft Directive could still go to the EP plenary, where the full European Parliament could still pass the law.

Tuesday, 22 January 2013

The Irish Presidency Work Programme

Ireland took over the presidency of the Council of the European Union at the start of the year, and last Wednesday Taoiseach Enda Kenny, leader of the Fine Gael-Labour (EPP-PES) coalition government, outlined the priorities of the presidency to the European Parliament. Sustainability, jobs and growth are the central mantra of the presidency, though the familar buzzwords didn't stop Kenny from attempting rhetorical flight in the Strasbourg chamber, enthusing about the European family.



In his speech to the European Parliament, Kenny outlined a large work programme, from CAP and CFP reform to collective copyright management and data protection. The Data Protection package is one of the biggest legislative changes and a flagship policy of the Commission. There's been worries that the law won't be passed before the parliament ends, causing the draft to lapse and the work to go to waste, so there will have to be a big push from the presidency to make progress here.

Interestingly, while he stressed the need to pass the 2-Pack of legislation (which I’ve written about here) and the importance of the European Semester, Kenny also expressed a willingness to engage with the Parliament on the democratic deficit – let’s see if any constructive measures make it to the statute books.

A major topic was, of course, breaking the link between sovereigns and banking debt, with the banking union and progress on the implementation of the Single Supervisory Mechanism. On trade, Kenny looked forward to the authorisation and opening of negotiations with the US, along with negotiations with Japan, Canada and ASEAN.

Finally, Kenny couldn't help plugging Ireland's big tourism campaign - The Gathering!
 

You can see a list of the measures behind these priorities here.

Tuesday, 25 September 2012

Reports of US breaching EU PNR Agreement

The transfer of Passenger Name Record Data - the information you hand over to airlines when you book a flight - from EU airlines to the US government has been a controversial issue in Brussels, with the transfers taking place for a decade on one basis or another without a satisfactory agreement in place to regulate it.

Earlier this year the European Parliament ratified an agreement with the US to regulate - and make legal in the EU - the transfer of this personal data to the US government for anti-terrorism and crime fighting purposes. I was against this agreement because it is spectacularly disproportionate and infringed privacy rights: data can be held for far too long (over a decade) for practically any purpose whatsoever. Sadly Sophie In't Veld's report advising rejection of the agreement was voted down in Committee and the Parliament ratified the agreement in plenary.

However it seems that the US hasn't been satisfied with even this gift of a treaty, with reports that the US government has been collecting data on people on flights that do not take off or land in the US, in contravention of the agreement. The S&D Group in the European Parliament has called on the Justice Commissioner Malmstrom to account for this before the LIBE Committee in Parliament:

"S&D spokesperson on civil liberties, justice and home affairs, Claude Moraes MEP, said:
 
"The media reports show that the US may be requesting data which falls outside the scope of the EU-US PNR agreement. We signed up to the agreement on strict conditions and we need clear answers if EU citizens' data is being collected contrary to spirit of the agreement.
 
"If our citizens' data is being collected for flights simply going through US airspace, then this could be against EU data protection laws. We are taking this matter very seriously and that is why the S&Ds have requested that Commissioner Malmström comes to the civil liberties committee to give MEPs a full picture of the situation regarding US collection of EU citizens' PNR data.""

It would not be the first time the Parliament has been disappointed by poor results from bad treaties.

Wednesday, 15 August 2012

A European SWIFT?: the Commission outlines available options

Just after the Lisbon Treaty came into force, the European Parliament used its new power to block the SWIFT Treaty with the US, which would give the US Department of Homeland Security access to financial transaction data for anti-terrorism purposes. The problem was there was no way of targeting suspected individuals and no judicial oversight: financial transaction information would be handed over in bulk (based on search categories) to the US government to search through.

After some changes (Europol gained the role of verifying the compliance of US requests under the treaty for data) and heavy lobbying that included a vice-presidential visit to the European Parliament, the EP voted through a re-negotiated treaty. Since then it turns out that the negotiated safeguards are wholly inadequate, with general data covering a global area for an essentially unlimited time being provided to the US DHS.

Part of SWIFT II was that the US would help the EU establish its own system (Article 11), and the Commission has published a communication on the options on setting up a European Terrorist Financial Tracking System (PDF). A more targeted approach to data collection is one of the aims of a European system, so that these systems are less intrusive into the privacy of citizens.

The Communication doesn't pick a particular option, and there will be an Impact Assessment based on a study the Commission contracted out in 2010. The Communication also promises that the Impact Assessment will pay particular attention to the necessity and proportionality of a European system and its impact on fundamental rights - given the poor use of statistics in the PNR proposals, I can't say I've much confidence in the quality of impact assessments in the area of justice and home affairs.


Goals:

Two main goals have been identified:

"• the system must provide an effective contribution to the fight against terrorism and its financing within the European Union;

• the system must contribute to limiting the amount of personal data transferred to third countries. The system should provide for the processing of the data required to run it on EU territory, subject to EU data protection principles and legislation."

A European TFTS could provide a useful extra tool in the fight against terrorism, and given the European basis of SWIFT (it's based in Belgium), designing a system that respects civil liberties and fundamental rights would have a positive knock-on effect in the EU's security relations with the US and other countries when it comes to finance tracking by ensuring that any transfers of data also comply with fundamental rights.

More specifically the system will cover:

"• preparing and issuing (legally valid) requests to the designated provider(s) of financial messaging services for the raw data to be provided to an authorised recipient or recipients. This involves determining the message categories to be requested, how often such messages should be sent, and maintaining contacts with the providers on these issues;

• monitoring and authorising requests to the designated provider(s) for such raw data. This involves verifying whether the request for the raw data have been prepared in accordance with the applicable limitations;

• receiving and storing (processing) the raw data from the designated provider(s), including the implementation of an adequate system of physical and electronic data security;

• running the actual searches on the data provided, in line with the applicable legal framework; on the basis of requests for such searches from authorities of the Member States, the U.S. or other third States on the basis of clearly defined conditions and safeguards, or on the own initiative of the authority (or authorities) entrusted with processing the data;

• monitoring and authorising the running of searches on the data provided;

• analysing the results of the searches, through combining these results with other available information or intelligence;

• distributing the results of the searches (without further analysis) or the results of the analyses to authorised recipients;

• implementing an appropriate data protection regime, including applicable retention times, logging obligations, handling requests for access, correction and deletion, etc."

Options (from page 9 onwards):

The Communication makes it clear that a hybrid solution is preferable to an exclusively national or exclusively centralised approach, so all of the options are designed along hybrid lines with differing degrees of (de)centralisation.

Option 1: A central EU TFTS unit as a coordination and analytical unit cooperating with national law enforcement authorities. Under this system most of the data work would be done at the European level with national requests to the central unit. Europol or Eurojust are possibilities for performing the central unit's role.

Option 2: EU TFTS extraction service option. This would be the same as option 1, but the central unit would not carry out analysis based on the extracted data for national requests (only for EU or third country requests), and requests would be verified at the national level.

Option 3: A Financial Intelligence Unit: there would be a European FIU platform which would request data from SWIFT and/or other data providers on the basis of national FIU needs. National FIUs would carry out the analysis, etc., for their Member State. The FIU Platform could deal with third country requests and for EU institutions.

The FIU model bears a striking resemblance to the Passenger Information Units envisaged by the current proposed Passenger Name Record Directive (PDF), so I'm guessing that something close to option three will be what we see in the draft law. going with this model will bring up a lot of issues regarding safeguards and oversight, and how data analysis is used, as well as what scope the FIU Platform will have for transfering data on to third countries. Some of these issues will also remain for the other options, but at first glance it looks like option 2 provides a system with clearer lines of responsibility that also ensures that the information is delivered to national experts who can then get on with the job.


Two key aspects for a European TFTS.

A European TFTS has to be a system of individualised searches. The processing of bulk data is essentially casting a wide net, with government rummaging through everything that's been dredged up, whether or not the data belongs to non-suspects. Developing a system capable of delivering individualised searches is necessary if the system is to be equipped with sufficient safeguards to protect civil liberties.

The second key aspect for a European TFTS is that searches need to be subject to judicial oversight in the Member States - law authorities should not be able to issue searches whenever they want, but they should have to get judicial permission (or an equivalent process in national law) for a search based on specific legal grounds. This would help prevent data mining (or similar practices such as what goes on under the current treaty) and ensure that there are strong safeguards. These aren't the only safeguards necessary - retention periods and how far analysis shifts into profiling are other issues that need to be considered when the studies and the legislative proposal come out - but they are necessary. If these basic elements are missing from any TFTS, then it should be rejected. (The Communication mentions that Europol as a possibility for a role in verifying requests for data under the system, despite not being a judicial authority by any stretch of the imagination).

The contracted study should be finished by the end of the year and I assume the impact assessment and proposal will be published in 2013.

Tuesday, 17 July 2012

“I feel that we’ve been had!” – Report on the SWIFT Agreement


Blow to civil liberties as PNR deal passes

 BY CC greenefa.

In 2010 the EU ratified an agreement with the US called the SWIFT Agreement (or more technically: the “Terrorist Financial Tracking Programme” – PDF), after the first agreement was vetoed by the Parliament, and despite privacy concerns remaining for the second agreement. The SWIFT Agreement permits the transfer of financial transaction information to the US government for the purpose of counter-terrorism. The problem is that you can’t ask for someone’s transaction information, but data is transferred in bulk to the US, where they search through the information to see if they can find out anything relevant to counter-terrorism. As a check, the second agreement stipulates that Europol must check that requests for transfers are in compliance with the agreement. Given that Europol could gain from any leads from the information, it’s not exactly the impartial check of a judicial body.

The LIBE Committee debated the Second Report on the role of Europol by the Joint Supervisory Body on 21/6/2012 (you can watch it here). The first report (PDF) found some serious failings, including:

- Due to the abstract nature of transfer requests, proper verification of whether the requests are in line with the conditions of the Agreement is impossible.
 - Information provided orally to Europol affects their decision making, but cannot be reviewed by the JSB. Whether the deficiency in information in the requests is remedied by oral information is impossible to verify.
- Significant involvement of oral information renders proper internal and external audit impossible.

Recommendations:

- Inform the JSB on the results of the review in policies and procedures for Europol’s role. - Ensure the ability of the Europol Data Protection Officer to carry out his role.
- Ensure hard-deletion of Article 4 data (data to the US where Europol has to verify their requests), which where inputted into some of Europol’s information processing systems before the upgrading of the security level.
- Contact the US Treasury Department and ensure that adequate information is provided with requests.
- Ensure verifications by Europol are made based on written requests, along with any supplemental documents, in order to allow for proper internal and external audit.

The Second Report notes that all US data requests to date have been approved and that some of the reasons are too generic. Many of the request applications included “copy and paste” texts and the information provided was out-of-date and already in the public domain, and oral information is still being provided to Europol in order for it to make decisions. Also, there is no geographic limitation to these requests (data concerning the whole world is requested), and the requests submitted on a monthly basis for a month in duration (so effectively data transfer is ongoing all year round with little limitation).

The JSB concluded that 2 of its recommendations from its previous report have been implemented, while progress is ongoing for the other 3. The EU and US have signed an agreement for a second person to be posted from the EU to the US Treasury Department to oversee the operation of the agreement. The Overseer currently in place has been involved in intensive on-the-job training, and has been in US Treasury briefings. Clearly continuous information is being provided on generic and incomplete information with little restriction, so it’s hard to see how the current system provides adequate safeguards.

The full report however is not publically available or even available to the MEPs on the LIBE Committee – when the Committee requested access to the report, the JSB said it had no objections, and that there was nothing sensitive in the report that would prevent it from being disclosed. However, Europol stated that disclosure would threaten operational interests, so the report has not been disclosed. You can find the JSB’s public statement here: PDF.

Sophie in’t Veld and Jan Albrecht weren’t impressed (Veld: “I feel that we’ve been had!”). Veld highlighted that the EP was assured that there would be no data mining, but that the current procedure – of continuous and almost unlimited access – is much worse and goes further than what Parliament had expected. Veld objected to the secrecy of the report, saying that the Committee cannot fulfil its role of scrutinising Europol and the Agreement properly on the basis of a “3 page summary”. Albrecht said that the demands of MEPs have not been met after 2 years of the agreement, adding that if we have a functional fundamental rights jurisdiction, we could get this taken down in court.

While the role of the Europol Data Protection Officer seems to have been strengthened, it hardly seems like there are any safeguards on the flow of financial transaction data to the US. Without a sunset clause on the agreement, the European Parliament is in a fairly weak position to act against the treaty or to demand amendments. We seen the trend of PNR treaties on passenger information lead to a bad proposal for EU PNR, and soon the Commission will propose a TFTS for the EU. We need to make sure that we don’t throw away our civil liberties for little or no security gain simply because law enforcement authorities want our information and data.

Thursday, 19 April 2012

EU-US PNR vote today

The European Parliament is going to vote in plenary today on the EU-US PNR Agreement (you can watch the debate here - it's on now), which will permit the transfer of passenger data (including credit card, luggage and meal choice details) from airlines to US authorities when flying to the US. Rapporteur Sophie in 't Veld's report recommended that the agreement be rejected due to a lack of guarantees that US authorities won't use the data for purposes other than the fight against terrorism and serious transnational crime, and because EU citizens will not have sufficient access to legal redress under the agreement.

However the LIBE Committee rejected this report and the EP is likely to accept the agreement, though the BBC reports that it may be by a thin majority. It seems that worries over the US bypassing the EU and making bilateral agreements with national governments and a sense that the EP has already made at least some display of strength over forcing a renegotiation have fed into the desire to vote for the agreement.

Friday, 30 March 2012

The Data Protection Regulation: a few thoughts

The Commission's proposed Data Protection Regulation (PDF) is a massive piece of legislation, and it touches many debates and issues: the right to be forgotten, the approach towards companies, what data protection really means to us as a society, the powers of the Commission, and the debates surrounding subsidiarity and having a comprehensive approach. I thought I'd note a few thoughts and impressions on the debate so far.


The Right to be Forgotten and what data protection means to us.

Data protection might be a right under EU Law (Article 8 of the Charter of Fundamental Rights), but it has a mixed profile across the EU. In some countries - particularly Germany; see this week's Der Spiegel for example - it is a prominent issue, but in others there isn't so much awareness. I think that this changes when you start to talk about the privacy issues behind the technical term "data protection" - how companies (such as Google and Facebook) process and use information on you, and how governments do the same for everything from welfare to law enforcement. It's about privacy, but it's also about the freedom of the individual in society: whether it is government or business, the individual shouldn't have their freedom in society unfairly limited because of how organisations collect and use data concerning them.

The EU is more advanced in many ways than the US when it comes to data protection/privacy, but there's also a debate on whether the EU is going too far, and if the EU just wants to turn the clock back to a privacy golden age or freeze privacy standards as they were before the internet. I personally think it goes deeper than a fear of the internet age - the principles of data protection can be found back in 1981 in a Council of Europe convention - and it's about a genuine cultural attitude to privacy.

A key debate about privacy and the internet age is the right to be forgotten (Article 17 in the proposal). Justice Commissioner Viviane Reding has recently said (in this week's privacy platform meeting) that it was part of the old 1995 directive on data protection (the law this regulation would replace), and that it was more a failure of the 1995 Directive that it couldn't be implemented properly. It's true that you could ask to have your data erased under the 1995 Directive, but the Regulation would impose an obligation for data controllers to try to contact those they may have transferred the data to, not to continue to publish or process it, so the right to be forgotten would be an innovation on the current law. Controllers only have to make a reasonable attempt to inform those they may have passed the data on to that the data subject has requested that their data be deleted, so they won't have to police the internet.

Should there be a right to be forgotten? I support a balanced right to be forgotten that respects the freedom of expression. Reding says that the right to be forgotten will only apply to data people themselves hand over, and it won't affect journalists or bloggers - but the proposal seems vague on this point, and there should be a more explicit attempt to balance the freedom of expression with data protection.


The Powers of the Commission.

As the proposal stands, there would be a LOT of delegated powers for the Commission, permitting the Commission to draw up some rules and definitions so that some articles can be implemented properly. This makes it difficult to know what parts of the Regulation will mean in practice. For example, Article 17(9) would give the Commission the power to draw up specific rules for the right to be forgotten in certain sectors - so the scope of the right to be forgotten can't really be explained on the basis of the current provision. Perhaps this is the provision Reding means when she says journalists will be exempt. With at least 26 such delegated powers (I haven't done a thorough count), it seems a sloppy approach to law-making by the Commission.


Subsidiarity and the Comprehensive Approach.

The Regulation won't cover the processing of data in the area of freedom, security and justice (this will be done by a proposed directive), a split in the general data protection framework that has been criticised by the European Data Protection Supervisor (PDF), among others, but both the Regulation and Directive will ensure that data protection rules apply to all data processing, not just for data that will cross borders. This has provoked a debate on subsidiarity: should all processing be covered; should the public sector be covered? Rather than a Regulation - which would mean a single, directly applicable law for the private and public sectors (except for justice and policing) - some call for a directive, so that Member States have more freedom to implement the law.

It's interesting to see the debate on subsidiarity around this law - I haven't seen much political debate on subsidiarity yet - and it seems that the implementation and legislation for rights is a key question for subsidiarity (traditionally the constitutional courts of Member States are keen to defend their role as guardians of citizens' rights, which may entail the trumping of EU law by national law). Practically, it doesn't make sense to have 27 differing laws on data protection since the added value for the internal market and citizens' rights is to have the same high standard everywhere with clear uniform rules on those data protection rights can be exercised. And when you consider the impact of globalisation on data protection, having a single EU standard that can be defended and promoted globally makes sense in the long term when it comes to protecting our privacy laws. In addition, Article 16(2) TFEU gives the EU a more general legislative power/legal base on regulating data protection than simply in connection with the internal market, which is pretty unique when it comes to fundamental rights, so the institutions have a few cards in their favour to play for harmonisation.


There may be a consensus on the need for updated data protection laws, but there's still plenty of room for argument.

Wednesday, 28 March 2012

Report on EU-US PNR Treaty rejected in Committee

Sophie in ‘t Veld’s (ALDE) report to the LIBE (Civil liberities, justice and home affairs) Committee was rejected yesterday. The report to reject the EU-US treaty failed in a vote of 23 votes for, 31 against, and 1 abstention.

The PNR treaty will confirm the transfer of passenger data on flights to the US to the Department of Homeland Security. In ‘t Veld had urged rejection of the treaty for several reasons, but chief among them was the loopholes which permitted the data to be used for unspecified purposes outside the treaty’s aim of fighting terrorism and serious transborder crime.

It’s likely that the EP will assent to the treaty in plenary now, avoiding a clash with the US similar to over the SWIFT I treaty.

Wednesday, 29 February 2012

The EU's PNR Directive in Parliament

As well as Sophie in ‘t Veld reporting on the proposed EU-US PNR Agreement on Monday, Timothy Kirkhope (ECR) presented his draft report on the EU’s own Passenger Name Record regime. The PNR Directive is technical, but it involves a huge amount of data collection on people not suspected of a crime, and the processing of data to create models used to identify unknown criminals. The law poses major questions on data protection, and there are also issues of how necessary and effective the system is, and how much of the costs airlines (and therefore consumers) will bear to pay for the system. I’ll divide this post into outlining and discussing the proposed directive and briefly looking at Kirkhope’s report to the Committee on civil liberties, justice and home affairs.

The PNR Directive.

The proposed PNR Directive (PDF) would introduce a system where a wide range of data gathered by airlines on passengers on flights into and out of the EU would be processed for the purposes of fighting terrorism and serious transnational crime. The data gathered includes the information on passports, flight arrival and departure times and destination, check in status, payment details, address and contact information, frequent flyer information, travel agent, travel itinerary, general remarks (including information on unaccompanied minors and their guardian’s contact details and relationship to the minor), seat number, baggage information, code share information, ticketing field information, and date of reservation/issue of ticket. This data would be collected from everyone on flights into and out of the EU regardless of whether or not they’re suspected of a crime and without distinction to how susceptible an air route is judged to be to use for terrorism of serious transnational crime (also the UK has suggested an amendment for the latter). This raises questions of proportionality.

PNR data is to be used in three different ways: re-actively, in real time, and pro-actively. The re-active use of PNR data is the use of data in the investigation or prosecution of a crime which has already taken place; use of PNR data in real time entails the use of data to arrest or place an individual under surveillance for a crime being committed or about to be committed; and the pro-active use of PNR data is using PNR data to build up criteria against to identify persons worthy of further surveillance or action. “Serious transnational crime” isn’t really harmonised by the Directive – it uses the list of crimes in the European Arrest Warrant, but Member States can decide to exclude some of these crimes from their transposing legislation if they think one is too “minor” – so the Directive can’t even decide what’s a “serious crime”!

The data is transferred by airlines to “Passenger Information Units” (PIUs) that will be set up to process and analyse the data, and alert national law enforcement agencies if necessary. PIUs can be national, or countries can set up joint PIUs if they want to share the costs. (The vast majority of EU Member States don’t have a PNR regime, so this PNR Directive will effectively introduce PNR systems into most Member States for the first time). The data will be retained for 30 days, after which it will be “depersonalised” (identifying data removed, but not deleted so it can still be restored and used) and retained in this masked state for a further 5 years. Data can be kept for longer if it’s used in criminal investigations or prosecutions. 5 years seems disproportionate if the data isn’t being used in an investigation or prosecution – and even the Council’s own legal service has suggested a maximum retention period of 2 years ("Draft Agreement on the Use of Passenger Name Records (PNR), Note for the Attention of Mr Stefano Manservisi Director General, DG Home, European Commission Legal Service, SJ.f(2011)603245, 18/5/2011").

Data subjects (people who own data that is being stored or processed) have rights of access, rectification and erasure, and the National Supervisory Authorities set up under EU data protection legislation (Framework Decision on Data Protection) monitor the PIUs’ use of data and assist data subjects with their requests to exercise their rights. However the purposes for gathering and processing the data is so wide that it’s debateable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF).

So PNR faces a lot of questions on several fronts: is it necessary, does it work, are there cheaper and less invasive alternatives? So how does the draft report in the Committee deal with this?


Timothy Kirkhope’s report.

The draft report (PDF) has contains a long list of proposed amendments to the directive (it should be noted that the report is open to amendments from the Committee before it votes on the report as a whole).

Some of these amendments would clarify the scope of the Directive – by stating that it applies to airlines incorporated in the EU and that store data in the EU, and expanding the Directive to include intra-EU flights as well as flights entering and leaving the EU. By including intra-EU flights, there would obviously be a much, much greater amount of data gathered on people. In Committee it was explained that the Commission wanted the Directive to avoid including intra-EU flights so it could test the system out first (the Directive includes provision for a review in 5 years on whether to include intra-EU flights), while Kirkhope countered that gradual introductions of schemes rarely work in his experience. The costs of transferring data to the PIUs would be borne by the airlines, while Member States would pay for the PIUs and their work. Kirkhope said that the estimated costs that would be passed on to consumers in ticket prices would be between 10 to 18 cents.

The report’s amendments insert provisions regulating the transfer of data between Member States to ensure that safeguard standards are maintained and that data is only shared in certain circumstances. There are also new provisions to more extensively regulate the transfer of data to third countries, though the assessment is still left to Member States so there isn’t a common decision on the adequacy of a third country’s data protection standards like there is for internal market matters.

The amendments would also clarify the state of data after the initial 30 day period – the Directive uses the phrases “masked” and “anonymised”. Unfortunately, the draft report decides to simply change the phrasing to a more unified “masked” terminology rather than changing the procedure so identifying data will be deleted after 30 days. Some amendments do aim to strengthen data protection by setting down punishment for data breaches such as demotion, denial of system access, formal reprimands, and removal form duty, as well as an obligation to inform data subjects that might be affected by a data breach. National Supervisory Authorities would be given powers to take disciplinary action against persons responsible for a privacy breach, increasing their powers of independent oversight.

Kirkthorpe believes that the use of a PNR regime is necessary and proportional. While the necessity of the Directive is probably best debated by the Committee and whole Parliament, there are still questions over how proportional the Directive would be even with the report’s amendments, particularly over the targeting (or lack of targeting) of air routes, the oversight of creating and use of objective assessment criteria, and the length of the retention period. It does provide some good improvements to people’s rights to access, rectify and erase their data and makes it easier and more effective to exercise these rights (though the problem of the content of these rights given the wide use of data remains).

I’m very sceptical of the necessity for a PNR system – a lot of the analysis backing up the proposal seems to be based on numbers on the increase of crime together with rhetoric on fighting crime and anecdotal examples of how PNR could be used, rather than an analysis of the benefits of PNR versus the existing EU databases. It seems that we are being asked to accept the creation of a massive information gathering system on trust, and I’m not convinced.

Friday, 10 February 2012

The Anti-Counterfeiting Trade Agreement

I once had a work experience were I had to read through several contracts selling and assigning the right to turn a book into a TV programme and then give a presentation on who owned/did/does what. I'd only done a year at university and hadn't covered contract law or intellectual property law, so I was given a few textbooks on contract law and on copyright. As well as being one of the most interesting work experiences I ever did, it's also the only time I did anything to do with intellectual property law - while I was interested to read ACTA (PDF), I was a bit wary since I don't have the time to read into all the surrounding legislation and the debate on IPR. I do agree with this article over at The Atlantic, though: while some of the claims against ACTA might be a bit overblown, the trend in international IPR law is worryingly focused on the enforcement side, and ratcheting up enforcement standards without ever adapting to the issues brought up by our digital age. (A major debate is on whether copyrights do in fact encourage innovation and investment, or if the current laws actually detract from such innovation).

ACTA has rightly caused a huge reaction from the public, and the Party of European Socialists has come out attacking the treaty( PDF):

"The Party of European Socialists considers the Anti-Counterfeiting Trade Agreement (ACTA) to be fundamentally flawed in both content and process. There is a severe imbalance between the rights attributed to the users, service providers and rights holders.

The agreement, which is to be voted on by the European Parliament before summer 2012 and ratified by National Parliaments, is flawed in content for the following reasons; it gives undue power of oversight to internet providers; it infringes the privacy of internet users; and it will curtail developing countries access to generic medicines. It is flawed in process because of the secret manner in which the accord was agreed upon, and because of the significantly reduced time afforded to the European Parliament to scrutinise the final draft."


I haven't been able to find the positions of any other Europarties yet, but if you know them, let me know in the comments.

ACTA itself seems to raise a few questions over due process and the role of Internet Service Providers in policing IPR (which has serious implications for privacy and data protection - though it should be stressed that the actual role of ISPs would be decided by domestic legislation and ACTA does not require ISPs to take on a policing role). The EU has signed up to ACTA along with its Member States, but it has yet to be ratified and the European Parliament will make its decision this summer. The explanatory memorandum to the agreement makes clear that the Commission considers the agreement as adding noting new to current EU law on IPR, while leaving any additional obligations for judicial enforcement to be carried out by Member States as parties to the treaty. This doesn't strike me as a reason to be reassured by ACTA: if our legislation already goes further than ACTA, then where does that leave all our talk on this side of the Atlantic about being more enlightened about IPR and the internet? We still may have the safe harbour provisions that SOPA attacked, but ACTA clearly underlines that our approach is guided by a similar philosophy rather than being subjected to a serious debate about how the internet and digital media have changed the environment for IPR and how we should adapt (not to mention the price we might pay in terms of privacy and free speech to enforce these ever stricter laws).

So while not every evil assigned to ACTA finds backing in its vague provisions, it is another important step in the development of our IPR laws. We should take this opportunity to ask our MPs and MEPs to debate not just ACTA, but our approach to IPR in general. It's more than just this agreement.

You can sign the petition against ACTA here.

Also, Grahnlaw has been providing good coverage of this issue (see here, here and here for examples).

Wednesday, 18 January 2012

What legal action is the Commission taking against Hungary?

The Commission has announced that it will be taking legal action against Hungary, but only so much can be done under EU law. While people point out that:

"Viktor Orbán's regime combines the extreme centralisation of economic assets (including the expropriation of the private pension funds, of several public foundations and the forthcoming centralisation of the municipal government's assets) and the monopolisation of power in a single party that intends to dominate every aspect of social and private life, turning citizens into subjects. The improvised nature of many of the new laws creates a wide margin for arbitrary decisions that increase dependence and insecurity.

In addition to a frontal attack on civil liberties, the government has redistributed economic assets (particularly through the tax system and investment allocations) in favour of interest groups close to Fidesz and a restricted layer of the well-to-do. This group zealously defends the party's power and executes its guidelines.

At the same time – through the unilateral rewriting of the labour code, the restriction of union action and collective bargaining rights, the radical dismantling of social welfare nets and independent social care institutions – the government exposed the most vulnerable social groups (the poor, the unemployed, Roma, pensioners, sick and handicapped) to the unfolding economic crisis. Life is precarious for those who live on wages and have no reserves or additional revenue."


...the Commission doesn't have the jurisdiction (and neither does the European Court of Justice) to take Orban's government to task over all these issues. The Commission has decided to focus on the areas of the independence of the judiciary, the independence of the central bank, and the independence of Hungary's data protection authorities: probably because the EU legal case is strongest here. Let's look at some of the reasons behind the legal action:

"1) Independence of the national central bank

"The Commission has identified several breaches of primary law, notably breaches of Article 130 TFEU stipulating full independence of the central bank and of Article 127(4) TFEU requiring consultation with the ECB "on any draft legislative provision in its field of competence".

•Article 130 TFEU states that: “neither the ECB, nor national central bodies, from bank … shall seek or take instructions from Community institutions or any government of a Member State or from any other body”.

•Article 127(4) TFEU stipulates that "the ECB shall be consulted […] on any draft legislative provision in its field of competence"

Moreover, 14.2 of the Statute of the European System of Central Banks and of the ECB as well as Article 4 of Council decision (98/415/EC) on timely consultation of the ECB were not respected. On a number of elements, the Commission has invited the Hungarian authorities to provide clarification.

The infringements identified in the letter of formal notice concern both the MNB law ('Magyar Nemzeti Bank') but also the new constitution.

Under the MNB law, the Minister can participate directly in the meetings of the Monetary Council, offering to the government the possibility to influence the MNB from the inside. Similarly, the agenda of MNB meetings needs to be sent to the government in advance, thus impeding its capacity to hold confidential discussions. Also, changes in the remuneration scheme for the Governor are made again immediately applicable to the incumbent, while they should apply only as of a new term to avoid using salaries to put pressure on the MNB. Finally, the Governor and the members of the Monetary Council have to take an oath (of fidelity to the country and its interests) whose text is problematic given that the Governor of the MNB is also a member of the General Council of the ECB.

The Commission has doubts on the rules of dismissal for the Governor and the members of the Monetary Council which are prone to political interference (even the Parliament can propose to dismiss a member of the Monetary Council) and possible misuse. Also the frequent changes of the institutional framework of the MNB raise doubts, for instance via the increase in the number of Monetary Council members together with the possibility of increasing the number of deputy governors without due consideration of the MNB’s needs.

Moreover, a constitutional provision regulates the possible merger of the MNB with the financial supervisory authority. While the merger is not a problem as such, the MNB Governor would become a simple deputy chairman of the new structure, which would structurally encroach on his independence.

2) Independence of the judiciary

The infringement case affecting the judiciary focuses on the new retirement age for judges and prosecutors and relates to Hungary's decision to lower the mandatory retirement age for judges, prosecutors and public notaries from 70 years to the general pensionable age (62 years) as of 1 January 2012.

EU rules on equal treatment in employment (Directive 2000/78/EC) prohibit discrimination at the workplace on grounds of age. Under the case-law of the Court of Justice of the EU, an objective and proportionate justification is needed if a government decides to reduce the retirement age for one group of people and not for others. This principle was affirmed when the Court ruled on 13 September 2011 that prohibiting airline pilots from working after the age of 60 constitutes discrimination on grounds of age.

In Hungary's case, the Commission has not found any objective justification for treating judges and prosecutors differently than other groups, notably at a time when retirement ages across Europe are being progressively increased and not lowered. The situation is even more legally questionable because the government has already communicated to the Commission that it intends to raise the general retirement age to 65.

As regards the independence of the judiciary, the Commission is also asking Hungary for more information regarding new legislation on the organisation of the courts. Under the law, the president of a new National Judicial Office concentrates powers concerning the operational management of the courts, human resources, budget and allocation of cases. There is no longer collegial decision-making of the operational management of the courts or other appropriate safeguards. One person alone now makes all important decision on the judiciary, including as regards the appointment of judges. In addition, the mandate of the former president of the Supreme Court, who was elected for six years in June 2009, was prematurely terminated at the end of 2011. In contrast, other former judges of the Supreme Court continue their mandate as judges of the new Curia, which has replaced the Supreme Court. The Commission expects detailed answers of the Hungarian authorities to be able to decide whether further infringement proceedings are needed.

3) Independence of the data protection supervisory authority

The case on the data protection supervisor relates to Hungary's recent decision to create a new National Agency for Data Protection, replacing the current Data Protection Commissioner's Office as of 1 January 2012. As a result, the six-year term of the Data Protection Commissioner currently in office, who was appointed in 2008, will be prematurely put to an end. There are no interim measures until the term of the current Commissioner's term ends in 2014.The new rules also create the possibility that the prime minister and president could dismiss the new supervisor on arbitrary grounds.

The independence of data protection supervisors is guaranteed under Article 16 of the Treaty on the Functioning of the EU and Article 8 of the Charter of Fundamental Rights. In addition, EU rules on data protection (Directive 95/46/EC) require Member States to establish a supervisory body to monitor the application of the Directive acting in complete independence. This has been confirmed by the Court of Justice. In its ruling in a case concerning Germany (C-518/07 of 3 March 2010), the Court underlined that data protection supervisory authorities have to remain free from any external influence, including the direct or indirect influence of the state. The mere risk of political influence through state scrutiny is sufficient to hinder the independent performance of the supervisory authority's tasks, the Court ruled."


The outcry over what is going on in Hungary has been very political - in the sense that it's been about the high politics of rights and what makes a fair democracy - and rightly so. The Commission's response reveals the nature of the EU's power when it comes to protecting these key rights: as an organisation of sovereign Member States, the EU can only act where the Member States have contravened EU law. The EU treaties don't define a specific governing structure that Member States have to have, such as a presidential or parliamentary system or how their judiciary is organised (though it does set human rights and democratic tests for candidates to pass before they join), so the points of EU law can be quite narrow. This is especially obvious when it comes to the Commission's action over the judiciary laws - the action focuses on the unfair dismissal of serving judges, rather than the general separation of powers between the judiciary and the executive. The press release references these wider questions and demands answers, but whether or not there will be further legal action depends on whether or not the measures breach EU law.

The Commission (and the EU) is therefore not well placed to become a crusader for liberal democracy in its Member States, so there's a limit to what we can expect. The EU can, however, remove Hungary's EU voting rights via Article 7 TEU as a last resort, but this would require a super-majority. The Commission should investigate the changes to the electoral system and judiciary with an eye to using Article 7 if Hungary refuses to reverse any abuses. While the EU and the Commission's power might be limited (and we need to bear this in mind when Hungary claims it has changed its judicial rules in line with EU requirements), we should demand that all Member States live up to minimum democratic standards if they want to stay in the EU.

Today the European Parliament will be debating the Hungarian situation.

Wednesday, 30 June 2010

The Email Incident of 7th December 2007

The Activity Report of the Joint Supervisory Body of Eurojust for the year 2009 (PDF) was sent to the Council last week. I was taking a look through it to see if there was anything on preparations on data protection, particularly on anything SWIFT-related towards the end of 2009. The report does mention co-operation between Europol and Eurojust, and that the Lisbon Treaty will impact on data protection - however, the analysis of the impact of data protection provisions in the treaties will be in next year's report.

A section heading did jump out at me, though - "Email Incident of 7th December 2007":

"...a disruption of the e-mail service at Eurojust had taken place on 7 December 2007, as a side effect of an attempt to solve a problem caused by an accident in the use of the system the previous day. This incident had been investigated by the JSB in 2008 and a report presented to Eurojust. Eurojust’s final response to the JSB’s evaluation... was presented by the Acting Administrative Director of Eurojust, Mr Jacques Vos, at the meeting in February 2009. He outlined the measures that were being taken by Eurojust on the basis of the JSB’s recommendations to restore the trust of users in the integrity and inviolability of the e-mail system. Eurojust admitted that mistakes in judgement had been made at the time and recognised the considerable operational consequences that this incident created, but it was hoped to put this issue aside, to learn from it, to follow the JSB’s recommendations and to be better prepared to deal with future incidents."


What happened? Was it just a downed system? A hacker? Was information lost?

I looked up the previous year's report to see if it could shed more light on what exactly happened and what recommendations were made. The 2008 report (PDF) stated:

"Upon the request of the President of Eurojust, an ‘on the spot’ check was carried out at Eurojust on 17 March... The members of staff involved in this incident were interviewed and the log files were inspected. Subsequently, a report was submitted to the College of Eurojust on 24 April making several recommendations."


The report? "Confidential document."

It sounds like a security matter rather than a simple system failure, though I can't say for sure. I wonder how much information was lost, and how sensitive it was?

Tuesday, 29 June 2010

SWIFT II: European Data Protection Supervisor's Report to Council

The European Data Protection Supervisor yesterday sent a report (PDF) on the SWIFT II agreement (or TFTP agreement) to the Council. Given the criticism of the agreement from Parliament (though there is recent news of some agreed compromise), the EDPS report is interesting.

For example, at paragraph 5, the EDPS notes that the proposal does not see Article 16 TFEU (on data protection) as a legal basis, though the agreement and proposal note the data protection concerns. The report tersely notes: "...the EDPS reiterates that this agreement not only relates to the exchange of personal data, but also to the protection of these data. Article 16 TFEU is therefore not less relevant as legal basis than Articles 82 and 87 TFEU relating to law enforcement cooperation that have been chosen as legal bases."

The scope for future agreements on data protection and for a general agreement between the US and EU on data protection is discussed as well, particularly in paragraph 8. The EDPS recommends that the current proposal (agreement) be amended so that if there's a general agreement on data protection, it will apply - or at least get an agreement that it would apply to TFTP circumstances.

The EDPS takes a look at the question of privacy rights and the security question through explicitly rights-based language (Para 15):

"15. Against this background, the Commission proposal highlights the usefulness of the TFTP Programme, as put forward by the US Treasury and by the eminent person's reports. However, the condition laid down by Article 8 ECHR in order to justify interference with private life is "necessity" rather than "usefulness"."


The report goes on to flag up the same concerns that the agreement's critics in Parliament have highlighted: the retention of data for up to 5 years regardless of whether it's been extracted or if there's a "proved link with a specific investigation or prosecution.", and bulk transfers are the big concerns. In fact, paragraph 20 urges for a transitional approach to bulk data if it is to be used at all:

"...EDPS believes that solutions should be found to ensure that bulk transfers are replaced with mechanisms allowing financial transaction data to be filtered in the EU, and ensuring that only relevant and necessary data are sent to US Authorities. If these solutions could not be found immediately, then the Agreement should in any event strictly define a short transitional period after which bulk transfers are no longer allowed."


Also worth higlighting is the whithering criticism for handing the judicial oversight role to Europol:

"25. Moreover, Europol has specific interests in the exchange of personal data, on the basis of the proposed agreement. Article 10 of the proposal gives Europol the power to request for relevant information obtained through the TFTP, if it has a reason to believe that a person or an entity has a nexus to terrorism. It is hard to reconcile this power of Europol, which may be important for the fulfilment of Europol's task and which requires good relations with the US Treasury, with the task of Europol to ensure independent oversight.

26. Furthermore, the EDPS wonders to which extent the current legal framework entrusts Europol - especially without changing its legal basis pursuant to the ordinary procedure established by the Lisbon Treaty - with the tasks and powers to make an administrative request coming from a third country "binding" (Article 4.5) on a private company, which will thus become "authorized and required" to provide data to that third country. In this context it is useful to note that it is under the present state of EU law not evident whether a decision of Europol vis-à-vis a private company would be subject to judicial control by the European Court of Justice."


The report also criticises some aspects of the personal rights under the agreement when it comes to the correction/deletion of information. (As it's already turning into a long post, I'll let you read it [paragraphs 28-33], but it raises questions over the ability of people to exercise these rights). The EDPS also urges the inclusion of a sunset clause in the agreement to help encourage sustained work towards improving data protection under its provisions.

Overall the report echoes the concerns of the critical EP voices, while welcoming the changes make since SWIFT I. How much of an impact will it have in the Council? It's hard to tell how wedded the Member States are to the agreement, though it's interesting to note that the report mentions that the German Constitutional Court (Bundesverfassungsgericht) considers the retention of data over 6 months to be excessive, so it is possible that some Member States could share worries over the diminution of privacy rights of their citizens. What will be the extent of any agreed amendments be? Hopefully these clear calls will have a positive impact.