Showing posts with label justice and home affairs. Show all posts
Showing posts with label justice and home affairs. Show all posts

Tuesday, 4 February 2014

Stripping Citizenship

Last week the UK House of Commons voted on an amendment to the Immigration Bill that would empower the Home Secretary to strip foreign-born terrorist suspects of their UK citizenship, even if it would render them stateless. (Those with dual citizenship can already be stripped of their British citizenship). The amendment reads (p.3):

"(4A) But that does not prevent the Secretary of State from making an order under subsection (2) to deprive a person of a citizenship status if—
(a) the citizenship status results from the person’s naturalisation, and
(b) the Secretary of State is satisfied that the deprivation is conducive to the public good because the person, while having that citizenship status, has conducted him or herself in a manner which is seriously prejudicial to the vital interests of the United Kingdom, any of the Islands, or any British overseas territory.”

The decision doesn’t have to be made following a court ruling and it isn’t made by a court – it’s made by the Secretary of State herself. The amendment was proposed by the Home Office Secretary of State, Theresa May, and was reportedly aimed at drawing Tory back-benchers away from an amendment that would have limited criminals up for deportation’s ability to rely on the right to family life under the European Convention on Human Rights. That amendment was defeated with the help of Labour and the Liberal Democrats.

The vote is another example of how difficult it is for Cameron to control his back bench, which will be worrying for him come the European elections. At the moment the Conservatives are expecting to come behind UKIP in the May poll, but even with that factored into their calculations, the back benches may take the result as a spur to become even more rebellious.


Disappointingly, the anti-immigration rhetoric has meant that the other parties have failed to take a firm stand on the issue of taking away citizenship. On Question Time on Thursday, the Labour and Lib Dem representatives weren’t able to give a clear “yes” or “no” on whether or not they supported the idea. UK politics seems to be stuck on an illiberal course…

Friday, 10 January 2014

European Parliament wants to question Snowden

The European Parliament's LIBE Committee's Inquiry into the Electronic Mass Surveillance of European Citizens is not due to be published in March, and the Committee has voted to question the whistle-blower Edward Snowden via video-link. However The Guardian has ran a story on the draft of the report in which the Inquiry says the actions of the NSA and the UK's GCHQ "appear illegal".

The draft report states (PDF; main findings start at p.16):

"[The Inquiry] Condemns in the strongest possible terms the vast, systemic, blanket collection of the  personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of the press, thought and speech, as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding the extra-territoriality of national laws

[...]

[The Inquiry] Stresses that, despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities."

(Points 9,and 60 of the main findings).

Along with calling for the US and EU Member States to prohibit blanket mass surveillance activities and demanding that the UK, France, the Netherlands, Sweden and Germany revise their national intelligence laws in line with the European Convention on Human Rights, the rapporteur, S&D MEP Claude Moraes (UK),  called for the SWIFT Agreement with the US to be put on ice.

The SWIFT Agreement allows for the transfer of financial transaction data to the US, and has come in for a lot of criticism. The first attempt at agreement failed, but the European Parliament voted through a second renegotiated SWIFT deal earlier during this parliament.

Tagesschau reports that the inquiry may show that French and German intelligence agencies have also been carrying out similar surveillance programmes. This is probably widely suspected anyway, but for a parliamentary inquiry to finger France and Germany after the outrage expressed by those two countries would be very embarrassing. It would be particularly uncomfortable for Merkel, who is seen to have reacted to the NSA Affair slowly, and due to the controversial nature of the EU's own data retention laws in the country.

The European Parliament report won't have any binding effect, but the Inquiry is a strong political statement. As well as being a fundamental issue that needs investigation, this is a ticket to the central political stage. Questioning Snowden would be a major coup and turn the Inquiry into an international event. Though the Inquiry overwhelmingly wants to question Snowden (only 2 UK Conservatives on the Committee voted against the proposal), it is depending on Snowden wanting to use the platform - something that the US Congress fears and has warned against. It's hard to see why Snowden wouldn't take this opportunity to state his case personally and publicly.


EDIT: Ralf Grahn drew my attention to the draft report online, so I've changed the blog to include links and some extracts to it.

Thursday, 25 April 2013

Draft EU PNR Directive voted down at Committee Stage

The LIBE Committee of the European Parliament has shot down the draft Passenger Name Record Directive by a vote of 30-25, with the Liberal, Green and left wing groups voting against and the conservative groups for the draft law. The Directive concerned the collection of the information passengers give to airlines when booking a flight by law enforcement authorities (in the form of national "Passenger Information Units (PIUs)" that would analyse the data and pass on information to other law enforcement authorities). The data would be collected to fight terrorism and serious crime, and is a key plank of the Commission's counter-terrorism strategy.

I wrote about the PNR Directive at length last year. The information gathered covers everything from the flight to the food you order, so the authorities would be casting a wide net. There would be some rights for people to have their data corrected or deleted, but:

"However the purposes for gathering and processing the data is so wide that it’s debatable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

[...]

 There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF)."

While the draft parliamentary report (by LIBE rapporteur Timothy Kirkhope [ECR Group]) clarified some issues with the original text, it did little to address the scope of both the data gathered and the purposes that it could be used for (without further restricting and defining these, it would be very difficult for the system to be held to account in that most uses for the data would be lawful and citizens would have little substance to their data rights).

The draft Directive could still go to the EP plenary, where the full European Parliament could still pass the law.

Friday, 16 November 2012

Police Commissioner Elections and Devolution

Yesterday I voted in the Police and Crime Commissioner elections in England and Wales. The Police and Crime Commissioners will take over the role of the police authorities, through which local council members and independent members. The PCCs will control the budget of the police force and be able to hire/fire the chief constable. They will also set local policing priorities.

The idea for PCCs was presumably partly inspired by the de facto firing of chief constable Ian Blair in London by London mayor Boris Johnson, and the desire to bring the police under local democratic control. While I think there should be democratic oversight of the police, it's wrong to politicise policing so directly - it would be better for democratically elected councils with several responsibilities to hold the police accountable rather than a directly elected individual to do the job.

The campaign hasn't grabbed the national imagination - or the local for that matter - and in general the candidates have stressed that policing will stay independent, so there hasn't been the politicisation of policing that opponents to the plan, like me, feared. But with the powers of the office limited to setting the overall vision of the police, deciding on the chief constable, and making budgetary decisions where the PCC has little control beyond allocating the resources given to him/her, in the future the PCCs are likely going to turn into super-powered elected lobbyists for their policing region, lobbying for more money for more police. To some extent this has happened with the position of London Mayor, so it seems more likely to happen to this smaller office.

It would be better for local democracy to decide on the size of the area that's best suited to bringing decision-making in general closer to people without it being too far removed. If bigger local councils or regional assemblies could decide on matters such as policing and also have some control over the purse strings, then it would give people more control and responsibility over how to approach policing locally. This could be part of a more general devolution of power locally, though this runs up against the unpopularity of regionalisation in England.

Empowering local democracy is a good aim, and some lobbying for the local area is a good thing - after all, MPs are supposed to represent their constituency in the national debate on issues and bat for it - but it needs to have some rational structure that allows people to engage fully with what the priorities across several local issues should be. Proper devolution would create bodies big enough to take on responsibility for their areas and have the power to make substantive decisions, without being too far removed (a tough balance). This would open up a more engaged local debate and boost turnout, rather than creating a English and Welsh political landscape that's littered with elected offices of varying sizes with little rhyme or reason as to how they join up to make streamlined, effective and accountable local government.

Wednesday, 17 October 2012

Why not have a referendum on justice co-operation?

In the UK the Conservatives have been blundering about with EU policy again. Home Secretary Theresa May, who talked about rolling back the free movement of people not so long ago, is now talking up the possibility of the UK opting out of the area of freedom, justice and security altogether. The coalition LibDems have not exactly killed the idea, but pulled the rug from under May when he said that no decision had been made, leaving May to provide the House of Commons with an empty statement about the government's "current thinking".

There's a lot of comment about how short-sighted it is to pull out of justice co-operation, and on how the Conservative approach to the EU has been a shambolic case of issuing announcements with little thought and then scrambling to deal with the aftermath. While I agree that opting out of the JHA area en bloc is a terrible idea that would weaken the UK's security, I'm confused over why the Tories have been so inept over this issue: why not have a referendum on justice co-operation?

Seriously. If Nick Clegg will only go as far as saying that nothing has been agreed yet (suggesting that the LibDems might be reconciled to the opt-out if the UK opts back into several JHA measures), and ministers are going to engage in such policy kite-flying, then why not put the issue to the people or make noises about doing so? It would give the people a referendum on the EU, let people express an opinion on at least one aspect of the EU relationship that the Conservatives want re-balancing (and why not gauge opinion on what aspects of the EU the public want to buy into?), and would allow the Conservatives to partly deliver on their promise of a referendum on the Lisbon Treaty (in this case opting in or out of the post-Lisbon justice area).

The Home Secretary would not have been able to make a statement straight away, but the Conservatives could have started agitating for a referendum, and there is general agreement that some EU referendum has to happen sometime soon. It would have given the Conservatives space to test waters and refine their position and avoided statement grandstanding while winning a political point on the issue. Sounds like a better strategy than the current farcical posturing.

So why not have a referendum? Perhaps it's because it would be awkward for the party of law and order to campaign for opting out of law and order co-operation - maybe it's just simply politically uncomfortable as a gamble, with little likelihood of success. It's hard to sell the idea that the justice system won't suffer from the opt-out because we'll go back to the EU and negotiate specific opt-ins: not exactly a great rallying cry. And even a total opt-out with no subsequent opt-ins would be a hard sell.

In other words, if you hold a referendum on justice co-operation, the Europhiles would probably be the winners. Now that would be a Tory nightmare worse than their own bungling.

Thursday, 27 September 2012

Appealing the Indeterminate Sentencing Ruling

The European Court of Human Rights in Strasbourg has ruled, rightly, that indeterminate sentencing in the UK without the means for prisoners to demonstrate that they have reformed is contrary to their human rights:

"Indeterminate sentences were introduced on the understanding that rehabilitative treatment would be made available to those prisoners concerned.

But the ruling published on Tuesday said the court found the "considerable delays in the applicants making any progress in their sentences had been the result of lack of resources, planning and realistic consideration of the impact of the sentencing scheme introduced in 2005".

The European judges note that the problems with IPP prisoners were the subject of "universal criticism" in the British courts. The ruling said the three inmates had been left in privately run local prisons for two and half years, where there had been few, if any, rehabilitation programmes.

"The stark consequence of the failure to make available the necessary resources was that the applicants had no realistic chance of making objective progress towards a real reduction or elimination of the risk they posed by the time their tariff periods expired," says the ruling.

"Moreover, once the applicants' tariff had expired, their detention had been justified solely on the grounds of the risk they had posed to the public and the need for access to rehabilitative treatment at that stage became all the more pressing"."

The  UK coalition government seems to have agreed with this assessment before the Court made its ruling, since it has announced the end to indeterminate sentencing. However:

"The new justice secretary, Chris Grayling, told MPs he was disappointed by the judgment, and intended to appeal against it. He said: "It is not an area where I welcome the court seeking to make rulings.""

I'd like to hear what areas he thinks a human rights court should be making rulings, if not in the area of the right to liberty. It's also striking that the government is planning to appeal a ruling against a policy with which it no longer agrees - perhaps Conservative ministers enjoy the feeling that they could bring in sentences that effectively lock people up for longer than their sentencing without any hope of release!

In any case ensuring that the criminal justice system is fair and transparent - in other words, that it complies with the rule of law - is a basic part of human rights law, and it's exactly in these types of circumstances that the court should be intervening against the arbitrary actions of the state.

Tuesday, 25 September 2012

Reports of US breaching EU PNR Agreement

The transfer of Passenger Name Record Data - the information you hand over to airlines when you book a flight - from EU airlines to the US government has been a controversial issue in Brussels, with the transfers taking place for a decade on one basis or another without a satisfactory agreement in place to regulate it.

Earlier this year the European Parliament ratified an agreement with the US to regulate - and make legal in the EU - the transfer of this personal data to the US government for anti-terrorism and crime fighting purposes. I was against this agreement because it is spectacularly disproportionate and infringed privacy rights: data can be held for far too long (over a decade) for practically any purpose whatsoever. Sadly Sophie In't Veld's report advising rejection of the agreement was voted down in Committee and the Parliament ratified the agreement in plenary.

However it seems that the US hasn't been satisfied with even this gift of a treaty, with reports that the US government has been collecting data on people on flights that do not take off or land in the US, in contravention of the agreement. The S&D Group in the European Parliament has called on the Justice Commissioner Malmstrom to account for this before the LIBE Committee in Parliament:

"S&D spokesperson on civil liberties, justice and home affairs, Claude Moraes MEP, said:
 
"The media reports show that the US may be requesting data which falls outside the scope of the EU-US PNR agreement. We signed up to the agreement on strict conditions and we need clear answers if EU citizens' data is being collected contrary to spirit of the agreement.
 
"If our citizens' data is being collected for flights simply going through US airspace, then this could be against EU data protection laws. We are taking this matter very seriously and that is why the S&Ds have requested that Commissioner Malmström comes to the civil liberties committee to give MEPs a full picture of the situation regarding US collection of EU citizens' PNR data.""

It would not be the first time the Parliament has been disappointed by poor results from bad treaties.

Friday, 21 September 2012

Justice Scorecards

Viviane Reding, the Justice Commissioner, has announced a Justice Scorecard. The concern over justice and the rule of law in Hungary and Romania lately prompted the move. Romania is subject to reports on the condition of its justice system.

On EUObserver:

""I am prepared to come once a year before this house to share with all of you the commission's assessment of the justice systems of the 27 member states," she told MEPs in Strasbourg.

The scoreboard would gauge the various strengths and weaknesses of each member state by benchmarking judicial "strength, efficiency and reliability.

People from Reding's department would probe the national set-ups and issue annual reports, paying particular attention to the independence of the judiciary.

[...]

Reding now wants to extend such annual reports [Romania is subject to annual reports] to the rest of Europe and claims to have the backing of several member state ministries, including Germany's foreign minister.

"We need such a new mechanism. Because our infringement procedures are too technical and too slow to react in situations of high risk to the rule of law," she said."

It's a good idea because the infringement procedures deal with the technical and narrow infringements of EU law, which is not set up to deal with broad rule of law and judiciary matters, but co-ordination in justice and home affairs between national justice systems. This means that the infringement proceedings don't actually address the core issue of the protection of the rule of law and fundamental rights, but national leaders can claim that their proposals and measures are compatible with European laws and values. I'd have preferred it if such reports were to be issued by the Fundamental Rights Agency to ensure more independence (and continuity - will these scorecards continue after Reding has left the department?), but this is a good start.

Monday, 27 August 2012

Security chiefs worried about UK withdrawal from EU security cooperation

The Observer reported yesterday that former police and intelligence chiefs wrote a letter to David Cameron and Nick Clegg urging the UK to stay within the area of freedom, justice and security part of the EU:

"Written by William Hughes, director general of the Serious Organised Crime Agency from 2004 to 2010, it is signed by former Metropolitan police commissioners Lords Blair and Imbert, as well as Sir Stephen Lander, the ex-head of MI5, and other eminent figures.

[...]

The UK must decide by next summer if it wants to remain fully involved with existing EU justice and police measures or opt out. In their letter to Cameron and Clegg, the signatories say the latter course would have disastrous consequences for the fight against international paedophile gangs and investigations into terrorist networks.

"The growth in cross-border criminal activity within Europe is both an inevitable byproduct of the free movement of goods, services, capital and people under the single market, and a serious policing and security challenge," they say. "Responding to an increasingly international criminal environment requires modern international legal and policing tools, fast and effective cross-border co-operation and the ability to raise standards and share best practice with our closest security partners."

British officers, they say, are at the forefront of shaping effective co-operation. "British law enforcement bodies are now constantly communicating, co-operating and collaborating with EU agencies and other national policing partners in pursuing serious organised criminal and terrorist networks.""

I'm not the biggest fan of recent EU security policy - current policy on Passenger Name Record data and counter-terrorist financial tracking with the US and possibly within the EU is very flawed and without sufficient safeguards - but the value of being a part of this area, and whether or not the UK should opt out, should be much more widely debated. After all if the clamour is for repatriation of powers, surely possible withdrawal from a whole area (and former "pillar") of the EU should attract more comment?

Wednesday, 15 August 2012

A European SWIFT?: the Commission outlines available options

Just after the Lisbon Treaty came into force, the European Parliament used its new power to block the SWIFT Treaty with the US, which would give the US Department of Homeland Security access to financial transaction data for anti-terrorism purposes. The problem was there was no way of targeting suspected individuals and no judicial oversight: financial transaction information would be handed over in bulk (based on search categories) to the US government to search through.

After some changes (Europol gained the role of verifying the compliance of US requests under the treaty for data) and heavy lobbying that included a vice-presidential visit to the European Parliament, the EP voted through a re-negotiated treaty. Since then it turns out that the negotiated safeguards are wholly inadequate, with general data covering a global area for an essentially unlimited time being provided to the US DHS.

Part of SWIFT II was that the US would help the EU establish its own system (Article 11), and the Commission has published a communication on the options on setting up a European Terrorist Financial Tracking System (PDF). A more targeted approach to data collection is one of the aims of a European system, so that these systems are less intrusive into the privacy of citizens.

The Communication doesn't pick a particular option, and there will be an Impact Assessment based on a study the Commission contracted out in 2010. The Communication also promises that the Impact Assessment will pay particular attention to the necessity and proportionality of a European system and its impact on fundamental rights - given the poor use of statistics in the PNR proposals, I can't say I've much confidence in the quality of impact assessments in the area of justice and home affairs.


Goals:

Two main goals have been identified:

"• the system must provide an effective contribution to the fight against terrorism and its financing within the European Union;

• the system must contribute to limiting the amount of personal data transferred to third countries. The system should provide for the processing of the data required to run it on EU territory, subject to EU data protection principles and legislation."

A European TFTS could provide a useful extra tool in the fight against terrorism, and given the European basis of SWIFT (it's based in Belgium), designing a system that respects civil liberties and fundamental rights would have a positive knock-on effect in the EU's security relations with the US and other countries when it comes to finance tracking by ensuring that any transfers of data also comply with fundamental rights.

More specifically the system will cover:

"• preparing and issuing (legally valid) requests to the designated provider(s) of financial messaging services for the raw data to be provided to an authorised recipient or recipients. This involves determining the message categories to be requested, how often such messages should be sent, and maintaining contacts with the providers on these issues;

• monitoring and authorising requests to the designated provider(s) for such raw data. This involves verifying whether the request for the raw data have been prepared in accordance with the applicable limitations;

• receiving and storing (processing) the raw data from the designated provider(s), including the implementation of an adequate system of physical and electronic data security;

• running the actual searches on the data provided, in line with the applicable legal framework; on the basis of requests for such searches from authorities of the Member States, the U.S. or other third States on the basis of clearly defined conditions and safeguards, or on the own initiative of the authority (or authorities) entrusted with processing the data;

• monitoring and authorising the running of searches on the data provided;

• analysing the results of the searches, through combining these results with other available information or intelligence;

• distributing the results of the searches (without further analysis) or the results of the analyses to authorised recipients;

• implementing an appropriate data protection regime, including applicable retention times, logging obligations, handling requests for access, correction and deletion, etc."

Options (from page 9 onwards):

The Communication makes it clear that a hybrid solution is preferable to an exclusively national or exclusively centralised approach, so all of the options are designed along hybrid lines with differing degrees of (de)centralisation.

Option 1: A central EU TFTS unit as a coordination and analytical unit cooperating with national law enforcement authorities. Under this system most of the data work would be done at the European level with national requests to the central unit. Europol or Eurojust are possibilities for performing the central unit's role.

Option 2: EU TFTS extraction service option. This would be the same as option 1, but the central unit would not carry out analysis based on the extracted data for national requests (only for EU or third country requests), and requests would be verified at the national level.

Option 3: A Financial Intelligence Unit: there would be a European FIU platform which would request data from SWIFT and/or other data providers on the basis of national FIU needs. National FIUs would carry out the analysis, etc., for their Member State. The FIU Platform could deal with third country requests and for EU institutions.

The FIU model bears a striking resemblance to the Passenger Information Units envisaged by the current proposed Passenger Name Record Directive (PDF), so I'm guessing that something close to option three will be what we see in the draft law. going with this model will bring up a lot of issues regarding safeguards and oversight, and how data analysis is used, as well as what scope the FIU Platform will have for transfering data on to third countries. Some of these issues will also remain for the other options, but at first glance it looks like option 2 provides a system with clearer lines of responsibility that also ensures that the information is delivered to national experts who can then get on with the job.


Two key aspects for a European TFTS.

A European TFTS has to be a system of individualised searches. The processing of bulk data is essentially casting a wide net, with government rummaging through everything that's been dredged up, whether or not the data belongs to non-suspects. Developing a system capable of delivering individualised searches is necessary if the system is to be equipped with sufficient safeguards to protect civil liberties.

The second key aspect for a European TFTS is that searches need to be subject to judicial oversight in the Member States - law authorities should not be able to issue searches whenever they want, but they should have to get judicial permission (or an equivalent process in national law) for a search based on specific legal grounds. This would help prevent data mining (or similar practices such as what goes on under the current treaty) and ensure that there are strong safeguards. These aren't the only safeguards necessary - retention periods and how far analysis shifts into profiling are other issues that need to be considered when the studies and the legislative proposal come out - but they are necessary. If these basic elements are missing from any TFTS, then it should be rejected. (The Communication mentions that Europol as a possibility for a role in verifying requests for data under the system, despite not being a judicial authority by any stretch of the imagination).

The contracted study should be finished by the end of the year and I assume the impact assessment and proposal will be published in 2013.

Friday, 27 April 2012

US PNR Deal passes

After the European Parliament consented to the US PNR Agreement by 409 to 226 votes (strangely the EUObserver thinks this is "half-hearted" support; I call it a pretty solid majority), the Council has also passed the Agreement.

The treaty will probably come into force on 1st June 2012 (PDF).

The Parliament is also currently debating the EU's own PNR system, which monitors passengers on flights into and out of the EU (though it may be extended to cover flights within the EU if the proposal is amended) by collecting the flight information of all passengers. The LIBE Committee's draft report has been published (PDF), and there are over 400 proposed amendments to the proposed Directive (PDF 1 and 2).

Wednesday, 28 March 2012

Report on EU-US PNR Treaty rejected in Committee

Sophie in ‘t Veld’s (ALDE) report to the LIBE (Civil liberities, justice and home affairs) Committee was rejected yesterday. The report to reject the EU-US treaty failed in a vote of 23 votes for, 31 against, and 1 abstention.

The PNR treaty will confirm the transfer of passenger data on flights to the US to the Department of Homeland Security. In ‘t Veld had urged rejection of the treaty for several reasons, but chief among them was the loopholes which permitted the data to be used for unspecified purposes outside the treaty’s aim of fighting terrorism and serious transborder crime.

It’s likely that the EP will assent to the treaty in plenary now, avoiding a clash with the US similar to over the SWIFT I treaty.

Wednesday, 29 February 2012

The EU's PNR Directive in Parliament

As well as Sophie in ‘t Veld reporting on the proposed EU-US PNR Agreement on Monday, Timothy Kirkhope (ECR) presented his draft report on the EU’s own Passenger Name Record regime. The PNR Directive is technical, but it involves a huge amount of data collection on people not suspected of a crime, and the processing of data to create models used to identify unknown criminals. The law poses major questions on data protection, and there are also issues of how necessary and effective the system is, and how much of the costs airlines (and therefore consumers) will bear to pay for the system. I’ll divide this post into outlining and discussing the proposed directive and briefly looking at Kirkhope’s report to the Committee on civil liberties, justice and home affairs.

The PNR Directive.

The proposed PNR Directive (PDF) would introduce a system where a wide range of data gathered by airlines on passengers on flights into and out of the EU would be processed for the purposes of fighting terrorism and serious transnational crime. The data gathered includes the information on passports, flight arrival and departure times and destination, check in status, payment details, address and contact information, frequent flyer information, travel agent, travel itinerary, general remarks (including information on unaccompanied minors and their guardian’s contact details and relationship to the minor), seat number, baggage information, code share information, ticketing field information, and date of reservation/issue of ticket. This data would be collected from everyone on flights into and out of the EU regardless of whether or not they’re suspected of a crime and without distinction to how susceptible an air route is judged to be to use for terrorism of serious transnational crime (also the UK has suggested an amendment for the latter). This raises questions of proportionality.

PNR data is to be used in three different ways: re-actively, in real time, and pro-actively. The re-active use of PNR data is the use of data in the investigation or prosecution of a crime which has already taken place; use of PNR data in real time entails the use of data to arrest or place an individual under surveillance for a crime being committed or about to be committed; and the pro-active use of PNR data is using PNR data to build up criteria against to identify persons worthy of further surveillance or action. “Serious transnational crime” isn’t really harmonised by the Directive – it uses the list of crimes in the European Arrest Warrant, but Member States can decide to exclude some of these crimes from their transposing legislation if they think one is too “minor” – so the Directive can’t even decide what’s a “serious crime”!

The data is transferred by airlines to “Passenger Information Units” (PIUs) that will be set up to process and analyse the data, and alert national law enforcement agencies if necessary. PIUs can be national, or countries can set up joint PIUs if they want to share the costs. (The vast majority of EU Member States don’t have a PNR regime, so this PNR Directive will effectively introduce PNR systems into most Member States for the first time). The data will be retained for 30 days, after which it will be “depersonalised” (identifying data removed, but not deleted so it can still be restored and used) and retained in this masked state for a further 5 years. Data can be kept for longer if it’s used in criminal investigations or prosecutions. 5 years seems disproportionate if the data isn’t being used in an investigation or prosecution – and even the Council’s own legal service has suggested a maximum retention period of 2 years ("Draft Agreement on the Use of Passenger Name Records (PNR), Note for the Attention of Mr Stefano Manservisi Director General, DG Home, European Commission Legal Service, SJ.f(2011)603245, 18/5/2011").

Data subjects (people who own data that is being stored or processed) have rights of access, rectification and erasure, and the National Supervisory Authorities set up under EU data protection legislation (Framework Decision on Data Protection) monitor the PIUs’ use of data and assist data subjects with their requests to exercise their rights. However the purposes for gathering and processing the data is so wide that it’s debateable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF).

So PNR faces a lot of questions on several fronts: is it necessary, does it work, are there cheaper and less invasive alternatives? So how does the draft report in the Committee deal with this?


Timothy Kirkhope’s report.

The draft report (PDF) has contains a long list of proposed amendments to the directive (it should be noted that the report is open to amendments from the Committee before it votes on the report as a whole).

Some of these amendments would clarify the scope of the Directive – by stating that it applies to airlines incorporated in the EU and that store data in the EU, and expanding the Directive to include intra-EU flights as well as flights entering and leaving the EU. By including intra-EU flights, there would obviously be a much, much greater amount of data gathered on people. In Committee it was explained that the Commission wanted the Directive to avoid including intra-EU flights so it could test the system out first (the Directive includes provision for a review in 5 years on whether to include intra-EU flights), while Kirkhope countered that gradual introductions of schemes rarely work in his experience. The costs of transferring data to the PIUs would be borne by the airlines, while Member States would pay for the PIUs and their work. Kirkhope said that the estimated costs that would be passed on to consumers in ticket prices would be between 10 to 18 cents.

The report’s amendments insert provisions regulating the transfer of data between Member States to ensure that safeguard standards are maintained and that data is only shared in certain circumstances. There are also new provisions to more extensively regulate the transfer of data to third countries, though the assessment is still left to Member States so there isn’t a common decision on the adequacy of a third country’s data protection standards like there is for internal market matters.

The amendments would also clarify the state of data after the initial 30 day period – the Directive uses the phrases “masked” and “anonymised”. Unfortunately, the draft report decides to simply change the phrasing to a more unified “masked” terminology rather than changing the procedure so identifying data will be deleted after 30 days. Some amendments do aim to strengthen data protection by setting down punishment for data breaches such as demotion, denial of system access, formal reprimands, and removal form duty, as well as an obligation to inform data subjects that might be affected by a data breach. National Supervisory Authorities would be given powers to take disciplinary action against persons responsible for a privacy breach, increasing their powers of independent oversight.

Kirkthorpe believes that the use of a PNR regime is necessary and proportional. While the necessity of the Directive is probably best debated by the Committee and whole Parliament, there are still questions over how proportional the Directive would be even with the report’s amendments, particularly over the targeting (or lack of targeting) of air routes, the oversight of creating and use of objective assessment criteria, and the length of the retention period. It does provide some good improvements to people’s rights to access, rectify and erase their data and makes it easier and more effective to exercise these rights (though the problem of the content of these rights given the wide use of data remains).

I’m very sceptical of the necessity for a PNR system – a lot of the analysis backing up the proposal seems to be based on numbers on the increase of crime together with rhetoric on fighting crime and anecdotal examples of how PNR could be used, rather than an analysis of the benefits of PNR versus the existing EU databases. It seems that we are being asked to accept the creation of a massive information gathering system on trust, and I’m not convinced.

Monday, 27 February 2012

In 't Veld to propose EP rejection of EU-US PNR Agreement

Sophie in 't Veld (ALDE), rapporteur on the EU-US Passenger Name Record Agreement (Text) will present her report to the committee on civil liberties, justice and home affairs today. The PNR agreement will permit the transfer of Passenger Name Record data for passengers on flights from the EU to the US to fight terrorism and serious crime. PNR data is all the data from the machine-readable part of the passport (name, etc.) plus the times of departure and arrival, place of departure and arrival, check in time/status, payment details, luggage details, and other general information.

If the Parliament does vote for rejection, it will be a big blow to the US and those in the EU who have been trying to set the rules for this data transfer. In fact, the PNR saga has been going on for about a decade now, since the US adopted its PNR regime in the wake of the September 11 attacks, setting penalties for airlines that refused to transfer the PNR data they collect (airlines collect PNR data for commercial purposes). This left EU airlines in the position where they would be punished by the US if they didn't hand over the data, and by EU data protection laws if they did. An agreement in 2004 fell foul of an ECJ judgment over the legal base used, and an agreement in 2007 was never assented to by the EP (as required under the Lisbon Treaty after December 2009), so it only applied provisionally. The European Parliament called for new agreements with the US (and Canada and Australia) to bring them more into line with data protection rights (the Committee voted to assent to the new Australian agreement in October).

There have been several concerns raised over the agreement, mainly on data protection grounds. In her report, in 't Veld highlights that the necessity and proportionality of PNR systems haven't been satisfactorily established - in fact, with the EU's own proposed PNR Directive, this is also the case (PDF) - when information gathering could be done on a smaller scale (e.g. via an API system that just covers passport and flight departure/arrival data); that the agreement does not limit the use of data to fighting terrorism and serious crime; that data does not have to be destroyed, but can be held indefinitely: despite its use being restricted over time, it could still be accessed and used. It is also pointed out that the agreement does not provide a sufficient protection against the use of sensitive data by the US Department of Homeland Security (data indicating race, religion, sexual orientation, etc); that there aren't sufficient guarantees that data will be equally well protected if it's transferred to another country from the US; and that the agreement might not provide EU citizens with adequate means of judicial address.

She says (PDF):

"The call for a coherent approach and a single set of principles to govern international agreements on the transfer of PNR data was an approach embraced by the Commission and the Council. However, the Agreement with the US differs fundamentally from this approach as well as from the Agreement with Australia, concluded on 13 December 2011. This Agreement was considered to be sufficiently consistent with the criteria set out by Parliament, while the Agreement with the US departs from the approach that had been agreed by the European Parliament, the Commission and the Council in 2010. Additionally, compared to the first EU US PNR Agreement of 2004, this 2011 Agreement even represents a deterioration on many points. Having in mind that the European Parliament sought annulment of the 2004 Agreement before the Court of Justice, your Rapporteur will recommend the European Parliament to decline to consent to the conclusion of the Agreement."


I hope the Committee votes for this report - the case for PNR regimes is quite shaky, with high levels of data collection from people who aren't suspected of any crime, for no proven gains in effectiveness over less invasive and data protection-compliant alternatives. Rejecting the PNR Agreement would be the second time this parliament that the EP has blocked an US-EU Agreement - the first being over SWIFT I (which prompted heavy lobbying by the US). Blocking this agreement would not only put an end to invasive data gathering, but also raise the profile of the EP and of the importance of data protection rights in the US's security dealings with the EU.

The report will be presented to the Committee at 15:00 CET. The Committee will vote on the report on March 20th, and the plenary will vote on the agreement in April.

Friday, 23 September 2011

Deal on the European Protection Order Directive

The Council and Parliament have reached a deal on the European Protection Order Directive, originally proposed by Member States, ensuring that it will sail through the first and second legislative readings. The EPOD is aimed at protecting people subject to protection orders under their national criminal law, while allowing them to exercise their free movement rights (draft legislation PDF here). The Directive would apply to protection orders made by national authorities under criminal law (there's a separate measure dealing with civil law), which impose restrictions on persons that pose a risk to another such as:

"(a) a prohibition from entering certain localities, places or defined areas where the protected person resides or that he visits;

(b) a prohibition or regulation of contact, in any form, with the protected person, including by phone, electronic or ordinary mail, fax or any other means; or

(c) a prohibition or regulation on approaching the protected person closer than a prescribed
distance." [Article 5]


Protection orders would be issued normally by Member States under their national law, but if the person they are meant to protect resides in another Member State or wants to move to another Member State, they can request a EPO to extend the protection in the original national protection order so they are covered in their host Member State. So the proposed EPOD works on a modified mutual recognition model - the national measures made in one Member State are recognised and enforced in another Member State, though in this case a request for a European version would need to be made, and then the executing Member State would transpose it via a national measure. The Directive would only apply to victims/potential victims of crime, and not witnesses, so it isn't part of some European witness protection scheme.

From a legal perspective, this modified route to mutual recognition is quite interesting, and shows some movement on the use of mutual recognition measures by allowing for the difference in Member State's legal systems (a mix of criminal, civil and administrative measures). I haven't taken a close look at the jurisdiction/competence issues around the mini-Member State directives that will be EPOs, however. Hopefully the Parliament hasn't missed anything it might later regret...