Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Friday, 10 January 2014

European Parliament wants to question Snowden

The European Parliament's LIBE Committee's Inquiry into the Electronic Mass Surveillance of European Citizens is not due to be published in March, and the Committee has voted to question the whistle-blower Edward Snowden via video-link. However The Guardian has ran a story on the draft of the report in which the Inquiry says the actions of the NSA and the UK's GCHQ "appear illegal".

The draft report states (PDF; main findings start at p.16):

"[The Inquiry] Condemns in the strongest possible terms the vast, systemic, blanket collection of the  personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of the press, thought and speech, as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding the extra-territoriality of national laws

[...]

[The Inquiry] Stresses that, despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities."

(Points 9,and 60 of the main findings).

Along with calling for the US and EU Member States to prohibit blanket mass surveillance activities and demanding that the UK, France, the Netherlands, Sweden and Germany revise their national intelligence laws in line with the European Convention on Human Rights, the rapporteur, S&D MEP Claude Moraes (UK),  called for the SWIFT Agreement with the US to be put on ice.

The SWIFT Agreement allows for the transfer of financial transaction data to the US, and has come in for a lot of criticism. The first attempt at agreement failed, but the European Parliament voted through a second renegotiated SWIFT deal earlier during this parliament.

Tagesschau reports that the inquiry may show that French and German intelligence agencies have also been carrying out similar surveillance programmes. This is probably widely suspected anyway, but for a parliamentary inquiry to finger France and Germany after the outrage expressed by those two countries would be very embarrassing. It would be particularly uncomfortable for Merkel, who is seen to have reacted to the NSA Affair slowly, and due to the controversial nature of the EU's own data retention laws in the country.

The European Parliament report won't have any binding effect, but the Inquiry is a strong political statement. As well as being a fundamental issue that needs investigation, this is a ticket to the central political stage. Questioning Snowden would be a major coup and turn the Inquiry into an international event. Though the Inquiry overwhelmingly wants to question Snowden (only 2 UK Conservatives on the Committee voted against the proposal), it is depending on Snowden wanting to use the platform - something that the US Congress fears and has warned against. It's hard to see why Snowden wouldn't take this opportunity to state his case personally and publicly.


EDIT: Ralf Grahn drew my attention to the draft report online, so I've changed the blog to include links and some extracts to it.

Tuesday, 12 November 2013

The European Cloud - Europe's Response to the NSA Scandal?

Negotiations over the EU-US trade deal reopened yesterday, demonstrating that the NSA affair has not halted progress here despite the calls from the European Parliament for talks to be suspended. At the same time the Parliament's Civil Liberties, Justice and Home Affairs Committee (LIBE) continues to hold sessions on its inquiry into the spying allegations. Neelie Kroes, the Commissioner that heads the Digital Agenda policy, has said that while the spying revelations are shocking and unacceptable, the spying will probably continue - "Let's not be naive". Instead Kroes argues that Europe should focus on building its digital infrastructure and single market in the internet.

In the EU the spying scandal does not look like it will produce any sharp changes in policy direction, but rather an acceleration of existing policies as the Commission and others capitalise on the political fallout from the affair. For the Data Protection Regulation this has already meant a reversal of the bill's dilution that had been brought about under the influence of lobbyists, and for Kroes it means pushing the European Cloud.

The European Cloud Strategy was adopted by the Commission last year, aiming to boost European cloud computing by sorting through problems of technical standards, data portability, clear cloud computing contracts and user trust. The policy is mostly economically focused, noting that cloud computing can generate jobs and economic growth while providing opportunities for cost-cutting for small and medium businesses. However, cloud computing concerns issues of data protection as well as copyright issues. As the EU works through its data protection reforms, the fact that 85% of cloud computing services are US based will surely raise concerns not only over how much the EU needs to do to catch up in this market, but also over how effective European privacy rules will be in practice.

With European expert groups meeting on how to approach cloud computing contracts and a European Cloud Partnership mulling commercial strategy, the technical discussions seem removed from the headlines in the media, but the Commission probably does see this as part of the solution (as well as using the crisis to promote its policies). First, the Commission's strongest in the single market, so boosting European internet businesses so European consumers (and others) have an alternative to the US-based cloud is one of the few things they can actually do, so they would be naturally inclined to favour this policy. Second, the best way for Brussels to exert its regulatory power in an area (and one of the few ways it can exert any power) is to have a strong market in that area and then come up with high standards for it, setting the pace in the global marketplace.

In a sense, Kroes makes a good point. It is hard to imagine that the Franco-German push to put transatlantic spying on a "legal footing" will do much, if anything, to reduce actual levels of spying. Improving the market position of the EU would help provide an alternative and allow the EU to stamp its data protection philosophy on to the global economy more effectively - and the political impetus behind such an economic policy is unlikely to fizzle out as quickly as the focus on spying may do.

However, this isn't enough - we should and need to push more forcefully to ensure that security services here and in the US are more politically accountable. It is not enough that what they do is legal: after all, it would hardly solve the problem to provide that legal backing wherever it's currently lacking. Rather we need to have a more critical approach to the demands of security for ever more information and resources, and to have a real debate over how we balance safety and security and civil liberties.

Because while we can never have total security, we can run out of privacy.

Friday, 25 October 2013

EU reaction to the NSA Affair

The fallout from the NSA Affair and Snowden's leaks continue, with revelations that Angela Merkel's mobile phone was hacked causing worldwide headlines (though there's been some criticism of Merkel for taking so long over these allegations, and indications that the NSA has been spying on German citizens, seriously, as Der Standard pointedly notes with the headline "Und ploetzlich ist es ein Problem" ["And suddenly it is a problem"]). The Guardian is reporting that the number of tapped heads of government is probably much higher, and the European Council has finally been roused too - it turns out that prime ministers don't like to be spied on. Now everything from the halting of data-sharing agreements to cancelling the free trade talks is on the table (after all, it's much harder to negotiate if you're being spied on).

The European Parliament has also signalled its displeasure, voting for a motion calling for the end of the SWIFT agreement. It's not binding, and the Commission has responded by stating that there is no indication of wrong-doing under the SWIFT Agreement (or "Terrorist Financial Tracking Programme" - PDF). Parliament's issues with SWIFT aren't new to the NSA revelations, however. After a troubled birth (the Parliament voted down the first agreement before passing the second after lobbying from Vice-President Joe Biden), last year the report before Parliament on the implementation of the safeguards in the agreement caused disquiet - it turned out that the full report wasn't even made available to MEPs to review. (Notably, the European Data Protection Supervisor had criticised some of the key provisions of the draft SWIFT Agreement).

The Commission has said that the agreement has effective safeguards, and that it's waiting on the response to a request for reassurances from the US. It's not planning to suspend the agreement.

Martin Schulz, the President of the European Parliament has also said that the free trade talks with the US should be suspended in the light of the spying affair.

The most notable moves, though, probably come over the draft Data Protection Regulation. The European Parliament has adopted its position on the law this week, which has hardened. The subject of intense lobbying, the biggest impact of the Snowden-leak was to reverse the watering down of the proposed law, with the security of citizens' data in the hands of US companies a key concern. The bill still has a long way to go, and it has to be agreed with the Council before it can be signed into law.

But what does this all add up to? At the end of this week the EU still transfers the same kind of data to the US as at the start, and there is little coherence in the EU's position. Most demands amount to the suspension of agreements or negotiations, and it will take a while to see what actually comes out of this. If we are ever going to see better data protection standards and a more regulated approach to intelligence and police work, we have to have clear standards and guidelines on how we shape these laws. When it comes to the EU, a proper regard for the necessity and proportionality of proposed security laws within the EU and agreements with third countries has to be stressed. And the Commission must drop its deference of the security services if it is to enforce and monitor agreements - or even draw up laws.

Thursday, 25 April 2013

Draft EU PNR Directive voted down at Committee Stage

The LIBE Committee of the European Parliament has shot down the draft Passenger Name Record Directive by a vote of 30-25, with the Liberal, Green and left wing groups voting against and the conservative groups for the draft law. The Directive concerned the collection of the information passengers give to airlines when booking a flight by law enforcement authorities (in the form of national "Passenger Information Units (PIUs)" that would analyse the data and pass on information to other law enforcement authorities). The data would be collected to fight terrorism and serious crime, and is a key plank of the Commission's counter-terrorism strategy.

I wrote about the PNR Directive at length last year. The information gathered covers everything from the flight to the food you order, so the authorities would be casting a wide net. There would be some rights for people to have their data corrected or deleted, but:

"However the purposes for gathering and processing the data is so wide that it’s debatable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

[...]

 There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF)."

While the draft parliamentary report (by LIBE rapporteur Timothy Kirkhope [ECR Group]) clarified some issues with the original text, it did little to address the scope of both the data gathered and the purposes that it could be used for (without further restricting and defining these, it would be very difficult for the system to be held to account in that most uses for the data would be lawful and citizens would have little substance to their data rights).

The draft Directive could still go to the EP plenary, where the full European Parliament could still pass the law.

Tuesday, 25 September 2012

Reports of US breaching EU PNR Agreement

The transfer of Passenger Name Record Data - the information you hand over to airlines when you book a flight - from EU airlines to the US government has been a controversial issue in Brussels, with the transfers taking place for a decade on one basis or another without a satisfactory agreement in place to regulate it.

Earlier this year the European Parliament ratified an agreement with the US to regulate - and make legal in the EU - the transfer of this personal data to the US government for anti-terrorism and crime fighting purposes. I was against this agreement because it is spectacularly disproportionate and infringed privacy rights: data can be held for far too long (over a decade) for practically any purpose whatsoever. Sadly Sophie In't Veld's report advising rejection of the agreement was voted down in Committee and the Parliament ratified the agreement in plenary.

However it seems that the US hasn't been satisfied with even this gift of a treaty, with reports that the US government has been collecting data on people on flights that do not take off or land in the US, in contravention of the agreement. The S&D Group in the European Parliament has called on the Justice Commissioner Malmstrom to account for this before the LIBE Committee in Parliament:

"S&D spokesperson on civil liberties, justice and home affairs, Claude Moraes MEP, said:
 
"The media reports show that the US may be requesting data which falls outside the scope of the EU-US PNR agreement. We signed up to the agreement on strict conditions and we need clear answers if EU citizens' data is being collected contrary to spirit of the agreement.
 
"If our citizens' data is being collected for flights simply going through US airspace, then this could be against EU data protection laws. We are taking this matter very seriously and that is why the S&Ds have requested that Commissioner Malmström comes to the civil liberties committee to give MEPs a full picture of the situation regarding US collection of EU citizens' PNR data.""

It would not be the first time the Parliament has been disappointed by poor results from bad treaties.

Tuesday, 17 July 2012

“I feel that we’ve been had!” – Report on the SWIFT Agreement


Blow to civil liberties as PNR deal passes

 BY CC greenefa.

In 2010 the EU ratified an agreement with the US called the SWIFT Agreement (or more technically: the “Terrorist Financial Tracking Programme” – PDF), after the first agreement was vetoed by the Parliament, and despite privacy concerns remaining for the second agreement. The SWIFT Agreement permits the transfer of financial transaction information to the US government for the purpose of counter-terrorism. The problem is that you can’t ask for someone’s transaction information, but data is transferred in bulk to the US, where they search through the information to see if they can find out anything relevant to counter-terrorism. As a check, the second agreement stipulates that Europol must check that requests for transfers are in compliance with the agreement. Given that Europol could gain from any leads from the information, it’s not exactly the impartial check of a judicial body.

The LIBE Committee debated the Second Report on the role of Europol by the Joint Supervisory Body on 21/6/2012 (you can watch it here). The first report (PDF) found some serious failings, including:

- Due to the abstract nature of transfer requests, proper verification of whether the requests are in line with the conditions of the Agreement is impossible.
 - Information provided orally to Europol affects their decision making, but cannot be reviewed by the JSB. Whether the deficiency in information in the requests is remedied by oral information is impossible to verify.
- Significant involvement of oral information renders proper internal and external audit impossible.

Recommendations:

- Inform the JSB on the results of the review in policies and procedures for Europol’s role. - Ensure the ability of the Europol Data Protection Officer to carry out his role.
- Ensure hard-deletion of Article 4 data (data to the US where Europol has to verify their requests), which where inputted into some of Europol’s information processing systems before the upgrading of the security level.
- Contact the US Treasury Department and ensure that adequate information is provided with requests.
- Ensure verifications by Europol are made based on written requests, along with any supplemental documents, in order to allow for proper internal and external audit.

The Second Report notes that all US data requests to date have been approved and that some of the reasons are too generic. Many of the request applications included “copy and paste” texts and the information provided was out-of-date and already in the public domain, and oral information is still being provided to Europol in order for it to make decisions. Also, there is no geographic limitation to these requests (data concerning the whole world is requested), and the requests submitted on a monthly basis for a month in duration (so effectively data transfer is ongoing all year round with little limitation).

The JSB concluded that 2 of its recommendations from its previous report have been implemented, while progress is ongoing for the other 3. The EU and US have signed an agreement for a second person to be posted from the EU to the US Treasury Department to oversee the operation of the agreement. The Overseer currently in place has been involved in intensive on-the-job training, and has been in US Treasury briefings. Clearly continuous information is being provided on generic and incomplete information with little restriction, so it’s hard to see how the current system provides adequate safeguards.

The full report however is not publically available or even available to the MEPs on the LIBE Committee – when the Committee requested access to the report, the JSB said it had no objections, and that there was nothing sensitive in the report that would prevent it from being disclosed. However, Europol stated that disclosure would threaten operational interests, so the report has not been disclosed. You can find the JSB’s public statement here: PDF.

Sophie in’t Veld and Jan Albrecht weren’t impressed (Veld: “I feel that we’ve been had!”). Veld highlighted that the EP was assured that there would be no data mining, but that the current procedure – of continuous and almost unlimited access – is much worse and goes further than what Parliament had expected. Veld objected to the secrecy of the report, saying that the Committee cannot fulfil its role of scrutinising Europol and the Agreement properly on the basis of a “3 page summary”. Albrecht said that the demands of MEPs have not been met after 2 years of the agreement, adding that if we have a functional fundamental rights jurisdiction, we could get this taken down in court.

While the role of the Europol Data Protection Officer seems to have been strengthened, it hardly seems like there are any safeguards on the flow of financial transaction data to the US. Without a sunset clause on the agreement, the European Parliament is in a fairly weak position to act against the treaty or to demand amendments. We seen the trend of PNR treaties on passenger information lead to a bad proposal for EU PNR, and soon the Commission will propose a TFTS for the EU. We need to make sure that we don’t throw away our civil liberties for little or no security gain simply because law enforcement authorities want our information and data.

Friday, 10 February 2012

The Anti-Counterfeiting Trade Agreement

I once had a work experience were I had to read through several contracts selling and assigning the right to turn a book into a TV programme and then give a presentation on who owned/did/does what. I'd only done a year at university and hadn't covered contract law or intellectual property law, so I was given a few textbooks on contract law and on copyright. As well as being one of the most interesting work experiences I ever did, it's also the only time I did anything to do with intellectual property law - while I was interested to read ACTA (PDF), I was a bit wary since I don't have the time to read into all the surrounding legislation and the debate on IPR. I do agree with this article over at The Atlantic, though: while some of the claims against ACTA might be a bit overblown, the trend in international IPR law is worryingly focused on the enforcement side, and ratcheting up enforcement standards without ever adapting to the issues brought up by our digital age. (A major debate is on whether copyrights do in fact encourage innovation and investment, or if the current laws actually detract from such innovation).

ACTA has rightly caused a huge reaction from the public, and the Party of European Socialists has come out attacking the treaty( PDF):

"The Party of European Socialists considers the Anti-Counterfeiting Trade Agreement (ACTA) to be fundamentally flawed in both content and process. There is a severe imbalance between the rights attributed to the users, service providers and rights holders.

The agreement, which is to be voted on by the European Parliament before summer 2012 and ratified by National Parliaments, is flawed in content for the following reasons; it gives undue power of oversight to internet providers; it infringes the privacy of internet users; and it will curtail developing countries access to generic medicines. It is flawed in process because of the secret manner in which the accord was agreed upon, and because of the significantly reduced time afforded to the European Parliament to scrutinise the final draft."


I haven't been able to find the positions of any other Europarties yet, but if you know them, let me know in the comments.

ACTA itself seems to raise a few questions over due process and the role of Internet Service Providers in policing IPR (which has serious implications for privacy and data protection - though it should be stressed that the actual role of ISPs would be decided by domestic legislation and ACTA does not require ISPs to take on a policing role). The EU has signed up to ACTA along with its Member States, but it has yet to be ratified and the European Parliament will make its decision this summer. The explanatory memorandum to the agreement makes clear that the Commission considers the agreement as adding noting new to current EU law on IPR, while leaving any additional obligations for judicial enforcement to be carried out by Member States as parties to the treaty. This doesn't strike me as a reason to be reassured by ACTA: if our legislation already goes further than ACTA, then where does that leave all our talk on this side of the Atlantic about being more enlightened about IPR and the internet? We still may have the safe harbour provisions that SOPA attacked, but ACTA clearly underlines that our approach is guided by a similar philosophy rather than being subjected to a serious debate about how the internet and digital media have changed the environment for IPR and how we should adapt (not to mention the price we might pay in terms of privacy and free speech to enforce these ever stricter laws).

So while not every evil assigned to ACTA finds backing in its vague provisions, it is another important step in the development of our IPR laws. We should take this opportunity to ask our MPs and MEPs to debate not just ACTA, but our approach to IPR in general. It's more than just this agreement.

You can sign the petition against ACTA here.

Also, Grahnlaw has been providing good coverage of this issue (see here, here and here for examples).

Wednesday, 30 June 2010

The Email Incident of 7th December 2007

The Activity Report of the Joint Supervisory Body of Eurojust for the year 2009 (PDF) was sent to the Council last week. I was taking a look through it to see if there was anything on preparations on data protection, particularly on anything SWIFT-related towards the end of 2009. The report does mention co-operation between Europol and Eurojust, and that the Lisbon Treaty will impact on data protection - however, the analysis of the impact of data protection provisions in the treaties will be in next year's report.

A section heading did jump out at me, though - "Email Incident of 7th December 2007":

"...a disruption of the e-mail service at Eurojust had taken place on 7 December 2007, as a side effect of an attempt to solve a problem caused by an accident in the use of the system the previous day. This incident had been investigated by the JSB in 2008 and a report presented to Eurojust. Eurojust’s final response to the JSB’s evaluation... was presented by the Acting Administrative Director of Eurojust, Mr Jacques Vos, at the meeting in February 2009. He outlined the measures that were being taken by Eurojust on the basis of the JSB’s recommendations to restore the trust of users in the integrity and inviolability of the e-mail system. Eurojust admitted that mistakes in judgement had been made at the time and recognised the considerable operational consequences that this incident created, but it was hoped to put this issue aside, to learn from it, to follow the JSB’s recommendations and to be better prepared to deal with future incidents."


What happened? Was it just a downed system? A hacker? Was information lost?

I looked up the previous year's report to see if it could shed more light on what exactly happened and what recommendations were made. The 2008 report (PDF) stated:

"Upon the request of the President of Eurojust, an ‘on the spot’ check was carried out at Eurojust on 17 March... The members of staff involved in this incident were interviewed and the log files were inspected. Subsequently, a report was submitted to the College of Eurojust on 24 April making several recommendations."


The report? "Confidential document."

It sounds like a security matter rather than a simple system failure, though I can't say for sure. I wonder how much information was lost, and how sensitive it was?

Tuesday, 29 June 2010

SWIFT II: European Data Protection Supervisor's Report to Council

The European Data Protection Supervisor yesterday sent a report (PDF) on the SWIFT II agreement (or TFTP agreement) to the Council. Given the criticism of the agreement from Parliament (though there is recent news of some agreed compromise), the EDPS report is interesting.

For example, at paragraph 5, the EDPS notes that the proposal does not see Article 16 TFEU (on data protection) as a legal basis, though the agreement and proposal note the data protection concerns. The report tersely notes: "...the EDPS reiterates that this agreement not only relates to the exchange of personal data, but also to the protection of these data. Article 16 TFEU is therefore not less relevant as legal basis than Articles 82 and 87 TFEU relating to law enforcement cooperation that have been chosen as legal bases."

The scope for future agreements on data protection and for a general agreement between the US and EU on data protection is discussed as well, particularly in paragraph 8. The EDPS recommends that the current proposal (agreement) be amended so that if there's a general agreement on data protection, it will apply - or at least get an agreement that it would apply to TFTP circumstances.

The EDPS takes a look at the question of privacy rights and the security question through explicitly rights-based language (Para 15):

"15. Against this background, the Commission proposal highlights the usefulness of the TFTP Programme, as put forward by the US Treasury and by the eminent person's reports. However, the condition laid down by Article 8 ECHR in order to justify interference with private life is "necessity" rather than "usefulness"."


The report goes on to flag up the same concerns that the agreement's critics in Parliament have highlighted: the retention of data for up to 5 years regardless of whether it's been extracted or if there's a "proved link with a specific investigation or prosecution.", and bulk transfers are the big concerns. In fact, paragraph 20 urges for a transitional approach to bulk data if it is to be used at all:

"...EDPS believes that solutions should be found to ensure that bulk transfers are replaced with mechanisms allowing financial transaction data to be filtered in the EU, and ensuring that only relevant and necessary data are sent to US Authorities. If these solutions could not be found immediately, then the Agreement should in any event strictly define a short transitional period after which bulk transfers are no longer allowed."


Also worth higlighting is the whithering criticism for handing the judicial oversight role to Europol:

"25. Moreover, Europol has specific interests in the exchange of personal data, on the basis of the proposed agreement. Article 10 of the proposal gives Europol the power to request for relevant information obtained through the TFTP, if it has a reason to believe that a person or an entity has a nexus to terrorism. It is hard to reconcile this power of Europol, which may be important for the fulfilment of Europol's task and which requires good relations with the US Treasury, with the task of Europol to ensure independent oversight.

26. Furthermore, the EDPS wonders to which extent the current legal framework entrusts Europol - especially without changing its legal basis pursuant to the ordinary procedure established by the Lisbon Treaty - with the tasks and powers to make an administrative request coming from a third country "binding" (Article 4.5) on a private company, which will thus become "authorized and required" to provide data to that third country. In this context it is useful to note that it is under the present state of EU law not evident whether a decision of Europol vis-à-vis a private company would be subject to judicial control by the European Court of Justice."


The report also criticises some aspects of the personal rights under the agreement when it comes to the correction/deletion of information. (As it's already turning into a long post, I'll let you read it [paragraphs 28-33], but it raises questions over the ability of people to exercise these rights). The EDPS also urges the inclusion of a sunset clause in the agreement to help encourage sustained work towards improving data protection under its provisions.

Overall the report echoes the concerns of the critical EP voices, while welcoming the changes make since SWIFT I. How much of an impact will it have in the Council? It's hard to tell how wedded the Member States are to the agreement, though it's interesting to note that the report mentions that the German Constitutional Court (Bundesverfassungsgericht) considers the retention of data over 6 months to be excessive, so it is possible that some Member States could share worries over the diminution of privacy rights of their citizens. What will be the extent of any agreed amendments be? Hopefully these clear calls will have a positive impact.

Wednesday, 16 June 2010

SWIFT II Sent to Council and Parliament

The new SWIFT agreement (or the "Terrorist Finance Tracking Programme") has been reached between the Commission and the US, and the agreement has been sent to the Council and Parliament for assent. Green MEP Jan Albrecht has written about the new agreement and uploaded a PDF of it here. Statewatch also released a PDF of the agreement here.

So does the new agreement address the concerns of the Parliament? Privacy is the central issue, and the long preamble to the deal takes care to highlight the tradition of privacy rights and protection in each jurisdiction (though MEPs tend not to see US privacy laws in the most flattering of lights), but a few new changes have been introduced to try and reassure Parliament.

Elements of the deal include: some oversight by Europol; that the data, if relevant to tackling terrorism by European authorities, will be forwarded to them; data providers can seek redress; citizens can request the erasure, correction or blocking of their information; the deal can be paused or cancelled upon notification after the first 6 months (though the cancellation would take place 6 months after notification); after the deal expires, it is automatically renewed each year for a year unless cancelled; there are provisions for passing on the data to third parties in some cases.

The safeguards are unlikely to fill the EP will a lot of confidence. Europol is an agency to aid work against organised crime, etc. in the EU - and therefore more likely to have a "police" outlook rather than a more impartial judge's outlook on how legal the transfer of data is. Having Eurojust look at the transfer of data to ensure that it complies would be better, as it would have more legal expertise, but a specialised legal review board would be better, in my opinion. In any case, despite the constant references in the deal that applications for data will be on specific data, the net will be quite wide in reality, since Swift only deals with bulk packages of data, and cannot separate them out.

If the data being transferred is bulk data, then it devalues the oversight - some private data will be transferred anyway, so there will already be a high tolerance for its transfer. There would presumably have to be quite a big breach of the agreement for Europol to stop a transfer (though my understanding is that they check that the application is correct, rather than going through the data itself - I doubt they have the resources to do that). The US have undertaken to delete data irrelevant to the deal's purpose, but effective safeguards are what the EP's after.

It's hard to see how effective the citizen's right to erasure, etc. would be. It would be rare that people would discover that data concerning them has been transferred, so how often can these rights be expected to be exercised? Effective safeguards before transfer are vital under these circumstances. Ideally there would be an application to a judicial panel for specific information, which would then be passed on if it complied with the deal.

Jan also brings up the question of how long the data would be retained for in his post. 5 years is too much, though if it was an exceptional period for an exceptional investigation and subject to rigorous safeguards and scrutiny, then such retention may be justifiable. Clearly such conditions aren't satisfied here.

Will it pass in Parliament? I hope not, and there are plenty of reasons here for the EP to reject it. However, there may be pressure to accept it to prevent the US from making bilateral deals and circumventing the EP altogether (though the US would have to consider how that could sour relations with the EP on matters that it cannot circumvent them).


On L'Europe en Blogs, there's an interview with the Commissioner for Home Affairs (whose department this falls under) here.