Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, 4 February 2014

Stripping Citizenship

Last week the UK House of Commons voted on an amendment to the Immigration Bill that would empower the Home Secretary to strip foreign-born terrorist suspects of their UK citizenship, even if it would render them stateless. (Those with dual citizenship can already be stripped of their British citizenship). The amendment reads (p.3):

"(4A) But that does not prevent the Secretary of State from making an order under subsection (2) to deprive a person of a citizenship status if—
(a) the citizenship status results from the person’s naturalisation, and
(b) the Secretary of State is satisfied that the deprivation is conducive to the public good because the person, while having that citizenship status, has conducted him or herself in a manner which is seriously prejudicial to the vital interests of the United Kingdom, any of the Islands, or any British overseas territory.”

The decision doesn’t have to be made following a court ruling and it isn’t made by a court – it’s made by the Secretary of State herself. The amendment was proposed by the Home Office Secretary of State, Theresa May, and was reportedly aimed at drawing Tory back-benchers away from an amendment that would have limited criminals up for deportation’s ability to rely on the right to family life under the European Convention on Human Rights. That amendment was defeated with the help of Labour and the Liberal Democrats.

The vote is another example of how difficult it is for Cameron to control his back bench, which will be worrying for him come the European elections. At the moment the Conservatives are expecting to come behind UKIP in the May poll, but even with that factored into their calculations, the back benches may take the result as a spur to become even more rebellious.


Disappointingly, the anti-immigration rhetoric has meant that the other parties have failed to take a firm stand on the issue of taking away citizenship. On Question Time on Thursday, the Labour and Lib Dem representatives weren’t able to give a clear “yes” or “no” on whether or not they supported the idea. UK politics seems to be stuck on an illiberal course…

Tuesday, 17 July 2012

“I feel that we’ve been had!” – Report on the SWIFT Agreement


Blow to civil liberties as PNR deal passes

 BY CC greenefa.

In 2010 the EU ratified an agreement with the US called the SWIFT Agreement (or more technically: the “Terrorist Financial Tracking Programme” – PDF), after the first agreement was vetoed by the Parliament, and despite privacy concerns remaining for the second agreement. The SWIFT Agreement permits the transfer of financial transaction information to the US government for the purpose of counter-terrorism. The problem is that you can’t ask for someone’s transaction information, but data is transferred in bulk to the US, where they search through the information to see if they can find out anything relevant to counter-terrorism. As a check, the second agreement stipulates that Europol must check that requests for transfers are in compliance with the agreement. Given that Europol could gain from any leads from the information, it’s not exactly the impartial check of a judicial body.

The LIBE Committee debated the Second Report on the role of Europol by the Joint Supervisory Body on 21/6/2012 (you can watch it here). The first report (PDF) found some serious failings, including:

- Due to the abstract nature of transfer requests, proper verification of whether the requests are in line with the conditions of the Agreement is impossible.
 - Information provided orally to Europol affects their decision making, but cannot be reviewed by the JSB. Whether the deficiency in information in the requests is remedied by oral information is impossible to verify.
- Significant involvement of oral information renders proper internal and external audit impossible.

Recommendations:

- Inform the JSB on the results of the review in policies and procedures for Europol’s role. - Ensure the ability of the Europol Data Protection Officer to carry out his role.
- Ensure hard-deletion of Article 4 data (data to the US where Europol has to verify their requests), which where inputted into some of Europol’s information processing systems before the upgrading of the security level.
- Contact the US Treasury Department and ensure that adequate information is provided with requests.
- Ensure verifications by Europol are made based on written requests, along with any supplemental documents, in order to allow for proper internal and external audit.

The Second Report notes that all US data requests to date have been approved and that some of the reasons are too generic. Many of the request applications included “copy and paste” texts and the information provided was out-of-date and already in the public domain, and oral information is still being provided to Europol in order for it to make decisions. Also, there is no geographic limitation to these requests (data concerning the whole world is requested), and the requests submitted on a monthly basis for a month in duration (so effectively data transfer is ongoing all year round with little limitation).

The JSB concluded that 2 of its recommendations from its previous report have been implemented, while progress is ongoing for the other 3. The EU and US have signed an agreement for a second person to be posted from the EU to the US Treasury Department to oversee the operation of the agreement. The Overseer currently in place has been involved in intensive on-the-job training, and has been in US Treasury briefings. Clearly continuous information is being provided on generic and incomplete information with little restriction, so it’s hard to see how the current system provides adequate safeguards.

The full report however is not publically available or even available to the MEPs on the LIBE Committee – when the Committee requested access to the report, the JSB said it had no objections, and that there was nothing sensitive in the report that would prevent it from being disclosed. However, Europol stated that disclosure would threaten operational interests, so the report has not been disclosed. You can find the JSB’s public statement here: PDF.

Sophie in’t Veld and Jan Albrecht weren’t impressed (Veld: “I feel that we’ve been had!”). Veld highlighted that the EP was assured that there would be no data mining, but that the current procedure – of continuous and almost unlimited access – is much worse and goes further than what Parliament had expected. Veld objected to the secrecy of the report, saying that the Committee cannot fulfil its role of scrutinising Europol and the Agreement properly on the basis of a “3 page summary”. Albrecht said that the demands of MEPs have not been met after 2 years of the agreement, adding that if we have a functional fundamental rights jurisdiction, we could get this taken down in court.

While the role of the Europol Data Protection Officer seems to have been strengthened, it hardly seems like there are any safeguards on the flow of financial transaction data to the US. Without a sunset clause on the agreement, the European Parliament is in a fairly weak position to act against the treaty or to demand amendments. We seen the trend of PNR treaties on passenger information lead to a bad proposal for EU PNR, and soon the Commission will propose a TFTS for the EU. We need to make sure that we don’t throw away our civil liberties for little or no security gain simply because law enforcement authorities want our information and data.

Wednesday, 29 February 2012

The EU's PNR Directive in Parliament

As well as Sophie in ‘t Veld reporting on the proposed EU-US PNR Agreement on Monday, Timothy Kirkhope (ECR) presented his draft report on the EU’s own Passenger Name Record regime. The PNR Directive is technical, but it involves a huge amount of data collection on people not suspected of a crime, and the processing of data to create models used to identify unknown criminals. The law poses major questions on data protection, and there are also issues of how necessary and effective the system is, and how much of the costs airlines (and therefore consumers) will bear to pay for the system. I’ll divide this post into outlining and discussing the proposed directive and briefly looking at Kirkhope’s report to the Committee on civil liberties, justice and home affairs.

The PNR Directive.

The proposed PNR Directive (PDF) would introduce a system where a wide range of data gathered by airlines on passengers on flights into and out of the EU would be processed for the purposes of fighting terrorism and serious transnational crime. The data gathered includes the information on passports, flight arrival and departure times and destination, check in status, payment details, address and contact information, frequent flyer information, travel agent, travel itinerary, general remarks (including information on unaccompanied minors and their guardian’s contact details and relationship to the minor), seat number, baggage information, code share information, ticketing field information, and date of reservation/issue of ticket. This data would be collected from everyone on flights into and out of the EU regardless of whether or not they’re suspected of a crime and without distinction to how susceptible an air route is judged to be to use for terrorism of serious transnational crime (also the UK has suggested an amendment for the latter). This raises questions of proportionality.

PNR data is to be used in three different ways: re-actively, in real time, and pro-actively. The re-active use of PNR data is the use of data in the investigation or prosecution of a crime which has already taken place; use of PNR data in real time entails the use of data to arrest or place an individual under surveillance for a crime being committed or about to be committed; and the pro-active use of PNR data is using PNR data to build up criteria against to identify persons worthy of further surveillance or action. “Serious transnational crime” isn’t really harmonised by the Directive – it uses the list of crimes in the European Arrest Warrant, but Member States can decide to exclude some of these crimes from their transposing legislation if they think one is too “minor” – so the Directive can’t even decide what’s a “serious crime”!

The data is transferred by airlines to “Passenger Information Units” (PIUs) that will be set up to process and analyse the data, and alert national law enforcement agencies if necessary. PIUs can be national, or countries can set up joint PIUs if they want to share the costs. (The vast majority of EU Member States don’t have a PNR regime, so this PNR Directive will effectively introduce PNR systems into most Member States for the first time). The data will be retained for 30 days, after which it will be “depersonalised” (identifying data removed, but not deleted so it can still be restored and used) and retained in this masked state for a further 5 years. Data can be kept for longer if it’s used in criminal investigations or prosecutions. 5 years seems disproportionate if the data isn’t being used in an investigation or prosecution – and even the Council’s own legal service has suggested a maximum retention period of 2 years ("Draft Agreement on the Use of Passenger Name Records (PNR), Note for the Attention of Mr Stefano Manservisi Director General, DG Home, European Commission Legal Service, SJ.f(2011)603245, 18/5/2011").

Data subjects (people who own data that is being stored or processed) have rights of access, rectification and erasure, and the National Supervisory Authorities set up under EU data protection legislation (Framework Decision on Data Protection) monitor the PIUs’ use of data and assist data subjects with their requests to exercise their rights. However the purposes for gathering and processing the data is so wide that it’s debateable how much substance there is to these rights. For example, PIUs can use the data for general analysis work and to update and create criteria for “objective assessment criteria” to identify unknown criminals – a very wide purpose to use and process data, so PIUs could probably refuse under the Directive to erase a person’s data even if they aren’t suspected of a crime. Also, this use of objective assessment criteria means that the PNR regime is open to the profiling of individuals by law enforcement authorities, where they might be put under closer scrutiny simply because they happened to match a certain pattern of behaviour. There are no safeguards for independent external review of these objective factors (the National Supervisory Authorities don’t seem to have the power to do so), and nor has there been an assessment of the effectiveness of this method in identifying unknown criminals versus the false identification of innocent people.

There’s also little satisfactory evidence that PNR is necessary or effective for fighting terrorism and serious transnational crime. We already have the Schengen Information System, the Visa Information System and the Carrier’s Directive (Link) permitted the use of a less invasive Advance Passenger Information system in 2004, where airlines would transfer passport information of passengers and flight arrival/destination details (rather than the whole gamut of PNR information) – but there’s been no assessment of the effectiveness of API, or whether changes in it or the other systems could provide a cheaper and less invasive alternative. The main advantage offered by PNR is presumably the detection of unknown criminals. The Commission has used crime statistics to highlight the levels of serious crime and terrorism to establish the need for further security measures to be introduced and it has also used statistics on the of PNR data in drug seizures (see its impact assessment here: PDF) Interestingly, some of these impressive PNR statistics derive from some Member States which do not currently have a national PNR regime! (Like Belgium - PDF).

So PNR faces a lot of questions on several fronts: is it necessary, does it work, are there cheaper and less invasive alternatives? So how does the draft report in the Committee deal with this?


Timothy Kirkhope’s report.

The draft report (PDF) has contains a long list of proposed amendments to the directive (it should be noted that the report is open to amendments from the Committee before it votes on the report as a whole).

Some of these amendments would clarify the scope of the Directive – by stating that it applies to airlines incorporated in the EU and that store data in the EU, and expanding the Directive to include intra-EU flights as well as flights entering and leaving the EU. By including intra-EU flights, there would obviously be a much, much greater amount of data gathered on people. In Committee it was explained that the Commission wanted the Directive to avoid including intra-EU flights so it could test the system out first (the Directive includes provision for a review in 5 years on whether to include intra-EU flights), while Kirkhope countered that gradual introductions of schemes rarely work in his experience. The costs of transferring data to the PIUs would be borne by the airlines, while Member States would pay for the PIUs and their work. Kirkhope said that the estimated costs that would be passed on to consumers in ticket prices would be between 10 to 18 cents.

The report’s amendments insert provisions regulating the transfer of data between Member States to ensure that safeguard standards are maintained and that data is only shared in certain circumstances. There are also new provisions to more extensively regulate the transfer of data to third countries, though the assessment is still left to Member States so there isn’t a common decision on the adequacy of a third country’s data protection standards like there is for internal market matters.

The amendments would also clarify the state of data after the initial 30 day period – the Directive uses the phrases “masked” and “anonymised”. Unfortunately, the draft report decides to simply change the phrasing to a more unified “masked” terminology rather than changing the procedure so identifying data will be deleted after 30 days. Some amendments do aim to strengthen data protection by setting down punishment for data breaches such as demotion, denial of system access, formal reprimands, and removal form duty, as well as an obligation to inform data subjects that might be affected by a data breach. National Supervisory Authorities would be given powers to take disciplinary action against persons responsible for a privacy breach, increasing their powers of independent oversight.

Kirkthorpe believes that the use of a PNR regime is necessary and proportional. While the necessity of the Directive is probably best debated by the Committee and whole Parliament, there are still questions over how proportional the Directive would be even with the report’s amendments, particularly over the targeting (or lack of targeting) of air routes, the oversight of creating and use of objective assessment criteria, and the length of the retention period. It does provide some good improvements to people’s rights to access, rectify and erase their data and makes it easier and more effective to exercise these rights (though the problem of the content of these rights given the wide use of data remains).

I’m very sceptical of the necessity for a PNR system – a lot of the analysis backing up the proposal seems to be based on numbers on the increase of crime together with rhetoric on fighting crime and anecdotal examples of how PNR could be used, rather than an analysis of the benefits of PNR versus the existing EU databases. It seems that we are being asked to accept the creation of a massive information gathering system on trust, and I’m not convinced.

Wednesday, 16 June 2010

SWIFT II Sent to Council and Parliament

The new SWIFT agreement (or the "Terrorist Finance Tracking Programme") has been reached between the Commission and the US, and the agreement has been sent to the Council and Parliament for assent. Green MEP Jan Albrecht has written about the new agreement and uploaded a PDF of it here. Statewatch also released a PDF of the agreement here.

So does the new agreement address the concerns of the Parliament? Privacy is the central issue, and the long preamble to the deal takes care to highlight the tradition of privacy rights and protection in each jurisdiction (though MEPs tend not to see US privacy laws in the most flattering of lights), but a few new changes have been introduced to try and reassure Parliament.

Elements of the deal include: some oversight by Europol; that the data, if relevant to tackling terrorism by European authorities, will be forwarded to them; data providers can seek redress; citizens can request the erasure, correction or blocking of their information; the deal can be paused or cancelled upon notification after the first 6 months (though the cancellation would take place 6 months after notification); after the deal expires, it is automatically renewed each year for a year unless cancelled; there are provisions for passing on the data to third parties in some cases.

The safeguards are unlikely to fill the EP will a lot of confidence. Europol is an agency to aid work against organised crime, etc. in the EU - and therefore more likely to have a "police" outlook rather than a more impartial judge's outlook on how legal the transfer of data is. Having Eurojust look at the transfer of data to ensure that it complies would be better, as it would have more legal expertise, but a specialised legal review board would be better, in my opinion. In any case, despite the constant references in the deal that applications for data will be on specific data, the net will be quite wide in reality, since Swift only deals with bulk packages of data, and cannot separate them out.

If the data being transferred is bulk data, then it devalues the oversight - some private data will be transferred anyway, so there will already be a high tolerance for its transfer. There would presumably have to be quite a big breach of the agreement for Europol to stop a transfer (though my understanding is that they check that the application is correct, rather than going through the data itself - I doubt they have the resources to do that). The US have undertaken to delete data irrelevant to the deal's purpose, but effective safeguards are what the EP's after.

It's hard to see how effective the citizen's right to erasure, etc. would be. It would be rare that people would discover that data concerning them has been transferred, so how often can these rights be expected to be exercised? Effective safeguards before transfer are vital under these circumstances. Ideally there would be an application to a judicial panel for specific information, which would then be passed on if it complied with the deal.

Jan also brings up the question of how long the data would be retained for in his post. 5 years is too much, though if it was an exceptional period for an exceptional investigation and subject to rigorous safeguards and scrutiny, then such retention may be justifiable. Clearly such conditions aren't satisfied here.

Will it pass in Parliament? I hope not, and there are plenty of reasons here for the EP to reject it. However, there may be pressure to accept it to prevent the US from making bilateral deals and circumventing the EP altogether (though the US would have to consider how that could sour relations with the EP on matters that it cannot circumvent them).


On L'Europe en Blogs, there's an interview with the Commissioner for Home Affairs (whose department this falls under) here.

Tuesday, 5 January 2010

An Explosive Security Test

Airport security has had one of its regular revivals as a news topic since the attempted bombing in the US, and there's always questions of liberty versus security. But a airport security has reared its head in Europe is far stranger circumstances today, when it emerged that explosives were smuggled into Ireland after a security test by Slovakian authorities went wrong.

It seems that a security test was run, where explosives would be smuggled past airport security in Bratislava airport to see if they'd be spotted (much like the security test at public buildings in the US a few months ago). However, instead of using a civil servant or someone trained in the security sector, the explosives were simply planted on an unsupecting traveller.

Airport security missed the explosives, and the man flew on to Dublin, and went home, without knowing he was carrying illegal material. He didn't notice what had been planted in his luggage, and it wasn't discovered until Bratislava informed the Irish Gardaí (police) - three days later.

It just seems amazing that Bratislava could put someone who was essentially an unsuspecting passer-by through something like that, and that it took 3 days to contact Irish authorities!

This comes as yesterday the Spanish rotating presidency of the Council pushed for greater intelligence sharing to combat terrorism. Although it wasn't military intelligence in this case, information sharing between member states' authorities are meant to be made easier by the EU and the Lisbon Treaty - though it's not clear what the source of any communications problems were at this point.