Showing posts with label terrorism. Show all posts
Showing posts with label terrorism. Show all posts

Tuesday, 25 September 2012

Reports of US breaching EU PNR Agreement

The transfer of Passenger Name Record Data - the information you hand over to airlines when you book a flight - from EU airlines to the US government has been a controversial issue in Brussels, with the transfers taking place for a decade on one basis or another without a satisfactory agreement in place to regulate it.

Earlier this year the European Parliament ratified an agreement with the US to regulate - and make legal in the EU - the transfer of this personal data to the US government for anti-terrorism and crime fighting purposes. I was against this agreement because it is spectacularly disproportionate and infringed privacy rights: data can be held for far too long (over a decade) for practically any purpose whatsoever. Sadly Sophie In't Veld's report advising rejection of the agreement was voted down in Committee and the Parliament ratified the agreement in plenary.

However it seems that the US hasn't been satisfied with even this gift of a treaty, with reports that the US government has been collecting data on people on flights that do not take off or land in the US, in contravention of the agreement. The S&D Group in the European Parliament has called on the Justice Commissioner Malmstrom to account for this before the LIBE Committee in Parliament:

"S&D spokesperson on civil liberties, justice and home affairs, Claude Moraes MEP, said:
 
"The media reports show that the US may be requesting data which falls outside the scope of the EU-US PNR agreement. We signed up to the agreement on strict conditions and we need clear answers if EU citizens' data is being collected contrary to spirit of the agreement.
 
"If our citizens' data is being collected for flights simply going through US airspace, then this could be against EU data protection laws. We are taking this matter very seriously and that is why the S&Ds have requested that Commissioner Malmström comes to the civil liberties committee to give MEPs a full picture of the situation regarding US collection of EU citizens' PNR data.""

It would not be the first time the Parliament has been disappointed by poor results from bad treaties.

Wednesday, 15 August 2012

A European SWIFT?: the Commission outlines available options

Just after the Lisbon Treaty came into force, the European Parliament used its new power to block the SWIFT Treaty with the US, which would give the US Department of Homeland Security access to financial transaction data for anti-terrorism purposes. The problem was there was no way of targeting suspected individuals and no judicial oversight: financial transaction information would be handed over in bulk (based on search categories) to the US government to search through.

After some changes (Europol gained the role of verifying the compliance of US requests under the treaty for data) and heavy lobbying that included a vice-presidential visit to the European Parliament, the EP voted through a re-negotiated treaty. Since then it turns out that the negotiated safeguards are wholly inadequate, with general data covering a global area for an essentially unlimited time being provided to the US DHS.

Part of SWIFT II was that the US would help the EU establish its own system (Article 11), and the Commission has published a communication on the options on setting up a European Terrorist Financial Tracking System (PDF). A more targeted approach to data collection is one of the aims of a European system, so that these systems are less intrusive into the privacy of citizens.

The Communication doesn't pick a particular option, and there will be an Impact Assessment based on a study the Commission contracted out in 2010. The Communication also promises that the Impact Assessment will pay particular attention to the necessity and proportionality of a European system and its impact on fundamental rights - given the poor use of statistics in the PNR proposals, I can't say I've much confidence in the quality of impact assessments in the area of justice and home affairs.


Goals:

Two main goals have been identified:

"• the system must provide an effective contribution to the fight against terrorism and its financing within the European Union;

• the system must contribute to limiting the amount of personal data transferred to third countries. The system should provide for the processing of the data required to run it on EU territory, subject to EU data protection principles and legislation."

A European TFTS could provide a useful extra tool in the fight against terrorism, and given the European basis of SWIFT (it's based in Belgium), designing a system that respects civil liberties and fundamental rights would have a positive knock-on effect in the EU's security relations with the US and other countries when it comes to finance tracking by ensuring that any transfers of data also comply with fundamental rights.

More specifically the system will cover:

"• preparing and issuing (legally valid) requests to the designated provider(s) of financial messaging services for the raw data to be provided to an authorised recipient or recipients. This involves determining the message categories to be requested, how often such messages should be sent, and maintaining contacts with the providers on these issues;

• monitoring and authorising requests to the designated provider(s) for such raw data. This involves verifying whether the request for the raw data have been prepared in accordance with the applicable limitations;

• receiving and storing (processing) the raw data from the designated provider(s), including the implementation of an adequate system of physical and electronic data security;

• running the actual searches on the data provided, in line with the applicable legal framework; on the basis of requests for such searches from authorities of the Member States, the U.S. or other third States on the basis of clearly defined conditions and safeguards, or on the own initiative of the authority (or authorities) entrusted with processing the data;

• monitoring and authorising the running of searches on the data provided;

• analysing the results of the searches, through combining these results with other available information or intelligence;

• distributing the results of the searches (without further analysis) or the results of the analyses to authorised recipients;

• implementing an appropriate data protection regime, including applicable retention times, logging obligations, handling requests for access, correction and deletion, etc."

Options (from page 9 onwards):

The Communication makes it clear that a hybrid solution is preferable to an exclusively national or exclusively centralised approach, so all of the options are designed along hybrid lines with differing degrees of (de)centralisation.

Option 1: A central EU TFTS unit as a coordination and analytical unit cooperating with national law enforcement authorities. Under this system most of the data work would be done at the European level with national requests to the central unit. Europol or Eurojust are possibilities for performing the central unit's role.

Option 2: EU TFTS extraction service option. This would be the same as option 1, but the central unit would not carry out analysis based on the extracted data for national requests (only for EU or third country requests), and requests would be verified at the national level.

Option 3: A Financial Intelligence Unit: there would be a European FIU platform which would request data from SWIFT and/or other data providers on the basis of national FIU needs. National FIUs would carry out the analysis, etc., for their Member State. The FIU Platform could deal with third country requests and for EU institutions.

The FIU model bears a striking resemblance to the Passenger Information Units envisaged by the current proposed Passenger Name Record Directive (PDF), so I'm guessing that something close to option three will be what we see in the draft law. going with this model will bring up a lot of issues regarding safeguards and oversight, and how data analysis is used, as well as what scope the FIU Platform will have for transfering data on to third countries. Some of these issues will also remain for the other options, but at first glance it looks like option 2 provides a system with clearer lines of responsibility that also ensures that the information is delivered to national experts who can then get on with the job.


Two key aspects for a European TFTS.

A European TFTS has to be a system of individualised searches. The processing of bulk data is essentially casting a wide net, with government rummaging through everything that's been dredged up, whether or not the data belongs to non-suspects. Developing a system capable of delivering individualised searches is necessary if the system is to be equipped with sufficient safeguards to protect civil liberties.

The second key aspect for a European TFTS is that searches need to be subject to judicial oversight in the Member States - law authorities should not be able to issue searches whenever they want, but they should have to get judicial permission (or an equivalent process in national law) for a search based on specific legal grounds. This would help prevent data mining (or similar practices such as what goes on under the current treaty) and ensure that there are strong safeguards. These aren't the only safeguards necessary - retention periods and how far analysis shifts into profiling are other issues that need to be considered when the studies and the legislative proposal come out - but they are necessary. If these basic elements are missing from any TFTS, then it should be rejected. (The Communication mentions that Europol as a possibility for a role in verifying requests for data under the system, despite not being a judicial authority by any stretch of the imagination).

The contracted study should be finished by the end of the year and I assume the impact assessment and proposal will be published in 2013.

Tuesday, 29 June 2010

SWIFT II: European Data Protection Supervisor's Report to Council

The European Data Protection Supervisor yesterday sent a report (PDF) on the SWIFT II agreement (or TFTP agreement) to the Council. Given the criticism of the agreement from Parliament (though there is recent news of some agreed compromise), the EDPS report is interesting.

For example, at paragraph 5, the EDPS notes that the proposal does not see Article 16 TFEU (on data protection) as a legal basis, though the agreement and proposal note the data protection concerns. The report tersely notes: "...the EDPS reiterates that this agreement not only relates to the exchange of personal data, but also to the protection of these data. Article 16 TFEU is therefore not less relevant as legal basis than Articles 82 and 87 TFEU relating to law enforcement cooperation that have been chosen as legal bases."

The scope for future agreements on data protection and for a general agreement between the US and EU on data protection is discussed as well, particularly in paragraph 8. The EDPS recommends that the current proposal (agreement) be amended so that if there's a general agreement on data protection, it will apply - or at least get an agreement that it would apply to TFTP circumstances.

The EDPS takes a look at the question of privacy rights and the security question through explicitly rights-based language (Para 15):

"15. Against this background, the Commission proposal highlights the usefulness of the TFTP Programme, as put forward by the US Treasury and by the eminent person's reports. However, the condition laid down by Article 8 ECHR in order to justify interference with private life is "necessity" rather than "usefulness"."


The report goes on to flag up the same concerns that the agreement's critics in Parliament have highlighted: the retention of data for up to 5 years regardless of whether it's been extracted or if there's a "proved link with a specific investigation or prosecution.", and bulk transfers are the big concerns. In fact, paragraph 20 urges for a transitional approach to bulk data if it is to be used at all:

"...EDPS believes that solutions should be found to ensure that bulk transfers are replaced with mechanisms allowing financial transaction data to be filtered in the EU, and ensuring that only relevant and necessary data are sent to US Authorities. If these solutions could not be found immediately, then the Agreement should in any event strictly define a short transitional period after which bulk transfers are no longer allowed."


Also worth higlighting is the whithering criticism for handing the judicial oversight role to Europol:

"25. Moreover, Europol has specific interests in the exchange of personal data, on the basis of the proposed agreement. Article 10 of the proposal gives Europol the power to request for relevant information obtained through the TFTP, if it has a reason to believe that a person or an entity has a nexus to terrorism. It is hard to reconcile this power of Europol, which may be important for the fulfilment of Europol's task and which requires good relations with the US Treasury, with the task of Europol to ensure independent oversight.

26. Furthermore, the EDPS wonders to which extent the current legal framework entrusts Europol - especially without changing its legal basis pursuant to the ordinary procedure established by the Lisbon Treaty - with the tasks and powers to make an administrative request coming from a third country "binding" (Article 4.5) on a private company, which will thus become "authorized and required" to provide data to that third country. In this context it is useful to note that it is under the present state of EU law not evident whether a decision of Europol vis-à-vis a private company would be subject to judicial control by the European Court of Justice."


The report also criticises some aspects of the personal rights under the agreement when it comes to the correction/deletion of information. (As it's already turning into a long post, I'll let you read it [paragraphs 28-33], but it raises questions over the ability of people to exercise these rights). The EDPS also urges the inclusion of a sunset clause in the agreement to help encourage sustained work towards improving data protection under its provisions.

Overall the report echoes the concerns of the critical EP voices, while welcoming the changes make since SWIFT I. How much of an impact will it have in the Council? It's hard to tell how wedded the Member States are to the agreement, though it's interesting to note that the report mentions that the German Constitutional Court (Bundesverfassungsgericht) considers the retention of data over 6 months to be excessive, so it is possible that some Member States could share worries over the diminution of privacy rights of their citizens. What will be the extent of any agreed amendments be? Hopefully these clear calls will have a positive impact.

Wednesday, 16 June 2010

SWIFT II Sent to Council and Parliament

The new SWIFT agreement (or the "Terrorist Finance Tracking Programme") has been reached between the Commission and the US, and the agreement has been sent to the Council and Parliament for assent. Green MEP Jan Albrecht has written about the new agreement and uploaded a PDF of it here. Statewatch also released a PDF of the agreement here.

So does the new agreement address the concerns of the Parliament? Privacy is the central issue, and the long preamble to the deal takes care to highlight the tradition of privacy rights and protection in each jurisdiction (though MEPs tend not to see US privacy laws in the most flattering of lights), but a few new changes have been introduced to try and reassure Parliament.

Elements of the deal include: some oversight by Europol; that the data, if relevant to tackling terrorism by European authorities, will be forwarded to them; data providers can seek redress; citizens can request the erasure, correction or blocking of their information; the deal can be paused or cancelled upon notification after the first 6 months (though the cancellation would take place 6 months after notification); after the deal expires, it is automatically renewed each year for a year unless cancelled; there are provisions for passing on the data to third parties in some cases.

The safeguards are unlikely to fill the EP will a lot of confidence. Europol is an agency to aid work against organised crime, etc. in the EU - and therefore more likely to have a "police" outlook rather than a more impartial judge's outlook on how legal the transfer of data is. Having Eurojust look at the transfer of data to ensure that it complies would be better, as it would have more legal expertise, but a specialised legal review board would be better, in my opinion. In any case, despite the constant references in the deal that applications for data will be on specific data, the net will be quite wide in reality, since Swift only deals with bulk packages of data, and cannot separate them out.

If the data being transferred is bulk data, then it devalues the oversight - some private data will be transferred anyway, so there will already be a high tolerance for its transfer. There would presumably have to be quite a big breach of the agreement for Europol to stop a transfer (though my understanding is that they check that the application is correct, rather than going through the data itself - I doubt they have the resources to do that). The US have undertaken to delete data irrelevant to the deal's purpose, but effective safeguards are what the EP's after.

It's hard to see how effective the citizen's right to erasure, etc. would be. It would be rare that people would discover that data concerning them has been transferred, so how often can these rights be expected to be exercised? Effective safeguards before transfer are vital under these circumstances. Ideally there would be an application to a judicial panel for specific information, which would then be passed on if it complied with the deal.

Jan also brings up the question of how long the data would be retained for in his post. 5 years is too much, though if it was an exceptional period for an exceptional investigation and subject to rigorous safeguards and scrutiny, then such retention may be justifiable. Clearly such conditions aren't satisfied here.

Will it pass in Parliament? I hope not, and there are plenty of reasons here for the EP to reject it. However, there may be pressure to accept it to prevent the US from making bilateral deals and circumventing the EP altogether (though the US would have to consider how that could sour relations with the EP on matters that it cannot circumvent them).


On L'Europe en Blogs, there's an interview with the Commissioner for Home Affairs (whose department this falls under) here.