Select Committee on European Union Twenty-First Report


CHAPTER 3: the 2004 agreement: negotiation and conclusion

The EC Data Protection Directive

28.  As we have said, the Aviation and Transportation Security Act of 2001 required airlines to supply PNR data to the CBP within the DHS. However Article 25 of the 1995 EC Data Protection Directive[13] provides that personal information originating from within EU Member States may be transferred to a third country only if that country "ensures an adequate level of protection." The adequacy of the level of protection is assessed in the light of all the circumstances surrounding the data transfer, in particular the purpose of the transfer and its duration.

29.  The Commission decided that the United States did not ensure an adequate level of protection for PNR data transferred from Member States, which were therefore obliged to prevent the transfer of PNR data to the United States. The airlines were thus in the position that the transfer of PNR data to the United States was a breach of EC law, and of the national laws implementing the Directive;[14] but a failure to transfer the data would lead to sanctions in the United States which might extend to heavy fines and ultimately to a loss of landing rights.

30.  Article 25 of the Directive provides that where the Commission has found that data protection in a third country is inadequate, it may enter into negotiations with that country; and if at the conclusion of those negotiations it receives satisfactory assurances from that country, it can make a finding that the level of protection offered is now adequate—an "adequacy decision".

EU/US negotiations

31.  An interim arrangement allowed CBP to access PNR data from the beginning of March 2003. Intensive discussions with the EU resulted in commitments by the United States to address EU concerns on access, processing, use, storage, and protection of the PNR information. At the same time, led by the DHS, the United States Government engaged in an effort to obtain an adequacy decision from the Commission which would authorise permanent access to PNR data for CBP.

32.  On 16 December 2003 the Commission announced details of an agreement reached with the United States on the transfer of PNR data to US authorities. The Commission negotiators obtained from the United States a number of concessions on the amount of data to be sent and how the data would be handled. The European Parliament had previously expressed strong reservations about how and what sort of data would be exchanged, and had argued that such an agreement would infringe EU citizens' privacy law rights. The Commissioner in charge of the negotiations, Frits Bolkestein, told the Parliament that the US negotiators had moved significantly from their initial position. He explained that clear limits had been fixed on the amount of data to be transferred, with a closed list of 34 data elements. In addition, the United States had agreed to store the data for only 3.5 years, rather than the 50 years it had initially wanted. Three and a half years was the time of duration of the Agreement. Thirdly, the United States had finally accepted, after having refused earlier, a safeguard in the form of a joint review to be carried out with the EU authorities at least every year. Lastly, the United States was also willing to recognise the right of EU data protection authorities to represent any European passenger whose complaint to the DHS had not been satisfactorily resolved.

33.  When the US authorities began negotiations with the EU in February 2003 they sought to include 38 data elements. The Article 29 Working Party[15] considered these in their Opinion 4/2003 adopted on 13 June 2003 and concluded that twenty of them were acceptable. These included No Show history (where the passenger buys a ticket but does not travel), and Go show (the purchase of a ticket at the airport at the last minute). In the course of negotiations the United States dropped the number of data elements they required to 34. Strangely, the four which they dropped were among those which the Working Party had thought acceptable: identifiers for free tickets, number of bags, number of bags on each segment, and voluntary/involuntary upgrades.

34.  The 34 data elements on the final list accordingly include 18 which the Working Party thought went "well beyond what could be considered adequate, relevant and not excessive". Those which particularly concerned the Working Party were the General remarks, OSI (Other Service-Related Information) and SSI/SSR (Special Service Information/Special Service Requests.[16] It is here that sensitive data can appear—defined as "personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and data concerning the health or sex life of the individual".[17] An example given to us would be a request by a passenger for halal food.[18]

35.  There is thus nothing magical about the number 34, when it comes to deciding on data elements. The Agreement concluded by the EU with Canada in 2005, to which we refer in detail in paragraphs 91 to 94, contains 25 data elements; in preliminary negotiations with the Australians, they are asking for only 19 data elements.[19] Although all 34 data elements are potentially available in the case of each passenger, "CBP believes that it will be rare that an individual PNR will include a full set of the identified data".[20] We have been told that PNR data consisting of ten data elements are more usual.

36.  On 29 January 2004 the Article 29 Working Party gave a formal opinion on the draft Agreement.[21] It noted that there had been some improvement in the Undertakings now offered on how the data would be handled, but took the view that they would still not justify an adequacy decision. The Working Party concluded that the purposes of the data transfer should be limited to fighting terrorism and specific terrorism-related crimes to be defined; the lists of data elements and the data retention periods should be proportionate; data subjects should have access to their data and to an independent redress mechanism; and the commitments should be legally binding on the United States.

37.  Professor Stefano Rodota, the then Chairman of the Article 29 Working Party, addressed the LIBE Committee of the European Parliament the following month to explain the Working Party's "inadequacy" finding. He explained that in the view of the Working Party the proposed adequacy decision was likely to be in breach both of Article 8 (privacy) and Article 6 (right to a fair trial) of the European Convention on Human Rights. There was no possibility of appeal to an independent authority in the United States or elsewhere that would have authority to review data transfer. The lack of explicit guarantees was exacerbated by the very considerable level of discretion granted to the United States administration by the current text. It violated at least three cardinal principles of EU law: necessity, purpose and proportionality. It did not impose a limit on the types of authorities to which passenger data could legally be transferred, nor did it afford the EU any safeguards against the United States changing the nature of their undertakings by reference to alleged changes in circumstances. As we show in Chapter 5, this proved to be a prescient remark. Professor Rodota concluded by drawing attention to the Report which this Committee had recently published which fully supported the "inadequacy" finding of the Article 29 Working Party.[22]

Conclusion of the 2004 Agreement

38.  There was little change in the Undertakings between January and May 2004. Nevertheless the Commission adopted an Adequacy Decision on 14 May 2004, amounting to a formal finding that, for the purposes of Article 26(5) of the Directive, the Undertakings offered by the CBP on 11 May 2004 and annexed to the Commission Decision provided adequate protection for the data of passengers flying to or from the United States. Three days after the adoption of the Commission Adequacy Decision, the Council on 17 May 2004 adopted a Decision authorising the signature on behalf of the EC of an Agreement with the United States—the 2004 PNR Agreement. The Agreement was signed in Washington D.C. on 28 May 2004 by a representative of the Presidency on behalf of the EU and by the then Secretary of the DHS on behalf of the United States. It entered into force on that day.[23]

39.  The Commission Adequacy Decision is set out in Appendix 4. The Undertakings are annexed to it. The list of 34 PNR data elements required by CBP forms an attachment to the Undertakings. The text of the Agreement itself is set out in Appendix 5.

40.  There is sometimes confusion about the purpose of this Agreement. It was not intended to authorise the transfer of PNR data by the airlines to the US authorities, nor does it purport to do so. Its purpose was to legalise the "pulling" by CBP of PNR data from air carriers' registration systems if and only if this took place in accordance with the Commission Adequacy Decision, and hence in accordance with the Undertakings offered by the United States and annexed to that Decision.

The Undertakings

41.  The Undertakings given by the US authorities which enabled the Commission to issue its Adequacy Decision are set out in full in Appendix 4. The following are some of the most significant:

42.  These Undertakings, while in no way diminishing the value of PNR as a tool in combating terrorism, would, if strictly adhered to and interpreted in the spirit of the Agreement, have constituted a valuable restriction on the use of PNR data which might well have justified the Commission's Adequacy Decision. However there are other Undertakings which considerably diminish the value of these. Undertaking 47 provides that "These Undertakings do not create or confer any right or benefit on any person or party, private or public." In other words, they are a statement of intent, but cannot be relied on in a court of law. Breach of an undertaking could not be used to support a claim by a person that his PNR data had been misused and that he had thereby suffered loss.

43.  Undertakings 34 and 35 can be and, as will appear in Chapter 5, have been used to make very significant changes to the PNR data elements, to the Undertakings themselves, and hence to the uses to which the data elements can be put. The first of these Undertakings reads:

"No statement herein shall impede the use or disclosure of PNR data to relevant government authorities, where such disclosure is necessary for the protection of the vital interests of the data subject or of other persons, in particular as regards significant health risks. Disclosures for these purposes will be subject to the same conditions for transfers set forth in paragraphs 31 and 32 of these Undertakings."

There is nothing to say who is to determine, and on what basis, what is a "vital interest" of the data subject, when disclosure is "necessary", or which are the "relevant" government authorities to which disclosure is made.

44.  Undertaking 35 reads:

"No statement in these Undertakings shall impede the use or disclosure of PNR data in any criminal judicial proceedings or as otherwise required by law. CBP will advise the European Commission regarding the passage of any US legislation which materially affects the statements made in these Undertakings."

This means that changes in United States law which require PNR data to be used for other purposes will override the Undertakings.

Cost

45.  Airlines are commercial organisations. They are of course concerned with the safety of their passengers, their crews and their aircraft, but ultimately their aim is to make a profit. When, three years ago, we considered a draft EU Directive[24] on the obligation by carriers to communicate passenger information to Government authorities, we received evidence from the Board of Airline Representatives in the UK (BARUK), the British Air Transport Association (BATA), Britannia Airways and British Airways, all complaining about the burden (not just the cost) that the proposed Directive would place on them.[25] That report was published in February 2004, when negotiations on the 2004 Agreement were drawing to a close, and our report referred to these, and commented on the burden such an Agreement would place on air carriers.[26]

46.  In the context of this inquiry BATA have sent us evidence of their own, incorporating the views of British Airways and Virgin Atlantic. (p 54) The airlines believe that the cost of providing the data should lie with the requesting authority. We believe their hopes of achieving this are minimal, given that the negotiating mandate of the Council and Commission does not include any reference to the cost.[27] There are however other burdens which could and should be lightened, and which we consider in paragraphs124 to 130 below.

Informing the travelling public

47.  Passengers intending to fly to the United States have a right to be told in advance that significant personal data will be transferred to the US authorities. The onus must not be on the passenger to seek this information; it is the airline's duty to provide it.

48.  In a formal Opinion[28] the Article 29 Working Party has put forward a short model form and a longer response to Frequently Asked Questions which would enable airlines to carry out this duty in a consistent and satisfactory way. The Working Party suggests that the following methods should be used:

  • if the booking is made through a travel agent, the passenger should be given the short form and, if he or she requests it, the longer form;
  • if the booking is made by telephone, the short form should be read to the passenger, who should be told how to access the longer form (e.g. by visiting a website);
  • if the booking is made on the internet, the short form should appear on the screen without the passenger having to take any positive step, and the short form should enable the passenger to click on the longer form.

49.  It is important that intending passengers should be aware of who will receive their personal data, and subject to what conditions. We agree with the Working Party that the airlines should be responsible for informing passengers, and we endorse the Working Party's proposals.

50.  Some airlines already provide information of this type. By way of illustration we show what people booking a British Airways flight online, regardless of the destination, are able to access if they wish to check to which government authorities British Airways may pass the personal data they have provided.

TABLE 1

British Airways: Frequently Asked Questions
Question
Where can I find details of the access to British Airways booking records for US and other governments?
Answer
Under U.S. Law, U.S. Customs and Border Protection (CBP) will receive certain travel and reservation information, known as Passenger Name Record or PNR data, about passengers flying between the European Union and the U.S.
CBP has undertaken that it uses this PNR data for the purposes of preventing and combating terrorism and other transnational serious crimes. The PNR may include information provided during the booking process or held by airlines or travel agents. The information will be retained for at least three years and six months and may be shared with other authorities.
Airlines are also required by UK laws to provide passenger data to UK Customs and Immigration. It is expected that passenger data will have to be disclosed to other governments such as Australia and Canada in the near future. Accordingly any information we hold about you and your travel arrangements may be disclosed to the customs and immigration authorities of any country in your itinerary.
Q1. What data do you hold about me which may be accessed? We hold data about you which we require for the purpose of conducting business with you. This may include details you have told us about any medical, disability, or health conditions you may have; payment details; contact information; and any special requirements you have specified.
Q2. Who will you pass the data to, and who will they share it with? The data will be given to the Border Control authorities, for example, Customs, of countries which have a legal right to acquire the data. They may share it with other enforcement authorities for the purposes of preventing and combating terrorism and other serious criminal offences
Q3. What if I refuse you permission to release my data to the authorities? If you are flying to or through a country which requires the information, we will have to cancel your reservation and will be unable to carry you to or through that country.
Q4. Which countries have legislation to permit access to my data? At present, there is legislation in Australia, Canada, UK, and USA requiring carriers to grant access to passenger information. Other countries may follow in the future.
Q5. What will the authorities be using the data for? Data is used for enforcement purposes, including use in threat analysis to identify and interdict potential terrorists, and other threats to national and public security; and to focus government resources on high risk concerns, thereby facilitating and safeguarding bona-fide travellers.
Q6. Are my credit card details included? If payment has been made by credit card and this data is included in your passenger information record, the authorities may view details.
Q7. How long will data be held for? Each country should hold the data for no longer than is required for the purpose for which it was stored.
Q8. Will the data be transmitted in a secure fashion? Yes, British Airways will pass the data to the authorities by secure means.



13  
Directive 95/46 of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, OJ L281, 23 November 1995, p 31. Back

14   In the United Kingdom, section 4 of and Schedule 1 to the Data Protection Act 1998. Back

15   The Data Protection Working Party established under Article 29 of the Data Protection Directive 95/46/EC. Back

16   These are commonly referred to as general remarks and open fields: see Undertaking 5. Back

17   Defined in Undertaking 9: see paragraph 40 and Appendix 3. Back

18   Mr Bayo Delgado, Q 196. Back

19   Dr Gus Hosein, Q 36. Back

20   Undertaking 4. Back

21   Opinion 2/2004 on the Adequate Protection of Personal Data contained in the PNR of Air Passengers to be transferred to the United States, Bureau of Customs and Border Protection (US CBP). Back

22   Fighting illegal immigration: should carriers carry the burden? Fifth Report, Session 2003-04, HL Paper 29, paragraphs 30 to 34. Back

23   As stated in the judgment of the European Court of Justice, paragraph 32. Back

24   Subsequently adopted as Directive 2004/82/EC on the obligation of carriers to communicate passenger data, OJ 2004 L 261/24. Back

25   The evidence is published on pages 15-19 of the report Fighting illegal immigration: should carriers carry the burden? Fifth Report, Session 2003-04, HL Paper 29. Back

26   Ibid., paragraphs 30-34. Back

27   Evidence of the Department for Transport Aviation Directorate, which would have preferred the mandate to include a reference to the cost (p 55). Back

28   Opinion 2/2007 of 15 February 2007. Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007