Select Committee on European Union Written Evidence


Memorandum by the Information Commissioner

  1.  The Information Commissioner has responsibility for promoting and enforcing the Data Protection Act 1998 and the Freedom of Information Act 2000. He is independent from government and promotes access to official information and the protection of personal information. The Commissioner does this by providing guidance to individuals and organisations, solving problems where he can, and taking appropriate action where the law is broken. The comments in this evidence are primarily from the data protection perspective.

  2.  The Commissioner has been involved in the data protection issues arising from the transfer of airline passenger data from the EU to US authorities for their own purposes from the time that the US authorities first imposed such a requirement on UK airlines. His work in this area has primarily been in the context of his membership of the Article 29 Working Party established under the EU Data Protection Directive and consisting of the national data protection authorities of each EU member state. Given that the issue affects personal data held by all airlines flying from EU member States to the US, an EU wide solution to the problem has always been seen as the most effective approach. Annex 1 provides a full account of that involvement including the data protection issues that arise and the various solutions that have been adopted.

  3.  At the heart of data protection concerns is the need to balance the legitimate interests of states to control who enters their own territory and ensure the safety of their own citizens and visitors with the need to ensure that this is undertaken in a manner consistent with necessary data protection and privacy safeguards. This has centred upon whether the arrangements put in place amount to an adequate level of data protection. Key data protection concerns focus on the following areas:

    —  A proper legal basis for requiring the information.

    —  Minimising the data transferred to that strictly necessary and avoiding sensitive personal data such as information on religious beliefs.

    —  Limiting the purpose for which the data can be used to areas of pressing need.

    —  Limiting wider disclosure to where strictly necessary.

    —  Appropriate retention periods guaranteeing that data is only kept for the minimum period necessary.

    —  Transparency for passengers though adequate information when they book flights.

    —  Redress for individuals if problems occur and their right to access information held about themselves.

    —  Appropriate security to safeguard against unauthorised access.

    —  Appropriate technical solutions for the transfer of data ( a "push" system of airlines sending the necessary data rather than a "pull" one where the US authorities gain access to reservation systems and draw down the information they require).

    —  Effective inspection and review mechanisms to ensure safeguards are being applied in practice.

  4.  The Commissioner and his colleagues on the Article 29 Working Party have always worked together to try to ensure that the agreements signed between the EU and third countries such as the US have these essential safeguards in place. They are keen that any new agreement with the US should be negotiated on the basis that safeguards will be included to ensure that all the matters listed in paragraph 3 above are addressed. In particular there should be no reduction of the level of protection afforded by the current arrangements.

  5.  The Article 29 Working Party has made clear that an agreement with the US at EU level is preferable to bilateral agreements between the US and particular member states. An EU level agreement will help ensure a consistent and harmonised approach to personal data protection. The Working Party has already identified key areas where attention should be paid during negotiations on a new agreement (WP 122).[1] These are:

    —  At the very least, the preservation of the current level of protection and the further integration of the US undertakings into the agreement itself.

    —  Taking account of the previous opinions of the Working Party. These include the need to reduce the number of specified data items collected to those that have proved of true value based on experience.

    —  Mandatory use of a "push" system now that technical arrangements are in place (the delays in moving to a push system are of major current concern to the Working Party as the appropriate technical measures now appear to be available but a "push" system remains in place with the airlines and the US authorities holding each other responsible for the failure to move to a "push" system).

    —  Strict purpose limitation to ensure that data is only used for the limited purposes for which it was transferred and also that it is not transferred subsequently to third parties for wider unconnected purposes.

    —  Continuation of the annual joint review mechanism to help ensure compliance with the specified safeguards.

  6.  The Commissioner and his EU counterparts have noted with concern that mechanisms provided for at paragraph 7 of the Undertakings for consultation by the US with the EU on the expansion of the data items appear to have been used in practice as a basis for unilateral declaration by the US side of their intention to expand the items. This is not what the Commissioner and his counterparts envisaged by a consultative arrangement. (Exchange of letters between the US DHS and EU expanding data elements to include further frequent flyer information-2006/C259/01 & 02).

  7.  The Commissioner and his EU counterparts are concerned to ensure that the safeguards in any agreement are complied with in practice. As mentioned in paragraph 5 above, the continuation of the annual joint review mechanism is an essential safeguard that will help ensure compliance with restrictions such as those on wider use. One joint review took place under the previous arrangements and the continued delay in undertaking a further joint review can only undermine confidence that the safeguards are effective. The concerns that some have expressed that EU PNR data may be used outside the terms of the current undertaking, in that it is processed on the US "Automated Targeting System" could more readily be addressed if timely reviews were to are take place.

  8.  The Commissioner and the Article 29 Working Party believe that as international air transport operates on a global basis, a global solution to the PNR issue is desirable. An instrument established under the auspices of the International Civil Aviation Organisation (ICAO) could set out a common set of data items and procedures that all states could follow. This would be preferable to each state specifying its own requirements and then concluding an ever increasing number of bilateral agreements. Achieving a common international instrument with appropriate data protection safeguards would ensure a consistent approach and reduce confusion for airlines and passengers.

  9.  The different approaches taken by individual states are already apparent. The agreement concluded by the EU with Canada in response to their demands for EU PNR data is a case in point. This differs from the US requirements in a number of respects. An obvious example is the data items required. There are 34 in the case of the US and 25 in the case of Canada. Furthermore with Canada the "general remarks" text fields are excluded. This appears to be a more proportionate approach to the problem. The Article 29 Working Party concluded that the arrangements put in place did amount to an adequate level of data protection as compared with the US where, in their view, they did not (WP103).[2] Other significant factors included the mandatory use of a "push" system and the existence of an independent data protection supervisory regime in Canada.

  10.  The Commissioner and his EU colleagues are eager to help inform the forthcoming negotiations with the US on a new agreement by providing advice and assistance. The Article 29 Working Party has established a dedicated PNR sub group to work on passenger data issues in which the Information Commissioner's staff participate. The sub group, on behalf of the Working Party have organised a workshop on PNR issues on 26 March in Brussels to help inform the forthcoming negotiations. A wide variety of participants and speakers have been invited including the Chairman of Sub Committee F. The sub group has worked in close cooperation with the European Parliament's LIBE committee who are also organising a connected event.

  11.  The Information Commissioner believes that it is vital that as states seek to protect their citizens from terrorist and other criminal acts they adopt a considered and proportionate approach to the collection and processing of personal information. The acquisition and retention of a wide range of personal details, many of which prove to be of no more than marginal value, only serves to undermine public confidence. There is risk that excessive data collection and use will start to erode the very freedoms that the states are seeking to protect. The Commissioner believes that the twin pubic policy objectives of public safety and data protection are reconcilable and should be achievable in any agreement concluded with the US authorities.

Richard Thomas

5 March 2007

Annex 1

THE INFORMATION COMMISSIONER'S INVOLVEMENT IN THE EU /US PASSENGER NAME RECORD AGREEMENT

1.  BACKGROUND

  Airlines operating scheduled air services record what is known as passenger name record data (PNR) on passengers who make reservations on their flights. These records are usually maintained on central shared customer reservation systems (CRS) operated by third parties on the airlines' collective behalf. Most prominent of these in Europe is Amadeus which most European airlines use. This contains records relating to the fights of participating airlines and can be accessed and updated by the airlines and third parties such as travel agents who can create and amend records when dealing with a passenger's reservation.

  The PNR contains a variety of information about passengers ranging from flight details, method of payment, dietary preferences and free text information containing general remarks. In addition to the PNR airlines create what is know as APIS data when a passenger checks in. This is held on the airline's own departure control systems(DCS).

  In the aftermath of 9/11 US authorities realised the potential security benefits of having prior notice of passengers arriving in their territory to enable them to check against watch lists and undertake passenger profiling. The data held as PNR was seen as particularly valuable. The US Government passed a legal statute (Title 49 United States Code section 44909 (3) and Title 19 Code of Federal Regulations section 122.49b). This required each air carrier operating passenger flights to or from the US to provide US Customs and Border Protection (CBP) with electronic access to PNR data to the extent that it is collected and contained in the carrier's automated reservation and departure control systems. Airlines failing to comply with the US requirements faced sanctions ranging from delays in offloading passengers, through to substantial fines and ultimately denial of landing rights.

2.  DATA PROTECTION ISSUES

  PNR details of airline passengers are personal data within the meaning of the EU Data Protection Directive 95/46/EC and the UK Data Protection Act 1998. At the heart of data protection legislation are standards that must be followed by those who process personal information about individuals. These provide safeguards to ensure that individuals' personal details are handled correctly and in appropriate ways. The principles, in essence, require that personal information is:

    —  Fairly and lawfully processed.

    —  Processed for limited purposes.

    —  Adequate, relevant and not excessive.

    —  Accurate.

    —  Not kept for longer than necessary.

    —  Processed in line with individuals' rights.

    —  Kept secure.

    —  Not transferred to countries without adequate protection.

  One of the requirements of both pieces of legislation is that personal data processed by data controllers in the EU are not transferred outside the European Economic Area (EEA) unless there is an adequate level of protection (Principle 8 -DPA 1998- Art 25&26 EU DP Directive). There are exceptions to this rule known as derogations (Schedule 4 -DPA 1998). These include circumstances such as where an individual has consented to the transfer, where the transfer is necessary for the performance of a contract with an individual or where the European Commission has made a finding that an adequate level of protection exists in the third country. The requirement by the US authorities to have direct access to European carriers" PNR records meant that personal data would be transferred outside the EEA to the US. The US, although having some laws, such as the Federal Privacy Act. which include elements familiar in data protection legislation, has no general DP law similar to the laws in place in European Union member states and now in place in many other countries around the world. The European Commission had made no adequacy finding in respect of the US. Any transfers by airlines of personal data held in the EU were therefore potentially in breach of the EU legislation prohibiting transfers outside the EEA unless there were other grounds for concluding that adequate protection existed or unless another derogation applied.

  The extent of the personal data required by the US included potentially sensitive data such as dietary preferences which could reveal religious beliefs. The lack of any established safeguards for the receipt and recording of such PNR data in particular called into question whether there was an adequate level of protection in the arrangements. If airlines were therefore prohibited from transferring the required PNR details this could have led to sanctions being imposed by the US authorities including denial of landing rights.

3.  PROPOSED DATA PROTECTION SOLUTION

  The national EU data protection supervisory authorities (the Information Commissioner and his counterparts in the rest of the EU) meet regularly together as a working party established under Article 29 of the EU Data Protection Directive. This is known as the Article 29 Working Party. The Working Party realised that there was a serious problem that needed resolving in a way that addressed legitimate US concerns about homeland security whilst at the same time respecting the privacy and data protection rights of passengers. It called upon the European Commission to look to adopting an EU wide solution (WP66). The European Commission then took an initiative based upon its powers to make an adequacy finding under the EU Directive. Once such a finding was in place airlines would then be able to transfer data to the US. The aim of the Commission was to broker an agreement with the US Government that put in place data protection safeguards in the US authorities' handling of personal data. These safeguards would then provide the basis for the Commission make a finding of adequacy.

  One of the roles of the Working Party is to provide opinions. This includes a requirement to give its view to the European Commission on any proposed adequacy findings (WP78 &87). The Working Party therefore became engaged in the process of determining whether the arrangements put in place by the US for PNR data represented an adequate level of protection. Ultimately findings of adequacy are made by the European Commission. They do not have to follow the opinion of the Working Party.

  Once negotiations between the US and the European Commission commenced US action against airlines for failure to implement the US PNR requirements was temporarily suspended. During the negotiations, the European Commission provided regular updates to meetings of the Article 29 Working Party. The Working Party developed a number of opinions based upon the different proposals being put forward. In doing so they were aware that in the absence of an agreement individual national data protection authorities would have the power to take action against any airlines that transferred personal data outside the EEA. However once an adequacy finding had been made by the European Commission such transfers could take place without the risk of such enforcement action. The Article 29 Working Party was committed to the process of securing an adequacy finding but wanted this done on terms that reflected what it saw as proper safeguards as set out in its various opinions.

  The process adopted by the European Commission resulted in an international agreement between the US and the European Union. This was underpinned by a binding undertaking made by US Department of Homeland Security Bureau of Customs and Border Protection. The undertaking involved US commitment to put in place restrictions and safeguards that would ensure an adequate level of protection.

  The undertaking provides restrictions on:

    —  the purposes for which PNR data can be used in the US ( essentially terrorism, serious crimes of a transnational nature and flights from warrants).

    —  the number of PNR items to be accessed.

    —  accessing sensitive data.

    —  use of a pull system of access to PNR data.

    —  retention periods.

    —  access by third parties.

  The undertaking also provided for security measures, redress for individuals, supervision by DHS Chief Privacy Officer and a joint review mechanism on an annual basis.

  The Commission, having noted the Working Party's opinion proceeded to make its finding that an adequate level of protection had been secured in the undertaking. The Article 29 Working Party's position (WP 95) was that whilst substantial progress had been made on securing safeguards a number of significant areas still needed addressing. The European Parliament was consulted by the Commission as part of the process and expressed reservations over the proposed arrangements. This resulted in the matter being referred by the Parliament to the European Court of Justice.

4.  THE INFORMATION COMMISSIONER'S POSITION

  The Information Commissioner was supportive of the efforts to secure safeguards in the US and to use these as the basis for an adequacy finding. However he took the view that it was at least arguable that a derogation from the need for an adequate level could apply on the basis that transfers of personal data were necessary for the airlines to perform their contacts with passengers (Schedule 4 (3) -DPA 1998). The argument behind this was that in practice an airline would not be able to fly a passenger to the US if it did not provide PNR data because the airline would suffer severe sanctions which might include denial of landing rights. Nevertheless he was convinced that an adequacy finding would prove a more effective long-term solution.In particular airlines. would have greater legal certainty and the US would have in place data protection safeguards which might not otherwise exist. Whilst the Information Commissioner shared the continued concerns expressed by the Article 29 Working Party, he took the view that the results of the negotiations with the US authorities did represent a substantial improvement on what might have otherwise been the situation.

5.  IMPLEMENTATION AND SUBSEQUENT ACTION

  Since the implementation of the agreement, undertaking and adequacy finding further efforts have been made to ensure a proper level of data protection is delivered in the practical operation of the arrangements. In particular the Article 29 Working Party's sub group dealing with PNR issues has liaised with the Association of European Airlines (AEA) over how the arrangements work in practice as well as to expedite the technical arrangements necessary to move from a "pull" system to a "push" system. The Working Party has also developed advice to airlines on how best to inform passengers that their PNR details are passed on to the US authorities (WP 97).

  One of the important data protection safeguards included in the undertaking provided by the US was an annual joint review with the European Commission. One joint review has taken place examining the practical arrangements put in place by the US to comply with the undertaking. The EU side of the review team included three members from national data protection authorities. The United Kingdom was represented. A version of the Commission Staff Working Paper summarising the outcome of the joint review has been published.

6.  EUROPEAN COURT OF JUSTICE RULING

  The reference of the international agreement and the Commission's adequacy finding by the European Parliament to the European Court of Justice resulted in a judgment issued on the 30th May 2006. The ECJ ruled that the agreement and the adequacy finding should be annulled. The annulment was founded on the Commission not using the correct legal basis for these instruments rather than any consideration of whether the measures themselves represented an adequate level of protection. The Court stayed the effect of the judgment until 30 September 2006 to give the Commission time to identify and implement a more appropriate legal basis. A failure to put arrangements in place would have once more called into question whether transfers of personal data to the US authorities complied with EU and national data protection law.

7.  CURRENT AGREEMENT BETWEEN THE US AND EU

  As the ECJ judgment was stayed the existing finding of adequacy remained in place for the short term. The Article 29 Working Party adopted opinions (WP122 & WP124) which supported the efforts by the Commission and Council to conclude a new agreement before the 1st October 2006. The Working Party was keen to ensure that any agreement at least preserved the data protection safeguards in the existing arrangements. They also hoped that it would take into account the previously expressed concerns. In the event a new agreement was concluded carrying forward the undertaking of DHS CBP and effectively preserving the status quo until negotiations could take place on a new long term agreement. This was on the basis of a Council Decision (2006/729/CFSP/JHA). The terms of the agreement have been clarified by an exchange of letters between the DHS and the Council Presidency/ Commission (2006/C 259/01 &02)

8.  FUTURE ARRANGEMENTS

  The Information Commissioner and his colleagues on the Article 29 Working Party remain committed to ensuring that any new agreement incorporates appropriate data protection safeguards and does not result in any lessening of the protection established in the current arrangements. Key safeguards sought in any new agreement include:

    —  Limitation of the amount of data transferred to that strictly necessary.

    —  Limitations on the purposes for which the data can be used including restrictions on who it may be disclosed to.

    —  An effective mechanism for supervising compliance with the agreement.

    —  Mandatory use of a "push" system removing the need for US authorities to interrogate EU airline systems.


1   http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2006/wp122_en.pdf Back

2   http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2005/wp103_en.pdf Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007