Memorandum by the Information Commissioner
1. The Information Commissioner has responsibility
for promoting and enforcing the Data Protection Act 1998 and the
Freedom of Information Act 2000. He is independent from government
and promotes access to official information and the protection
of personal information. The Commissioner does this by providing
guidance to individuals and organisations, solving problems where
he can, and taking appropriate action where the law is broken.
The comments in this evidence are primarily from the data protection
perspective.
2. The Commissioner has been involved in
the data protection issues arising from the transfer of airline
passenger data from the EU to US authorities for their own purposes
from the time that the US authorities first imposed such a requirement
on UK airlines. His work in this area has primarily been in the
context of his membership of the Article 29 Working Party established
under the EU Data Protection Directive and consisting of the national
data protection authorities of each EU member state. Given that
the issue affects personal data held by all airlines flying from
EU member States to the US, an EU wide solution to the problem
has always been seen as the most effective approach. Annex 1 provides
a full account of that involvement including the data protection
issues that arise and the various solutions that have been adopted.
3. At the heart of data protection concerns
is the need to balance the legitimate interests of states to control
who enters their own territory and ensure the safety of their
own citizens and visitors with the need to ensure that this is
undertaken in a manner consistent with necessary data protection
and privacy safeguards. This has centred upon whether the arrangements
put in place amount to an adequate level of data protection. Key
data protection concerns focus on the following areas:
A proper legal basis for requiring
the information.
Minimising the data transferred to
that strictly necessary and avoiding sensitive personal data such
as information on religious beliefs.
Limiting the purpose for which the
data can be used to areas of pressing need.
Limiting wider disclosure to where
strictly necessary.
Appropriate retention periods guaranteeing
that data is only kept for the minimum period necessary.
Transparency for passengers though
adequate information when they book flights.
Redress for individuals if problems
occur and their right to access information held about themselves.
Appropriate security to safeguard
against unauthorised access.
Appropriate technical solutions for
the transfer of data ( a "push" system of airlines sending
the necessary data rather than a "pull" one where the
US authorities gain access to reservation systems and draw down
the information they require).
Effective inspection and review mechanisms
to ensure safeguards are being applied in practice.
4. The Commissioner and his colleagues on
the Article 29 Working Party have always worked together to try
to ensure that the agreements signed between the EU and third
countries such as the US have these essential safeguards in place.
They are keen that any new agreement with the US should be negotiated
on the basis that safeguards will be included to ensure that all
the matters listed in paragraph 3 above are addressed. In particular
there should be no reduction of the level of protection afforded
by the current arrangements.
5. The Article 29 Working Party has made
clear that an agreement with the US at EU level is preferable
to bilateral agreements between the US and particular member states.
An EU level agreement will help ensure a consistent and harmonised
approach to personal data protection. The Working Party has already
identified key areas where attention should be paid during negotiations
on a new agreement (WP 122).[1]
These are:
At the very least, the preservation
of the current level of protection and the further integration
of the US undertakings into the agreement itself.
Taking account of the previous opinions
of the Working Party. These include the need to reduce the number
of specified data items collected to those that have proved of
true value based on experience.
Mandatory use of a "push"
system now that technical arrangements are in place (the delays
in moving to a push system are of major current concern to the
Working Party as the appropriate technical measures now appear
to be available but a "push" system remains in place
with the airlines and the US authorities holding each other responsible
for the failure to move to a "push" system).
Strict purpose limitation to ensure
that data is only used for the limited purposes for which it was
transferred and also that it is not transferred subsequently to
third parties for wider unconnected purposes.
Continuation of the annual joint
review mechanism to help ensure compliance with the specified
safeguards.
6. The Commissioner and his EU counterparts
have noted with concern that mechanisms provided for at paragraph
7 of the Undertakings for consultation by the US with the EU on
the expansion of the data items appear to have been used in practice
as a basis for unilateral declaration by the US side of their
intention to expand the items. This is not what the Commissioner
and his counterparts envisaged by a consultative arrangement.
(Exchange of letters between the US DHS and EU expanding data
elements to include further frequent flyer information-2006/C259/01
& 02).
7. The Commissioner and his EU counterparts
are concerned to ensure that the safeguards in any agreement are
complied with in practice. As mentioned in paragraph 5 above,
the continuation of the annual joint review mechanism is an essential
safeguard that will help ensure compliance with restrictions such
as those on wider use. One joint review took place under the previous
arrangements and the continued delay in undertaking a further
joint review can only undermine confidence that the safeguards
are effective. The concerns that some have expressed that EU PNR
data may be used outside the terms of the current undertaking,
in that it is processed on the US "Automated Targeting System"
could more readily be addressed if timely reviews were to are
take place.
8. The Commissioner and the Article 29 Working
Party believe that as international air transport operates on
a global basis, a global solution to the PNR issue is desirable.
An instrument established under the auspices of the International
Civil Aviation Organisation (ICAO) could set out a common set
of data items and procedures that all states could follow. This
would be preferable to each state specifying its own requirements
and then concluding an ever increasing number of bilateral agreements.
Achieving a common international instrument with appropriate data
protection safeguards would ensure a consistent approach and reduce
confusion for airlines and passengers.
9. The different approaches taken by individual
states are already apparent. The agreement concluded by the EU
with Canada in response to their demands for EU PNR data is a
case in point. This differs from the US requirements in a number
of respects. An obvious example is the data items required. There
are 34 in the case of the US and 25 in the case of Canada. Furthermore
with Canada the "general remarks" text fields are excluded.
This appears to be a more proportionate approach to the problem.
The Article 29 Working Party concluded that the arrangements put
in place did amount to an adequate level of data protection as
compared with the US where, in their view, they did not (WP103).[2]
Other significant factors included the mandatory use of a "push"
system and the existence of an independent data protection supervisory
regime in Canada.
10. The Commissioner and his EU colleagues
are eager to help inform the forthcoming negotiations with the
US on a new agreement by providing advice and assistance. The
Article 29 Working Party has established a dedicated PNR sub group
to work on passenger data issues in which the Information Commissioner's
staff participate. The sub group, on behalf of the Working Party
have organised a workshop on PNR issues on 26 March in Brussels
to help inform the forthcoming negotiations. A wide variety of
participants and speakers have been invited including the Chairman
of Sub Committee F. The sub group has worked in close cooperation
with the European Parliament's LIBE committee who are also organising
a connected event.
11. The Information Commissioner believes
that it is vital that as states seek to protect their citizens
from terrorist and other criminal acts they adopt a considered
and proportionate approach to the collection and processing of
personal information. The acquisition and retention of a wide
range of personal details, many of which prove to be of no more
than marginal value, only serves to undermine public confidence.
There is risk that excessive data collection and use will start
to erode the very freedoms that the states are seeking to protect.
The Commissioner believes that the twin pubic policy objectives
of public safety and data protection are reconcilable and should
be achievable in any agreement concluded with the US authorities.
Richard Thomas
5 March 2007
Annex 1
THE INFORMATION COMMISSIONER'S INVOLVEMENT
IN THE EU /US PASSENGER NAME RECORD AGREEMENT
1. BACKGROUND
Airlines operating scheduled air services record
what is known as passenger name record data (PNR) on passengers
who make reservations on their flights. These records are usually
maintained on central shared customer reservation systems (CRS)
operated by third parties on the airlines' collective behalf.
Most prominent of these in Europe is Amadeus which most European
airlines use. This contains records relating to the fights of
participating airlines and can be accessed and updated by the
airlines and third parties such as travel agents who can create
and amend records when dealing with a passenger's reservation.
The PNR contains a variety of information about
passengers ranging from flight details, method of payment, dietary
preferences and free text information containing general remarks.
In addition to the PNR airlines create what is know as APIS data
when a passenger checks in. This is held on the airline's own
departure control systems(DCS).
In the aftermath of 9/11 US authorities realised
the potential security benefits of having prior notice of passengers
arriving in their territory to enable them to check against watch
lists and undertake passenger profiling. The data held as PNR
was seen as particularly valuable. The US Government passed a
legal statute (Title 49 United States Code section 44909 (3) and
Title 19 Code of Federal Regulations section 122.49b). This required
each air carrier operating passenger flights to or from the US
to provide US Customs and Border Protection (CBP) with electronic
access to PNR data to the extent that it is collected and contained
in the carrier's automated reservation and departure control systems.
Airlines failing to comply with the US requirements faced sanctions
ranging from delays in offloading passengers, through to substantial
fines and ultimately denial of landing rights.
2. DATA PROTECTION
ISSUES
PNR details of airline passengers are personal
data within the meaning of the EU Data Protection Directive 95/46/EC
and the UK Data Protection Act 1998. At the heart of data protection
legislation are standards that must be followed by those who process
personal information about individuals. These provide safeguards
to ensure that individuals' personal details are handled correctly
and in appropriate ways. The principles, in essence, require that
personal information is:
Fairly and lawfully processed.
Processed for limited purposes.
Adequate, relevant and not excessive.
Not kept for longer than necessary.
Processed in line with individuals'
rights.
Not transferred to countries without
adequate protection.
One of the requirements of both pieces of legislation
is that personal data processed by data controllers in the EU
are not transferred outside the European Economic Area (EEA) unless
there is an adequate level of protection (Principle 8 -DPA 1998-
Art 25&26 EU DP Directive). There are exceptions to this rule
known as derogations (Schedule 4 -DPA 1998). These include circumstances
such as where an individual has consented to the transfer, where
the transfer is necessary for the performance of a contract with
an individual or where the European Commission has made a finding
that an adequate level of protection exists in the third country.
The requirement by the US authorities to have direct access to
European carriers" PNR records meant that personal data would
be transferred outside the EEA to the US. The US, although having
some laws, such as the Federal Privacy Act. which include elements
familiar in data protection legislation, has no general DP law
similar to the laws in place in European Union member states and
now in place in many other countries around the world. The European
Commission had made no adequacy finding in respect of the US.
Any transfers by airlines of personal data held in the EU were
therefore potentially in breach of the EU legislation prohibiting
transfers outside the EEA unless there were other grounds for
concluding that adequate protection existed or unless another
derogation applied.
The extent of the personal data required by
the US included potentially sensitive data such as dietary preferences
which could reveal religious beliefs. The lack of any established
safeguards for the receipt and recording of such PNR data in particular
called into question whether there was an adequate level of protection
in the arrangements. If airlines were therefore prohibited from
transferring the required PNR details this could have led to sanctions
being imposed by the US authorities including denial of landing
rights.
3. PROPOSED DATA
PROTECTION SOLUTION
The national EU data protection supervisory
authorities (the Information Commissioner and his counterparts
in the rest of the EU) meet regularly together as a working party
established under Article 29 of the EU Data Protection Directive.
This is known as the Article 29 Working Party. The Working Party
realised that there was a serious problem that needed resolving
in a way that addressed legitimate US concerns about homeland
security whilst at the same time respecting the privacy and data
protection rights of passengers. It called upon the European Commission
to look to adopting an EU wide solution (WP66). The European Commission
then took an initiative based upon its powers to make an adequacy
finding under the EU Directive. Once such a finding was in place
airlines would then be able to transfer data to the US. The aim
of the Commission was to broker an agreement with the US Government
that put in place data protection safeguards in the US authorities'
handling of personal data. These safeguards would then provide
the basis for the Commission make a finding of adequacy.
One of the roles of the Working Party is to
provide opinions. This includes a requirement to give its view
to the European Commission on any proposed adequacy findings (WP78
&87). The Working Party therefore became engaged in the process
of determining whether the arrangements put in place by the US
for PNR data represented an adequate level of protection. Ultimately
findings of adequacy are made by the European Commission. They
do not have to follow the opinion of the Working Party.
Once negotiations between the US and the European
Commission commenced US action against airlines for failure to
implement the US PNR requirements was temporarily suspended. During
the negotiations, the European Commission provided regular updates
to meetings of the Article 29 Working Party. The Working Party
developed a number of opinions based upon the different proposals
being put forward. In doing so they were aware that in the absence
of an agreement individual national data protection authorities
would have the power to take action against any airlines that
transferred personal data outside the EEA. However once an adequacy
finding had been made by the European Commission such transfers
could take place without the risk of such enforcement action.
The Article 29 Working Party was committed to the process of securing
an adequacy finding but wanted this done on terms that reflected
what it saw as proper safeguards as set out in its various opinions.
The process adopted by the European Commission
resulted in an international agreement between the US and the
European Union. This was underpinned by a binding undertaking
made by US Department of Homeland Security Bureau of Customs and
Border Protection. The undertaking involved US commitment to put
in place restrictions and safeguards that would ensure an adequate
level of protection.
The undertaking provides restrictions on:
the purposes for which PNR data can
be used in the US ( essentially terrorism, serious crimes of a
transnational nature and flights from warrants).
the number of PNR items to be accessed.
accessing sensitive data.
use of a pull system of access to
PNR data.
access by third parties.
The undertaking also provided for security measures,
redress for individuals, supervision by DHS Chief Privacy Officer
and a joint review mechanism on an annual basis.
The Commission, having noted the Working Party's
opinion proceeded to make its finding that an adequate level of
protection had been secured in the undertaking. The Article 29
Working Party's position (WP 95) was that whilst substantial progress
had been made on securing safeguards a number of significant areas
still needed addressing. The European Parliament was consulted
by the Commission as part of the process and expressed reservations
over the proposed arrangements. This resulted in the matter being
referred by the Parliament to the European Court of Justice.
4. THE INFORMATION
COMMISSIONER'S
POSITION
The Information Commissioner was supportive
of the efforts to secure safeguards in the US and to use these
as the basis for an adequacy finding. However he took the view
that it was at least arguable that a derogation from the need
for an adequate level could apply on the basis that transfers
of personal data were necessary for the airlines to perform their
contacts with passengers (Schedule 4 (3) -DPA 1998). The argument
behind this was that in practice an airline would not be able
to fly a passenger to the US if it did not provide PNR data because
the airline would suffer severe sanctions which might include
denial of landing rights. Nevertheless he was convinced that an
adequacy finding would prove a more effective long-term solution.In
particular airlines. would have greater legal certainty and the
US would have in place data protection safeguards which might
not otherwise exist. Whilst the Information Commissioner shared
the continued concerns expressed by the Article 29 Working Party,
he took the view that the results of the negotiations with the
US authorities did represent a substantial improvement on what
might have otherwise been the situation.
5. IMPLEMENTATION
AND SUBSEQUENT
ACTION
Since the implementation of the agreement, undertaking
and adequacy finding further efforts have been made to ensure
a proper level of data protection is delivered in the practical
operation of the arrangements. In particular the Article 29 Working
Party's sub group dealing with PNR issues has liaised with the
Association of European Airlines (AEA) over how the arrangements
work in practice as well as to expedite the technical arrangements
necessary to move from a "pull" system to a "push"
system. The Working Party has also developed advice to airlines
on how best to inform passengers that their PNR details are passed
on to the US authorities (WP 97).
One of the important data protection safeguards
included in the undertaking provided by the US was an annual joint
review with the European Commission. One joint review has taken
place examining the practical arrangements put in place by the
US to comply with the undertaking. The EU side of the review team
included three members from national data protection authorities.
The United Kingdom was represented. A version of the Commission
Staff Working Paper summarising the outcome of the joint review
has been published.
6. EUROPEAN COURT
OF JUSTICE
RULING
The reference of the international agreement
and the Commission's adequacy finding by the European Parliament
to the European Court of Justice resulted in a judgment issued
on the 30th May 2006. The ECJ ruled that the agreement and the
adequacy finding should be annulled. The annulment was founded
on the Commission not using the correct legal basis for these
instruments rather than any consideration of whether the measures
themselves represented an adequate level of protection. The Court
stayed the effect of the judgment until 30 September 2006 to give
the Commission time to identify and implement a more appropriate
legal basis. A failure to put arrangements in place would have
once more called into question whether transfers of personal data
to the US authorities complied with EU and national data protection
law.
7. CURRENT AGREEMENT
BETWEEN THE
US AND EU
As the ECJ judgment was stayed the existing
finding of adequacy remained in place for the short term. The
Article 29 Working Party adopted opinions (WP122 & WP124)
which supported the efforts by the Commission and Council to conclude
a new agreement before the 1st October 2006. The Working Party
was keen to ensure that any agreement at least preserved the data
protection safeguards in the existing arrangements. They also
hoped that it would take into account the previously expressed
concerns. In the event a new agreement was concluded carrying
forward the undertaking of DHS CBP and effectively preserving
the status quo until negotiations could take place on a new long
term agreement. This was on the basis of a Council Decision (2006/729/CFSP/JHA).
The terms of the agreement have been clarified by an exchange
of letters between the DHS and the Council Presidency/ Commission
(2006/C 259/01 &02)
8. FUTURE ARRANGEMENTS
The Information Commissioner and his colleagues
on the Article 29 Working Party remain committed to ensuring that
any new agreement incorporates appropriate data protection safeguards
and does not result in any lessening of the protection established
in the current arrangements. Key safeguards sought in any new
agreement include:
Limitation of the amount of data
transferred to that strictly necessary.
Limitations on the purposes for which
the data can be used including restrictions on who it may be disclosed
to.
An effective mechanism for supervising
compliance with the agreement.
Mandatory use of a "push"
system removing the need for US authorities to interrogate EU
airline systems.
1 http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2006/wp122_en.pdf Back
2
http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2005/wp103_en.pdf Back
|