Select Committee on European Union Minutes of Evidence


Examination of Witnesses (Questions 1-19)

DR GUS HOSEIN

28 FEBRUARY 2007

  Q1  Chairman:  Doctor, you are very welcome.

  Dr Hosein: Thank you for having me.

  Q2  Chairman: I am sorry your colleague has been waylaid. Thank you very much for coming to give evidence to us. For the record, this meeting is on the record and it is part of this Committee's inquiry into the EU/US Passenger Name Record Agreement, to be known as PNR from now on. Dr Hosein, I wonder whether, on your own behalf and on behalf of your colleague, you would like to give us an opening statement.

  Dr Hosein: Absolutely.

  Q3  Chairman: Would you be prepared to describe not only your own connection but, also, insofar as you are able to, speak on behalf of Privacy International. I know that Simon Davies is not here actually speaking on behalf of Privacy International but I think it would be helpful for the Committee to have your picture of what both organisations are and your interest in the subject of this inquiry.

  Dr Hosein: As background, today I am speaking as a Visiting Scholar of the American Civil Liberties Union, which is the largest civil liberties organisation in the United States, and which has taken the government to task on most of the anti-terrorism measures in the past few years. I am also a Senior Fellow of Privacy International, which is the organisation that Simon Davies is a Director of. Together, Simon and I have been working on EU/US surveillance measures since the 1990s, but particularly since 2001 with the advent of passenger data transfers and the more recent transfer of financial information, and so on and so forth. Together, Simon and I are also Visiting Fellows of the London School of Economics where we have done research on this issue and other issues, such as ID cards and communications surveillance. We have spoken before at various Committees in the House of Lords on those issues in the past. Specifically on Passenger Name Records and the transfer of data to the United States, we denote that US law does have a number of protections and safeguards; they have the Privacy Act 1974, for instance, which is a relatively strong safeguard against the abuse of information. The problem with that regime, however, is that it only protects the interests of US persons. That is, if you are not a US citizen or US resident that law does not apply to you. So that is why the whole transfer of data between the EU and the US is such a massive legal problem because American citizens have rights within the United States but EU citizens do not. Meanwhile, within the EU regime EU citizens and foreigners have privacy rights, and that is the battle between the two blocs. I am not sure if you were briefed on the latest news that has emerged from the United States but the Washington Post today has run an article about a new data mining programme that has emerged from the Department of Homeland Security that seems to be the son of Total Information Awareness, which was the programme that was shut down a few years ago; somehow it has re-emerged and the Department of Homeland Security has promised the American public they have nothing to worry about because they have only been using foreigners' data and across America there is not that concern about the data of foreigners. That is the general problem that we deal with on a daily basis when it comes to this issue; the legal black hole, and then there is the inattention to data outside of the US by Americans.

  Q4  Chairman: Thank you very much. You used the expression "data mining". Can you explain what you mean by that?

  Dr Hosein: Data mining is the collection of vast amounts of information from various sources and then running algorithms against that data to draw patterns and conclusions. So if you are able to develop a profile of what you imagine a terrorist would be like—what kind of mobile phone company that terrorist would use; what kind of travel patterns, what kind of telephone patterns, and so on and so forth—and then collect vast amounts of information about vast amounts of people the theory is that using advanced algorithms you can identify other people with similar profiles to that terrorist.

  Q5  Lord Foulkes of Cumnock: Can I ask one question about the organisation? Ironically, I know a bit more about the American Civil Liberties Union than about Privacy International. Although Simon Davies is not here you obviously work very closely with him. Is it a membership organisation, Privacy International, and how many members does it have, if it is?

  Dr Hosein: It is not a membership organisation it is a watch-over organisation with an advisory board of 50 people from 30 countries established in 1992. So we have been a London-based organisation since that time.

  Q6  Lord Foulkes of Cumnock: Is it a registered charity?

  Dr Hosein: It is a limited liability company.

  Lord Foulkes of Cumnock: It is a limited liability company. Does it have a sort of charter or—what do they call these things?

  Baroness D'Souza: A mission statement.

  Q7  Lord Foulkes of Cumnock: A mission statement! Thank you very much.

  Dr Hosein: Yes, I have not memorised the mission statement but, generally, we act as a watch-dog organisation looking at surveillance policies and freedom of expression policies emerging around the world. We have conducted campaigns in Australia, the Philippines, New Zealand and, of course, in the United States and across Europe. In the past few years we have been very busy with the European Parliament and lobbying against some of the proposals emerging from the European Commission.

  Q8  Lord Harrison: Can I just ask a supplementary on data mining? Has it existed long enough for conclusions to be drawn as to how effective it is? If these algorithms are used against vast amounts of data have they indeed thrown up profiles of people who are then examined and who are found to fit the frame and, indeed, may have had such tendencies that we should want to be aware of? I gather from your tone that you have some doubt about the effectiveness, but I do not know whether perhaps you could illumine that.

  Dr Hosein: For the sake of being fair and slightly academic, I will give you one example where it does not work and one example where you could say it has worked. The jury is still out as to whether data mining works; there have not been enough open studies to verify what kind of algorithm was used, whether it was a fair algorithm, what kind of data was used, whether the data was actually reliable, which is one of the key problems because sometimes the data is inaccurate but they then make judgments against you. This is exactly the problem with PNR, but I will come back to that in a second. The first case I will give you is MATRIX. The acronym stands for multi-state access to law enforcement information, but I cannot remember the exact words. It was a private company that offered this service to the US Government after September 11 2001. They approached the Department of Justice in the United States and said: "We are willing to run a data mining office; set up data that we have gotten from member companies and from the Government and we are going to help you identify terrorists". The company also told the US Government that because of the law in the United States the US Government is unable to do this but because this company is a private company they are able to process this information without any due regard for civil liberties. So the company then ran, against this mass dataset, the profiles of the 19 hijackers and said: "Who else in the United States resembles these 19 hijackers?" If I recall correctly the exact number was 250,000 Americans who were just like those 19 hijackers. So there was a lot of fury but, also, excitement over the idea of data mining. Apart from selling this product to the Department of Justice, this company then went to all of the States to try to sell it to each and every one of the States, so that their police would be able to have access to these data stores, and so on and so forth, but because of the public uproar and because of the number of errors that emerged every State ended up abandoning that programme and falling out of it to the point where there was only one State left standing, and that was the State of Florida. Then, finally, the project came to a close. So that is one of the cases where it does not particularly work well. In the Washington Post article this morning I read about this new data mining scheme that has not been tested openly, but the proponents of the scheme have said it has proven to be useful in the situation of Guantanamo Bay, where they have data-mined the detainees. Originally, before the data mining, they identified the detainees they knew were caught up with bad people and they developed a profile based on those bad people and applied it to the rest of the detainees, and were then able to identify the detainees who were innocent. So in that sense data mining is applied to prove that you are an innocent, not to identify the guilty. So that is a case where, arguably, you could say data mining has worked in that small situation based on I-do-not-know-what kind of data they have on these detainees. However, when you apply data mining to a large population, such as a country, you have the inherent problems of how good is the algorithm, how reliable is the data and how legal is this entire process? In the United States, for instance, data mining is tantamount to being illegal. After the uproar over Total Information Awareness, which was the first programme to be developed by the Department of Defense, eventually Congress (and, remember, this is actually a Republican Congress) pulled the funding and said: "You are no longer allowed to do research in this area". Then there was another data mining programme through passenger surveillance of Computer-Aided Passenger Pre-Screening programme, just to make sure that violent offenders do not board aeroplanes, and eventually the funding was pulled on that and the Department of Homeland Security admitted that the system could not be built, so they had to move on. On top of that, a piece of legislation was passed saying that no funding can go towards a data mining programme of any sort in the United States, ones that apply to the general population. Somehow these programmes keep on emerging but there is no funding for them.

  Q9  Lord Jopling: Who are the people who are doing the research to try to demonstrate that data mining works and what access do they have to what some of us would think was the most sensitive intelligence information, like, for instance, material gathered by Menwith Hill in Yorkshire? How deeply are the people who are trying to establish this system permitted to go into sensitive intelligence information?

  Dr Hosein: To begin with your last question first, the individuals who are involved have the highest levels of clearance in the United States Government. They are former directors of agencies. Two of them have been admirals in the Navy—so they have the highest possible clearance. On the exact departments that have been doing this work, one department was the Department of Homeland Security. They have been responsible for the passenger surveillance programme, in particular, and that applies particularly to the sub-agency within the Department of Homeland Security, which is the Transport Security Administration. Another department in the Department of Homeland Security that has been doing data mining has been the Customs and Border Police. That is the department that, it emerged, was doing profiling of all passengers to the United States. This news just emerged in November about an Automated Targeting System. The most significant research programme on data mining emerged from the Department of Defense, from the Department of Defense that was responsible for the creation of the Arpanet, which eventually evolved through to become the Internet. This is where the brightest of the bright do their research within the Department of Defense, and they were responsible for Total Information Awareness (or the Terrorist Information Awareness programme, as it was renamed). So it is always those with the highest clearances making use of various forms of data. You rightly pointed out the data issue.

  Q10  Lord Jopling: Before you go on to that, you did refer to "private company" earlier on. Does some of this research take place outside the various defence departments of state, whoever they are?

  Dr Hosein: There are a number of private contractors who are interested in selling these types of services. So the company behind the MATRIX system was eventually bought up by Reed Elsevier, the publishing company. There are a number of consultants who advise on these projects from the private sector, particularly from Booz Allen Hamilton, which is a company that is the largest contractor for IT to the US Government, particularly because three of their five directors are former heads of the intelligence agencies, such as the National Security Agency and the Central Intelligence Agency. One of their vice-presidents was appointed the Head of National Intelligence in the United States. So it is these types of firms that are aiding the research in this field. There are also academic institutions, and I am afraid I cannot list them off the top of my head, who get funding to conduct research on the algorithms of data mining, but they do not get access to the wide variety of data. To come back to the data issue, the source of the data is always a source of controversy. At first the US Government approached a number of airlines in the United States, such as Northwest and JetBlue, and there are quiet agreements to transfer all data to the Department of Homeland Security to test out these algorithms historically, to see if they would be able to sustain a real environment. Once the news of these transfers emerged, passengers filed a number of legal complaints against these companies, saying: "We did not consent to our data to be used". When that strategy failed the Department of Homeland Security then said: "Okay, we will use the data of foreigners", particularly the EU passengers under the PNR Agreement. So the PNR Agreement that emerged in 2004 between the EU and the US permitted for the use of the data on EU passengers for the testing of what was then known as the Computer-Aided Passenger Pre-Screening system, or CAPPS-II. The most recent news about data mining from the United States is that it uses foreigner data and anonymised data of American citizens, so, again, that is going to be a source of controversy because American citizens are going to ask: "How anonymised is this data before you mined it?".

  Q11  Baroness D'Souza: I gather from what you say that the ban on funding for the Government itself to undertake this kind of data mining activity does not extend to the American Government paying private companies or academic research institutions for research that they are doing?

  Dr Hosein: I believe that is entirely correct.

  Q12  Baroness D'Souza: So, in fact, the American Government is funding it.

  Dr Hosein: Absolutely. After the Total Information Awareness programme met its demise a lot of the researchers and the research funds that had been allocated to this were actually put into what are called "black budgets", so within the budgets that other people could not see. Then there is the other strategy, which was when we found out about the Automated Targeting System, which is the data mining programme that is conducted at the US border, which we just discovered in November of this past year. The way that the US Government got around the funding problem is that this targeting system was originally applied to cargo. So it was developed and funded to apply to cargo—the ship moving the cargo, who sent the cargo, and so on and so forth. What the Customs and Border Police failed to notify Congress was that they then started adding passenger data to this same machine. So, in a sense, additional funding was not required. In a sense, it was a "bait-and-switch"; it is: "Here, fund this cargo-profiling system", and, "Oh, lo and behold we are applying this to passenger data". It is leading to Congressional hearings because there is this concern that regardless somehow this scheme is illegal under US law.

  Q13  Lord Marlesford: Is all of what you have been saying purely related to terrorism or does it also cover other forms of serious crime?

  Dr Hosein: It is important to note, first, that the PNR transfer agreement applies to terrorism and serious crime and organised crime of a trans-national nature. So it is a little broader than terrorism already. The MATRIX system was being applied beyond terrorism as well, and the Automated Targeting System (again, this is something that we learned about in November), according to its mandate and according to the statements made to the public from the Department of Homeland Security, is for combating terrorism, serious crime and border offences. So it has broadened out in its purpose, and I would almost say that its primary purpose never was terrorism per se; its primary purpose was to help manage the flow of information heading towards the US Government regarding foreign travellers.

  Q14  Chairman: I think Lord Marlesford has very helpfully set the scene for our first question! You have defined for us very concisely the purpose of the PNR agreement, which is to enhance the security of the United States, both against terrorism and against organised crime. To what extent do you think this has actually been effective? It is a difficult answer, but can I also, at the risk of pre-empting a later question, ask you to draw a comparison between the effectiveness of the PNR Agreement and the effectiveness of a visa system?

  Dr Hosein: It is inevitable that the mass surveillance of a given population has some advantages; it is inevitable that you will be able to pick out somebody amongst the masses. For instance, with the US VISIT system, which is the fingerprinting system at the borders, the government is very fond of saying they have had 80 million people travel through the United States and get fingerprinted and they have caught 2,000 people. They did not say they were 2,000 terrorists but they said they had caught 2,000 people. If you do the calculations, that is a 0.000025 per cent success rate. So I am not entirely sure what you are looking for when it comes to effectiveness. It is easy to say how effective this is, it is harder to prove it, in the sense that when passenger data was first considered as useful data for the US Government, it was originally considered for the Computer-Aided Passenger Pre-Screening System, or CAPPS-II (which I will refer to as CAPPS-II from now on). Since that time the CAPPS-II system has failed. The former Secretary of Homeland Security, Tom Ridge, when he gave his press conference about how they were shutting down CAPPS-II, he literally took a knife to his heart and said: "We're cutting it; we're killing it; it's dead", not only because of the privacy concern but the technological concerns. This is where we get into the whole area of the actual effectiveness of this data. I have spoken at length with a number of industry officials in the airline industry and they always reiterate very carefully that PNR is not some beautiful dataset that every government is dying to get their hands on; PNR is a highly unreliable set of data. There are misspellings of names and there is inaccurate information taken down generally about eating, seating, and so on and so forth. It is not this perfect set of data. As a result, how useful is this imperfect set of data? When you promise to use it for data mining it is highly dangerous because you are going to start identifying the wrong people for the wrong crimes, as we have seen emerge in the United States with their own watch-list—the "no-fly" list is what it is called—where they verify names of people before they get on aeroplanes within the United States. There have been 30,000 complaints against that watch-list of people who have been unable to get on `planes. We have not heard similar situations about foreigners being unable to get in the United States because there is no duty to report on these issues.

  Q15  Chairman: Can I interrupt you there? You referred to unreliability. To what extent, from your understanding of where the PNR Agreement stands, does the Agreement take into account that degree of unreliability?

  Dr Hosein: Absolutely not at all. In all the political rhetoric (and this debate is mostly about political rhetoric) it has only been about how this data is inherently useful for the war on terror; there has been no critical questions regarding the integrity of the data. I have to admit, when I discovered that this—it was only about a year ago—data was not reliable, I was shocked because I bought into the whole argument that this was essential.

  Q16  Chairman: I am sorry, I interrupted you.

  Dr Hosein: One final point, which is that it is important to remember that when the US Government passed the law regarding access to Passenger Name Records it was actually just one line within a large piece of legislation. The one line said that the US Government may demand from foreign carriers to hand over Passenger Name Records. That is all it said. It is a massive piece of legislation, and one line. Somehow that one line emerged and developed into this massive surveillance system. I do not believe the US Congress is fully aware of how far it has gone.

  Q17  Lord Jopling: The Agreement lists the 34 "data elements". I wonder if you could tell us to what extent those 34 items are used. Are there some which have not been used at all? I wonder if you could tell me which of them are, in practice, used and exploited.

  Dr Hosein: I have to provide a very large caveat before I answer that, which is that very few people understand how this data is being used, and the reason very few people understand is because there has not been open review. The only review of the US Government's use of Passenger Name Records occurred in 2005 and was conducted by a number of EU officials and two officials from the Data Protection Commission Offices; one being the Assistant Information Commissioner in the United Kingdom and one being a Deputy Commissioner in Germany. They conducted the only review that has taken place and when they conducted the review they were forced to sign non-disclosure agreements by the US Government, so they could not, other than what was within the legal mandate, discuss the general operations of the data mining and how it is actually conducted. That report was only published last year (the report that eventually emerged, which was heavily redacted) and still to this date we are unable to fully understand how this information is being used. So, having said that, the controversial points when it comes to 34 fields of data focus particularly on what are numbers 26 and number 27, the OSI information and the SSI/SSR information. These are the fields that could contain sensitive personal information of a medical nature or a religious nature. So this could be where a request for halal food is made or if it says you have heart disease. It also discloses information about your travelling companions, so it could say you are travelling with somebody who is not your official, legal partner, and so on and so forth. The situation after the first agreement between the EU and the US was that this data would be `pulled' to the United States by the US Government, which would then log into the reservation systems and grab this data themselves. Or, if it was possible, the carriers would send this data to the US Government, at which point the US Government would filter the sensitive fields. So they would go through all the data and delete the data that said anything about the food requests or your travelling companions. The review that took place in 2005 gave the US Government a favourable note on this; it said that the US Government had effectively implemented this filtering process. The question always emerges why do the carriers not filter this information before they send it on to the US Government, and many of the carriers I have spoken to are very happy to do so, but there are a select few carriers, including British Airways, who are reluctant to filter the information; they prefer to send the wholesale information to the US Government and let the US Government take care of the filtering.

  Q18  Baroness D'Souza: Why?

  Dr Hosein: I believe it is slightly beyond my competency to say why, but I would guess it is because of the cost issues.

  Q19  Lord Jopling: How on earth do airlines or anybody else know if you are travelling to New York or somewhere with your mistress or somebody else? You have got two separate names and two separate bookings, maybe. How on earth does anybody know who your travelling companion is?

  Dr Hosein: The seating arrangements and whether at the time of booking you requested to sit with somebody else would probably be stored within the PNR.


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007