Examination of Witnesses (Questions 40-50)
DR GUS
HOSEIN
28 FEBRUARY 2007
Q40 Lord Jopling: Sorry, you have
confused me. You started answer my question by saying that you
did think fingerprinting was an invasion of privacy. You then
went on to say that fingerprinting is not problematic. Which did
you mean?
Dr Hosein: I said that in a specific and proportionate
environment fingerprinting by its nature is not necessarily a
bad thing. I started by saying that my personal opinion is I equate
fingerprinting with being treated like a criminal, but I do understand
the modern world and the spread of biometrics which, Prime Minister
Tony Blair is very fond of saying, the world has moved on, technology
has moved on and biometrics are becoming a part of daily life.
I do accept that people are willing to, say, use a fingerprint
to get into a building, if it is a highly secure building and
so on because they know that data is kept securely and so on and
so forth. Do I still consider it an invasion of privacy? It depends
on the situation, who is doing it and the reasons for which it
is being done.
Baroness D'Souza: It is the context and
proportion.
Q41 Earl of Listowel: I see in question
11 we deal with one of the concerns that I wanted to raise and
it came up in the answer you gave first to Lord Foulkes, which
is the worry about the safeguards; if they are not sufficient
they alienate and will be unhelpful in the cause of preventing
terrorism. The question I wanted to ask you, if you can help with
this, is the commission that reported on the 9/11 attacks, if
I remember correctly, particularly focused on lack of co-operation
between the different agencies and an over-reliance on electrical
information and data rather than human intelligence on the ground
in Iraq and elsewhere, for instance in the Middle East. Listening
to what you are saying there seems to be a sort of echo again
in terms of what we have been discussing just now, so my concern
is I recognise absolutely Lord Foulkes' concern, but is there
a danger of displacing, in all this drama you were describing,
one's energy towards gathering lots of information which may not
necessarily be that helpful and not concentrating on the main
problems which may be about human capacity and about the capacity
of various departments within the US to work together effectively
and to develop perhaps the people working at the front line to
be able to detect people? I am not expressing myself very well,
but do you see what I mean?
Dr Hosein: Absolutely, I see what you mean.
More often than not I believe in most of the cases where there
has been prevention of terrorist atrocities, most of the intelligence
that led to those arrests was from human intelligence. The classic
case of this is the July 7 investigations into the bombers; I
heard one of the police who was the head of the investigation
when he spoke at an event at Portcullis House last year. He said
that they never relied on the communication records of the terrorists
within their investigations, which I found amazing because the
Home Secretary just a month before pushed a policy through the
European Union on the collection, storage and retention of communications
data of all EU citizens on the grounds that it would help prevent
terrorism. There is a difference between the political debate
that takes place which is very much about changing the balance,
reconsidering proportionality and so on and so forth, which then
provides for mass surveillance and the real fight that goes on
which is the human intelligence, the people in the field trying
to conduct investigations undercover and so on and so forth. Unfortunately,
I have to stop there because I am not an expert on human intelligence
and I worry that I would actually end up saying something that
is wrong, but I do agree with the sentiments expressed.
Q42 Lord Foulkes of Cumnock: Could
I just ask one question following Lord Jopling's question? You
answered Lord Jopling by saying that fingerprinting is an inexact
science, and you gave that one example; I could have given you
an example from Scotland and the Shirley McKee case as well. Surely
that argues for increasing the amount of information to be collected
because fingerprinting is not 100 per cent accurate, it might
only be 99.8 per cent, and therefore you need other biometric
data and when you put them altogether you get up nearer 100 per
cent. Is that not right?
Dr Hosein: There are more intelligent scientists
than I who could answer that, but based on the information I have
seen, first of all, fingerprinting is not even close to 99 per
cent. It has varied, depending on the algorithms used and the
size of the databases, between 60 and 85 per centlet us
say it is 95 per cent. 95 per cent is still a very low measure
when you apply it to the size of a population of, say, 60 million
or 80 million. The other argument is the larger the database is
the more margin for error you almost have to accept.
Q43 Lord Foulkes of Cumnock: You
bring in another category of measurement like iris scanning.
Dr Hosein: Yes. I am going to refer to the work
of the creator of iris scanning, John Daugman, who is a better
statistician than I am. He said that we should not fall for the
trap that increasing the number of biometrics necessarily decreases
the fault level, it actually can compound the problem, so he argues
that it is possible that instead of using unreliable fingerprints
compounded with iris scans which were introduced not long ago,
just use iris scans which have, arguably, a 99 per cent effectiveness
rate; do not compound it with fingerprints. That is why the ID
card programme in this country has moved away from iris scanning
for the time being and they are focusing first on facial recognition,
which has alarmingly low success rates, and moving to fingerprints
which have a much higher success rate.
Q44 Lord Foulkes of Cumnock: I could
go on, but I will not, I will do what I am told. Do you think
the joint review procedure is appropriate to monitor the workings
of the agreement?
Dr Hosein: In theory it is absolutely appropriate.
The 2004 Agreement said there would be yearly reviews done by
EU officials, including data protection commissioners, so we have
hoped for the best. We are considering it as a bad situation with
the agreement that emerged in 2004. The first review was done
in 2005; as I mentioned, the report was not released until 2006,
it was heavily redacted, we were not even given the names of individuals
within the EU who were involved. On top of that, the EU officials
who were involved had to sign a non-disclosure agreement so they
could not actually openly discuss any of the other discoveries
they had made in their discussions with the United States Government
and they expressed their deep displeasure with this, the fact
that they had to sign a non-disclosure agreement, so this is not
exactly what I would call an open review. The 2006 review that
was supposed to take place was cancelled because of the negotiations
that were going on, and the United States Government has said
that there will be no further reviews until after the next agreement
has gone through. What was promised to be three reviews in three
years has turned out to be one review in three years with no promise
of further reviews, so it has been inadequate. The privacy commissioners
across Europe are calling for more reviews; they are not going
to get it but they are calling for the next agreement to have
stronger review powers. I am not optimistic that this is going
to be the case. Having said that, the review that took place in
2005 we discovered just a few weeks ago that that review had discovered
that the United States was doing data miningI am sorry,
I should not use that word politically. There was already a targeting
system and the 2005 review had discovered that this was being
applied to passenger data. Nobody else in the United States Government
knew this, US Congress did not know this, the US public did not
know this, but the European Commissioners involved and the European
officials involved knew about ATS, but they were not going to
tell anybody about it because of the non-disclosure agreement.
There is, therefore, a very awkward situation where the review
might have been highly successful had they been given enough ability
to communicate their findings and for the review to take place
more periodically, but unfortunately the politics of the situation
prevent this from happening.
Lord Foulkes of Cumnock: That is useful
information for our visit to Brussels when we take evidence from
the Commission.
Q45 Chairman: If Lord Foulkes agrees,
the next question we have really covered, but I would like to
rephrase it. That is, do you think there is an awareness? I should
first of all say I am sure this Committee accepts that there is
a serious security problem that needs to be addressed, but do
you think that the public understand that one of the advantages
of PNR is that they do not have to go through the sometimes rather
tiresome visa procedure and, whatever the worries there are or
may be about data protection, that is actually quite a significant
advantage for the travelling individual?
Dr Hosein: Based on my knowledge
of the politics within the United States I would openly answer
by saying I do not believe that the two issues are related. I
do not believe that the visa waiver programme and passenger name
records are related at all. Politically they are related in that
if `you give us PNR, we will expand the visa waiver programme',
but to my knowledge and my understanding there has been no discussion
of throwing the United Kingdom out of the visa waiver programme
because BA does not hand over PNR; there has not been that kind
of quid pro quo over it, again, because different departments
deal with this and there is a different level of politics that
applies to it. As I said earlier, the visa waiver programme is
surrounded by a level of politics that is more about immigration
and not wanting anybody to enter the country without a visa, versus
the PNR agreement which is a different level of politics about
national security and so on and so forth.
Q46 Chairman: Do you detectand
this is probably not a fair question to ask youa difference
of attitude towards this whole subject between various EU countries?
For instance, I do not know how much you know about the French
attitude to PNR agreement.
Dr Hosein: The French CNILthat is the
privacy commission in Francehas been very active against
the PNR agreement, so much so that I know there are French commissioners
who no longer travel to the United States because they do not
want their PNR handed over and they do not want to be fingerprinted
either. So the French have been very active. Meanwhile, some of
the new Europe countriesas they are sometimes referred
toare annoyed that they are not part of the visa waiver
programme and hope that they can do anything to get into the visa
waiver programme, but they understandand again this is
the level of politics within the US Government and it will take
years for this to actually evolve [en rule]although the United
States might make promises to the EU that they will consider this,
it is a much more separate process that takes place. It is the
Department of Homeland Security that does the negotiations on
PNR, it is the State Department that is responsible for dealing
with such issues as the visa waiver programme.
Q47 Earl of Listowel: I want to go
back to an answer you gave earlier about safeguards and the importance
of those, looking at the importance of safeguards protecting public
information from the point of view of winning hearts and minds
in the battle against terrorism. We have recognised from the invasion
of Iraq and other places that there is a danger of well-intentioned
action backfiring in a way and contributing to ill-will towards
us and other nations. Do you have enough information to work out
in the balance whether the activities we have been discussing
this morning are actually perhaps having a perverse effect, or
is there not enough information yet to see whether that is happening
or not?
Dr Hosein: I want to preface my answer by saying
that I find it amazing that people are so activated by the US
collection of this information and, in a sense, it is almost an
anti-American attitude that has emerged over the US collecting
this information. They see no problem with their own government
or other governments collecting this information, but we seem
to be missing the debate. This is something that is happening
everywhere but we are focusing a lot on the US because the US
was the first to ask for this information but they are also doing
the worst job at managing this information. I will give you two
examples that really link to the hearts and minds argument that
you are proposing. The first is news from earlier this week from
Canada about the law school examin order to apply for law
school in North America you have to write an exam. It has emerged
that Canadian citizens are being fingerprinted before they take
this exam, and there is an uproar saying all these fingerprints
are being sent to the US Government, they could be accessed under
the USA Patriot Act, they could be abused and so on and so forth,
and there is this sense of discomfort over it. Arguably, if you
ask why you are taking fingerprints for a foreign exam it is to
make sure you do not take the exam under multiple names and so
on and so forth, so there might be a reason for it. However, there
is such a concern that because this information is going to the
US it is going to be abused and the US has lost its higher moral
ground for collecting this information. Then it was discovered
that the LSATthat is the name of the examhas been
doing this fingerprinting process for a number of years. There
was not a problem about it before when it was taking place, but
now there is a concern because it is the Americans. My second
example perhaps explains why there is this emerging concern, particularly
in Canada, and that is the case of Maher Arar. Some of you around
this table might know this story, but he is a Syrian-born Canadian
who was travelling from a wedding in Tunisiahis wife's
family is from Tunisiahe was flying back to Ottawa where
he lived, flying through the JFK airport in New York and he was
detained by the Americans as a terrorist. They kept him for a
number of days; they interrogated him and said "Okay, we
are going to send you back home." He said, "That's great"
and they sent him to Syria via Jordanthey did not send
him to Canada, they sent him to Syria where he was detained for
11 months in prison and tortured, according to his claims and
according to a judicial commission taking place in Canada. Finally,
the Syrians established that he was innocent and he was sent back
to Canada. In investigations as to why this had taken place, what
basis did the Americans have to say that this individual was a
terrorist, the Americans said that they had gotten information
from the Canadian Government in a data-sharing agreement. The
Canadian Government, through the Royal Canadian Mounted Police,
were doing an investigation on somebody that Arar knew, so they
had listed Arar in a database saying "of interest in this
investigation because he knows the suspect". This information
was then transferred to a different database within Canada where
he was just included in a list of people of interest, there was
no longer this link to somebody of interest, he was the person
of interest. As a matter of custom this data was regularly shared
with the US Government where it was put into their border database,
the TECS database, where he was put in as a person of interest
and suspected terrorist and that is why the Americans reacted
the way they did and sent him to Syria, and the rest of the story
is Canadian history. The Canadians are very angry about this and
to this day actually he is still on the US no-fly list, he cannot
board a plane that flies above the United States. The Americans
refuse to acknowledge that he is innocent, but the Canadian Government
has just awarded him a million dollars apologising for the entire
affair. There is therefore a sense of disquiet in America about
the US Government getting access to data; any transfer of data
in a private schemelike private companies doing outsourcing
dealshas led to unions protesting en masse and saying how
can our personal information collected by our union end up in
the US where it can be accessed under the Patriot Act? Do I consider
it is a serious concern? I do not believe that the US Government
is dying to use the Patriot Act to get access to all this information,
but as you say it is a hearts and minds issue. There is a level
of disquiet which is alarming and the lack of confidence in transport
data flows is again alarming to the point where it could lead
to a breakdown.
Q48 Lord Marlesford: This is going
back to Lord Jopling's question and Lord Foulkes' questions, because
I am not absolutely clear on them. First, do you accept that a
democratic state does need to know and know for certain who people
are? Secondly, if biometrics are a method of identifying people
and you have one biometric which gives a hit, that may merely
raise a question, not be certain, but if you have a second biometric
that makes the same hit that must really produce a very considerable
degree of certainty?
Dr Hosein: In a democratic state is it necessary
for individuals to be known and identified? I would say that that
is absolutely correct; I would say not just in a democratic state
but in a modern economy personal information and identity information
is very much a currency in its own right and can lead to more
advanced economies, more advanced markets and so on and so forth.
I do not believe there is much doubt over this. I believe that
doubt emerges on how this is actually realised, so your argument
about biometrics and the various uses of biometrics within, say,
the national identity scheme, there is a scientific argument to
support what you are saying but that is not the reason why we
have fingerprints being proposed for the ID card scheme. There
are two reasons why fingerprints are being proposed for the ID
card scheme: first, because when they were proposing the ID card
scheme the Government was adamant about it being an international
obligation, and the international obligation says that fingerprints
may be collected. The EU said that two fingerprints should be
collected for biometric passports, so that is why we are moving
down the route of fingerprints. The other reason why we are moving
down the route of fingerprints when it comes to the national identity
card scheme is because the police were sold on the idea that one
of the benefits of the scheme would be that there are 900,000
fingerprints left at scenes of crime over the years that have
not been matched to a criminal, so the police were told if we
run this identity card scheme, we will fingerprint the entire
population and you can verify those 900,000 fingerprints against
the British population of fingerprints once we have the national
identity card scheme off the ground. It was not really about the
effectiveness of the technology, it was not about the 99 per cent
(which is 95 per cent) effectiveness, it was really, first, about
a way of getting the bill acceptable through the creation of an
international obligation and, second, a way of getting the bill
to be acceptable to the police who had previously voiced a number
of concerns about identity schemes but were happy with the fact
that there was this benefit of the fingerprints left at scenes
of crime.
Q49 Lord Foulkes of Cumnock: Do you
accept that no one is obliged to visit the United States, not
even Canadian citizens, either to transit or to go to the US for
a visit, and therefore every non-US citizen can choose to retain
totally their privacy if they wish?
Dr Hosein: Do I accept that you do not have
to travel to the United States? No, I do not; this is a line of
argument the Government tried to use with the ID cards saying
the ID cards are voluntary because you do not need to get a passport,
it is not mandatory by law that I get a passport, but it was soon
accepted that if you want to be a functioning part of the economy
you need to have a passport, you need to travel, so therefore
you are going to have to get a ID card with a fingerprint. It
is the same idea with the United States; I travel to the United
States about 12 times a year, never for a vacation, it is always
for work. A lot of people do, the amount of people travelling
between the United Kingdom and the United States is something
like 10,000 a day are transferring back and forth between the
US and the United Kingdom; are these all just people going on
vacation? A large majority of people are business travellers,
who really have no choice over this. But even if it was just voluntary,
it does not mean that you can voluntarily give up all of your
rights just because you want access to a specific environment.
The rule of law requires that countries implement a number of
safeguards to prevent abuse, and we all accept that that is the
way governments operate. That is the way the EU operated when
it created the EU directive on data protection, saying you can
process information but there are certain safeguards. The US is
free to fingerprint foreigners coming in because, look, it is
not the say of the UK Government to influence how the US Government
fingerprints people, but when we are talking of the transfer of
data that originally resides in the United Kingdom or across the
EU, that is protected by the laws of this country and the EU,
which is then sent in breach of these laws to the US where it
is processed in breach of those laws, we are talking of an issue
of sovereignty between countries and it is perfectly reasonable
for the EU and the United Kingdom to ask that the data that was
collected in this country under the laws of this country ought
to be protected when it is transferred elsewhere, and the fact
that it is not is a serious concern to both sides. I will give
you the example of the Swift case. Swift is an international banking
co-operative which collects information on our inter-bank transfers
and enables inter-bank transfers. It was discovered in June last
year that the intelligence agencies in the United States had been
getting almost all the data from Swift regarding transfers of
money around the world, and it was being handed over to the intelligence
agencies for their data mining purposes. This was a shock to the
global community; it was a shock that our banking transactionseven
inter-bank transfers between, say, France and Germanyare
being sent to the US Government for scrutiny. Some would say what
is the sovereignty of the US Government to do that, but the EU
was saying "Hold on, that is actually illegal, why are you
collecting this information?" It was the same with PNR; when
PNR was originally being discussed it was about the US Government
getting access to the reservation systems to look at all PNR,
not just the PNR of people travelling to the United States. That
is why I would say that this debate really is about civil liberties
generally; it is not about the ability to give up your rights
just in order to get access to one specific situation because
it is not about you getting access to that specific situation,
it is about the mass surveillance of mass activities.
Lord Harrison: My Lord Chairman, given
our interest in fingerprinting this morning I feel we should all
re-read Mark Twain's Pudding Head Wilson which I think
was the first ever novel written on fingerprinting, and it might
give us some wit and wisdom there.
Chairman: We will read it into the record.
Q50 Lord Harrison: Two very quick
questions, if I may, Dr Hosein. First of all, is data collected
on no-shows as opposed to go-shows, because I would have thought
that might be quite interesting; secondly, in the negotiations
for the new agreement there are likely to be requests for more
data to be put to wider use and kept for longer. What do you think
are the main dangers against which the negotiators should guard?
Dr Hosein: Passenger name records are collected
when somebody decides to book a flight and even if they cancel
that flight that PNR is still in the reservations system. If they
do not show up at the airport as a no-show, it just gets logged
within the no-show, they did not show up, they did not fly. This
happens a lot and it happens mostly to business travellers; I
have been a no-show on a number of flights around the world, just
because you are too late to get to the airport or you decide to
take the train instead and so on and so forth. This information
is useful, but at the same time why is it that useful to be transferred
to the United States on passengers who have not travelled to the
United States. The mere fact that they have booked a flight and
did not show up, that is not interesting, that is only of interest
to the carrier who is possibly losing money or charging somebody
for a service that was not given. On the future negotiations,
the secretary of the Department of Homeland Security in late August
last year wrote an editorial in the Washington Post. It
was after the arrest of the liquid bomb case in this country and
he declared that the intention for Passenger Name Records was
for greater access and greater use. The United States Government
does not understand why the data can only be retained for three
and a half years. They say that as a matter of custom data in
the United States Government is kept for at least four years and,
as I said, the fingerprint data that is collected is kept for
100 years and the PNR of most other countries is collected for
40 years. Secretary Chertoff's point was that he is going to push
for at least eight years retention, so that is what you can expect
in the next round of negotiations. What are the dangers? The danger
is going to be this confusion over the visa waiver programme;
I think the US Government is going to offer to the EU a lot more
than it can actually deliver in exchange for the EU agreeing to
keep quiet over PNR. Already I had a call from a journalist yesterday
who is running a story tomorrow; she said that the mandate given
to the negotiators from the EUwhich was just handed down
a couple of weeks agoincludes demanding reciprocity, not
only reciprocity from the US on PNR information, but also information
derived from PNR. This is an interesting situation, because of
course the classic example of this is a KLM flight to MexicoI
believe it was last yearwas bound to fly over US territory
and the Americans had identified a problematic passenger and ordered
that plane to turn around and return to Europe, which is entirely
within the rights of the Americans to do. That plane landed back
in Europe and everybody got off the plane and went their separate
ways. The Americans never notified who was on that plane who was
problematic, never notified the officials to perhaps stop this
person in Europe. I was speaking to one Member of the European
Parliament yesterday and she said it was quite shocking. Of course
we would love to know if there are suspected terrorists on planes,
and if the Americans could share that information with us when
that person returns we would investigate the situation. That is
one way of looking at the problem. The other way of looking at
the problem is that the EU does not collect PNR generally. There
is some collection in this country by Customs and Excise, but
it does not collect PNR generally. It does not process this data
because it is problematic and possibly illegal and the collection
of PNR that the Americans want is possibly disproportionate and
there is a whole debate about this. What the negotiators have
a mandate to do now is say to the Americans yes, you can have
our PNR on the condition that whatever you do with it, such as
the automated targeting system you apply to it, the data profiling
you apply to it, can you send us that data back so we know if
it is problematic in the future. In a sense this is the rendition
of data, this is like the EU saying we cannot process this information
in the EU, we cannot data-mine it, so how about we outsource that
to the United States, the United States does all the dirty work
for us in a way that we cannot do and they will give us back the
data. I worry that these kinds of promises, these kinds of trades,
will be part of the next round of negotiations and that is how
the Americans might very well get their eight years of retention
if not 40 years of retention, the use of data-mining which was
not properly enabled within the first agreement and the wide uses
of the data.
Chairman: Dr Hosein, you have been extremely
helpful and I want to thank you very much indeed for your very
full but fluent replies. I am sorry that you found yourself having
to speak for two people, but may I congratulate you on the way
in which you admirably covered the agenda. Please convey our regrets
to Simon Davies and, indeed, if we are at fault in our transport
system convey our apologies to him. I am sorry that we were not
able to see him, but thank you very much indeed for doing the
work of two with admirable care and helpfulness.
Baroness D'Souza: Hear, hear.
Chairman: I wish you all the best; thank
you very much.
|