Select Committee on European Union Minutes of Evidence


Examination of Witnesses (Questions 40-50)

DR GUS HOSEIN

28 FEBRUARY 2007

  Q40  Lord Jopling: Sorry, you have confused me. You started answer my question by saying that you did think fingerprinting was an invasion of privacy. You then went on to say that fingerprinting is not problematic. Which did you mean?

  Dr Hosein: I said that in a specific and proportionate environment fingerprinting by its nature is not necessarily a bad thing. I started by saying that my personal opinion is I equate fingerprinting with being treated like a criminal, but I do understand the modern world and the spread of biometrics which, Prime Minister Tony Blair is very fond of saying, the world has moved on, technology has moved on and biometrics are becoming a part of daily life. I do accept that people are willing to, say, use a fingerprint to get into a building, if it is a highly secure building and so on because they know that data is kept securely and so on and so forth. Do I still consider it an invasion of privacy? It depends on the situation, who is doing it and the reasons for which it is being done.

  Baroness D'Souza: It is the context and proportion.

  Q41  Earl of Listowel: I see in question 11 we deal with one of the concerns that I wanted to raise and it came up in the answer you gave first to Lord Foulkes, which is the worry about the safeguards; if they are not sufficient they alienate and will be unhelpful in the cause of preventing terrorism. The question I wanted to ask you, if you can help with this, is the commission that reported on the 9/11 attacks, if I remember correctly, particularly focused on lack of co-operation between the different agencies and an over-reliance on electrical information and data rather than human intelligence on the ground in Iraq and elsewhere, for instance in the Middle East. Listening to what you are saying there seems to be a sort of echo again in terms of what we have been discussing just now, so my concern is I recognise absolutely Lord Foulkes' concern, but is there a danger of displacing, in all this drama you were describing, one's energy towards gathering lots of information which may not necessarily be that helpful and not concentrating on the main problems which may be about human capacity and about the capacity of various departments within the US to work together effectively and to develop perhaps the people working at the front line to be able to detect people? I am not expressing myself very well, but do you see what I mean?

  Dr Hosein: Absolutely, I see what you mean. More often than not I believe in most of the cases where there has been prevention of terrorist atrocities, most of the intelligence that led to those arrests was from human intelligence. The classic case of this is the July 7 investigations into the bombers; I heard one of the police who was the head of the investigation when he spoke at an event at Portcullis House last year. He said that they never relied on the communication records of the terrorists within their investigations, which I found amazing because the Home Secretary just a month before pushed a policy through the European Union on the collection, storage and retention of communications data of all EU citizens on the grounds that it would help prevent terrorism. There is a difference between the political debate that takes place which is very much about changing the balance, reconsidering proportionality and so on and so forth, which then provides for mass surveillance and the real fight that goes on which is the human intelligence, the people in the field trying to conduct investigations undercover and so on and so forth. Unfortunately, I have to stop there because I am not an expert on human intelligence and I worry that I would actually end up saying something that is wrong, but I do agree with the sentiments expressed.

  Q42  Lord Foulkes of Cumnock: Could I just ask one question following Lord Jopling's question? You answered Lord Jopling by saying that fingerprinting is an inexact science, and you gave that one example; I could have given you an example from Scotland and the Shirley McKee case as well. Surely that argues for increasing the amount of information to be collected because fingerprinting is not 100 per cent accurate, it might only be 99.8 per cent, and therefore you need other biometric data and when you put them altogether you get up nearer 100 per cent. Is that not right?

  Dr Hosein: There are more intelligent scientists than I who could answer that, but based on the information I have seen, first of all, fingerprinting is not even close to 99 per cent. It has varied, depending on the algorithms used and the size of the databases, between 60 and 85 per cent—let us say it is 95 per cent. 95 per cent is still a very low measure when you apply it to the size of a population of, say, 60 million or 80 million. The other argument is the larger the database is the more margin for error you almost have to accept.

  Q43  Lord Foulkes of Cumnock: You bring in another category of measurement like iris scanning.

  Dr Hosein: Yes. I am going to refer to the work of the creator of iris scanning, John Daugman, who is a better statistician than I am. He said that we should not fall for the trap that increasing the number of biometrics necessarily decreases the fault level, it actually can compound the problem, so he argues that it is possible that instead of using unreliable fingerprints compounded with iris scans which were introduced not long ago, just use iris scans which have, arguably, a 99 per cent effectiveness rate; do not compound it with fingerprints. That is why the ID card programme in this country has moved away from iris scanning for the time being and they are focusing first on facial recognition, which has alarmingly low success rates, and moving to fingerprints which have a much higher success rate.

  Q44  Lord Foulkes of Cumnock: I could go on, but I will not, I will do what I am told. Do you think the joint review procedure is appropriate to monitor the workings of the agreement?

  Dr Hosein: In theory it is absolutely appropriate. The 2004 Agreement said there would be yearly reviews done by EU officials, including data protection commissioners, so we have hoped for the best. We are considering it as a bad situation with the agreement that emerged in 2004. The first review was done in 2005; as I mentioned, the report was not released until 2006, it was heavily redacted, we were not even given the names of individuals within the EU who were involved. On top of that, the EU officials who were involved had to sign a non-disclosure agreement so they could not actually openly discuss any of the other discoveries they had made in their discussions with the United States Government and they expressed their deep displeasure with this, the fact that they had to sign a non-disclosure agreement, so this is not exactly what I would call an open review. The 2006 review that was supposed to take place was cancelled because of the negotiations that were going on, and the United States Government has said that there will be no further reviews until after the next agreement has gone through. What was promised to be three reviews in three years has turned out to be one review in three years with no promise of further reviews, so it has been inadequate. The privacy commissioners across Europe are calling for more reviews; they are not going to get it but they are calling for the next agreement to have stronger review powers. I am not optimistic that this is going to be the case. Having said that, the review that took place in 2005 we discovered just a few weeks ago that that review had discovered that the United States was doing data mining—I am sorry, I should not use that word politically. There was already a targeting system and the 2005 review had discovered that this was being applied to passenger data. Nobody else in the United States Government knew this, US Congress did not know this, the US public did not know this, but the European Commissioners involved and the European officials involved knew about ATS, but they were not going to tell anybody about it because of the non-disclosure agreement. There is, therefore, a very awkward situation where the review might have been highly successful had they been given enough ability to communicate their findings and for the review to take place more periodically, but unfortunately the politics of the situation prevent this from happening.

  Lord Foulkes of Cumnock: That is useful information for our visit to Brussels when we take evidence from the Commission.

  Q45  Chairman: If Lord Foulkes agrees, the next question we have really covered, but I would like to rephrase it. That is, do you think there is an awareness? I should first of all say I am sure this Committee accepts that there is a serious security problem that needs to be addressed, but do you think that the public understand that one of the advantages of PNR is that they do not have to go through the sometimes rather tiresome visa procedure and, whatever the worries there are or may be about data protection, that is actually quite a significant advantage for the travelling individual?

  Dr Hosein: Based on my knowledge of the politics within the United States I would openly answer by saying I do not believe that the two issues are related. I do not believe that the visa waiver programme and passenger name records are related at all. Politically they are related in that if `you give us PNR, we will expand the visa waiver programme', but to my knowledge and my understanding there has been no discussion of throwing the United Kingdom out of the visa waiver programme because BA does not hand over PNR; there has not been that kind of quid pro quo over it, again, because different departments deal with this and there is a different level of politics that applies to it. As I said earlier, the visa waiver programme is surrounded by a level of politics that is more about immigration and not wanting anybody to enter the country without a visa, versus the PNR agreement which is a different level of politics about national security and so on and so forth.

  Q46  Chairman: Do you detect—and this is probably not a fair question to ask you—a difference of attitude towards this whole subject between various EU countries? For instance, I do not know how much you know about the French attitude to PNR agreement.

  Dr Hosein: The French CNIL—that is the privacy commission in France—has been very active against the PNR agreement, so much so that I know there are French commissioners who no longer travel to the United States because they do not want their PNR handed over and they do not want to be fingerprinted either. So the French have been very active. Meanwhile, some of the new Europe countries—as they are sometimes referred to—are annoyed that they are not part of the visa waiver programme and hope that they can do anything to get into the visa waiver programme, but they understand—and again this is the level of politics within the US Government and it will take years for this to actually evolve [en rule]although the United States might make promises to the EU that they will consider this, it is a much more separate process that takes place. It is the Department of Homeland Security that does the negotiations on PNR, it is the State Department that is responsible for dealing with such issues as the visa waiver programme.

  Q47  Earl of Listowel: I want to go back to an answer you gave earlier about safeguards and the importance of those, looking at the importance of safeguards protecting public information from the point of view of winning hearts and minds in the battle against terrorism. We have recognised from the invasion of Iraq and other places that there is a danger of well-intentioned action backfiring in a way and contributing to ill-will towards us and other nations. Do you have enough information to work out in the balance whether the activities we have been discussing this morning are actually perhaps having a perverse effect, or is there not enough information yet to see whether that is happening or not?

  Dr Hosein: I want to preface my answer by saying that I find it amazing that people are so activated by the US collection of this information and, in a sense, it is almost an anti-American attitude that has emerged over the US collecting this information. They see no problem with their own government or other governments collecting this information, but we seem to be missing the debate. This is something that is happening everywhere but we are focusing a lot on the US because the US was the first to ask for this information but they are also doing the worst job at managing this information. I will give you two examples that really link to the hearts and minds argument that you are proposing. The first is news from earlier this week from Canada about the law school exam—in order to apply for law school in North America you have to write an exam. It has emerged that Canadian citizens are being fingerprinted before they take this exam, and there is an uproar saying all these fingerprints are being sent to the US Government, they could be accessed under the USA Patriot Act, they could be abused and so on and so forth, and there is this sense of discomfort over it. Arguably, if you ask why you are taking fingerprints for a foreign exam it is to make sure you do not take the exam under multiple names and so on and so forth, so there might be a reason for it. However, there is such a concern that because this information is going to the US it is going to be abused and the US has lost its higher moral ground for collecting this information. Then it was discovered that the LSAT—that is the name of the exam—has been doing this fingerprinting process for a number of years. There was not a problem about it before when it was taking place, but now there is a concern because it is the Americans. My second example perhaps explains why there is this emerging concern, particularly in Canada, and that is the case of Maher Arar. Some of you around this table might know this story, but he is a Syrian-born Canadian who was travelling from a wedding in Tunisia—his wife's family is from Tunisia—he was flying back to Ottawa where he lived, flying through the JFK airport in New York and he was detained by the Americans as a terrorist. They kept him for a number of days; they interrogated him and said "Okay, we are going to send you back home." He said, "That's great" and they sent him to Syria via Jordan—they did not send him to Canada, they sent him to Syria where he was detained for 11 months in prison and tortured, according to his claims and according to a judicial commission taking place in Canada. Finally, the Syrians established that he was innocent and he was sent back to Canada. In investigations as to why this had taken place, what basis did the Americans have to say that this individual was a terrorist, the Americans said that they had gotten information from the Canadian Government in a data-sharing agreement. The Canadian Government, through the Royal Canadian Mounted Police, were doing an investigation on somebody that Arar knew, so they had listed Arar in a database saying "of interest in this investigation because he knows the suspect". This information was then transferred to a different database within Canada where he was just included in a list of people of interest, there was no longer this link to somebody of interest, he was the person of interest. As a matter of custom this data was regularly shared with the US Government where it was put into their border database, the TECS database, where he was put in as a person of interest and suspected terrorist and that is why the Americans reacted the way they did and sent him to Syria, and the rest of the story is Canadian history. The Canadians are very angry about this and to this day actually he is still on the US no-fly list, he cannot board a plane that flies above the United States. The Americans refuse to acknowledge that he is innocent, but the Canadian Government has just awarded him a million dollars apologising for the entire affair. There is therefore a sense of disquiet in America about the US Government getting access to data; any transfer of data in a private scheme—like private companies doing outsourcing deals—has led to unions protesting en masse and saying how can our personal information collected by our union end up in the US where it can be accessed under the Patriot Act? Do I consider it is a serious concern? I do not believe that the US Government is dying to use the Patriot Act to get access to all this information, but as you say it is a hearts and minds issue. There is a level of disquiet which is alarming and the lack of confidence in transport data flows is again alarming to the point where it could lead to a breakdown.

  Q48  Lord Marlesford: This is going back to Lord Jopling's question and Lord Foulkes' questions, because I am not absolutely clear on them. First, do you accept that a democratic state does need to know and know for certain who people are? Secondly, if biometrics are a method of identifying people and you have one biometric which gives a hit, that may merely raise a question, not be certain, but if you have a second biometric that makes the same hit that must really produce a very considerable degree of certainty?

  Dr Hosein: In a democratic state is it necessary for individuals to be known and identified? I would say that that is absolutely correct; I would say not just in a democratic state but in a modern economy personal information and identity information is very much a currency in its own right and can lead to more advanced economies, more advanced markets and so on and so forth. I do not believe there is much doubt over this. I believe that doubt emerges on how this is actually realised, so your argument about biometrics and the various uses of biometrics within, say, the national identity scheme, there is a scientific argument to support what you are saying but that is not the reason why we have fingerprints being proposed for the ID card scheme. There are two reasons why fingerprints are being proposed for the ID card scheme: first, because when they were proposing the ID card scheme the Government was adamant about it being an international obligation, and the international obligation says that fingerprints may be collected. The EU said that two fingerprints should be collected for biometric passports, so that is why we are moving down the route of fingerprints. The other reason why we are moving down the route of fingerprints when it comes to the national identity card scheme is because the police were sold on the idea that one of the benefits of the scheme would be that there are 900,000 fingerprints left at scenes of crime over the years that have not been matched to a criminal, so the police were told if we run this identity card scheme, we will fingerprint the entire population and you can verify those 900,000 fingerprints against the British population of fingerprints once we have the national identity card scheme off the ground. It was not really about the effectiveness of the technology, it was not about the 99 per cent (which is 95 per cent) effectiveness, it was really, first, about a way of getting the bill acceptable through the creation of an international obligation and, second, a way of getting the bill to be acceptable to the police who had previously voiced a number of concerns about identity schemes but were happy with the fact that there was this benefit of the fingerprints left at scenes of crime.

  Q49  Lord Foulkes of Cumnock: Do you accept that no one is obliged to visit the United States, not even Canadian citizens, either to transit or to go to the US for a visit, and therefore every non-US citizen can choose to retain totally their privacy if they wish?

  Dr Hosein: Do I accept that you do not have to travel to the United States? No, I do not; this is a line of argument the Government tried to use with the ID cards saying the ID cards are voluntary because you do not need to get a passport, it is not mandatory by law that I get a passport, but it was soon accepted that if you want to be a functioning part of the economy you need to have a passport, you need to travel, so therefore you are going to have to get a ID card with a fingerprint. It is the same idea with the United States; I travel to the United States about 12 times a year, never for a vacation, it is always for work. A lot of people do, the amount of people travelling between the United Kingdom and the United States is something like 10,000 a day are transferring back and forth between the US and the United Kingdom; are these all just people going on vacation? A large majority of people are business travellers, who really have no choice over this. But even if it was just voluntary, it does not mean that you can voluntarily give up all of your rights just because you want access to a specific environment. The rule of law requires that countries implement a number of safeguards to prevent abuse, and we all accept that that is the way governments operate. That is the way the EU operated when it created the EU directive on data protection, saying you can process information but there are certain safeguards. The US is free to fingerprint foreigners coming in because, look, it is not the say of the UK Government to influence how the US Government fingerprints people, but when we are talking of the transfer of data that originally resides in the United Kingdom or across the EU, that is protected by the laws of this country and the EU, which is then sent in breach of these laws to the US where it is processed in breach of those laws, we are talking of an issue of sovereignty between countries and it is perfectly reasonable for the EU and the United Kingdom to ask that the data that was collected in this country under the laws of this country ought to be protected when it is transferred elsewhere, and the fact that it is not is a serious concern to both sides. I will give you the example of the Swift case. Swift is an international banking co-operative which collects information on our inter-bank transfers and enables inter-bank transfers. It was discovered in June last year that the intelligence agencies in the United States had been getting almost all the data from Swift regarding transfers of money around the world, and it was being handed over to the intelligence agencies for their data mining purposes. This was a shock to the global community; it was a shock that our banking transactions—even inter-bank transfers between, say, France and Germany—are being sent to the US Government for scrutiny. Some would say what is the sovereignty of the US Government to do that, but the EU was saying "Hold on, that is actually illegal, why are you collecting this information?" It was the same with PNR; when PNR was originally being discussed it was about the US Government getting access to the reservation systems to look at all PNR, not just the PNR of people travelling to the United States. That is why I would say that this debate really is about civil liberties generally; it is not about the ability to give up your rights just in order to get access to one specific situation because it is not about you getting access to that specific situation, it is about the mass surveillance of mass activities.

  Lord Harrison: My Lord Chairman, given our interest in fingerprinting this morning I feel we should all re-read Mark Twain's Pudding Head Wilson which I think was the first ever novel written on fingerprinting, and it might give us some wit and wisdom there.

  Chairman: We will read it into the record.

  Q50  Lord Harrison: Two very quick questions, if I may, Dr Hosein. First of all, is data collected on no-shows as opposed to go-shows, because I would have thought that might be quite interesting; secondly, in the negotiations for the new agreement there are likely to be requests for more data to be put to wider use and kept for longer. What do you think are the main dangers against which the negotiators should guard?

  Dr Hosein: Passenger name records are collected when somebody decides to book a flight and even if they cancel that flight that PNR is still in the reservations system. If they do not show up at the airport as a no-show, it just gets logged within the no-show, they did not show up, they did not fly. This happens a lot and it happens mostly to business travellers; I have been a no-show on a number of flights around the world, just because you are too late to get to the airport or you decide to take the train instead and so on and so forth. This information is useful, but at the same time why is it that useful to be transferred to the United States on passengers who have not travelled to the United States. The mere fact that they have booked a flight and did not show up, that is not interesting, that is only of interest to the carrier who is possibly losing money or charging somebody for a service that was not given. On the future negotiations, the secretary of the Department of Homeland Security in late August last year wrote an editorial in the Washington Post. It was after the arrest of the liquid bomb case in this country and he declared that the intention for Passenger Name Records was for greater access and greater use. The United States Government does not understand why the data can only be retained for three and a half years. They say that as a matter of custom data in the United States Government is kept for at least four years and, as I said, the fingerprint data that is collected is kept for 100 years and the PNR of most other countries is collected for 40 years. Secretary Chertoff's point was that he is going to push for at least eight years retention, so that is what you can expect in the next round of negotiations. What are the dangers? The danger is going to be this confusion over the visa waiver programme; I think the US Government is going to offer to the EU a lot more than it can actually deliver in exchange for the EU agreeing to keep quiet over PNR. Already I had a call from a journalist yesterday who is running a story tomorrow; she said that the mandate given to the negotiators from the EU—which was just handed down a couple of weeks ago—includes demanding reciprocity, not only reciprocity from the US on PNR information, but also information derived from PNR. This is an interesting situation, because of course the classic example of this is a KLM flight to Mexico—I believe it was last year—was bound to fly over US territory and the Americans had identified a problematic passenger and ordered that plane to turn around and return to Europe, which is entirely within the rights of the Americans to do. That plane landed back in Europe and everybody got off the plane and went their separate ways. The Americans never notified who was on that plane who was problematic, never notified the officials to perhaps stop this person in Europe. I was speaking to one Member of the European Parliament yesterday and she said it was quite shocking. Of course we would love to know if there are suspected terrorists on planes, and if the Americans could share that information with us when that person returns we would investigate the situation. That is one way of looking at the problem. The other way of looking at the problem is that the EU does not collect PNR generally. There is some collection in this country by Customs and Excise, but it does not collect PNR generally. It does not process this data because it is problematic and possibly illegal and the collection of PNR that the Americans want is possibly disproportionate and there is a whole debate about this. What the negotiators have a mandate to do now is say to the Americans yes, you can have our PNR on the condition that whatever you do with it, such as the automated targeting system you apply to it, the data profiling you apply to it, can you send us that data back so we know if it is problematic in the future. In a sense this is the rendition of data, this is like the EU saying we cannot process this information in the EU, we cannot data-mine it, so how about we outsource that to the United States, the United States does all the dirty work for us in a way that we cannot do and they will give us back the data. I worry that these kinds of promises, these kinds of trades, will be part of the next round of negotiations and that is how the Americans might very well get their eight years of retention if not 40 years of retention, the use of data-mining which was not properly enabled within the first agreement and the wide uses of the data.

  Chairman: Dr Hosein, you have been extremely helpful and I want to thank you very much indeed for your very full but fluent replies. I am sorry that you found yourself having to speak for two people, but may I congratulate you on the way in which you admirably covered the agenda. Please convey our regrets to Simon Davies and, indeed, if we are at fault in our transport system convey our apologies to him. I am sorry that we were not able to see him, but thank you very much indeed for doing the work of two with admirable care and helpfulness.

  Baroness D'Souza: Hear, hear.

  Chairman: I wish you all the best; thank you very much.





 
previous page contents

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007