Select Committee on European Union Minutes of Evidence


Memorandum by Professor Elspeth Guild, Radboud University, Nijmegen, Senior Research Fellow, Centre for European Policy Studies (CEPS)

INTRODUCTION

  1. The collection, retention, manipulation, exchange and correction of personal data in Europe has once again become a matter of substantial interest. The last time data use constituted an important political issue in Europe, in the 1970s, the result (at the European level) was the Council of Europe's Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data opened for signature in 1981. This Convention, to which all EU Member States are parties, still sets the standard for data use in Europe.

21 MARCH 2007

  2. The EU adopted Directive 95/46 on data protection, based largely on the Council of Europe's standard, which had to be transposed by the Member States by 25 October 1998.[1] The Commission prepared a first report on its transposition in 2003. The European Data Protection Supervisor was created in 2001 to provide an independent body to ensure that the fundamental rights and freedoms of individuals—in particular their privacy—are respected when the EC institutions and bodies process personal data or develop new policies.

  3. Since the attacks in the USA of 11 September 2001, data use has once again moved up the political agenda. The combination of very substantial technological advances in the collection, retention, use and storage of data and the enhanced concerns about security provided a new environment for data issues. One of the outcomes of the new environment was the decision by the US authorities to collect and retain data on individuals coming to the US by air a measure intended to increase US security.[2] This US legal act, however, had consequences for data protection in the EU. In order to provide a common basis for the transmission of personal data by EU transport companies to the US authorities, an agreement was entered into between the EU and US on 28 May 2004 regulating the field. The agreement was attacked before the European Court of Justice by the European Parliament on a number of grounds, not least the inadequacy of protection of individual data. On 30 May 2006, the European Court of Justice found that the agreement had been adopted on the wrong legal basis and gave the parties until 30 September 2006 to adopt a new agreement on the correct basis.[3]

  4. On 6 October 2006 the Council adopted a decision to enter into a new agreement with the USA regulating PNR and the new EU US agreement was published on 11 October 2006 (though subject to language checks).[4] In this note I will address some of the issues which arise as a result of the new agreement, in particular, as regards difference between the first agreement and the new one which affect the protection of data.

THE KEY ISSUES REGARDING THE NEW AGREEMENT

  5. The EU and US took the opportunity of the necessity to adopt a new agreement to include a number of changes to it, notwithstanding the fact that the agreement is a temporary one and new negotiations are to commence to replace it. For the EU, the original PNR provision consists of three main documents—the Council Decision approving signature, the agreement and the Undertakings of the Department of Home Land Security of 11 May 2004. The new provision includes the Council Decision, which is now substantially developed, the Agreement which remains substantially the same (though there are some changes of significance) and a letter of interpretation dated 11 October 2006 from the US Department of Homeland Security which effectively unilaterally amends the Undertakings in so far as the letter states how the US authorities interpret the provision of the Undertaking and states certain changes to the Undertakings. Twelve issues were identified as key regarding the new agreement and its interpretation.[5]

  6. Push-Pull: under the first agreement, the US authorities (in the form of the Homeland Security Department) had the power to enter the data bases of carriers and to pull out information (limited to the 34 specified items in the Undertaking) which it wanted. The reason for this was that European carriers did not have in place the technology to deal with the preferable (from the perspective of data protection) system of push—where the US authorities would have to make a request and the carriers would provide the specified information. It was agreed in 2004 that the system would move to a push one as soon as the technology was in place. According to the EU's Working Party on Protection of Individuals regarding the Processing of Personal Data, report dated 14 June 2006, all the technical requirements are in place for a push system to be implemented. Nonetheless, the new agreement states that US authorities should be allowed to access data directly.

  7. Time Limits and Frequency: under the 2004 agreement the US authorities had only 72 hours before a flight to seek data and a limit on the number of times it can check data. Under the new agreement the 72 hour limit is no longer final and there is no limit on the number of times the US authorities can check the data.

  8. Purpose Limitation: the purposes for which data could be use were already fairly wide in the first agreement, including of course preventing and combating terrorism, related crimes, serious crimes that are transnational in nature, flights from warrants or custody for the designated crimes. In the second agreement as augmented by the letter of understanding, the data may be used also in the context of infectious disease for the protection of vital interests which itself is subject to a wide scope.

  9. Sharing data: the new agreement and its various associated documents widen substantially the number of agencies with which the US authorities may share data. It is not entirely clear whether the EU authorities have a clear description of the agencies which may be provided with data on EU citizens.

  10. Number and nature of the data: the letter of understanding states that the US authorities must have the option to seek additional data, particularly if the system moves to a push rather than pull format (this of course raises questions as to whether the US authorities have been strictly complying with the limit on the data they are permitted to obtain under the pull system). The Working Party on Protection of Individuals with regarding to the Processing of Personal Data in its report of 14 June 2006 specified that only 19 data items were, it its opinion appropriate for sharing (and the list of 19 differs not only in number but in elements from the list of 34 under the current agreement).

  11. Data Retention: Under the initial agreement data had to be destroyed after 3.5 years (at least in principle). In the new agreement's letter of understanding, the US authorities indicate that as no data will actually have had to be destroyed before the end of the current agreement "questions of whether and when to destroy PNR data collected in accordance with the Undertakings will be addressed by the United States and the European Union as part of future discussions".

  12. Evaluation: A joint evaluation took place in May 2004. The report of this evaluation is not public, though it would be very helpful if it were released as no doubt it would reassure EU citizens as to the propriety of data use by the US authorities. In the new agreement doubt is cast over whether there will ever be another joint evaluation.

  13. Data Protection: the Council in its Decision deems the US authorities to be satisfactory for EU data protection purposes. This raises questions about whether this is in fact the case.

  14. Legal status: it is very unclear what the legal status of the letter of understanding is. It appears not only to interpret the agreement and the Undertakings but to amend and change them as well as to point to changes the US authorities will seek in the future.

  15. Democratic and Parliamentary Scrutiny: this is a very intra EU issue, the result of the European Court of Justice Decision. The new legal base for the agreement does not provide a role of the European Parliament. As preparations are already taking place towards the negotiation of yet another agreement to replace the current one, the European Parliament is much concerned about how its views will be taken into account.

  16. Implications for transfer of other data: there are concerns about the consequences of the PNR agreement for other data transfer agreements.

  17. This provides an impressive list of concerns which have been raised by the European Parliament's Rapporteur, however, it does not cover all of the issues which the new agreement raises, in particular, redress and protection of the individual.

PROTECTING THE INDIVIDUAL

  18. As a result of the transfer of faulty data from the Canadian authorities to their US, counterparts Mr Arar, a dual Canadian/Syrian citizen was stopped when in transit in New York on his way to Canada on suspicion of terrorist involvement in September 2002. He was sent to Syria where he was detained and tortured for over a year. When he finally returned to Canada in October 2003 a Federal Inquiry led by a retired Supreme Court judge was established to determine how this had happened. The Inquiry published its findings in September 2006 which exonerated Mr Arar of any suspicion of involvement with terrorist activities and found serious flaws in the manner by which data had been transferred by Canadian services to their US counterparts on the basis of which Mr Arar was suspected by the US authorities of involvement with terrorism. On 26 January 2007 the Canadian Prime Minister issued a formal apology to Mr Arar and offered him compensation in the amount of CAN$10.5 million.

  19. Inaccurate data transmission can have horrifying consequences for the individual, as in the case of Mr Arar. It can also be very expensive for governments.

  20. The new EU—US PNR Agreement contains an innovation over its predecessor in that it states "this Agreement does not create or confer any right of benefit on any other person or entity, private or public". Is this to be understood as seeking to deprive someone like Mr Arar from obtaining redress in the event that his data are improperly transmitted and used? If so this is a very unfortunate attempt by the parties to deny responsibility for their acts.

  21. The new Council Decision approving the Agreement also contains a new article 4 which states that Member States may exercise their existing powers to suspend data flows to the US authorities in order to protect individuals with regard to the processing of their personal data in two cases:

    —  Where a competent US authority has determined that the Department of Homeland Security is in breach of the applicable standards of protection; or

    —  Where there is a substantial likelihood that the applicable standards of protection are being infringed, there are reasonable grounds for believing that the DHS is not taking or will not take adequate and timely steps to settle the case at issue, the continuing transfer would create an imminent risk to grave harm to data subjects, and the competent authorities in the Member States have made reasonable efforts in the circumstances to provide DHS with notice and an opportunity to respond.

  22. The first part of this article moves responsibility for determining data breaches on the US authorities in accordance with their laws. As the person who will be affected is the EU citizen, this may not be entirely satisfactory. As was the case for Mr Arar, the US authorities have refused even to entertain the request by the Canadian authorities for information regarding his treatment, let alone participate in determining the truth or compensating Mr Arar for the damage which their action caused him.

  23. The second part of the provision moves responsibility for protection of citizens of the Union to their national governments. In terms of EU solidarity, this is very unfortunate as it clearly and unambiguously breaks the common responsibility of the Member States to protect their citizens. Further, it places the bar exceeding high in respect of a decision to cease to participate in the data provision system. Further, it permits one Member State to determine that the US authorities are not applying a standard of protection which is required but it does not provide for any solidarity from the other Member States. If this is a common agreement, then the commitments must be common as well.

  24. If the citizen of one Member State is at risk of treatment like that which the US authorities meted to Mr Arar, all Member States should be engaged in the protection of that citizen and act in solidarity to protect all citizens of the Union against harmful use of personal data.

20 February 2007






1   It has now been augmented by Directive 2002/58. Back

2   The US Aviation and Transportation Security Act 2001. Back

3   For a detailed discussion of the issues of the PNR decision see E Guild and E Brouwer, The Political Life of Data: The ECJ Decision on the PNR agreement between the EU and the US CEPS, Brussels, 2006. Back

4   Council Document 13216/06. Back

5   Letter 10 October 2006 Sophie in't Veld, MEP, rapporteur for the EU-US agreement on PNR to Commissioner Frattini. Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007