Select Committee on European Union Minutes of Evidence


Examination of Witnesses (Questions 120-139)

Professor Elspeth Guild and Mr Tony Bunyan

21 MARCH 2007

  Q120  Chairman: We will be seeing Mr Hustinx's deputy in Brussels tomorrow, so we will be able to pursue that with him.

  Mr Bunyan: So our Government is claiming they can check this against a main database. The National Audit Office report in January said that using that passport picture digitised on a chip would not be accurate on any database holding more than 10,000 items. Excuse me, they have got more than 10,000 already, so there is a problem over which technology we are talking about—the picture or the fingerprints. All I am saying is there is a risk and one must not think of those as being absolutely accurate systems.

  Q121  Chairman: Professor Guild, do you want to add to that?

  Professor Guild: I am not particularly familiar with the E Border Programme so I would not address that particular question.

  Q122  Baroness Henig: The current US data retention period is 40 years. Would a period considerably longer than 3.5 years cause any problems?

  Mr Bunyan: I think the US Visit Programme, I may be incorrect, is longer than 40 years, but we can look into that.

  Q123  Baroness Henig: At least 40 years.

  Mr Bunyan: The 3.5 years one is quite interesting, because why 3.5 years? The Data Protection Working Party, again, in the European Union has looked at this issue, so this period of 3.5 years is only 3.5 years because that is the length of the EU/US agreement; it has no other basis to it whatsoever, other than it is going to run out next July. People are not aware that there actually is an EU PNR scheme being constructed. We have our own scheme, which is concerned with the entry of people into the European Union. That is not just visa people; if we go out of the European Union we are going to be checked. That set of data may be held, but the limit on that data (this is an EU Directive in April 2004) is that it may be held for 24 hours, unless there is a specific reason why it can be held for longer. In other words, you cannot hold this mass of information for longer than 24 hours unless you have a reason for holding it for longer than 24 hours. I would go on that advice, at the end of the day, because I do have great respect for Peter Hustinx and for the Article 29 Working Party, if you look back at the history of their reporting. They do look at each measure individually, which may have different purposes: some may be entry systems, some may be what has been discussed as a European Union entry and exit system, which is obviously a more complicated system. So I do not think we should see 3.5 years as being set in stone; I think we have got to look at the new proposal when it comes up, which has to be reached by July next year, see what extra information the United States wants to have and make a decision about how to set some limits. Where they may need to hold it for longer, what are the limits on that? I would leave that question open until we see the new draft agreement, presumably some time later this year.

  Q124  Baroness Bonham-Carter of Yarnbury: Can I ask a supplementary to that? You are saying you would agree that 3.5 years is too short a period?

  Mr Bunyan: I do not know. I would start out with the EU Directive of 2004, which is the only one we have got, which says it may only be held for 24 hours.

  Q125  Baroness Bonham-Carter of Yarnbury: Is that sensible? What can you do with information that you are only holding for 24 hours?

  Mr Bunyan: As Elspeth says, it is being collected for commercial purposes, is made available for other purposes, and the first purpose is to check should that person be allowed to travel. The second purpose is, if that person does travel, are they a threat to whichever country they are travelling to? So the purpose of collecting this data is, firstly, to book a ticket, and the second purpose is to judge whether that person is a threat on that `plane or is going to be a threat in the country they arrive into. Now, if you want to have a third purpose at some point in the future you have got to show good reason to do it, which is what the Article 29 Committee is saying, because you have collected for one purpose, you are already using it for one other purpose, which is to guarantee airline security, which I totally agree with, which is to stop terrorists entering your country, which I totally agree with, but if you want to start using it for other purposes then you have to show good reason, and we have got to see a proposal in writing. That is what they are saying. So the 3.5 years is a bit artificial because it just happens to be the length of time of the present EU/US agreement. There is no particular reason why it is 3.5 years; it could have been ten years, it could have been two years; it was just set to fit the length of time of the agreement.

  Q126  Baroness Bonham-Carter of Yarnbury: The Minister has told us that Member States may refuse to supply PNR data if they are not confident that departments with which the Department for Homeland Security shares PNR data provide adequate protection. This is a question for Mr Bunyan because we know what Professor Guild feels. Surely the power could never be exercised if all Member States had to agree?

  Mr Bunyan: Quite clearly, you have got to have an EU-wide agreement. There are a number of other areas—like disagreeing with the US over its open skies policy, or whatever—where what we see is the US trying to negotiate bilaterally, particularly with the newer Member States of the European Union, and trying to undermine the EU having a position on it. We have to have a process here where the EU has to agree with the United States that it has got to have proper data protection, we need to know who is getting access to that information and we need to have a proper review process. Only in that way can we start to build up our rights in terms of why is our data being collected, what is it being used for and who is it being passed on to? It would not be a good idea for Member States to individually have agreements.

  Professor Guild: I would say it is clearly illusory to suggest that power could be exercised by one Member State. Therefore, even to include such an option is to create an illusion of possibility of an exercise of a power. If we have concerns and if we genuinely think that information should be refused, it must be done on a common basis; it has to be done on the basis of solidarity. I would only add one other point on the question of retention periods, which I think is important. I agree entirely with Tony's position: data must be collected for a purpose, the purpose must be clearly stated and the period of retention must be proportionate to the purpose which is intended. That is the first step. The second step is that the retention period of any particular set of data may be shorter or longer, depending on who is going to have access to that data. So, for instance, banking data is collected and retained for very long periods of time but there are extremely strict rules on access to that data. Therefore, who gets to look at the data affects also the legitimacy of the length of time for which it can be retained. However, the first question is the purpose—what purpose is this for—secondly, what data is collected, and, thirdly, who gets access to it?

  Q127  Lord Teverson: It seems to me that one of the areas around this is that everybody wants to prevent terrorism and organised crime, or whatever, but for an operation to be successful and to keep public confidence there has to be confidence in the review process. There was quite a bit of controversy about the review that took place in 2005, and on conversations which have taken place on the American side I think we would say there is probably some indignance that they feel hard-done-by by the criticism that was levelled at them in the process of that review. Could you tell us whether you think the review process is adequate at the moment, or how that should be changed?

  Mr Bunyan: The point is that if the EU has an agreement with the United States I make the presumption that that is an agreement between equal partners. If you have a detailed agreement, many pages long, which was examined in the Parliament by the Council and subject to criticism but, in the end, there was agreement, and now there is a new agreement, if we are entering this as equal partners you cannot have one partner (and the team which went from the EU was a high-level team of officials) in a situation where they say that there were a number of records where access was limited and they were not given hard copies of certain procedural advice. You cannot have that situation. To add insult to injury, the EU team was actually, and I quote, "required to sign confidentiality agreements exposing them to criminal sanctions for any breach". This is not the way you work when you have two equal partners. So I think the EU needs to put its foot down and say: "If we are equal partners you can have access to our data but we must have access to your data. Here are our officials, let us have the names of your officials, and let us be full partners, for goodness sake".

  Q128  Lord Foulkes of Cumnock: Who are you quoting from there?

  Mr Bunyan: The quote is from the European Commission report on this joint review process.

  Professor Guild: Of course, we do not know if there will be ever be another review. At the moment it seems quite unclear. Without a review we have no idea how we are going to provide any kind of assurance to anyone on what is being done with the data. I think there is quite an important difference of perspective, clearly, from the EU side and from the US side, in the EU data protection is considered an important job of the state; it is not the job of the individual to enforce their privacy rights, it is the duty of the state to protect the data of the individual. Therefore, we have Data Protection Supervisors who have these roles which are particularly important. The US perspective has always been that it is the individual's right to enforce the right of privacy, the private sector against the state, so of course you are going to have a different way of looking at what a joint supervisory body should be doing and what the role of a European data protection authority should be.

  Q129  Lord Teverson: Could I ask five simple points? What do you think should be the basis of a review clause in a new agreement? What are the headline things that need to be in that?

  Professor Guild: Clearly, there must be a full review of the correct application of the agreement; any issues in respect of differences in interpretation on the meaning of the agreement and the application of the agreement need to be specified in the report which both sides put forward; the report needs to be made public with, of course, if necessary, sensitive data removed or controlled, (we have many computer systems for doing that); it needs to be published, it needs to be timely and it needs to provide an opportunity for additional opinions by those who have been responsible for carrying out the review.

  Q130  Lord Harrison: Let us pass on to another possible disequilibrium. Dr Gus Hosein has told us that travellers who are not US citizens are not covered by the US data protection laws but can apply under the freedom of information laws in the US if they want to know how their data have been used. In your view, is that an adequate and effective means of redress? Are there other ways of challenging misuse of data by the US authorities? If there are, what are your positive suggestions about strengthening?

  Mr Bunyan: I know Gus Hosein and, indeed, I have worked with him and others actually in putting a freedom of information question in the United States on other issues. I do think it is a little difficult because certainly we needed a bit of help about which department to send the questions to, etc. One of the biggest problems we have here is the United States has never been prepared to tell the European Union exactly which agencies get access to this data. In other words, they are unable to tell us, although there are lots of agencies at federal, state and local level. A figure was mentioned in relation to the first agreement that something like 1,500 agencies might get access. Last October, in the middle of the re-negotiation, it was a bit worrying (this is the point I am making about how many agencies) because the US law was changed and it turns out if the agreement is there and the US changes its law then so does the content of this agreement, apparently. According to the executive order enacted on, number 11388, the Department for Homeland Security was told, basically, to extend the number of agencies and: "the US may not be impeded by a certain provision in the undertaking in the EU/US agreement to restrict information sharing amongst US agencies. The undertaking should be interpreted and applied so as not to impede the sharing of PNR data by the DHS and other authorities". So there is a problem here: who are you giving the information to? We would have a competent authority in each EU Member State you could go to which would then be responsible for finding out where that data had been passed to and had been further processed. The problem for us is we do not know how many agencies have access to it.

  Q131  Lord Harrison: At the moment, what does Joe Bloggs do?

  Mr Bunyan: There is a provision within the agreement to make a complaint. The problem is, what are the powers of the body you are complaining to? Are they able to find out what has happened to the data?

  Q132  Lord Harrison: There is no posting box, as it were, to lodge the first complaint.

  Mr Bunyan: There is in the information which is circulated; there is an address in the United States to which you can complain, but it is one that has been set up as an administrative measure not as part of US law, if I can put it like that. The US law is the 1974 Privacy Act which protects the data protection rights of all US citizens. However, that Act does not extend to non-US citizens. We have to remember this issue is not just cropping up on the Passenger Name Record, it is cropping up over the whole Swift scandal—the access to banking data. I have seen the minutes of some of the EU/US high-level meetings, and I am quite surprised that so much time has passed and the EU has not finally put its foot down a little bit and said: "Look, we have got Swift, we have got PNR and there are other things coming up. You really must get a law, like Canada has got or other countries have got, in order that we do not keep having this problem."

  Q133  Lord Foulkes of Cumnock: Surely, my Lord Chairman, the freedom of information laws in the US, as I understand it, are far more extensive than they are here, are they not? You can get lots more information; we can get information even about things that are happening here from the United States.

  Mr Bunyan: In the main. It is not necessarily true when you are talking about the justice department when you are getting this kind of information. Yes, they do have good freedom of information laws, but it does take time and you have still got to know who to write to and you have still got to know how to frame the question. You may have to write to a number of agencies. Let us remember the case which came before this Committee before: there was the famous case, many years ago, of two Welsh football players (this is under the Schengen system) who were arrested in Luxembourg, went on to a system, then got arrested again, and it took them three years to get their names off the record because they had done nothing wrong. They had to get the European Commission to track down that Belgium was holding information, and the United Kingdom which passed it to various embassies around Europe.

  Q134  Lord Foulkes of Cumnock: That is nothing to do with the United States.

  Mr Bunyan: The point I am making is that once data is being held on you and can be passed to innumerable agencies how do you find out what data those innumerable agencies have got? If it is wrong, how do you get it corrected? I use the EU example because it is one of the rare examples we have got of how difficult it is for an individual, once they get on to a list or get wrongly on to a list, to get off the list. I do think that bears example. At least here we know there is a Schengen authority, at least we have got national contacts and can do something, but in the United States where do you begin?

  Q135  Lord Foulkes of Cumnock: You mentioned 1,500 agencies. Where does that figure come from?

  Mr Bunyan: From the United States themselves.

  Q136  Lord Foulkes of Cumnock: But whom in the United States? You just read out a quotation—

  Mr Bunyan: You are asking me to remember exactly which official from the United States said this about four years ago. I do not know. I can certainly find the reference to it, and there was a figure supplied as part of the negotiation. * We are not just inventing these figures; they are as a result of us having studied this over the last five years.

*See supplementary evidence from Mr Bunyan page 39.

Lord Foulkes of Cumnock: My Lord Chairman, I think it is very important, when evidence is being taken by a Committee of Parliament, that sources are quoted and figures are not given, because figures get repeated and repeated and repeated, and people start believing they are accurate without any justification at all.

Chairman: I entirely take your point and I think that if you can track down the answer to that question it would be very helpful if you could let us know in writing later.

Lord Marlesford: Going back to Mr Bunyan's first question, I think, you mentioned that out of 64 million—how many was it—

  Q137  Lord Harrison: Twelve hundred.

  Mr Bunyan: This was the Acting Director of the Visit Programme, and he said that 63 million passengers were processed and entry denied to (and I am quoting here) "1200 criminals and immigration violators".

  Q138  Lord Marlesford: You were saying that was a rather small number.

  Mr Bunyan: This is an opinion, obviously. I was giving you the facts and then offering an opinion that this seemed quite a small number, especially as it is not broken down, especially when we are talking about trying to deter terrorists from this.

  Q139  Lord Marlesford: Can you just remind us how many non-American citizens were involved in the 9/11 hijacking?

  Mr Bunyan: I do not know that figure.

Lord Marlesford: I think it was 19.

  Chairman: We must move on. Have either of you any last point you want to make on this subject? In which case, thank you very much indeed. I should have thanked you earlier, Professor Guild, for your written evidence. Also, just to let you both know, we do have a copy of the Commission's staff working paper on the joint review. That is also a useful part of our written evidence. Thank you both very much.

21 MARCH 2007



 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007