Examination of Witnesses (Questions 120-139)
Professor Elspeth Guild and Mr Tony Bunyan
21 MARCH 2007
Q120 Chairman: We will be seeing
Mr Hustinx's deputy in Brussels tomorrow, so we will be able to
pursue that with him.
Mr Bunyan: So our Government is claiming they
can check this against a main database. The National Audit Office
report in January said that using that passport picture digitised
on a chip would not be accurate on any database holding more than
10,000 items. Excuse me, they have got more than 10,000 already,
so there is a problem over which technology we are talking aboutthe
picture or the fingerprints. All I am saying is there is a risk
and one must not think of those as being absolutely accurate systems.
Q121 Chairman: Professor Guild, do
you want to add to that?
Professor Guild: I am not particularly familiar
with the E Border Programme so I would not address that particular
question.
Q122 Baroness Henig: The current
US data retention period is 40 years. Would a period considerably
longer than 3.5 years cause any problems?
Mr Bunyan: I think the US Visit Programme, I
may be incorrect, is longer than 40 years, but we can look into
that.
Q123 Baroness Henig: At least 40
years.
Mr Bunyan: The 3.5 years one is quite interesting,
because why 3.5 years? The Data Protection Working Party, again,
in the European Union has looked at this issue, so this period
of 3.5 years is only 3.5 years because that is the length of the
EU/US agreement; it has no other basis to it whatsoever, other
than it is going to run out next July. People are not aware that
there actually is an EU PNR scheme being constructed. We have
our own scheme, which is concerned with the entry of people into
the European Union. That is not just visa people; if we go out
of the European Union we are going to be checked. That set of
data may be held, but the limit on that data (this is an EU Directive
in April 2004) is that it may be held for 24 hours, unless there
is a specific reason why it can be held for longer. In other words,
you cannot hold this mass of information for longer than 24 hours
unless you have a reason for holding it for longer than 24 hours.
I would go on that advice, at the end of the day, because I do
have great respect for Peter Hustinx and for the Article 29 Working
Party, if you look back at the history of their reporting. They
do look at each measure individually, which may have different
purposes: some may be entry systems, some may be what has been
discussed as a European Union entry and exit system, which is
obviously a more complicated system. So I do not think we should
see 3.5 years as being set in stone; I think we have got to look
at the new proposal when it comes up, which has to be reached
by July next year, see what extra information the United States
wants to have and make a decision about how to set some limits.
Where they may need to hold it for longer, what are the limits
on that? I would leave that question open until we see the new
draft agreement, presumably some time later this year.
Q124 Baroness Bonham-Carter of Yarnbury:
Can I ask a supplementary to that? You are saying you would agree
that 3.5 years is too short a period?
Mr Bunyan: I do not know. I would start out
with the EU Directive of 2004, which is the only one we have got,
which says it may only be held for 24 hours.
Q125 Baroness Bonham-Carter of Yarnbury:
Is that sensible? What can you do with information that you are
only holding for 24 hours?
Mr Bunyan: As Elspeth says, it is being collected
for commercial purposes, is made available for other purposes,
and the first purpose is to check should that person be allowed
to travel. The second purpose is, if that person does travel,
are they a threat to whichever country they are travelling to?
So the purpose of collecting this data is, firstly, to book a
ticket, and the second purpose is to judge whether that person
is a threat on that `plane or is going to be a threat in the country
they arrive into. Now, if you want to have a third purpose at
some point in the future you have got to show good reason to do
it, which is what the Article 29 Committee is saying, because
you have collected for one purpose, you are already using it for
one other purpose, which is to guarantee airline security, which
I totally agree with, which is to stop terrorists entering your
country, which I totally agree with, but if you want to start
using it for other purposes then you have to show good reason,
and we have got to see a proposal in writing. That is what they
are saying. So the 3.5 years is a bit artificial because it just
happens to be the length of time of the present EU/US agreement.
There is no particular reason why it is 3.5 years; it could have
been ten years, it could have been two years; it was just set
to fit the length of time of the agreement.
Q126 Baroness Bonham-Carter of Yarnbury:
The Minister has told us that Member States may refuse to supply
PNR data if they are not confident that departments with which
the Department for Homeland Security shares PNR data provide adequate
protection. This is a question for Mr Bunyan because we know what
Professor Guild feels. Surely the power could never be exercised
if all Member States had to agree?
Mr Bunyan: Quite clearly, you have got to have
an EU-wide agreement. There are a number of other areaslike
disagreeing with the US over its open skies policy, or whateverwhere
what we see is the US trying to negotiate bilaterally, particularly
with the newer Member States of the European Union, and trying
to undermine the EU having a position on it. We have to have a
process here where the EU has to agree with the United States
that it has got to have proper data protection, we need to know
who is getting access to that information and we need to have
a proper review process. Only in that way can we start to build
up our rights in terms of why is our data being collected, what
is it being used for and who is it being passed on to? It would
not be a good idea for Member States to individually have agreements.
Professor Guild: I would say it is clearly illusory
to suggest that power could be exercised by one Member State.
Therefore, even to include such an option is to create an illusion
of possibility of an exercise of a power. If we have concerns
and if we genuinely think that information should be refused,
it must be done on a common basis; it has to be done on the basis
of solidarity. I would only add one other point on the question
of retention periods, which I think is important. I agree entirely
with Tony's position: data must be collected for a purpose, the
purpose must be clearly stated and the period of retention must
be proportionate to the purpose which is intended. That is the
first step. The second step is that the retention period of any
particular set of data may be shorter or longer, depending on
who is going to have access to that data. So, for instance, banking
data is collected and retained for very long periods of time but
there are extremely strict rules on access to that data. Therefore,
who gets to look at the data affects also the legitimacy of the
length of time for which it can be retained. However, the first
question is the purposewhat purpose is this forsecondly,
what data is collected, and, thirdly, who gets access to it?
Q127 Lord Teverson: It seems to me
that one of the areas around this is that everybody wants to prevent
terrorism and organised crime, or whatever, but for an operation
to be successful and to keep public confidence there has to be
confidence in the review process. There was quite a bit of controversy
about the review that took place in 2005, and on conversations
which have taken place on the American side I think we would say
there is probably some indignance that they feel hard-done-by
by the criticism that was levelled at them in the process of that
review. Could you tell us whether you think the review process
is adequate at the moment, or how that should be changed?
Mr Bunyan: The point is that if the EU has an
agreement with the United States I make the presumption that that
is an agreement between equal partners. If you have a detailed
agreement, many pages long, which was examined in the Parliament
by the Council and subject to criticism but, in the end, there
was agreement, and now there is a new agreement, if we are entering
this as equal partners you cannot have one partner (and the team
which went from the EU was a high-level team of officials) in
a situation where they say that there were a number of records
where access was limited and they were not given hard copies of
certain procedural advice. You cannot have that situation. To
add insult to injury, the EU team was actually, and I quote, "required
to sign confidentiality agreements exposing them to criminal sanctions
for any breach". This is not the way you work when you have
two equal partners. So I think the EU needs to put its foot down
and say: "If we are equal partners you can have access to
our data but we must have access to your data. Here are our officials,
let us have the names of your officials, and let us be full partners,
for goodness sake".
Q128 Lord Foulkes of Cumnock: Who
are you quoting from there?
Mr Bunyan: The quote is from the European Commission
report on this joint review process.
Professor Guild: Of course, we do not know if
there will be ever be another review. At the moment it seems quite
unclear. Without a review we have no idea how we are going to
provide any kind of assurance to anyone on what is being done
with the data. I think there is quite an important difference
of perspective, clearly, from the EU side and from the US side,
in the EU data protection is considered an important job of the
state; it is not the job of the individual to enforce their privacy
rights, it is the duty of the state to protect the data of the
individual. Therefore, we have Data Protection Supervisors who
have these roles which are particularly important. The US perspective
has always been that it is the individual's right to enforce the
right of privacy, the private sector against the state, so of
course you are going to have a different way of looking at what
a joint supervisory body should be doing and what the role of
a European data protection authority should be.
Q129 Lord Teverson: Could I ask five
simple points? What do you think should be the basis of a review
clause in a new agreement? What are the headline things that need
to be in that?
Professor Guild: Clearly, there must be a full
review of the correct application of the agreement; any issues
in respect of differences in interpretation on the meaning of
the agreement and the application of the agreement need to be
specified in the report which both sides put forward; the report
needs to be made public with, of course, if necessary, sensitive
data removed or controlled, (we have many computer systems for
doing that); it needs to be published, it needs to be timely and
it needs to provide an opportunity for additional opinions by
those who have been responsible for carrying out the review.
Q130 Lord Harrison: Let us pass on
to another possible disequilibrium. Dr Gus Hosein has told us
that travellers who are not US citizens are not covered by the
US data protection laws but can apply under the freedom of information
laws in the US if they want to know how their data have been used.
In your view, is that an adequate and effective means of redress?
Are there other ways of challenging misuse of data by the US authorities?
If there are, what are your positive suggestions about strengthening?
Mr Bunyan: I know Gus Hosein and, indeed, I
have worked with him and others actually in putting a freedom
of information question in the United States on other issues.
I do think it is a little difficult because certainly we needed
a bit of help about which department to send the questions to,
etc. One of the biggest problems we have here is the United States
has never been prepared to tell the European Union exactly which
agencies get access to this data. In other words, they are unable
to tell us, although there are lots of agencies at federal, state
and local level. A figure was mentioned in relation to the first
agreement that something like 1,500 agencies might get access.
Last October, in the middle of the re-negotiation, it was a bit
worrying (this is the point I am making about how many agencies)
because the US law was changed and it turns out if the agreement
is there and the US changes its law then so does the content of
this agreement, apparently. According to the executive order enacted
on, number 11388, the Department for Homeland Security was told,
basically, to extend the number of agencies and: "the US
may not be impeded by a certain provision in the undertaking in
the EU/US agreement to restrict information sharing amongst US
agencies. The undertaking should be interpreted and applied so
as not to impede the sharing of PNR data by the DHS and other
authorities". So there is a problem here: who are you giving
the information to? We would have a competent authority in each
EU Member State you could go to which would then be responsible
for finding out where that data had been passed to and had been
further processed. The problem for us is we do not know how many
agencies have access to it.
Q131 Lord Harrison: At the moment,
what does Joe Bloggs do?
Mr Bunyan: There is a provision within the agreement
to make a complaint. The problem is, what are the powers of the
body you are complaining to? Are they able to find out what has
happened to the data?
Q132 Lord Harrison: There is no posting
box, as it were, to lodge the first complaint.
Mr Bunyan: There is in the information which
is circulated; there is an address in the United States to which
you can complain, but it is one that has been set up as an administrative
measure not as part of US law, if I can put it like that. The
US law is the 1974 Privacy Act which protects the data protection
rights of all US citizens. However, that Act does not extend to
non-US citizens. We have to remember this issue is not just cropping
up on the Passenger Name Record, it is cropping up over the whole
Swift scandalthe access to banking data. I have seen the
minutes of some of the EU/US high-level meetings, and I am quite
surprised that so much time has passed and the EU has not finally
put its foot down a little bit and said: "Look, we have got
Swift, we have got PNR and there are other things coming up. You
really must get a law, like Canada has got or other countries
have got, in order that we do not keep having this problem."
Q133 Lord Foulkes of Cumnock: Surely,
my Lord Chairman, the freedom of information laws in the US, as
I understand it, are far more extensive than they are here, are
they not? You can get lots more information; we can get information
even about things that are happening here from the United States.
Mr Bunyan: In the main. It is not necessarily
true when you are talking about the justice department when you
are getting this kind of information. Yes, they do have good freedom
of information laws, but it does take time and you have still
got to know who to write to and you have still got to know how
to frame the question. You may have to write to a number of agencies.
Let us remember the case which came before this Committee before:
there was the famous case, many years ago, of two Welsh football
players (this is under the Schengen system) who were arrested
in Luxembourg, went on to a system, then got arrested again, and
it took them three years to get their names off the record because
they had done nothing wrong. They had to get the European Commission
to track down that Belgium was holding information, and the United
Kingdom which passed it to various embassies around Europe.
Q134 Lord Foulkes of Cumnock: That
is nothing to do with the United States.
Mr Bunyan: The point I am making is that once
data is being held on you and can be passed to innumerable agencies
how do you find out what data those innumerable agencies have
got? If it is wrong, how do you get it corrected? I use the EU
example because it is one of the rare examples we have got of
how difficult it is for an individual, once they get on to a list
or get wrongly on to a list, to get off the list. I do think that
bears example. At least here we know there is a Schengen authority,
at least we have got national contacts and can do something, but
in the United States where do you begin?
Q135 Lord Foulkes of Cumnock: You
mentioned 1,500 agencies. Where does that figure come from?
Mr Bunyan: From the United States themselves.
Q136 Lord Foulkes of Cumnock: But
whom in the United States? You just read out a quotation
Mr Bunyan: You are asking me to remember exactly
which official from the United States said this about four years
ago. I do not know. I can certainly find the reference
to it, and there was a figure supplied as part of the negotiation.
* We are not just inventing these figures; they are as a result
of us having studied this over the last five years.
*See supplementary evidence from Mr Bunyan page 39.
Lord Foulkes of Cumnock: My Lord Chairman, I think
it is very important, when evidence is being taken by a Committee
of Parliament, that sources are quoted and figures are not given,
because figures get repeated and repeated and repeated, and people
start believing they are accurate without any justification at
all.
Chairman: I entirely
take your point and I think that if you can track down the answer
to that question it would be very helpful if you could let us
know in writing later.
Lord Marlesford:
Going back to Mr Bunyan's first question, I think, you mentioned
that out of 64 millionhow many was it
Q137 Lord Harrison: Twelve hundred.
Mr Bunyan: This was the Acting Director of the
Visit Programme, and he said that 63 million passengers were processed
and entry denied to (and I am quoting here) "1200 criminals
and immigration violators".
Q138 Lord Marlesford: You were saying
that was a rather small number.
Mr Bunyan: This is an opinion, obviously. I
was giving you the facts and then offering an opinion that this
seemed quite a small number, especially as it is not broken down,
especially when we are talking about trying to deter terrorists
from this.
Q139 Lord Marlesford: Can you just
remind us how many non-American citizens were involved in the
9/11 hijacking?
Mr Bunyan: I do not know that figure.
Lord Marlesford: I think it was 19.
Chairman: We must move on. Have either
of you any last point you want to make on this subject? In which
case, thank you very much indeed. I should have thanked you earlier,
Professor Guild, for your written evidence. Also, just to let
you both know, we do have a copy of the Commission's staff working
paper on the joint review. That is also a useful part of our written
evidence. Thank you both very much.
21 MARCH 2007
|