Examination of Witnesses (Questions 200-215)
22 MARCH 2007
MR JOAQUIN
BAYO DELGADO
AND MR
HIELKE HIJMANS
Q200 Baroness D'Souza: Would you
not agree though in that context, it is argued by many, that the
more data stats you have got the less the likelihood is that you
will have false identities?
Mr Hijmans: Why?
Baroness D'Souza: I agree with you, but
it is said because of the matching.
Q201 Lord Foulkes of Cumnock: Can
I follow up on this because Lady D'Souza and I had a discussion
about this on the way over. Surely the more information you get
the more accurate your identification is. Supposing, for example,
which happened to me with my car licence, my name was spelled
wrongly with an "a" instead of an "o". All
the other information coming together would say, "Hey, wait
a minute, this chap is the fellow who lives at this address, that
is his date of birth, therefore it is George Foulkes", even
though it is spelled wrongly, so that makes it much more accurate,
that seems to be obvious. Can I give you another example. If you
are trying to find a location then you get directions and different
ones, so you get two directions and they cross, you get three
and they cross, you get four and they cross, 15 cross and then
there is one which does not, that is the one that is wrong because
all the others are pointing in the right direction, so you get
a much more accurate identification of the exact person.
Mr Bayo Delgado: It is true that the more data
you have, the more accurate identification you have, that is obvious
because of what you said, but that is not the issue at stake in
this case. You have to take into account that the amount of data
which are gathered is not precisely to identify only. The gathering
of these data has many other purposes for security reasons. Therefore,
if you have excessive data you are going beyond what is necessary
for the true purpose of the gathering of data, which is not only
identification but you may profile people in a discriminatory
way, you could have possible inaccuracies, et cetera. From the
identification perspective you are right, but I do not think these
are identification issues. The main one is what do you do with
all the data which have been gathered, and then with those data
the authorities try to guess other types of implications, not
so much identity but intentions, terrorist intentions, et cetera.
Mr Hijmans: It is good to understand that the
gathering of PNR data by the United States is not so much for
the identification of the person because they would not need these
data because everyone has their passport data, which is called
API data, as you know, so it is more to combine all kinds of information.
Q202 Chairman: To cross-check.
Mr Hijmans: Yes, and then of course if you cross-check
it is useful to have more data because cross-checking is easier
but, also, the risk from the other side to abuse the data, to
secure it, it has all kinds of risks, mainly because if you combine
all kinds of data about people you get to know things about people
which go far beyond the purpose.
Q203 Baroness D'Souza: Is there a
greater risk of error?
Mr Bayo Delgado: I think so and also you have
to bear in mind that this gathering of data is done in a way which
is not transparent as to the use of that data, therefore I think
errors are more likely to happen.
Q204 Chairman: The rather shocking
case of the Canadian, Maher Arar, who was taken to Syria and spent
a year there, what went wrong in that case? Do we know? Why was
he misidentified?
Mr Hijmans: I do not know.
Q205 Chairman: Is it known?
Mr Hijmans: It is not known in any case.
Q206Lord Foulkes of Cumnock: On the data retention
periods, we have been exploring the three and a half years and
we found out that was the result of negotiations. The Americans
have a period of 40 years. Why does there need to be a fixed period,
or would 70 years not work? Why would it create any problems for
you?
Mr Bayo Delgado: Again, this is a question of
focusing on the purpose of that data. In fact, in our mind the
three and a half years are already excessive, but it came to be
like this because the period was first agreed and when you are
negotiating, of course, you come to a term which is something
in between. Again, here, the aspect of data retention has a lot
to do with what we were saying before, there are problems with
such a long period, if we are talking about 40 years or even more,
as you mentioned. Why? Because, for example, the security of the
data, to keep the data in a secure way, poses a tremendous problem
if it is not decided to keep the data for a short period rather
than a long period. Secondly, the more data you have which belongs
to the past, old data, the accuracy of the data, which is one
of the principles of data protection has to be warranted and it
is difficult to warranty the accuracy of data which goes back
years.
Mr Hijmans: If you think about yourself, if
it is about your flying behaviour on a flight 20 years ago, would
you remember what happened 20 years ago? Would you remember exactly
what happened on that date, at that moment?
Q207 Lord Foulkes of Cumnock: That
does not matter. I can understand, you are data protection officers
and you are looking at it absolutely rightly and professionally,
but can I ask you to put yourself in the position of a counter-terrorist
officer. You know we have experience in Britain, particularly,
of Muslims who are sleepers, who are there not doing anything
for many years, maybe ten or even longer. Their pattern of movement
around the world, between Pakistan and Britain, back to Pakistan,
to Afghanistan, to Iraq or wherever, could be absolutely vital
in identifying terrorists but we may need to keep it for more
than three and a half years. Is that not vitally important? As
citizens, as opposed to data protection supervisors, do you not
think that is an important thing which needs to be done?
Mr Bayo Delgado: It is important to take all
proportionate measures to make things more secure and have parameters,
but I have doubts that this way of thinking of saying, "Let's
keep data for as long as we can, endlessly with no limit",
really gives you the results which you were suggesting. I am not
so sure that this is the case for the reasons we have already
mentioned. There is enormous disproportion between the effectiveness
of that long period of retention and the results of that retention,
it is absolutely disproportionate.
Mr Hijmans: The amount of data you need, the
amount of data you have to gather and the amount of data you have
to secure for a "maybe", and of course it is true there
is always the possibility that once you find someone who travelled
15 years before between Pakistan and Afghanistan, several times
up and down, there is always the possibility you will find someone.
On the other hand, the amount of data you will need to check all
movements of all people around the world and the risks with that
for not only data protection officers but also for citizens are
large.
Mr Bayo Delgado: You will always have the problem
of N number of years and N-plus one will always be the one which
is missing, so we have to put a limit on it.
Q208 Earl of Listowel: What are the
main differences in the Data Protection Framework between the
US and the European Union? What role have these differences played
in previous negotiations, and how are they likely to influence
the current ones?
Mr Bayo Delgado: The first thing we should point
out is that data protection in the European Union is seen as a
fundamental right and it has horizontal legislation on it, not
only covering the private sector but also the public sector, so
it is common legislation with general principles. The concept
in the United States is quite different because legislation is
only in a specific sector for a specific data processing aspect,
so there is no such general overview of these principles. Another
important thing that I want to underline as a difference is that
one of the basic elements of the conception of data protection
in the European context is specifically the existence of an independent
supervisory authority. I think this is crucial and is one of the
key elements of how we understand these fundamental rights, which
is not the case in the United States. This conception is not like
this which is also a difference when comparing the US and Canada.
In Canada you have such an independent authority, so that is very
important to underline in this respect.
Q209 Chairman: Surely the principle
of freedom of information is almost more important in the United
States than in Europe, is it not?
Mr Bayo Delgado: We also have this idea of freedom
of information. Indeed, the perspective EDPS takes on this is
an approach which combines the two possibilities.
Q210 Chairman: The availability of
intelligence information, for instance, in the United States under
the Freedom of Information Act goes far wider than anything in
Europe, does it not?
Mr Bayo Delgado: Yes. It is true that the conception
is also different in this respect and this is the perspective
also that is taken in this area of what we call "the right
of access" of the individual concerned. The right of access
is seen from the perspective of freedom of information in American
law. Also, if I were to resume in a word what the more crucial
aspect is, it is the need for proportionality. In the European
conception many of the principles relate to the idea of proportionality
and we have already referred to this idea, the data retention
periods, the amount of data which has to be gathered, they have
to be proportional and non-excessive to the purpose they are collected
for. This is something which is crucial and, therefore, when we
have dialogue with our American partners we have common grounds
of legal understanding, but when it comes to data protection,
these are substantial differences in the way we see things and
this is a fact, which it has been and will remain.
Mr Hijmans: With this PNR Agreement, the most
important thing is the fact that that under European Community
law, or at least under the law of the Member States, it is an
essential part of data protection that you also have protection
against the national government, the national law enforcement
agencies, who want to know information about you. Of course, there
is no protection that they cannot enter a database but there are
certain safeguards. In the US, privacy rights, data protection
rights, do not apply in general terms vis-a[acute]-vis intelligence
and police.
Mr Bayo Delgado: Here again we come to proportionality,
there is not this idea of being proportional.
Q211 Chairman: The difficulty of
proportionality is when you come to define the proportions.
Mr Bayo Delgado: Exactly. That is always the
case. These concepts which are very difficult to define are always
problematic, but that does not mean they do not exist and they
have to be applied.
Q212 Lord Marlesford: In September
2005 when you carried out a joint review in monitoring the 2004
Agreement did you feel that you got sufficient information to
be able to do it properly or were you limited by security considerations
as to what you could see? If so, did this matter in terms of the
effectiveness of your review?
Mr Bayo Delgado: The first thing I should clarify
is that this joint review was conducted by a team in which data
protection authorities were involved. The EDPS did not take part
among those authorities. The competence of the authorities who
were involved was to supervise the data protection rules in the
Member States, so they took part in this review and we have the
information which has been published and explained by these authorities.
It seems that they were reasonably satisfied with the facts they
got, although if you analyse the report then you could find some
aspects which could be there. I want to emphasise two things on
this: first of all, this review is fundamental, the fact that
a mechanism of revision has to take place periodically is fundamental
because it is the way to make sure that things are going the way
they should go. Secondly, there has only been one review at this
point and the second one has not yet been scheduled, so that is
something to worry about. In any case, in a future agreement this
mechanism should be present even with problems if they should
exist, but the mechanism has to be there, it is crucial.
Q213 Lord Teverson: We have been
told on occasions that travellers who are not US citizens are
not covered by the US data protection laws but can apply under
the freedom of information laws if they want to know how their
data is being used. First of all, I would be interested to know
whether you agree that is how you see it but, also, is that an
effective means of redress, and are there ways of challenging
the misuse of data by US authorities? This is talking about us
as individual citizens who want to have an issue about that data
with the United States?
Mr Bayo Delgado: In fact, you are right. I am
not an expert in American law and I am not supposed to be, but
I think it is the citizens and residents who can apply the freedom
of information law to get this information. I do not think this
is enough for the citizens, the key issue is not enough, because
we are talking about getting the information but when you get
the information about your data being processed imagine that there
is something to be rectified, so the problem does not end with
the possibility of accessing the information, it goes beyond the
access of information and this is what causes problems. It is
true that in the Undertakings there is mention of the possibility
of rectifying data which are not accurate but for an EU-citizen
who goes to the US it is difficult to imagine how he will go through
all this somewhat cumbersome system to get the information on
his data. Then if he thinks those data are not accurate and he
wants them to be deleted, for example, it is doubtful that he
will be able to do so.
Q214 Baroness D'Souza: There are
agencies that can do that but it is a question of how long it
would take.
Mr Hijmans: Also, the European agencies could
play a role in it as well. As a European citizen you could go
to your national data protection authority and they would help
you. In fact, you can also go to the CBP, the border authorities
of the US, and you can ask for rectification but it is mainly
what is foreseen, which is not the best system. You would go to
the administrative authority but there is no judicial review on
it, what we would always have in our countries is a judicial review
of the Decision.
Mr Bayo Delgado: An important aspect to add,
with our parameters is that the limitations, the exceptions to
this right of access and this right of rectification, we think
they have to clarify in which cases these can be the exception
to the general principle of giving this information. In the present
situation it is very vague as to which cases it can be denied.
If you combine this possible denial with this lack of judicial
recourse, then for the citizen it is difficult to act in a reasonable
way to have his right.
Q215 Chairman: I think we ought to
move on to our next inquiry but, on behalf of Lady D'Souza, can
I ask one quick factual question? Do you know how many complaints
have been referred by the European information commissioners?
Mr Bayo Delgado: We do not have figures but
my guess is very few. It is no wonder why it has been like this
for the reasons I have mentioned, and because of the situation
of a citizen who wants to go to the US, you can imagine that these
figures are, I would not dare say how many, in any case few.
Chairman: Thank you very much indeed
for that.
|