Select Committee on European Union Minutes of Evidence


Examination of Witnesses (Questions 200-215)

22 MARCH 2007

MR JOAQUIN BAYO DELGADO AND MR HIELKE HIJMANS

  Q200  Baroness D'Souza: Would you not agree though in that context, it is argued by many, that the more data stats you have got the less the likelihood is that you will have false identities?

  Mr Hijmans: Why?

  Baroness D'Souza: I agree with you, but it is said because of the matching.

  Q201  Lord Foulkes of Cumnock: Can I follow up on this because Lady D'Souza and I had a discussion about this on the way over. Surely the more information you get the more accurate your identification is. Supposing, for example, which happened to me with my car licence, my name was spelled wrongly with an "a" instead of an "o". All the other information coming together would say, "Hey, wait a minute, this chap is the fellow who lives at this address, that is his date of birth, therefore it is George Foulkes", even though it is spelled wrongly, so that makes it much more accurate, that seems to be obvious. Can I give you another example. If you are trying to find a location then you get directions and different ones, so you get two directions and they cross, you get three and they cross, you get four and they cross, 15 cross and then there is one which does not, that is the one that is wrong because all the others are pointing in the right direction, so you get a much more accurate identification of the exact person.

  Mr Bayo Delgado: It is true that the more data you have, the more accurate identification you have, that is obvious because of what you said, but that is not the issue at stake in this case. You have to take into account that the amount of data which are gathered is not precisely to identify only. The gathering of these data has many other purposes for security reasons. Therefore, if you have excessive data you are going beyond what is necessary for the true purpose of the gathering of data, which is not only identification but you may profile people in a discriminatory way, you could have possible inaccuracies, et cetera. From the identification perspective you are right, but I do not think these are identification issues. The main one is what do you do with all the data which have been gathered, and then with those data the authorities try to guess other types of implications, not so much identity but intentions, terrorist intentions, et cetera.

  Mr Hijmans: It is good to understand that the gathering of PNR data by the United States is not so much for the identification of the person because they would not need these data because everyone has their passport data, which is called API data, as you know, so it is more to combine all kinds of information.

  Q202  Chairman: To cross-check.

  Mr Hijmans: Yes, and then of course if you cross-check it is useful to have more data because cross-checking is easier but, also, the risk from the other side to abuse the data, to secure it, it has all kinds of risks, mainly because if you combine all kinds of data about people you get to know things about people which go far beyond the purpose.

  Q203  Baroness D'Souza: Is there a greater risk of error?

  Mr Bayo Delgado: I think so and also you have to bear in mind that this gathering of data is done in a way which is not transparent as to the use of that data, therefore I think errors are more likely to happen.

  Q204  Chairman: The rather shocking case of the Canadian, Maher Arar, who was taken to Syria and spent a year there, what went wrong in that case? Do we know? Why was he misidentified?

  Mr Hijmans: I do not know.

  Q205  Chairman: Is it known?

  Mr Hijmans: It is not known in any case.

  Q206Lord Foulkes of Cumnock: On the data retention periods, we have been exploring the three and a half years and we found out that was the result of negotiations. The Americans have a period of 40 years. Why does there need to be a fixed period, or would 70 years not work? Why would it create any problems for you?

  Mr Bayo Delgado: Again, this is a question of focusing on the purpose of that data. In fact, in our mind the three and a half years are already excessive, but it came to be like this because the period was first agreed and when you are negotiating, of course, you come to a term which is something in between. Again, here, the aspect of data retention has a lot to do with what we were saying before, there are problems with such a long period, if we are talking about 40 years or even more, as you mentioned. Why? Because, for example, the security of the data, to keep the data in a secure way, poses a tremendous problem if it is not decided to keep the data for a short period rather than a long period. Secondly, the more data you have which belongs to the past, old data, the accuracy of the data, which is one of the principles of data protection has to be warranted and it is difficult to warranty the accuracy of data which goes back years.

  Mr Hijmans: If you think about yourself, if it is about your flying behaviour on a flight 20 years ago, would you remember what happened 20 years ago? Would you remember exactly what happened on that date, at that moment?

  Q207  Lord Foulkes of Cumnock: That does not matter. I can understand, you are data protection officers and you are looking at it absolutely rightly and professionally, but can I ask you to put yourself in the position of a counter-terrorist officer. You know we have experience in Britain, particularly, of Muslims who are sleepers, who are there not doing anything for many years, maybe ten or even longer. Their pattern of movement around the world, between Pakistan and Britain, back to Pakistan, to Afghanistan, to Iraq or wherever, could be absolutely vital in identifying terrorists but we may need to keep it for more than three and a half years. Is that not vitally important? As citizens, as opposed to data protection supervisors, do you not think that is an important thing which needs to be done?

  Mr Bayo Delgado: It is important to take all proportionate measures to make things more secure and have parameters, but I have doubts that this way of thinking of saying, "Let's keep data for as long as we can, endlessly with no limit", really gives you the results which you were suggesting. I am not so sure that this is the case for the reasons we have already mentioned. There is enormous disproportion between the effectiveness of that long period of retention and the results of that retention, it is absolutely disproportionate.

  Mr Hijmans: The amount of data you need, the amount of data you have to gather and the amount of data you have to secure for a "maybe", and of course it is true there is always the possibility that once you find someone who travelled 15 years before between Pakistan and Afghanistan, several times up and down, there is always the possibility you will find someone. On the other hand, the amount of data you will need to check all movements of all people around the world and the risks with that for not only data protection officers but also for citizens are large.

  Mr Bayo Delgado: You will always have the problem of N number of years and N-plus one will always be the one which is missing, so we have to put a limit on it.

  Q208  Earl of Listowel: What are the main differences in the Data Protection Framework between the US and the European Union? What role have these differences played in previous negotiations, and how are they likely to influence the current ones?

  Mr Bayo Delgado: The first thing we should point out is that data protection in the European Union is seen as a fundamental right and it has horizontal legislation on it, not only covering the private sector but also the public sector, so it is common legislation with general principles. The concept in the United States is quite different because legislation is only in a specific sector for a specific data processing aspect, so there is no such general overview of these principles. Another important thing that I want to underline as a difference is that one of the basic elements of the conception of data protection in the European context is specifically the existence of an independent supervisory authority. I think this is crucial and is one of the key elements of how we understand these fundamental rights, which is not the case in the United States. This conception is not like this which is also a difference when comparing the US and Canada. In Canada you have such an independent authority, so that is very important to underline in this respect.

  Q209  Chairman: Surely the principle of freedom of information is almost more important in the United States than in Europe, is it not?

  Mr Bayo Delgado: We also have this idea of freedom of information. Indeed, the perspective EDPS takes on this is an approach which combines the two possibilities.

  Q210  Chairman: The availability of intelligence information, for instance, in the United States under the Freedom of Information Act goes far wider than anything in Europe, does it not?

  Mr Bayo Delgado: Yes. It is true that the conception is also different in this respect and this is the perspective also that is taken in this area of what we call "the right of access" of the individual concerned. The right of access is seen from the perspective of freedom of information in American law. Also, if I were to resume in a word what the more crucial aspect is, it is the need for proportionality. In the European conception many of the principles relate to the idea of proportionality and we have already referred to this idea, the data retention periods, the amount of data which has to be gathered, they have to be proportional and non-excessive to the purpose they are collected for. This is something which is crucial and, therefore, when we have dialogue with our American partners we have common grounds of legal understanding, but when it comes to data protection, these are substantial differences in the way we see things and this is a fact, which it has been and will remain.

  Mr Hijmans: With this PNR Agreement, the most important thing is the fact that that under European Community law, or at least under the law of the Member States, it is an essential part of data protection that you also have protection against the national government, the national law enforcement agencies, who want to know information about you. Of course, there is no protection that they cannot enter a database but there are certain safeguards. In the US, privacy rights, data protection rights, do not apply in general terms vis-a[acute]-vis intelligence and police.

  Mr Bayo Delgado: Here again we come to proportionality, there is not this idea of being proportional.

  Q211  Chairman: The difficulty of proportionality is when you come to define the proportions.

  Mr Bayo Delgado: Exactly. That is always the case. These concepts which are very difficult to define are always problematic, but that does not mean they do not exist and they have to be applied.

  Q212  Lord Marlesford: In September 2005 when you carried out a joint review in monitoring the 2004 Agreement did you feel that you got sufficient information to be able to do it properly or were you limited by security considerations as to what you could see? If so, did this matter in terms of the effectiveness of your review?

  Mr Bayo Delgado: The first thing I should clarify is that this joint review was conducted by a team in which data protection authorities were involved. The EDPS did not take part among those authorities. The competence of the authorities who were involved was to supervise the data protection rules in the Member States, so they took part in this review and we have the information which has been published and explained by these authorities. It seems that they were reasonably satisfied with the facts they got, although if you analyse the report then you could find some aspects which could be there. I want to emphasise two things on this: first of all, this review is fundamental, the fact that a mechanism of revision has to take place periodically is fundamental because it is the way to make sure that things are going the way they should go. Secondly, there has only been one review at this point and the second one has not yet been scheduled, so that is something to worry about. In any case, in a future agreement this mechanism should be present even with problems if they should exist, but the mechanism has to be there, it is crucial.

  Q213  Lord Teverson: We have been told on occasions that travellers who are not US citizens are not covered by the US data protection laws but can apply under the freedom of information laws if they want to know how their data is being used. First of all, I would be interested to know whether you agree that is how you see it but, also, is that an effective means of redress, and are there ways of challenging the misuse of data by US authorities? This is talking about us as individual citizens who want to have an issue about that data with the United States?

  Mr Bayo Delgado: In fact, you are right. I am not an expert in American law and I am not supposed to be, but I think it is the citizens and residents who can apply the freedom of information law to get this information. I do not think this is enough for the citizens, the key issue is not enough, because we are talking about getting the information but when you get the information about your data being processed imagine that there is something to be rectified, so the problem does not end with the possibility of accessing the information, it goes beyond the access of information and this is what causes problems. It is true that in the Undertakings there is mention of the possibility of rectifying data which are not accurate but for an EU-citizen who goes to the US it is difficult to imagine how he will go through all this somewhat cumbersome system to get the information on his data. Then if he thinks those data are not accurate and he wants them to be deleted, for example, it is doubtful that he will be able to do so.

  Q214  Baroness D'Souza: There are agencies that can do that but it is a question of how long it would take.

  Mr Hijmans: Also, the European agencies could play a role in it as well. As a European citizen you could go to your national data protection authority and they would help you. In fact, you can also go to the CBP, the border authorities of the US, and you can ask for rectification but it is mainly what is foreseen, which is not the best system. You would go to the administrative authority but there is no judicial review on it, what we would always have in our countries is a judicial review of the Decision.

  Mr Bayo Delgado: An important aspect to add, with our parameters is that the limitations, the exceptions to this right of access and this right of rectification, we think they have to clarify in which cases these can be the exception to the general principle of giving this information. In the present situation it is very vague as to which cases it can be denied. If you combine this possible denial with this lack of judicial recourse, then for the citizen it is difficult to act in a reasonable way to have his right.

  Q215  Chairman: I think we ought to move on to our next inquiry but, on behalf of Lady D'Souza, can I ask one quick factual question? Do you know how many complaints have been referred by the European information commissioners?

  Mr Bayo Delgado: We do not have figures but my guess is very few. It is no wonder why it has been like this for the reasons I have mentioned, and because of the situation of a citizen who wants to go to the US, you can imagine that these figures are, I would not dare say how many, in any case few.

  Chairman: Thank you very much indeed for that.





 
previous page contents

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007