Select Committee on European Union Minutes of Evidence


Memorandum by Baroness Ashton, Parliamentary Under-Secretary of State, Department for Constitutional Affairs

CO -OPERATION BETWEEN THE NATIONAL SUPERVISORY AUTHORITIES AND THE EUROPEAN DATA PROTECTION SUPERVISOR (EDPS)

  1.  Provisions for co-operation between the national supervisory authorities and the EDPS are found in Article 53B of the Decision.[1] The national supervisory authorities and the EDPS will provide co-ordinated supervision of SIS II and co-operate actively in the framework of their responsibilities via the methods below (as required):

    —  exchanging relevant information;

    —  assisting each other in carrying out audits and inspections;

    —  examining difficulties of interpretation or application of the Decision;

    —  studying problems with the exercise of independent supervision or in the exercise of the rights of the data subject;

    —  drawing up harmonised proposals for joint solutions to any problems; and

    —  promoting awareness of data protection rights.

  2.  The national supervisory authorities of the Member States will have responsibility for supervising the SIS II data protection regime at Member State level: this will be the Information Commissioner in the UK. The EDPS will monitor the personal data processing activities of the Management Authority in line with Articles 46 and 47 of Regulation 45/2001.[2]

  3.  The Decision sets out that national supervisory authorities and the EDPS will meet twice a year, with the costs and servicing of meetings met by the EDPS. Further working methods will be developed jointly according to need. A joint report of activities is to be prepared every two years and sent to the European Parliament, the Council and the Management Authority.

  4.  The national supervisory authorities of the Member States currently participating in the first generation SIS co-operate through the Joint Supervisory Authority arrangements. The ICO and the EDPS have links with other national supervisory authorities, for example, through the Data Protection Directive Working Party. This body has a number of tasks similar to those in SIS II such as the development of European standards and common interpretations, and promoting awareness of data protection measures.

  5.  The DCA and the Home Office are content with the provisions for co-operation between the national supervisory authorities and the EDPS with regard to SIS II.

MONITORING ACCESS, AUTHORISED PERSONNEL AND TRAINING

  6.  Member States must put stringent measures in place to ensure high levels of security and confidentiality. The requirements for monitoring access in Article 10 of the Decision[3] include facility access controls, user controls, and data access controls. For example, it must be possible to subsequently verify users accessing a system and the data processing they have carried out.

  7.  Article 10 requires Member States to adopt security measures related to authorised personnel to (amongst other things):

    —  deny unauthorised persons access to data-processing facilities;

    —  prevent the use of automated data processing systems by unauthorised persons;

    —  ensure that persons authorised to use an automated data processing system only have access to the data covered by their access authorisation and with individual and unique user identities and confidential passwords only; and

    —  ensure that it is subsequently possible to verify and establish which personal data have been input into automated data processing systems; when; by whom; and for what purpose.

  8.  Article 10A[4] requires Member States to apply rules of professional secrecy or other equivalent obligations of confidentiality to all personnel required to work with SIS II data. These rules continue to apply after those staff transfer to a different area of work or change employer.

  9.  Every access to and all exchanges of data must be recorded in keeping with the requirements in Article 11[5] in order that the lawfulness of processing can be checked and security measures monitored. The records must show the data used to perform a search, the reference to the data transmitted, and the name of the competent authority and the person responsible for processing the data.

  10.  Member States must ensure that each authority adopts suitable measures to monitor their own compliance with the Decision (Article 11A[6]) and co-operates with the national supervisory authority.

  11.  Personnel must be given appropriate training on data security and data protection rules, and be informed of relevant criminal offences and penalties, before being authorised to process SIS II data (Article 11B[7]).

  12.  The measures in Article 10 are based on the data security measures in the Europol Convention. The Home Office has consulted DCA, SOCA and the Home Office SIS II Programme Team and no concerns have been expressed about the adequacy of these measures. A representative from the Joint Supervisory Authority (JSA), with responsibility for supervising data protection in SIS I+, attended the Schengen Acquis working group on 10 April 2006 and confirmed that the JSA, European Parliament and other interested parties were content with the data protection and security arrangements.

  13.  In addition to self monitoring and supervision by the national supervisory authority, Member States are evaluated before they may access SIS data as part of the Schengen evaluation process. A Schengen evaluation team conducts a data protection evaluation and checks that the necessary safeguards are in place in relation to access controls, authorised personnel and training.

  14.  Law enforcement access to SIS II data in the UK will be provided via a seamless link to the existing Police National Computer (PNC). All transactions on the PNC are logged and fully auditable thus ensuring that any search or update carried out on PNC/SIS II in the UK can be traced back to the originating member of staff. As noted above with regard to SIS II, the purpose for the transaction is also logged on the PNC.

  15.  The UK Sirene Bureau, located within SOCA, is the nominated agency responsible for SIS II management and security measures. SOCA will cooperate with the representatives of the operational users of SIS II (Joint Operational Authority, Sirene UK) to ensure that data protection and auditing responsibilities are agreed and published. The UK Sirene Bureau must also comply with applicable requirements in the UK Data Protection Act. The Information Commissioner's advice was sought at an early stage in the development of the UK Sirene Bureau. The Information Commissioner has the right to investigate the use of SIS II data by law enforcement agencies within the UK. In addition, the UK Sirene Bureau and the agencies using the system are subject to a peer review on a regular basis.

EUROPOL AND EUROJUST

  16.  Article 37A of the Decision provides Europol with the right to access and search data entered into SIS II. Using the information obtained from a search is subject to the consent of the Member State concerned. The handling of such information is governed by the Europol Convention, should the relevant Member State consent to the use of the data obtained.

  17.  Additionally, Europol must:

    —  record every search in accordance with the record-keeping requirements set out in Article 11;

    —  not transfer, copy or download parts of SIS II;

    —  limit access to specifically authorised personnel;

    —  adopt measures for security and confidentiality noted in Article 10;

    —  allow the Joint Supervisory Body (set up by the Europol Convention) to review access to and searches of SIS II data; and

    —  only communicate such information to third states and third bodies with the consent of the Member State concerned.

  18.  Article 37B provides equivalent rights for Eurojust. The Council Decision establishing Eurojust includes provisions relating to data protection and unauthorised processing, and the powers of the Joint Supervisory Authority; these are not affected by the SIS II Decision.

  19.  Eurojust must comply with the same requirements set out in paragraph 17.

  20.  The rules regarding the use of SIS II data by Europol and Eurojust are detailed, specific and proportionate and both the Home Office and DCA are content that they will safeguard the security of shared data. No concerns about these rules have been raised by other Member States.

SIS II AND THE DATA PROTECTION FRAMEWORK DECISION (DPFD)

  21.  The DPFD will provide common standards of data protection in the third pillar (police and judicial co-operation) and will provide an overarching data protection framework for existing and future EU instruments concerning the exchange of personal data.

  22.  Articles 48A and 49 of the SIS II Decision require that personal data is protected in accordance with Convention 108 of the Council of Europe 1981 for the protection of individuals with regard to automatic processing of personal data.[8] When the DPFD is implemented references to Convention 108 in third pillar instruments, including SIS II, will be taken to refer to the DPFD (DPFD Article 34(2), Document 11547/3/06 REV 3).

  23.  The data protection principles in Convention 108 (and subsequently in the DPFD) are supplemented or clarified in the SIS II Decision where necessary.

  24.  Other existing protections that will apply to SIS II include:

    —  Council of Europe Recommendation No R(87)15 1987 (regulating the use of personal data in the police sector).

    —  Regulation (EC) No 45/2001 (processing of personal data by the Community institutions).

    —  Europol Convention 1995 (provisions concerning data protection apply to processing by Europol).

    —  Council Decision 2002/187/JHA 2002 (provisions concerning data protection apply to processing by Eurojust).[9]

  25.  Title VI of the Schengen Convention 1990 contains provisions regarding the protection of personal data communicated outside the Schengen Information System. Those provisions will not be amended by the SIS II Decision, but will be replaced by the DPFD with regard to matters falling within the scope of Title VI of the TEU.

4 October 2006.



1   There are equivalent provisions in Article 31B of the SIS II Regulation. The UK has opted out of participating in the immigration and border control measures covered by the Regulation, but is a full participant in the police and judicial co-operation measures covered by the Council Decision Back

2   Regulation (EC) No 45/2001 on the protection of individuals with regard to the processing of personal data by the Community, institutions and bodies and on the free movement of such data. Back

3   Article 10 of the Regulation. Back

4   Article 10A of the Regulation. Back

5   Article 11 of the Regulation Back

6   Article 11A of the Regulation. Back

7   Article 11B of the Regulation. Back

8   The SIS II Regulation requires that personal data must be processed in accordance with the first pillar Data Protection Directive (95/46/EC). Back

9   The DPFD will not apply to the processing and protection of personal data under the instruments relating to Europol and Eurojust. Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007