Memorandum by Baroness Ashton, Parliamentary
Under-Secretary of State, Department for Constitutional Affairs
CO -OPERATION
BETWEEN THE
NATIONAL SUPERVISORY
AUTHORITIES AND
THE EUROPEAN DATA
PROTECTION SUPERVISOR
(EDPS)
1. Provisions for co-operation between the
national supervisory authorities and the EDPS are found in Article
53B of the Decision.[1]
The national supervisory authorities and the EDPS will provide
co-ordinated supervision of SIS II and co-operate actively in
the framework of their responsibilities via the methods below
(as required):
exchanging relevant information;
assisting each other in carrying
out audits and inspections;
examining difficulties of interpretation
or application of the Decision;
studying problems with the exercise
of independent supervision or in the exercise of the rights of
the data subject;
drawing up harmonised proposals for
joint solutions to any problems; and
promoting awareness of data protection
rights.
2. The national supervisory authorities
of the Member States will have responsibility for supervising
the SIS II data protection regime at Member State level: this
will be the Information Commissioner in the UK. The EDPS will
monitor the personal data processing activities of the Management
Authority in line with Articles 46 and 47 of Regulation 45/2001.[2]
3. The Decision sets out that national supervisory
authorities and the EDPS will meet twice a year, with the costs
and servicing of meetings met by the EDPS. Further working methods
will be developed jointly according to need. A joint report of
activities is to be prepared every two years and sent to the European
Parliament, the Council and the Management Authority.
4. The national supervisory authorities
of the Member States currently participating in the first generation
SIS co-operate through the Joint Supervisory Authority arrangements.
The ICO and the EDPS have links with other national supervisory
authorities, for example, through the Data Protection Directive
Working Party. This body has a number of tasks similar to those
in SIS II such as the development of European standards and common
interpretations, and promoting awareness of data protection measures.
5. The DCA and the Home Office are content
with the provisions for co-operation between the national supervisory
authorities and the EDPS with regard to SIS II.
MONITORING ACCESS,
AUTHORISED PERSONNEL
AND TRAINING
6. Member States must put stringent measures
in place to ensure high levels of security and confidentiality.
The requirements for monitoring access in Article 10 of the Decision[3]
include facility access controls, user controls, and data access
controls. For example, it must be possible to subsequently verify
users accessing a system and the data processing they have carried
out.
7. Article 10 requires Member States to
adopt security measures related to authorised personnel to (amongst
other things):
deny unauthorised persons access
to data-processing facilities;
prevent the use of automated data
processing systems by unauthorised persons;
ensure that persons authorised to
use an automated data processing system only have access to the
data covered by their access authorisation and with individual
and unique user identities and confidential passwords only; and
ensure that it is subsequently possible
to verify and establish which personal data have been input into
automated data processing systems; when; by whom; and for what
purpose.
8. Article 10A[4]
requires Member States to apply rules of professional secrecy
or other equivalent obligations of confidentiality to all personnel
required to work with SIS II data. These rules continue to apply
after those staff transfer to a different area of work or change
employer.
9. Every access to and all exchanges of
data must be recorded in keeping with the requirements in Article
11[5]
in order that the lawfulness of processing can be checked and
security measures monitored. The records must show the data used
to perform a search, the reference to the data transmitted, and
the name of the competent authority and the person responsible
for processing the data.
10. Member States must ensure that each
authority adopts suitable measures to monitor their own compliance
with the Decision (Article 11A[6])
and co-operates with the national supervisory authority.
11. Personnel must be given appropriate
training on data security and data protection rules, and be informed
of relevant criminal offences and penalties, before being authorised
to process SIS II data (Article 11B[7]).
12. The measures in Article 10 are based
on the data security measures in the Europol Convention. The Home
Office has consulted DCA, SOCA and the Home Office SIS II Programme
Team and no concerns have been expressed about the adequacy of
these measures. A representative from the Joint Supervisory Authority
(JSA), with responsibility for supervising data protection in
SIS I+, attended the Schengen Acquis working group on 10 April
2006 and confirmed that the JSA, European Parliament and other
interested parties were content with the data protection and security
arrangements.
13. In addition to self monitoring and supervision
by the national supervisory authority, Member States are evaluated
before they may access SIS data as part of the Schengen evaluation
process. A Schengen evaluation team conducts a data protection
evaluation and checks that the necessary safeguards are in place
in relation to access controls, authorised personnel and training.
14. Law enforcement access to SIS II data
in the UK will be provided via a seamless link to the existing
Police National Computer (PNC). All transactions on the PNC are
logged and fully auditable thus ensuring that any search or update
carried out on PNC/SIS II in the UK can be traced back to the
originating member of staff. As noted above with regard to SIS
II, the purpose for the transaction is also logged on the PNC.
15. The UK Sirene Bureau, located within
SOCA, is the nominated agency responsible for SIS II management
and security measures. SOCA will cooperate with the representatives
of the operational users of SIS II (Joint Operational Authority,
Sirene UK) to ensure that data protection and auditing responsibilities
are agreed and published. The UK Sirene Bureau must also comply
with applicable requirements in the UK Data Protection Act. The
Information Commissioner's advice was sought at an early stage
in the development of the UK Sirene Bureau. The Information Commissioner
has the right to investigate the use of SIS II data by law enforcement
agencies within the UK. In addition, the UK Sirene Bureau and
the agencies using the system are subject to a peer review on
a regular basis.
EUROPOL AND
EUROJUST
16. Article 37A of the Decision provides
Europol with the right to access and search data entered into
SIS II. Using the information obtained from a search is subject
to the consent of the Member State concerned. The handling of
such information is governed by the Europol Convention, should
the relevant Member State consent to the use of the data obtained.
17. Additionally, Europol must:
record every search in accordance
with the record-keeping requirements set out in Article 11;
not transfer, copy or download parts
of SIS II;
limit access to specifically authorised
personnel;
adopt measures for security and confidentiality
noted in Article 10;
allow the Joint Supervisory Body
(set up by the Europol Convention) to review access to and searches
of SIS II data; and
only communicate such information
to third states and third bodies with the consent of the Member
State concerned.
18. Article 37B provides equivalent rights
for Eurojust. The Council Decision establishing Eurojust includes
provisions relating to data protection and unauthorised processing,
and the powers of the Joint Supervisory Authority; these are not
affected by the SIS II Decision.
19. Eurojust must comply with the same requirements
set out in paragraph 17.
20. The rules regarding the use of SIS II
data by Europol and Eurojust are detailed, specific and proportionate
and both the Home Office and DCA are content that they will safeguard
the security of shared data. No concerns about these rules have
been raised by other Member States.
SIS II AND THE
DATA PROTECTION
FRAMEWORK DECISION
(DPFD)
21. The DPFD will provide common standards
of data protection in the third pillar (police and judicial co-operation)
and will provide an overarching data protection framework for
existing and future EU instruments concerning the exchange of
personal data.
22. Articles 48A and 49 of the SIS II Decision
require that personal data is protected in accordance with Convention
108 of the Council of Europe 1981 for the protection of individuals
with regard to automatic processing of personal data.[8]
When the DPFD is implemented references to Convention 108 in third
pillar instruments, including SIS II, will be taken to refer to
the DPFD (DPFD Article 34(2), Document 11547/3/06 REV 3).
23. The data protection principles in Convention
108 (and subsequently in the DPFD) are supplemented or clarified
in the SIS II Decision where necessary.
24. Other existing protections that will
apply to SIS II include:
Council of Europe Recommendation
No R(87)15 1987 (regulating the use of personal data in the police
sector).
Regulation (EC) No 45/2001 (processing
of personal data by the Community institutions).
Europol Convention 1995 (provisions
concerning data protection apply to processing by Europol).
Council Decision 2002/187/JHA 2002
(provisions concerning data protection apply to processing by
Eurojust).[9]
25. Title VI of the Schengen Convention
1990 contains provisions regarding the protection of personal
data communicated outside the Schengen Information System. Those
provisions will not be amended by the SIS II Decision, but will
be replaced by the DPFD with regard to matters falling within
the scope of Title VI of the TEU.
4 October 2006.
1 There are equivalent provisions in Article 31B of
the SIS II Regulation. The UK has opted out of participating in
the immigration and border control measures covered by the Regulation,
but is a full participant in the police and judicial co-operation
measures covered by the Council Decision Back
2
Regulation (EC) No 45/2001 on the protection of individuals with
regard to the processing of personal data by the Community, institutions
and bodies and on the free movement of such data. Back
3
Article 10 of the Regulation. Back
4
Article 10A of the Regulation. Back
5
Article 11 of the Regulation Back
6
Article 11A of the Regulation. Back
7
Article 11B of the Regulation. Back
8
The SIS II Regulation requires that personal data must be processed
in accordance with the first pillar Data Protection Directive
(95/46/EC). Back
9
The DPFD will not apply to the processing and protection of personal
data under the instruments relating to Europol and Eurojust. Back
|