Examination of Witnesses (Questions 248-259)
Baroness Ashton of Upholland
22 NOVEMBER 2006
Q248Chairman: Baroness Ashton, thank you very
much indeed for coming to answer our questions, and indeed to
say whatever you want to say to us. Perhaps for the record I should
say that this meeting is on the record, it is being broadcast
and it is, as you know very well, part of our scrutiny into the
Schengen Information System Mark II, I think known as Schengen
II, is it not, now, so we can cut out a few of those words. May
I thank you very much also for your written evidence, which you
sent us on 4 October; that was extremely helpful. Would you like
to say anything to start with?
Baroness Ashton of Upholland: On a slightly
tangential point, I just wanted to say to the Committee that I
am aware it has been difficult to organise diaries and I would
not want there to be any impression given that I am in any way
other than fully conversant with my responsibilities to Parliament
and to this Committee. Indeed, I am heading for the Arctic Circle
later on today to do a conference and I have actually altered
my arrangements. I will fly out there in the middle of the night
in order to be here. I know there have been some difficulties
in trying to arrange it and I would not want the Committee, for
one minute, to think that we are anything other than absolutely
alive to my parliamentary responsibilities.
Q249 Chairman: It is very kind of
you to say that. We are all very conscious of the pressures on
your diary and are all the more appreciative of your readiness
to come and give evidence to us today; so, again, welcome. Can
I start off by asking you has the SIS II, Schengen II, legislation
now been fully agreed between the Council and the European Parliament,
including the data protection implications of access to SIS II
data by the security services? At the risk perhaps of duplicating
some of the points you have made to us in writing, can you explain
what position the Government took on this issue and why?
Baroness Ashton of Upholland: Thank you, My
Lord Chairman. The First Reading agreement has been reached between
the European Parliament and the Council, which is good news. You
will know that a huge amount of work on this has gone in from
the UK side. There was an amendment put forward which was to allow
access for all authorities which actually were entering data in
SIS II, and of course in some Member States that would have provided
access for security services. You know that we do not accept and
do not believe that national security matters are covered in the
third pillar. The amendment was not acceptable. The Government
is quite comfortable with reverting to the position which exists,
which is that Member States nominate those agencies which will
have access to SIS II, regardless of whether they actually put
information in. We are quite comfortable that we are in a good
place on this and we look forward to what the Presidency will
do now, in terms of taking that forward.
Q250 Chairman: Thank you very much.
Is the Government content that the relationship between the Data
Protection Framework Decision and SIS II Decision is spelt out
sufficiently clearly in the texts? What is the current state of
discussions on the Framework Decision, and what are the outstanding
issues?
Baroness Ashton of Upholland: I am content that
it is covered, My Lord Chairman. You will know that both in the
SIS II document, in Article 50, and in the Article 34 in the Data
Protection Framework Decision document, (a) it spells out very
clearly in the data protection document that Convention 108, the
references to that will be superseded by the references to the
Data Protection Framework Decision, and that within Article 50
of the SIS II document there is the reference to in accordance
with the law of the Member State before they invoke that right
with access to the data. I am reasonably confident that has been
done very effectively. As you know, the data protection document
which will replace Convention 108 is the base set of arrangements
around data protection. SIS II is a much more detailed, particular
framework, which will apply, of course, in the particular contexts.
Q251 Lord Marlesford: Minister, can
I raise a point which I think is of fairly overriding importance
and the Committee has discussed with various people in the past.
Here we are, entering SIS II, and we are all very concerned with
the information, security, and all the rest of it, but the thing
which is also concerning us is to find that because we are not
"full members of Schengen" we are not getting access
to the full information of the Schengen system. What is the Government's
view of that denial of access and what will you do about it?
Baroness Ashton of Upholland: Inevitably, I
tread cautiously and carefully into territory which is absolutely
the responsibility of the Home Secretary and the Home Office.
However, within the Justice and Home Affairs portfolio we work
as a team, and certainly I have been party to conversations with
the Commission to see whether it is possible to expand and extend
the way in which we operate. We do, of course, reserve and remain
outside of large parts of the Schengen agreement, and alongside
the agreement and membership of that agreement goes the ability
to access all the information. There is a negotiation, I think,
which is always ongoing, to see how far we can access information.
Obviously, the purpose of all of this is to make sure that we
tackle issues such as serious and organised crime effectively;
there is no reluctance on behalf of other Member States or the
Commission to see the UK participate in that. However, because
we are outside Schengen per se, we do not have access and
never will. This is something you may wish to pick up with the
Home Office as well, because they will be far more up to date
on their negotiations than obviously I am, because those were
discussions during the Presidency and I have not had any subsequently.
Q252 Lord Avebury: The Minister was
making a distinction in her first reply between the agencies that
will have access to the SIS II information and those that can
enter data, which will be, as we understand it, any law enforcement
agency which is on a large list in the United Kingdom of some,
I think, 80 different police forces and other law enforcement
bodies. How will this large number of bodies make a distinction
between their initial collection of data, which is governed, as
we understand it, by domestic data protection law, and the cross-border
exchange of that data, particularly the entry of the data into
the SIS II System which is governed by the DPFD? As a supplementary
to that, could I ask you why the Government objects to applying
the DPFD to the domestic data protection issues?
Baroness Ashton of Upholland: There was an issue,
Lord Avebury, very simply, about the legal base, which is still
under discussion and negotiation, and inevitably we are cautious
about doing anything which would imply that, because something
is desirable, you can determine that the legal base is different
from that which actually exists. That is the legality side of
it. There is a pragmatic and practical side of it which goes alongside
that. In looking at the data protection questions, I have met
with all of the agencies which have been involved and they have
raised, quite understandably, specific points of concern. These
were notably that they did not wish to have two systems that were
fundamentally very different from each other, not least because
that could lead to mistakes or perhaps people not sharing information.
They were pleased with the way in which our data protection work
operates, or the Act operates, in that sense, and therefore were
keen to see what happens with the European Framework, as much
similarity as possible. I have taken those seriously on board
and what we would look to do is, assuming that the legal base
does not allow that this be moved into the third pillar, look
at our own domestic legislation in order to make them match as
far as possible. Ultimately, we want to make sure that the systems
work, but we want the standards that we have here, and hence my
officials, who have worked tirelessly on this for some months,
have been working closely both with the European Parliament and
the Commission and in the Working Groups to try to make sure that
is as effective as possible. We are making good progress on that.
Q253 Lord Avebury: If we did have
to alter our own Data Protection Act then that would have to be
slotted into the legislation programme. Are you satisfied that
you could reach agreement on this in time to go through all the
procedures of giving instructions to Parliamentary Counsel and
finding time within the legislative programme to do this before
we enter SIS II?
Baroness Ashton of Upholland: SIS II is some
way off, as you know. First of all, I do not know whether we will
need to alter our legislation. Secondly, we will have to look
at whether that is by primary or secondary legislation, if we
do, and then we will look at what we need to do. I do not think
actually we are into substantive changes at this stage. The fundamental
point, which I am pleased to put on the record, is that we would
look to make sure that we were not creating difficulties in this
very important area for our services and to take on board the
comments that they have made, quite rightly, about wanting a system
which looks as close to the other as it can. The issue, in a sense,
is that, if there is no legal basis to do that, we need to look
at it pragmatically and we are committed to doing that, and I
am happy to keep the Committee informed about that, because that
is an area of interest as we move forward. At this stage, I do
not know what, if anything, I need to do.
Q254 Lord Dubs: Why has the Government
not opted in to the jurisdiction of the Court of Justice over
third pillar issues? How often has this issue been reviewed and
when will it be reviewed next, if at all? Would opting in not
help to ensure a more consistent interpretation of third pillar
measures and the protection of individuals' rights, for example,
in the context of SIS II?
Baroness Ashton of Upholland: It is a big question
for a small Data Protection Minister. The last time it was discussed
was between the Constitutional Treaty discussions, and I understand
that it will be looked at again in 2007, at the end of the period
of reflection, I think it has been described as, when those issues
will be looked at again. There are lots of issues, for example,
workload, and so on, that I know the European Court will have
to think about. I cannot really say any more than that, at this
stage, for it is not in my hands, other than to answer the question
directly, which is that it will be looked at again at the end
of the period of reflection, in 2007.
Chairman: Thank you for that answer to
a big question.
Q255 Earl of Caithness: Minister,
there seems to be a discrepancy between the SIS II and the DPFD
as to the data subject's right of information. The DPFD does provide
a right to be informed whether data is held on oneself, who controls
that data and for what purpose it is held, and does the Government
agree that such a right should apply to policing and criminal
law, and SIS II in particular?
Baroness Ashton of Upholland: The quick answer
to that is, yes, we do. It is quite interesting, because in Article
50, I think it is, in Schengen, it is the only place that I can
see where, in a sense, the way that the Data Protection Framework
Decision is looking, and within the documentation, it gives a
kind of higher approach than elsewhere. The Data Protection Framework
is generally the sort of base-line and then you have got, within
Schengen, the ability to be more detailed and to have tighter
restrictions. Actually, this is the one place where the Data Protection
Framework Decision, I think, is stronger. What will happen, as
you will know, is that once the Data Protection Framework Decision
is finalised there then enters a period of discussion on all of
the documentation and all of the other issues where data protection
comes into play and, if I put it in the vernacular, what will
trump what. This is an area where I am very happy for the Data
Protection Framework Decision to trump Schengen, because we would
want to see exactly the same things apply that we have already
in our national law.
Q256 Earl of Caithness: Which document
is going to win, at the end of the day; is it going to be the
Schengen document or is it going to be the DPFD document which
is going to override the other? Secondly, Minister, should not
an awful lot of this have been thrashed out and explored before
even we got into thinking about SIS II.
Baroness Ashton of Upholland: The answer to
your question about override is that, in general, the Data Protection
Framework Decision is the base-line of data protection which applies
generally and there are specific tighter controls which generally
would override that, because they are better and stronger and
people feel more confident with them. As a generality, the Schengen
controls are better than the Data Protection Framework Decision
ever will be, because they are very specific, not because it is
not good but they are very specific. This is the only one where
I think the Data Protection Framework Decision, as it stands currently,
is better. The negotiations and discussions about what trumps
what and what overrides what can happen only when we have finally
got agreement on the Framework Decision, because, obviously, different
Member States are worried about different aspects of it, the Parliament
will have its say too, and we will end up, I trust, with a very
good document as soon as we possibly can, and a very good agreement,
and then those negotiations take place. I understand your concern
that we hurtle down the road and end up where we are without those
previous discussions taking place, but actually, in the context
that the working groups are into the very detailed part of the
discussions on Data Protection Framework Decision, and because
we know a great deal about what is being proposed in Schengen,
I do not think you need to worry about it. I think what we will
discover is that, the Schengen Information System, the SIS II
proposals on data protection are strong, the Data Protection Framework
Decision will be a very good, sound base, and it will be these
individual bits of discussion, not least around this, where the
decisions will be made on what will work best and which are better.
From our perspective, we think this is one which data protection
should override.
Q257 Baroness D'Souza: Minister,
your officials suggested that the Commission would make recommendations
for harmonised standards on data collection, but the SIS II Decision
appears to provide for the Commission to adopt binding rules.
Could you say which will prevail?
Baroness Ashton of Upholland: The Commission
are going to, as you know, make reporting and recommendations
on what they think should happen. I think what my officials were,
I will not say `trying to say' because I am not entirely sure,
I read the transcript but I cannot remember exactly what they
said, we think, but we do not know, that they may well propose
minimum standards, but at this stage we do not know what the Commission
itself is going to propose; that is where I think they were more
likely to end up.
Q258 Lord Dubs: Your officials suggested
that a further decision would be necessary as regards `one-to-many'
searching of biometric data on the SIS, but the SIS II Decision
appears to state that such searches will be approved automatically
following a Commission report on the available technology. Which
of the two is correct?
Baroness Ashton of Upholland: My officials are
completely right, as always; there is no question but it is exactly
as they said. It is the difference between identification and
verification, which I am sure you have discussed, and no doubt
we will discuss with colleagues from the Home Office. What will
happen is that the Commission will make a report; they are looking
at the technology to see whether it is appropriate and ready;
they will put that report to the Council. There would need to
be a unanimous decision to take that forward, if it was to go
forward in that way.
Q259 Baroness Henig: I understand
that the forthcoming German Presidency intends to propose that
the Prüm Convention will apply to all Member States as an
EU measure. Does the UK support this and would there then be a
conflict between the data protection provisions of the Prüm
Convention, on the one hand, and those of the DPFD and SIS II,
on the other?
Baroness Ashton of Upholland: The provisions
within Prüm allow for the national legislation to apply,
so there would not be a conflict in that sense, our national legislation
would apply, the Data Protection Framework Decision would apply
in Europe and, as I have said, there then has to be a way of looking
at it from a national and a European perspective, to see that
they tie in appropriately. The UK is not a member of the Prüm
Convention, as you know. Discussions are underway because Prüm
has much to offer, I think. I think in this Committee we have
talked before about the different groupings which enable Member
States to work together in particular ways and then hopefully
to take that experience further when it is appropriate. Again,
it will be for the Home Secretary to take this forward, but I
know he will have areas that he will want to look at very carefully
before taking us anywhere into the Convention, but it will certainly
be in discussion.
|