Memorandum by Mr Peter Hustinx, European
Data Protection Supervisor
The EDPS would like to focus on the following
elements, taken from the list of issues in the request for evidence:
1. On the implications of a small number
of Member States fixing the policy on matters of importance for
all the Member States (as in the case of Schengen).[1]
There is a fundamental difference
with Schengen: There is now a European legal framework which enables
the European Union to regulate the matters concerned and there
were actual plans to make use of it for the (main) matters covered
by the Prüm Convention. The Member States concerned nevertheless
opted for a multilateral treaty enabling them to sidestep the
thorny path of third pillar legislation by unanimous agreement.
They also evaded the substantive
and procedural requirements of enhanced cooperation, included
in Articles 40, 40A, 43 and 43A of the EU-Treaty. This is all
the more important since the procedure on enhanced cooperation
was compulsory, if at least eight Member States were participating.
However, only seven Member States signed the Prüm-Convention,
but they subsequently encouraged other Member States to join.
In the present situation, 16 Member
States proposed a Council Decision replacing the Prüm Convention.
Ipso facto, the other Member States are denied any chance
of a say in the choice of rules. They can only choose between
participating and not participating. Since the third pillar requires
unanimity, if one Member State says no, the way of enhanced cooperation
would be the appropriate one to choose as from now.
One could argue that the Prüm
Convention breaches the law of the European Union, for the reasons
mentioned above. However, this argument is mainly of a theoretical
nature, since the European Court of Justice has no competence
on this matter, nor does any other Court.
2. On the relationship of the Convention
with the negotiations on the draft Framework Decision on the exchange
of information under the principle of availability.
On the substantial differences: In
essence the draft Framework Decision requires all national information
available also to be directly accessible on line to other Member
States' authorities. Prüm is of a fundamentally different
nature: no direct access, but indirect access through reference
data. Furthermore, Prüm is not directed at information that
is available in the Member States, but to the contrary it requires
Member States to collect and store certain information. Finally,
Prüm is more limited, as far as types of information are
concerned.
The negotiations on the draft Framework
Decision were not conducted in a serious way within Council. It
seems that there was no willingness at all amongst the Member
States to really develop the principle of availability into a
legal instrument, in spite of the Hague Programme, approved by
the European Council in 2004.
It is at this stage not very useful
to link the Convention with the negotiations on the draft Framework
Decision, in the light of what has been said before. It is better
to link the Convention in particular with Council Framework Decision
2006/960/JHA of 18 December 2006 on simplifying the exchange of
information and intelligence between law enforcement authorities
of the Member States of the European Union (based on the Swedish
proposal) that must ensure that information and intelligence will
be provided to authorities of other Member States, on request.
3. Whether the provisions of the Convention
are justified by the need to combat terrorism and cross-border
crime?
An effective exchange of law enforcement
information is a key issue in police and judicial cooperation.
It is an essential part of the development of an area of freedom,
security and justice without internal borders that information
is available cross-border. An appropriate legal framework is needed
to facilitate the exchange.
It is a different issue to determine
whether the provisions of the Prüm Convention are necessary
and proportionate. The EDPS recalls that the Prüm Convention
has been set up as a "laboratory" for cross border exchange
of information, in particular DNA and fingerprints. It enabled
the Member States concerned to experiment with this exchange.
However, the proposal for a Council Decision is presented before
the experiments have been effectively put in practice, apart from
a very limited exchange between Germany and Austria.
It makes a difference of scale whether
one establishes a system of information exchange between a few
Member States, that already have experience with DNA-databases,
or if one establishes an EU-wide system, including Member States
that have no experience at all. Moreover, the small scale allows
close contacts between the Member States involved; those contacts
could also be used to monitor the risks for the protection of
the personal data of the persons concerned. Moreover the small
scale is much easier to supervise. So, even if the Prüm Convention
itself would be necessary and proportionate, this does by itself
not mean that the draft Council Decision should be evaluated in
the same sense.
In general, new legal instruments
on police and judicial cooperation should only be adopted after
an evaluation of the already existing legislative measures, leading
to the conclusion that those existing measures are not sufficient.
In the present case, in particular Council Framework Decision
2006/960/JHA should be examined.
4. On the relationship between the data
protection provisions of the Convention (and hence the implementing
Decision) and those of the draft Data Protection Framework Decision:
The Council Decision should build
on a general framework for data protection in the third pillar.
As stated on several other occasions,[2]
it is essential to the EDPS that specific legal instruments facilitating
the exchange of law enforcement informationlike the present
Council Decisionare not adopted before the adoption by
Council of a framework on data protection, guaranteeing an appropriate
level of data protection in conformity with the conclusions of
the EDPS in his two opinions on the Commission proposal for a
Council Framework Decision on data protection in the third pillar.
A legal framework for data protection
is a conditio sine qua non for the exchange of personal
data by law enforcement authorities, as is required by Article
30(1)(b) of the EU Treaty, and recognised in several EU policy
documents. However, in practice legislation facilitating exchange
of data is adopted before an adequate level of data protection
is guaranteed. This order should be reversed.
The provisions on data protection
in Chapter 7 of the draft Council Decision apply to data which
are or have been supplied pursuant to the decision. They deal
with a number of important issues and have been carefully drafted,
as specific provisions on top of a general framework for data
protection. Leaving apart details resulting from a more profound
examination, one could conclude that the provisions offer in substance
an appropriate protection. However, the field of application of
the provisions is limited to data that are or have been exchanged
between the Member States (this is at least how the EDPS understands
the text) and the provisions are intended to build on a general
framework for data protection that, as said, has not yet been
adopted.
5. Whether the provisions allowing automated
searching of DNA and fingerprint records are matched by adequate
safeguards.
The processing of DNA and fingerprint
data, both being biometric data, has a sensitive nature and requires
supplementary safeguards.
As to DNA data, reference can be
made to earlier EDPS-opinions.[3]
It is essential that the concept of DNA data is clearly defined
and that a difference is between DNA profiles and DNA data that
can provide information on genetic characteristics and/or the
health status of a person. Also progress in science has to be
taken into account: what is considered as an innocent DNA profile
at a certain moment in time, may at a later stage reveal much
more information than expected and needed.
The draft Council Decision limits
the availability to DNA profiles established from the non-coding
part of DNA. However, precise definitions of DNA-profiles, as
well as a procedure to establish such common definitions, pursuant
to the state of the art in science, are missing.
The draft Council Decision relies
on the presupposition that matching DNA profiles is the key instrument
in police cooperation. For this reason, all Member States have
to establish DNA data bases for the purposes of criminal justice.
Taking into account the costs of these data bases and the risks
from the perspective of data protection, a thorough ex ante assessment
is needed of the effectiveness of this instrument. The limited
experience in the exchange of DNA data between Germany and Austria
does not suffice.
28 February 2007
1 See also H Hijmans, "The third pillar in practice:
coping with inadequacies. Information sharing between Member States",
published on the EDPS-website. Back
2
See most recently, the EDPS-Opinion of 16 February 2007 on the
proposal for a Council Decision establishing the European Police
Office (EUROPOL). Back
3
See, in particular, Opinion of 28 February 2006 on the Proposal
for a Council Framework Decision on the exchange of information
under the principle of availability, point 55-64. Back
|