Select Committee on European Union Minutes of Evidence


Memorandum by Mr Peter Hustinx, European Data Protection Supervisor

  The EDPS would like to focus on the following elements, taken from the list of issues in the request for evidence:

  1.  On the implications of a small number of Member States fixing the policy on matters of importance for all the Member States (as in the case of Schengen).[1]

    —  There is a fundamental difference with Schengen: There is now a European legal framework which enables the European Union to regulate the matters concerned and there were actual plans to make use of it for the (main) matters covered by the Prüm Convention. The Member States concerned nevertheless opted for a multilateral treaty enabling them to sidestep the thorny path of third pillar legislation by unanimous agreement.

    —  They also evaded the substantive and procedural requirements of enhanced cooperation, included in Articles 40, 40A, 43 and 43A of the EU-Treaty. This is all the more important since the procedure on enhanced cooperation was compulsory, if at least eight Member States were participating. However, only seven Member States signed the Prüm-Convention, but they subsequently encouraged other Member States to join.

    —  In the present situation, 16 Member States proposed a Council Decision replacing the Prüm Convention. Ipso facto, the other Member States are denied any chance of a say in the choice of rules. They can only choose between participating and not participating. Since the third pillar requires unanimity, if one Member State says no, the way of enhanced cooperation would be the appropriate one to choose as from now.

    —  One could argue that the Prüm Convention breaches the law of the European Union, for the reasons mentioned above. However, this argument is mainly of a theoretical nature, since the European Court of Justice has no competence on this matter, nor does any other Court.

  2.  On the relationship of the Convention with the negotiations on the draft Framework Decision on the exchange of information under the principle of availability.

    —  On the substantial differences: In essence the draft Framework Decision requires all national information available also to be directly accessible on line to other Member States' authorities. Prüm is of a fundamentally different nature: no direct access, but indirect access through reference data. Furthermore, Prüm is not directed at information that is available in the Member States, but to the contrary it requires Member States to collect and store certain information. Finally, Prüm is more limited, as far as types of information are concerned.

    —  The negotiations on the draft Framework Decision were not conducted in a serious way within Council. It seems that there was no willingness at all amongst the Member States to really develop the principle of availability into a legal instrument, in spite of the Hague Programme, approved by the European Council in 2004.

    —  It is at this stage not very useful to link the Convention with the negotiations on the draft Framework Decision, in the light of what has been said before. It is better to link the Convention in particular with Council Framework Decision 2006/960/JHA of 18 December 2006 on simplifying the exchange of information and intelligence between law enforcement authorities of the Member States of the European Union (based on the Swedish proposal) that must ensure that information and intelligence will be provided to authorities of other Member States, on request.

  3.  Whether the provisions of the Convention are justified by the need to combat terrorism and cross-border crime?

    —  An effective exchange of law enforcement information is a key issue in police and judicial cooperation. It is an essential part of the development of an area of freedom, security and justice without internal borders that information is available cross-border. An appropriate legal framework is needed to facilitate the exchange.

    —  It is a different issue to determine whether the provisions of the Prüm Convention are necessary and proportionate. The EDPS recalls that the Prüm Convention has been set up as a "laboratory" for cross border exchange of information, in particular DNA and fingerprints. It enabled the Member States concerned to experiment with this exchange. However, the proposal for a Council Decision is presented before the experiments have been effectively put in practice, apart from a very limited exchange between Germany and Austria.

    —  It makes a difference of scale whether one establishes a system of information exchange between a few Member States, that already have experience with DNA-databases, or if one establishes an EU-wide system, including Member States that have no experience at all. Moreover, the small scale allows close contacts between the Member States involved; those contacts could also be used to monitor the risks for the protection of the personal data of the persons concerned. Moreover the small scale is much easier to supervise. So, even if the Prüm Convention itself would be necessary and proportionate, this does by itself not mean that the draft Council Decision should be evaluated in the same sense.

    —  In general, new legal instruments on police and judicial cooperation should only be adopted after an evaluation of the already existing legislative measures, leading to the conclusion that those existing measures are not sufficient. In the present case, in particular Council Framework Decision 2006/960/JHA should be examined.

  4.  On the relationship between the data protection provisions of the Convention (and hence the implementing Decision) and those of the draft Data Protection Framework Decision:

    —  The Council Decision should build on a general framework for data protection in the third pillar. As stated on several other occasions,[2] it is essential to the EDPS that specific legal instruments facilitating the exchange of law enforcement information—like the present Council Decision—are not adopted before the adoption by Council of a framework on data protection, guaranteeing an appropriate level of data protection in conformity with the conclusions of the EDPS in his two opinions on the Commission proposal for a Council Framework Decision on data protection in the third pillar.

    —  A legal framework for data protection is a conditio sine qua non for the exchange of personal data by law enforcement authorities, as is required by Article 30(1)(b) of the EU Treaty, and recognised in several EU policy documents. However, in practice legislation facilitating exchange of data is adopted before an adequate level of data protection is guaranteed. This order should be reversed.

    —  The provisions on data protection in Chapter 7 of the draft Council Decision apply to data which are or have been supplied pursuant to the decision. They deal with a number of important issues and have been carefully drafted, as specific provisions on top of a general framework for data protection. Leaving apart details resulting from a more profound examination, one could conclude that the provisions offer in substance an appropriate protection. However, the field of application of the provisions is limited to data that are or have been exchanged between the Member States (this is at least how the EDPS understands the text) and the provisions are intended to build on a general framework for data protection that, as said, has not yet been adopted.

  5.  Whether the provisions allowing automated searching of DNA and fingerprint records are matched by adequate safeguards.

    —  The processing of DNA and fingerprint data, both being biometric data, has a sensitive nature and requires supplementary safeguards.

    —  As to DNA data, reference can be made to earlier EDPS-opinions.[3] It is essential that the concept of DNA data is clearly defined and that a difference is between DNA profiles and DNA data that can provide information on genetic characteristics and/or the health status of a person. Also progress in science has to be taken into account: what is considered as an innocent DNA profile at a certain moment in time, may at a later stage reveal much more information than expected and needed.

    —  The draft Council Decision limits the availability to DNA profiles established from the non-coding part of DNA. However, precise definitions of DNA-profiles, as well as a procedure to establish such common definitions, pursuant to the state of the art in science, are missing.

    —  The draft Council Decision relies on the presupposition that matching DNA profiles is the key instrument in police cooperation. For this reason, all Member States have to establish DNA data bases for the purposes of criminal justice. Taking into account the costs of these data bases and the risks from the perspective of data protection, a thorough ex ante assessment is needed of the effectiveness of this instrument. The limited experience in the exchange of DNA data between Germany and Austria does not suffice.

28 February 2007





1   See also H Hijmans, "The third pillar in practice: coping with inadequacies. Information sharing between Member States", published on the EDPS-website. Back

2   See most recently, the EDPS-Opinion of 16 February 2007 on the proposal for a Council Decision establishing the European Police Office (EUROPOL). Back

3   See, in particular, Opinion of 28 February 2006 on the Proposal for a Council Framework Decision on the exchange of information under the principle of availability, point 55-64. Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007