| Previous Section | Back to Table of Contents | Lords Hansard Home Page |
Before I get there, I was leafing through some of my back papers on the exchange of data within the EU, which is relevant to this debate. I find that it always pays to keep past papers, no matter how old they are, because they can always be referred to and people can be reminded of what was said at the time. The then Secretary of State, David Blunkett, so many Home Secretaries ago, in a letter to the noble Lord, Lord Grenfell, the chairman of the Lords European Union Committee, said:
A large quantity of the data held by UK law enforcement authorities is tightly controlled even within the organisation concerned. This may be necessary for a variety of reasons, including privacy/data protection laws, national or personal security concerns, legal or ethical restrictions on the use to which information may be put, or the need to closely protect information during an investigation or pending a trial.
That is what Mr Blunkett said on 9 September 2004, and how hollow that statement now looks. During that inquiry into EU counterterrorism activities, the evidence we received from the Joint Supervisory Authority incorporating Europol, Eurojust, Schengen and Customs, also dated in September 2004, stated:
In addition to the right to respect for private and family life guaranteed by Article 8 of the ECHR and reaffirmed by Article 7 of the Charter of Fundamental Rights of the European Union, the new fundamental right to data protection is enshrined in Article 8 of the Charter. The draft Treaty Establishing a Constitution for Europe that includes the Charter, also guarantees in Article 1-51 the right to data protection and states that compliance with data protection rules shall be subject to the control of an independent authority.
I wonder whether the independent authority was consulted in either of the reports that we are discussing today.
I turn to the specifics. Especially on PrĂ1/4m, of course we recognise the real value of the exchange of information between states in fighting terrorism and serious international crime. Most noble Lords have referred to that. The noble Lord, Lord Wright of Richmond, in his opening, said that while accepting the exchange of information was critical in the fight against serious crime and terrorisma point addressed also by my noble friend Lady Ludford and the noble Lord, Lord Marlesfordthere was no consultation, no estimate of costs, no impact assessment and so on.
We must work closely with our international partners to ensure that those dangerous and serious criminals and terrorists who seek to threaten the UK and its citizens are prevented from doing so. However, our concerns are not about the intention of the PrĂ1/4m treaty but about the way in which it is being implemented. In that we agree with the concerns raised by the EU committee. The treaty of PrĂ1/4m, as we have heard, was negotiated and signed without any parliamentary oversight. The intergovernmental nature of co-operation in the field of security in the EU inhibits democratic checks where a treaty is presented, already negotiated, for ratification or rejection. Changes are not permitted.
In addition, transposing the provisions of the treaty of PrĂ1/4m into EU law through Council decision will leave the European Parliament, whose rapporteur is still to be appointed, with the simple consultation procedure. Is that the appropriate way to proceed with such a treaty when we are dealing with sensitive personal data? I do not think so, and my noble friend Lady Ludford suggested that we are going too fast properly to scrutinise EU law enforcement efforts. She referred to PrĂ1/4m as a particular scandal and not the way to run a whelk stall. She said that it was a merry-go-round out of control and that periodic reviews are simply not good enough.
We are very uneasy about how the security of such data can be protected when an exchange is taking place. We very much share the committees concerns in paragraphs 81 to 98, where it recommends that negotiations on the data protection framework decision, instead of being sidelined, should proceed in parallel with those on the PrĂ1/4m decision. What are the Government doing to ensure that the very high standards of data protection that the UK has applied to information processed in the law enforcement field are replicated across the EU?
I thank the Government for their response to the recommendation in paragraph 102, in which the committee states:
The threshold for holding DNA profiles on the United Kingdom DNA database is far lower than in any other Member State, and the proportion of the population on the database correspondingly far higher. The Government should as a matter of urgency examine the implications of DNA exchanges for those on the United Kingdom database.
I understand that there are roughly 4 million hits on the database at present. This worried me and I thank the Government for stating in their response:
The UK (as with other Member States) will decide which profiles on the national database should be exposed to search requests from other member states. There need be no assumption that all profiles would be searched routinely under PrĂ1/4m.
Can the Minister inform the House how the decision will be made about which profiles will be available for a search request? Will this be done, for instance, by type of crime or by sentence imposed? Will the DNA of those who have been arrested but not charged be available for searching? Will there be any parliamentary oversight of such decisions?
The EU-US passenger name record agreement is equally of great concern to us, as every noble Lord reminded us. Since the EU committees report was published, a new agreement has been put in place,
6 Dec 2007 : Column 1909
There will be greater data sharing across US agencies and with third countries. There is a weak legal mechanism for EU citizens to challenge misuse of their personal information. The data can be used,
So this use is not restricted just to terrorism or serious crime.
The agreements have ignored a number of questions. What data mining will occur? Rarely has there been much consideration of how these data are being put to use by the US Government. Why are all these data important and how are they being processed? The disclosures regarding the profiling system ATS raised more concerns in the US than they appear to have done within the EU, despite the fact that it leaves us to question whether the US is abiding by the agreements at all, while it implements secret risk assessment systems. How legally binding are these agreements? They do not hold the status of treaties within US law, and because they are not ratified by the US Senate, do not become binding US law.
Any promises made in the agreements regarding granting legal rights to EU citizens are not truly actionable. What about data from other sources? While major carriers have their own reservation systems, reservation systems are also outsourced or run by third parties. There are global reservation systems such as Galileo, Sabre and others, which are not within the remit of the agreement, because the agreement applies only to carriers databases. The computerised reservation systemsCRSwill permit broad access by US authorities to data regarding citizens from around the world without any restrictions, because many of the companies are based in the US or have databases within US jurisdiction. Similarly, EU citizens flying on any US-based airline, even from EU airports, have less control over their personal information, as those transfers are not governed by the agreements.
When I was travelling here in a taxi this afternoon, I was telling the driver about the debate in which I was about to speak, and I told her how difficult these arrangements are. I asked her whether she was aware that information on her would be picked up very quickly and known about if she decided to fly to the United States; and she was absolutely horrified. She asked, Why havent we heard about it?. I ask the same question, because the majority of British citizens have no idea what is being held on them.
Both reports raise a number of general concerns in relation to the mechanisms whereby the PrĂ1/4m treaty and the EU-US PNR agreement came into effect. There is a distinct lack of democratic oversight and parliamentary scrutiny, as many noble Lords have
6 Dec 2007 : Column 1910
Finally, how are we expected to believe that the Government, who cannot even protect the data of their citizens when they are being transferred between HMRC and the National Audit Office, as other noble Lords have said, have adequate procedures in place to protect personal data when they are being transferred to another country?
Baroness Neville-Jones: My Lords, a number of important points have been made in this debate on the two excellent reports from the committee chaired by the noble Lord, Lord Wright, who taught me much of the craft of diplomacy and negotiation that I learnt in the Foreign Office. He is a master practitioner.
I am sure that the House would agree with the aim of both agreements, which is to improve cross-border co-operation in combating terrorism, serious border crime and illegal immigration, in the case of the PrĂ1/4m agreement and, in the case of the passenger name record agreement between the United States and the EU, to combat terrorism. The question is whether the agreements fulfil their stated aims on acceptable conditions. Like the noble Lord, Lord Wright, and other speakers, I find in that respect that I have to be rather critical.
I shall take the PNR agreement first. Before I get to the substantive point, I echo the comments that have been made by a number of speakers to the effect that it is a pity, to put it mildly, that the Governments response to a report published in May came out only in October, almost five months after the report and two months after the agreement reported on had been struck. That obviously means that we are debating a report and a response after the point at which they can have any effect on the outcome. Moreover, a substantial number of the committees recommendations have been ignored in the final outcome, and that is a poor outcome for parliamentary scrutiny. All of this is against the background of an unsatisfactory negotiation with the United States involving a unilateral interpretative letter from the Americans. I entirely concur with what my noble friend Lord Marlesford said about the public interest being the loser in this respect.
On the substance of the issue, it is clear that there are many advantages to allowing the intelligence services of the United States to have access to certain information about people travelling to their country. My party supports such mutual help, provided that there are safeguards. Indeed, on this side of the House we would argue strongly that the United Kingdom would be better protected and more able to manage immigration if the Government took the importance of border protection as seriously as the United States. It is imperative to have real-time information about movement across our borders, so that at any time it will be possible to know how many people are in our territory and jurisdiction and who
6 Dec 2007 : Column 1911
In his reply, could the Minister say how relevant and successful the agreement with the United States has been in its proclaimed aim of combating terrorism? The committee expressed some anxiety that there was very little evidence on this point. Obviously, there may be a need for confidentiality, but it would be of interest to know whether such systems, which increase public and private-sector costs, are really effective in meeting their proclaimed objectives. We should not be frightened of reducing bureaucratic burdens if they turn out not to be fit for purpose or proportionate.
Protection of personal data is another area where public authorities need to be conscious of their duties to the owners of the datain this case, airline passengers. It is very easy for the state in its various guises to treat information about peoples identities as if it belonged to the state and not to the real owner, the individual. Now that personal data pass from airlines to US Customs and Border Protection within the Department of Homeland Security and the Transportation Security Administration, there must be an increased danger that the information may in practice be used for purposes for which it was not initially given. Can the Minister say if any regular monitoring procedures will be in place to ensure proper use of data and effective protection thereof?
This is not an idle consideration. Many UK citizens are going to be caught in this net. This is a real cause for concern on the part of ordinary citizens as more than 2 million Britons travel to the United States annually. In their response to the committees report the Government said that,
As the noble Baroness, Lady Ludford, noted, given that the new agreement doubles the previous retention period, from 3.5 to seven years and adds on a further eight years of dormant, non-operational retention, can the Minister explain what has changed fundamentally since 2004 to require this long period of retention? Why is this necessary? To what purposes might this vast quantity of data possibly be put? I will posit one uncomfortable possibility.
According to the Governments response to the committee, the PNR may be used,
Could the Minister explain the purport of this apparently vast let-out provision on potential use? Who is to judge the need for such use? Would British authorities be consulted in such cases? Indeed, would the UK authorities be informed? What would the data subject be allowed to know about the decision to protect their vital interests or those of other persons? Indeed, the PNR having been put in place in the name of combating terrorism, here is a provision which would permit, in an apparently wholly uncircumscribed way, the use of information given for this purpose to be used in anyI repeat, any
6 Dec 2007 : Column 1912
On this side of the House, our anxieties on that point are increased by the quantity of data demanded of travellers under the PNR. Anybody who has filled in the forms knows that they are quite intrusive and reach into personal and financial matters. Can the Minister please clarify the meaning of the quantity of data elements that are to be exchanged? The original agreement allowed for 34 types to be collected. The new agreement ostensibly reduces that to 19, but the Governments response to the committees report states that the number has been reduced as a result of the,
As the noble Baroness, Lady Ludford, remarked, that sounds less like a reduction in the amount of data that has to be given, than a recategorisation thereof; that is to say, bigger data groups. No doubt the Minister will inform us if another interpretation is possible.
The second of the reports under discussion today deals with the Council of Ministers decision based on the PrĂ1/4m treaty concerning cross-border data exchange in three areasDNA profiles, fingerprints and certain vehicle registration datawith the aim of combating terrorism, serious border crime and illegal immigration. The Conservative Benches are evidently not against such mutual assistance as a matter of principle, but the safeguards that apply at home to data protectionwhich, in our view, are in any case weak in implementation if not in conceptneed to be present to safeguard much wider exchange across borders, where the risks increase. We do not believe that these safeguards are in place.
As with the PNR agreement, the Government had at their disposal the committees report before they gave their agreement last summer to the Council decision. Despite that, as many noble Lords who have spoken in this debate have noticed, a considerable number of the points it madesome of them significanthave not been taken up or reflected in the outcome.
On the plus side, we on these Benches congratulate the Government on their success in removing provisions concerning the unauthorised entry of officials of one state into another. Against this, it is generally disappointing that more notice was not taken by the Government of the report. I share the view expressed by many speakers and I believe that the Government could have applied more leverage, given the need for unanimity to adopt the decision.
Procedure is important. Noble Lords have noted the strong desirability of proper information provided alongside proposals, including impact assessments in particular. The Conservative Benches consider that, whatever the formal position in relation to initiatives taken by member states as distinct from the Commission, Her Majestys Government will be serving the public interest in pressing for that rather than excusing failure to follow good practice. Rushing legislation through in the name of protection of the safety of societyand I fear that is what happened
6 Dec 2007 : Column 1913
As others have noticed, the Government commented in their reply that they saw no tangible benefits in that. I hope the day does not come when they have cause to rue this view. Given the increased powers which the UK Information Commissioner nowat lasthas had to be given by the Government as a result of the latest data losses in government, one might have thought that the obligation to consult the data supervisor would be seen as a useful protection for the Government and a potent means of forcing up other countries standards of data protection nearer to those already obtained in the UK.
In his opinion, the European data protection Supervisor made a number of critical comments on that decision. If the Government are not disposed to listen to the committee of this House, perhaps they will take the views of the European Data Protection Supervisor seriously. He complains of ambiguity in the purposes of collection and exchange. He queries the schemes proportionality, the failure properly to assess the value of data exchange so far and its relevance to wider exchange among all member states. He noted that some of the procedures governing handover by national authorities of data, on which HMG apparently intend to rely for protection, constitute derogations from the principle of availability. He does not say that this is wrong, but one is bound to wonder how long it will be before such reliance is challenged and the safeguards dependent on it weakened. What would then happen to the UK citizens right to receive protection from UK courts?
The European Data Protection Supervisor states categorically that the lack of a harmonised legal framework for data protection, which he considers a sine qua non of cross-border data exchange on this potential scale, is a serious shortcoming. The Government, on the other hand, state in their reply that they do not consider it necessary to complete work on a data framework before proceeding. One wonders about the prudence of this. The committee makes the same recommendation. The Government ought to be listening to such experts and to Parliament, and take their advice seriously instead of waiting until they have another data accident. How many more do the Government want?
Finally, like the noble Lord, Lord Jopling, I am concerned about the UK situation. We have over 3 million entries on the police databasemore than all other member states put together. On this database there are details of convicted criminals, people arrested but never convicted and volunteered samples of otherwise totally uninvolved people. It is, of course, open to question whether this should be the
6 Dec 2007 : Column 1914
Secondly, the protections are different. Not surprisingly, and perfectly reasonably, the German protections are lower. Relying entirely on national practice, and in a situation where there is an obligation on the state receiving a request for data to follow it up, can the House be confident that there will never be a case of information about a UK national improperly and unnecessarily crossing borders and/or being improperly released, thus rendering such data exchange open to challengequite apart from the damage that it might do to the individual concerned? I, for one, would not be so confident. It is surely unwise of the Government not to accept the need for national systems and practices in data protection and security to be made more compatible, if not fully aligned, before extending obligations in this field.
At the very least, data on a database should be carefully categorised. The noble Baroness, Lady Harris, made some pertinent points on this. It would also be reassuring to know that, when a data file is handed over, there was a definite time limit on the retention of that data file by the third-party country; this point is obscure. What can the Minister tell us about these various issues which will help quieten well founded anxieties on these various scores? Moreover, rushing this decision has meant that the committee's recommendation that there should be a reliable estimate of start-up costs before incorporation into EU law has been neglected, despite the European data supervisor taking the same view.
| Next Section | Back to Table of Contents | Lords Hansard Home Page |