Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Monday, 22 February 2010

ACTA attacked by European Data Protection Supervisor Hustinx

Today, Peter Hustinx, the European Data Protection Supervisor (EDPS), has attacked the ACTA negotiations with a 20-page opinion (PDF) that is absolutely harsh and absolutely clear.

This probably follows yesterday's leak of the (alleged) present Draft Internet Chapter of the ACTA that has caused an outcry in the web community (e.g. here & here) that is already very critical towards the secretive nature of the ACTA negotiation process.

One example of the secrecy is this recent refusal (PDF) of the EU Council to disclose ACTA negotiation documents.

And now the EDPS concludes inter alia:
The EDPS strongly encourages the European Commission to establish a public and transparent dialogue on ACTA, possibly by means of a public consultation, which would also help ensuring that the measures to be adopted are compliant with EU privacy and data protection law requirements.
and
Insofar as the current draft of ACTA includes or at least indirectly pushes for three strikes Internet disconnection policies, ACTA would profoundly restrict the fundamental rights and freedoms of European citizens, most notably the protection of personal data and privacy.
What is also notable is that the EDPS complains that he has not been consulted so far - a clear attack on an institution that is meant to protect us citizens against misuse of our private data.

Altogether, Peter Hustinx paints a picture that shows that the measures apparently foreseen infringe our rights to privacy and to freedom of expression - and the Commission and member states continue as if nothing is happening.

(found via Der Schockwellenreiter)

Friday, 27 November 2009

EU to hand all banking details of Europeans to the US

I am no expert in this field, but it really looks like member states on Monday might give unlimited access to all banking details of EU citizens to the USA.

According to Brussels Blogger this will be done without asking the same from the US, all has been decided without any parliament, and no citizen will be able to go to court against these measures.

In addition, member states want to push this through on Monday because on Tuesday the Lisbon Treaty enters into force an the European Parliament would need to participate in the decision-making then.

If this respects democracy and the rule of law, the East German State Security (Stasi) has been an organisation respecting basic human values and civic rights.

PS.: The Facebook group asking member states to stop their actions regarding SWIFT has been growing from 0 to 530 members within less than a day!

Monday, 17 August 2009

Massive data collection exercise at the EU/ Schengen external borders in August/ September


UPDATE: Find the results of the data collection exercise here.


According to a newly released Council document (dated 8 June; only partially public), the EU and Schengen member states will run a massive data collection exercise at the external borders from 31 August to 6 September 2009.

Initially planned for June and postponed to the dates indicated above (with the data being transferred to the Council Secretariat in mid-September), the goal of this exercise is
"comparable data on entries and exits of different categories of travelers at different types of external borders, currently not available in all Member States, that would be useful in preparatory work within the Commission with a view to submitting in the beginning of 2010 a legislative proposal on the creation of a system of electronic recording of entry and exit data."
In earlier discussions, member states had different opinions whether this data collection would include all border crossing points, and it is not clear whether this is the case or not. A Council document from May highlights that
"[t]he added value of the proposed exercise would be the gathering of comparable data on entries and exits of different categories of travelers at different types of external borders in the Member States"
while noting that
"the exercise is not aimed at establishing estimates on the total number of border crossings in Member States."
Since the documents are only partially public, it is not absolutely clear what kind of date will be assembled through which measures. It is also not clear whether this will be random sampling (e.g. every fifth/tenth/twentieth traveller) or a complete sampling of everyone crossing the border during this one week.

Since this will be a kind of test run for a standardised exit/entry database, it would be interesting to know what the European Data Protection Supervisor (or his national colleague) think about this exercise...

PS.: And also note that discussions on the Passenger Name Record (PNR) are continuing intransparently in the Council (see my previous coverage).

Monday, 30 March 2009

Legal issues in fighting terrorism in the EU: A response from the member states

The Commission has published a compilation document named
Synthesis of the replies from the Member States to the Questionnaire on criminal law, administrative law/procedural law and fundamental rights in the fight against terrorism
One of the main quotes from this document is the following (page 5):
[T]he absence of problems can be explained by a very low rate of terrorist activity. Some national authorities have not encountered any problem in prosecuting terrorist suspects because they have not been confronted with terrorist activities taking place in their territories.
In other words: Terrorism is not a problem in most countries of the European Union, while it is constantly overestimated by those actors who want to decrease the freedoms of citizens.

Very interesting is the table on page 15, listing the number of prosecutions and convictions for terrorist activities in the member states since 2001, with France and Spain showing peaks in convictions while the UK peaks for prosecutions (paranoia?!) among very low figures in other member states.

Further down in the text, we learn that "Cases of violations of data protection rules in relation to the fight against terrorism were ... reported by two Member States", namely Belgium and Germany.

Altogether, the document gives a nice little insight into how member states' legal systems are handling terrorism - anyone interested in the field will get useful details.

Wednesday, 28 January 2009

European Data Protection Day: Commission warning echoes around the globe

Today is the European Data Protection Day, a joint initiative of the European Commission and the Council of Europe to celebrate the "birthday" of the European Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data signed on 28 January 1981.

Is that why EU Commissioner Jacques Barrot warns young people to use Facebook? It feels like he is number 100 on the list of politicians to do so, and I kind of get bored.

But boredom is the biggest success of EU institutions these days, right?

Tuesday, 6 January 2009

The old Data Protection Supervisor of the European Union Peter Hustinx will remain in office for a new term

From Thursday, EU member states are invited to follow the recommendation by an expert committee and the vote by the European Parliament to officially re-appoint the Dutch Peter Hustinx as Data Protection Supervisor of the European Union for a new term starting from 13 Januar 2009.

The Assistant Data Protection Supervisor Joaquín Bayo Delgado will be replaced by the Italian Giovanni Buttarelli, who has been the Secretary General of the Italian Data Protection Authority for 12 years and has represented his country in working groups of the European Union (plus the Schengen Joint Supervisory Authority) as well as of the Council of Europe.

-----
Read also: the EU Commission press release, which - if the document linked at the beginning of this article is not wrong in saying that the formal appointment procedure will begin this Thursday - incorrectly states that the Council already approved Mr Hustinx and Mr Buttarelli.

Tuesday, 16 December 2008

Follow-up: EU working on a Passenger Name Record (PNR)

In August, I have written an article on the planned Passenger Name Record (PNR), and now a follow-up document (including Corrigendum 1 and Corrigendum 2) summarising discussions from July to November has been published by the EU Council
.

Let me quote the most important lines from the document:
  • [Air transport] operators are seeking the European Union's support to work towards the greatest possible harmonisation of the obligations imposed on them in order to limit the cost and the burden of legal responsibilities which they face to the minimum necessary.
  • Mr Gilles de Kerchove [the EU anti-terrorism co-ordinator] relayed the views of counter-terrorism services which he had consulted. These views are that in Europe, as elsewhere in the world, PNR data are undeniably useful in the field of counter-terrorism, partly on account of the specific vulnerability of terrorists when crossing international borders and partly on account of the significant and intrinsic potential afforded by the PNR tool.
  • [R]isks of discrimination, notably on ethnic or religious grounds, were eliminated by following the [Fundamental Rights] Agency's recommendations. 
  • A significant effort was made as regards the clarification and coherence of the data protection rules applicable, since specific rules have to be identified in the instrument, in particular to ensure that the limits imposed on the use of PNR data are strictly complied with. 
  • The approach of having a centralised PNR system at EU level has been rejected by a vast majority of delegations, and the Commission has refused it, particularly because of the technical complexity of such a tool which could have grave consequences for data security. 
  • A Passenger Information Unit (PIU) would be set up in each Member State to act as the public authority hosting the PNR database and ensuring compliance with the rules in force. 
  • The procedure for analysing the terrorist and criminal risk should be clearly delimited. 
  • The list of data to be transmitted can be reduced compared with the original proposal since it was not deemed necessary to maintain the information relating to unaccompanied minors which it contained. 
  • [R]igorous traceability of all access to the PNR database, all analyses and all transmissions made;
Still to be discussed are questions regarding sensitive data (i.e. special health needs of passangers), the retention period for data, as well as the possible exchange of bulk data.

In total, I am not really convinced that the effect of this PNR will outweight the reduction of privacy, and the risks of misuse of the data gathered by the authorities. Altogether, the progress report paints a rather positive and unproblematic picture, but I am not sure that the member states take due account of all critical matters connected to the database.

Sunday, 10 August 2008

EU working on Passenger Name Record (PNR)

While the news have recently covered the discussion about the exchange of passenger data between the USA and the European Union, the European Union itself is working on a proper Passenger Name Record (PNR).

The proposal for a respective draft regulation (document provided by statewatch.org) had been presented by the European Union Commission in November.

In a recently published EU Council document for the Multidisciplinary Group on Organised Crime (MDG), the French EU-Council presidency outlines the state of discussions and the further tasks. The initial considerations are:
It is paradoxical that while the European Union has agreed to transfer PNR data to third countries, it has not yet passed legislation enabling it to reap the benefits itself of such a system, which, as the experience of several Member States reveals, is an effective tool. It is naturally necessary to ensure that the European PNR system reflects the Union's commitment to fully respecting fundamental rights.
On this basis, several topics have been identified that need to be discussed:
  • FLEXIBILITY: It is necessary to delimit the margin of manoeuvre that Member States may be allowed in complying with future European standards adopted jointly;
  • FUCTIONAL AND GEOGRAPHICAL SCOPE: At this stage of the proceedings the Group has opted for restricting the application of the European PNR system to air transport;
  • PURPOSES OF THE PNR: a) The possible inclusion of purposes relating to integrated border management; b) Possible extension of the system's purpose of preventing and punishing terrorist and organised crime - already covered by the Commission proposal- to other serious crime;
  • FUNCTIONING OF THE EUROPEAN PNR: collecting and using the the PNR data;
  • PROTECTION OF AIR PASSENGERS' PERSONAL DATA
  • RELATIONS WITH THIRD COUNTRIES
  • COSTS
On the basis of these issues presented by the French Presidency, the Council will continue its discussions.

In an article by Statewatch discussing the PNR regulation, editor Tony Bunyan (photo) comments:
"This is yet another measure that places everyone under surveillance and makes everyone a "suspect" without any meaningful right to know how the data is used, how it is further processed and by whom. Moreover, the "profiling" of all airline passengers has no place in a democracy."
Meanwhile, British news report that the British government is dissatisfied with the European plan, quoting a Home Secretary document:
As currently drafted, there is a real risk that the EU PNR proposal would degrade e-Borders [explanation] by prohibiting the use of PNR data for combating immigration offences.

'We will therefore lobby strongly for the framework decision not to preclude the use of PNR for this purpose.'
It will be interesting to see what we will get in the end. I hope that the European Parliament will have a strong word to say on the final regulation, although it seems as if the is only subject to a simple consultation procedure.

If any MEP or MEP assistant is reading this, I would be more than glad to hear about the state of discussions in the European Parliament!