Tuesday, August 10, 2010
European Union Agency for Fundamental Rights: Document on Body Scanners
It addresses the following questions:
1. Which fundamental rights are at risk of being affected by the use of body scanners?
2. Is the use of a body scanner to be considered as processing personal data?
3. How could the requirements on the design and selection of body scanners best respect rules on data protection?
4. How can body scanners be assessed from a rule of law perspective?
5. Are there specific considerations to be taken into account when selecting people to be screened?
6. Should the person to be screened be given the choice between a body scanner and other screening methods?
7. Which information should be given to persons before they choose to be screened by a body scanner?
8. How intrusive are body scanners if compared to other screening methods?
9. Is the detection capability of body scanners an added value regarding security?
10. Which conditions should apply in order to address the concerns related to fundamental rights?
Thursday, July 8, 2010
EU Parliament Gives Green Light to EU-US SWIFT Agreement
Thursday, July 1, 2010
Detecter Deliverable: Border Control and Internal Security in the European Union
Executive summary
- Since the New York terrorist attacks in September 2001, border control is increasingly shaped by security considerations. This paper concentrates on the implications of this trend for the enjoyment of human rights protection by third-country nationals that seek to enter or have already gained access to European Union territory. The integration in the common border policy of threat assessments and risk analyses together with information gathering and sharing through the use of advanced technology has contributed to the perception that cross-border movements, and, in particular (potential)irregular immigration are closely related to serious criminality, including terrorism.
- In the development of a common border policy, the EU, together with its Member States, should ensure that control and surveillance over the external frontiers are implemented in full compliance with legally binding international and European human rights standards. This should include operations aimed at diverting “illegal immigration” when conducted beyond EU external borders and when carried out in cooperation with third countries.
- The legal mandate of the EU Border Control Agency, Frontex, should be clearly defined, in particular as regards the Agency’s competencies and corresponding responsibilities. Any coordination of or other involvement in border control operations by Frontex should be governed by clear guidelines which ensure respect for the principle of non-refoulement, including chain-refoulement, and the right to a fair and effective asylum procedure for any person claiming an international protection need.
- The integration of internal security aspects in EU border policy also affects the processing of personal data on third-country nationals. Such data are stored in centralised EU-operated databases and were originally collected for primarily immigration-related purposes. Promotion of access to sensitive personal immigration data, including fingerprints, by law enforcement authorities for purposes including the prevention of and fight against terrorism implies that non-EU citizens form a suspect category in itself. This raises serious questions concerning the legitimacy, including necessity and proportionality of the measure under data protection principles inherent in the right to privacy. It may, in addition, have serious implications for the principle of non-discrimination.
- Trends towards “interoperability” between EU-operated databases should be accompanied by the establishment of a comprehensive, specific and legally binding data protection framework with adequate safeguards to cover risks related to the large scale storage and use of personal data. The more authorities have access to sensitive personal information, the greater the risks of abuse, misuse, leaks and loss of data. This may have serious consequences, including with regard to the prohibition of torture and the principle of non-refoulement, if data on refugees and asylum-seekers reach authorities in their countries of origin.
- Applying systematically EU carrier sanctions regime on international carriers may obstruct refugees and asylum-seekers in seeking protection in the EU. Trends toward the extension of the carrier sanctions regime to include the transfer of passenger data to national authorities, including for counter-terrorism purposes, raise serious questions from the perspective of data protection principles. Refugee protection is further marginalilzed, while adding to the perception that cross-border movements are closely linked with criminality.
Wednesday, June 30, 2010
Comment: EDRI on the New SWIFT Deal
Unfortunately, the new adopted text still allows for bulk data transfers. The Parliament would have liked to replace bulk data with targeted searches carried out by an EU-based authority but according to MEP Birgit Sippel, "We cannot reduce the problem of bulk data for the moment as we do not have the technical
capability."
The retention period is still 5 years and there is no real system in place from the US on a binding legal redress. The US Privacy Act court clauses only apply to US citizens and legal residents. Therefore there is currently no right of judicial review for foreign citizens and residents (including EU) under the US law.
Another key critique to the current text is the role of Europol that should authorize the data transfer requests from the US. Besides the fact that Europol is not a judicial authority, as requested by the European Parliament in May 2010 Resolution, the incentive from this agency to limit the amount of data being transferred is extremely reduced due to the fact that they can actually request data searches from the US.
Detecter Deliverable: Unilateral Exceptions to International Law
Executive Summary
This paper on unilateral exceptions to human rights and international law in the fight against terrorism prepares the ground for two further deliverables under the DETECTER project, namely a policy-oriented paper summarizing the results and applying them in respect of EU law and policies, and a study specifically addressing detection technologies. It is well known that many governments have resorted to a wide range of constructions to justify, under international law, their unilateral exceptions to human rights in the name of countering terrorism. This paper seeks to take stock of a whole range of arguments, doctrines or constructions that states may resort to when seeking to justify their unilateral exceptions to human rights norms in the fight against terrorism. Many of those constructions have a valid legal basis and a proper scope of application. However, they also have their limitations, to the effect that often they affect only a specific treaty, or the availability of a procedure, but do not affect the substantive obligations of the state in question under international law. In many cases this results from the overlap of treaty law and customary norms of international law. Some of the constructions are open to abuse, i.e. bad faith efforts to distort international law to the detriment of human rights. Because of the complexity of the combined effect of the various excuses and exceptions, there is a need for a holistic approach that seeks to address the combined effect of the various constructions of unilateral exception.
Some of the main conclusions of the paper are highlighted in this executive summary. To start with:
- None of the constructions discussed affects a state's obligations under peremptory norms of international law (jus cogens).
- Outside that realm of peremptory norms, some of the constructions discussed have an impact upon both treaty law and customary international law, hence affecting the substantive human rights obligations of a state. This would be the case for the lex specialis effect of international humanitarian law during armed conflict but only when lex specialis is properly construed as an interpretive effect upon the scope or content of a particular human right.
- Counter-terrorism measures may qualify as permissible limitations on human rights, again when properly construed. This conclusion calls for a rigorous test for permissible limitations, rather than an all-encompassing act of 'balancing'.
- Most constructions discussed in this paper pertain merely to human rights treaties and do not affect the state's obligations under customary international law. As there is a high degree of substantive overlap between human rights treaties and customary norms of international law, resorting to these excuses therefore usually only has procedural consequences. It does not affect the substantive obligations of the state under international law, but precludes the competence of an international (or regional) human rights court or treaty body to address the breach of international law through its regular monitoring mechanisms.
- The most relevant constructions of unilateral exceptions to human rights treaty obligations are the power of a state to declare a state of emergency and to derogate from some but not all of its human rights treaty obligations, reduction of the scope of a state's human rights obligations when it acts outside its own territory, the right to enter permissible reservations upon the signature or ratification of a treaty and, in some cases, withdrawal from a treaty.
- There is some state practice of declaring a state of emergency because of acts of or a threat of terrorism. When applied under the fairly strict requirements for derogation enshrined in the treaties in question and when subject to international monitoring through the procedures available under the treaties in question, derogation is a permissible and even recommended mechanism for reacting to situations of a genuine threat to the life of the nation.
- Although the European Court of Human Rights has in some cases implied that a state is not subject to exactly the same obligations when it is, through its agents, acting outside its own territory, caution is required when resorting to this excuse. Other human rights treaties and customary norms of human rights law may remain applicable, and even the position of the European Court of Human Rights appears to be shifting (or inconsistent).
- Somewhat surprisingly, states have not resorted to reservations under human rights treaties with express reference to terrorism. However, a very small number of existing reservations, including in respect of the right to a fair trial, may have a bearing upon the treatment of terrorism suspects.
- Some, primarily regional, human rights treaties would allow for a state's unilateral withdrawal from the treaty. In practice, the option of withdrawal has figured in the political discourse, for instance after a government has received a ruling by a regional human rights court but no state has actually resorted to withdrawal from human rights treaties as a response to terrorism.
Tuesday, June 29, 2010
Detecter Deliverable: Privacy, Secret Detention Centres and Overflights
Executive Summary
- Article 17 of the International Covenant on Civil and Political Rights (ICCPR) establishes the right to privacy. The implementation of this right is monitored by the Human Rights Committee. The Committee has emphasized that interference in the right to privacy must be foreseeable; mechanisms should be established to prevent abuse of collected information and to ensure review, supervision and redress; and vulnerable groups should be protected. The Committee has, however, not established clear guidance about which substantive measures would be considered a violation of the right of privacy.
- News media and NGOs reported in 2005 about secret detention centres and overflights in Europe as part of US counter-terrorism strategy. Such activities gave rise to several human rights concerns. The Parliamentary Assembly of the Council of Europe initiated an inquiry into these matters. The Secretary General requested member states to provide relevant information. The European Commission for Democracy through Law (Venice Commission) prepared an opinion on the human rights aspects. Cooperation was also established with the European Parliament of the European Union. This cooperation uncovered suspicious patterns of military and civilian aircraft and indications of secret detention centres. They were also able to put political pressure on the respective international organs and on national governments. The Committee of Ministers of the Council of Europe, however, failed to follow up strongly, and the European Parliament deplored the lack of follow up by the Council of the European Union, and by member states.
- Several UN organs have been involved in the issues of secret detention and overflights, including the Human Rights Committee, the Committee Against Torture, the Special Rapporteur on the promotion and protection of human rights while countering terrorism, the Special Rapporteur on torture and other cruel, inhuman or degrading treatment or punishment, the Working Group on Arbitrary Detention and the Working Group on Enforced or Involuntary Disappearances. The UN organs have generally been more reactive than what was the case of the European Parliament and the Parliamentary Assembly. But all the bodies have, within their mandates, addressed these matters. They have helped to uncover certain facts, but have not been able to establish ‘hard facts’ about the relevant activities. These bodies have, however, the benefit of being able to have a more continuous focus on such cases. Furthermore, they have a global focus, and may thus engage in activities beyond the European context.
News: New US/EU Agreement on Transfer of SWIFT Banking Data
Final agreement on the new wording was reached on Friday (25 January). After the draft agreement had been initialled by Malmström on 10 June, MEPs had demanded
changes to the text concerning the bulk transfer of data, the creation of an EU counterpart to the US Terrorist Finance Tracking Programme (TFTP), and EU oversight of TFTP data-processing on US soil.
The three largest political groups in the Parliament – the centre-right EPP, centre-left PES and liberal ALDE – are now in favour of the agreement. In February, the Parliament, using new powers under the EU's Treaty of Lisbon, had rejected an interim agreement on SWIFT transfers.
Over at the Legalift Mathias Vermeulen has a discussion of some of the new restrictions build in to the new agreement, such as a ban on the use of this information for data mining, the possibility of administrative redress for EU citizens and the involvement of Europol in verifying and approving US requests for data.
In its coverage the Register points out that the European Data Protection Supervisor continues to question the need for mass transaction and long term storage of this data, and has additionally called for more oversight.
Thursday, May 20, 2010
News: Negotiations Reopen on US Access to SWIFT Bank Data
A Commission source told Euractiv.Com that “in the coming months little will be known about the substance of the actual negotiations”
The agreement will be concluded only after the adoption by the member states of the EU at qualified majority voting and the approval of the European Parliament. The Parliament introduced two weeks ago theconditions on the content of a future agreement, including for bulk transfers of personal data to the USA to be avoided, if necessary by processing them within the EU, and for Europe’s citizens to be guaranteed the right of appeal to the US authorities.
Wednesday, May 19, 2010
News: More European Anger at Google Invasions of Privacy
From Privacy Digest: Google have admitted gathering private data on internet use in the course of the taking photographs for the Google Street View programme.
Google acknowledged on Friday that it had collected snippets of private data around the world. In a blog post on its Web site, the company said information had been recorded as it was sent over unencrypted residential wireless networks as Google’s Street View cars with mounted recording equipment passed by.
The data collection, which Google said was inadvertent and the result of a programming error, took place in all the countries where Street View has been catalogued, including the United States and parts of Europe. Google apologized and said it had not used the information, which it plans to delete in conjunction with regulators.
The Register reports that both Germany prosecutors and the Czech Republic data protection agency have launched investigations:
In effect, Mountain View may have hoovered up emails and other private information if the Google cars travelled over Wi-Fi networks while one of its vehicles was in range. The firm had previously claimed that no payload data was ever intercepted.
Hamburg prosecutors said they had received a complaint against unnamed Google workers over the “unauthorised interception of data”, and confirmed that an investigation - that could take about a fortnight to determine if the allegations warrant a full-blown probe - was underway.
Wednesday, February 3, 2010
News: European Parliament due to Decide on SWIFT Soon
Adam Szubin, director of the Office of Foreign Assets control at the Treasury, said the intelligence programme processing the Swift data "provides perhaps the most important source on terrorism financing".
The European parliament looks set to block an interim agreement negotiated by the European Commission and representatives of the member states. "It's very unlikely to go in favour of the Swift agreement," one diplomat said.