Hiển thị các bài đăng có nhãn data protection. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn data protection. Hiển thị tất cả bài đăng

Thứ Sáu, 17 tháng 4, 2015

Biometric data and data protection law: the CJEU loses the plot


 

Steve Peers

Many people are increasingly concerned about adequate protection of their biometric data. To this end, the proposed EU data protection Regulation would classify that data as sensitive data, ensuring an extra degree of protection for it. But in the meantime, before that proposal is adopted, there are other EU measures which regulate the issue. Unfortunately, yesterday’s judgment of the CJEU in Willems and others does an inadequate job, with great respect, in applying the current EU rules to such data.

Background

The Willems judgment concerns biometric data collected for passports, as provided for in an EU Regulation of 2004, as amended in 2009. In fact, the CJEU has ruled on this Regulation several times before. In UK v Council, it (unconvincingly) ruledthat the UK could not participate in the Regulation, since it was closely linked to the parts of Schengen rules (the abolition of internal border controls) in which the UK didn’t participate. In Schwarz, it ruled that the Regulation was valid from two different angles, as it was correctly adopted using the ‘legal base’ allowing the EU to adopt measures on external border control, and the interference which it entailed with the right to privacy was justified by the interest in ensuring the identity of passport holders and the validity of the passport. Finally, the Court recently ruled on the privacy aspects of displaying names in passports (as discussed here).

Building on these judgments, the national court in Willems had two questions. First of all, did the Regulation apply to some types of identity cards, given that they can in effect be used as passports for travel within the EU? Secondly, the national court asked the CJEU to interpret the data protection rules applicable to the further use of biometric data after it was collected for the purposes of passports. The latter question stemmed from the concern of the litigants in this case that their biometric data would be stored on a centralised database with inadequate security, which would be used for other purposes without a clear identification of who would have access to it.

More precisely, the national court’s second question was whether ‘Article 4(3) of [the passport Regulation, read] in light of Articles 7 and 8 of the Charter of Fundamental Rights of the [EU], Article 8(2) of the [ECHR] and Article 7(f) of [the current data protection Directive], read in conjunction with Article 6(1)(b) of that Directive’, required a guarantee that when collecting biometric data under the Regulation, Member States had to apply a ‘purpose limitation’ rule that such data  could only be used for the original purpose for which the passport was issued.

Judgment

On the first question, the CJEU looked at the wording of the Regulation, which specified that it did not apply to ‘identity cards issued to [Member States’] nationals or to temporary passports and travel documents having a validity of 12 months or less’. The Court ruled that the words ‘having a validity of 12 months or less’ only set out the scope of the Regulation as regards ‘temporary passports and travel documents’, meaning that such documents werewithin the scope of the Regulation if they were valid for more than 12 months. On the other hand, the words ‘having a validity of 12 months or less’ did not set out the scope of the Regulation as regards national identity cards. So no identity cards fall within the scope of the Regulation, regardless of the period of their validity.

On the second question, the CJEU ruled that the passport Regulation only governed the use of data for the purposes of that Regulation. Any further use of that data, as specified in the preamble, was regulated by national law. It followed that the Regulation did not apply a purpose limitation rule upon Member States as regards biometric passport data. Because the Regulation did not apply to such uses by Member States, the EU Charter did not apply either, although such further use of data might be restricted by national law or the ECHR. Finally, as for the data protection Directive, the CJEU stated that ‘the referring court was requesting the interpretation of [the passport Regulation] and only that Regulation’, so there was no need to examine whether the data protection Directive affected national law on the further storage and use of biometric data collected for passport purposes.

Comments

I won’t mince words: this judgment is appalling.  It’s sensible enough as regards the scope of the passports Regulation itself, which clearly wasn’t intended to apply to any national identity cards or to the creation of government databases using biometric data. But the Court’s fundamental flaw is its failure to confirm and elaborate upon the application of the Charter and the data protection Directive to such databases.

Let’s examine those two points in turn. As regards the Charter, of course it’s true, as the Court says, that it only applies when a dispute falls within the scope of EU law. But the Court made that point only as regards the scope of the passports Regulation, before (not) answering the question about the data protection Directive. Logically the Court cannot conclude that this dispute is not linked to EU law before it assesses also whether the data protection Directive applies.

Anyway, if we apply the Court’s own case law, the link to the passports Regulation alone brings this issue within the scope of the Charter. In NS, a key judgment on the scope of the Charter, the EU’s Dublin Regulation left an option to Member States to decide in their national law whether to consider asylum applications which fell within the responsibility of another Member State. But the Court ruled that the Charter applied to such national discretion. More relevantly, in a line of cases starting with Promusicae, the Court applied the Charter in detail to a national optionto provide for the collection of personal data on use of the Internet set out in EU law. And in last year’s Digital Rights judgment, the Court invalidated the EU’s data retention Directive for the very reason that this Directive failed to effectively regulate the further national use of personal data collected pursuant to it.

As regards the question about the data protection Directive, the CJEU’s answer simply departs from reality. It is quite clearly not true that the national court was ‘only’ asking for an interpretation of the passport Regulation. As we can see from the text of the question excerpted above, it also asked the CJEU to interpret the data protection Directive. Admittedly, it only asked the CJEU to interpret the Directive in the context of the Regulation. But the CJEU does not make that distinction clear; and more importantly, that distinction just doesn’t matter.

Why? Because the CJEU has frequently rephrased questions by national courts in order to give a full reply to the EU law issues which they are actually having to address in the relevant litigation. The examples are legion, but the most relevant one is the judgment in Promusicae. In that case, which concerned mass interception of Internet users’ activity for the purposes of enforcing intellectual property rights, the national court only asked questions about EU intellectual property law and the e-commerce Directive. The CJEU quite rightly redrafted the questions in order to give an answer about the relevant data protection rules (in that case, the e-privacy Directive) as well. In Willems, the national court had already identified the relevance of the data protection Directive, so a comparatively minor redraft of its questions would have sufficed in order to ensure a reply that was fully relevant to the national litigation.

The Court’s ruling is also unsatisfactory in the broader context of the legislation and case law on similar issues. When it asserted that national law applied to databases of biometric data, the CJEU only selectively quoted from the preamble to the passports Regulation. Recital 4 of the preamble to the 2004 Regulation states that access to the data collected as regards biometric passports is ‘subject to any relevant provisions of [EU] law’. Moreover, the CJEU interpreted the data protection Directive as regards a comparable national database (a collection of information on foreign nationals) in the Huberjudgment. I should note that the data protection Directive also applies where the passport Regulation does not: to biometric information collected as regards identity cards, and to passport biometric information collected in the Member States that are not bound by the Regulation (the UK and Ireland). Finally, the Court’s indifference to the fate of biometric data collected by Member States as regards passports seriously undercuts its own rulinge in Schwarz, when it defended the validity of the passports Regulation on the basis of the limited scope of its interference with privacy rights (proportionality), and quoted the S and Marper judgment of the European Court of Human Rights to the effect that ‘the [EU] legislature must ensure that there are specific guarantees that the processing of such data will be effectively protected from misuse and abuse’.  

At first sight, these criticisms of the ruling may seem legalistic. But my concerns are about much more than the deep flaws in the Court’s legal reasoning here. As we all know, the scope of databases and mass surveillance of individuals (‘big data’) have increased exponentially in recent years. This raises huge human rights issues and EU law has a significant role to play. Last year, in its judgments in Digital Rights and Google Spain, the CJEU genuinely tried to grapple with these issues. Many aspects of these judgments have been criticised, but the Court is at its best when it fully engages in these important legal debates. When it avoids them, with the specious legalism it spouts in Willems, it is at its worst.
 
Image credit: Dailyalternative.co.uk
Barnard & Peers: chapter 9, chapter 26

Thứ Hai, 9 tháng 3, 2015

Basic data protection principles in the proposed Data Protection Regulation: Back to the Future?




Steve Peers

So far, 2015 is not like the Back to the Future movies promised it would be like. In particular, there are no hoverboards (drones are a poor substitute). Moreover, instead of agreeing a data protection framework fully fit for 2015, the Council is probably about to agree that the key principles of the law should remain as they were in 1995 – which might as well be 1985 (or even 1955) in terms of technology law.

Background

The negotiations on the EU’s proposed General Data Protection Regulation finally seem to be nearing the final stretch, as far as the Council is concerned. Member States’ ministers in the Council seem likely to agree later this week on two more parts of the proposed Regulation: on basic principles of data protection (text here) and on supervisory authorities, including the idea of a ‘one-stop shop’ for data protection supervision (text here).

Previously they had agreed on three other parts of the Regulation, namely rules on: territorial scope and external relations (see discussion here); public-interest exceptions (see here); and the roles of data controllers and processors (see here; see particularly the discussion of the ‘privacy seals’ rules here). (For full consolidated text of everything the Council has agreed to date, see here). If the proposed texts on principles and data protection authorities are indeed agreed this week, the Council mainly only has to agree on the scope and definitions in the Regulation, along with the rights of data subjects, such as the right to be forgotten (see discussion of the proposed text on that issue here), and related individual remedies.

This blog post focusses on the issue of basic data protection principles. The Commission’s proposalsuggested some fairly modest changes to these basic rules as compared to the current data protection Directive, although the European Parliament (EP) would like to go further than the Commission (see its position here). However, the Council’s position would entail very modest changes indeed to the status quo. For this aspect of data protection law, if the Council has its way, the EU’s lengthy legislative reform journey would end up much where it originally started.

Details

Currently, the data protection Directive begins with a clause (Article 5) which appears to give the Member States a great deal of discretion in how to apply the Directive. The CJEU effectively sidelined that clause in its ASNEFjudgment, emphasising instead the need for uniform interpretation of the Directive. The new Regulation would suppress this clause entirely, but the Council in particular wants to reintroduce a number of specific provisions referring back to national law. So in some respects, the current Directive resembles a Regulation already – but conversely, the future Regulation will continue to resemble a Directive. 

The basic principles of data protection as proposed and (nearly) agreed by the EU institutions are similar to the current Directive: fair and lawful processing; purpose limitation; data minimisation; accuracy; and storage minimisation. The changes would concern: the addition of ‘transparency’; some express protection for archiving or other scientific purposes; and the insertion of data security (by both the EP and the Council). The EP also suggests that the effective protection of rights should be listed as one of the principles. This is a useful suggestion, since although it might seem at first sight that such effective protection is a procedural, not a substantive rule, in the field of data protection it is necessary to ensure that procedural rights are built in to the system (the so-called ‘privacy by design’). An example would be a social network that makes it easy to complain that the user’s privacy has been violated.

Next, the proposal sets out the grounds for processing personal data, again based on the current Directive: consent; contract; compliance with a legal obligation; vital interests of the data subject; public interest or official authority; or legitimate interest of the controller or a third party, subject to an override for the privacy of the data subject. The latter rule is particularly important for the private sector, in the absence of consent or a contract, and the case law points in different directions. In ASNEF, the CJEU ruled that Member States restricted direct marketing companies too much in the interests of consumers, but in Google Spain(discussed here) it ruled that the privacy interests of those named in search results overrode Google’s financial interests as regards its search engine.

The rules would be amended to: refer to consent for specific purposes; extend to the vital interests of another person (according to the Council); and consider the interests of children as regards the ‘legitimate interests’ clause. (The Commission proposal, agreed by the EP, defines a child as anyone under 18; the Council has not agreed this definition yet). Also, the Commission would like to remove the possibility that the legitimate interests of third parties are a ground for processing, but the EP and Council both want to keep this. However, the EP wants to add an important new proviso that such private interests are linked to the ‘reasonable expectations’ of the data subject.  The Council also wants to retain the current rule that consent must be ‘unambiguous’, while the EP and Commission want to delete this adjective.

Furthermore, the institutions differ greatly on what happens if the purpose of data processing is changed. The Commission proposes that changing the purpose should be acceptable on any of the grounds for the initial processing of the data, except for the legitimate interests of the controller. The Council wants to allow a change of purpose for any of the grounds for the initial processing, including the legitimate interests of the controller; while the EP does not want to provide expressly for any incompatible processing at all. The Council’s position in particular would turn the purpose limitation principle into the very smallest of figleaves.

One of the most significant changes in the new rules would be a definition of consent (the CJEU has not yet been asked to clarify this concept under the current Directive). All the institutions agree that the data controller would have to prove consent. The Council’s version would add some very useful rules requiring the data controller to use plain language, while the EP would specify that the relevant contractual terms would be void. The institutions also agree that there should be an express power for the data subject to withdraw consent, although it’s arguable that such a power already exists implicitly under the current rules. Finally, the Commission wants a new clause that would reject the possibility of consent if there is a ‘significant imbalance’ between the data subject and the data controller, and the EP wants to disapply contract terms which are unnecessary for supplying a service. However, the Council rejects entirely the idea that the Regulation should protect Davids from Goliaths.

The other significant change would be a specific rule on children. The Commission proposes that information society services must get the consent of the parents of children under 13. This broadly reflects social networks’ practice of either requiring consent or not permitting younger children to join their network (as we know, this is not fully effective in practice). But the Council version, if agreed, will refer instead to national laws on contract, removing the reference to a particular age. For its part, the EP would broaden the scope of the clause to refer to all supply of goods and services, and would also add a very useful ‘plain language’ clause. Unfortunately, none of the EU institutions propose an amendment which would enormously improve the lives of parents across Europe: an EU-wide hour-long daily limit on children playing Minecraft.

Next, the proposed Regulation keeps largely intact the supposed prohibition on processing so-called sensitive personal data, namely data on racial origin, political opinions, religious beliefs, trade union membership and health or sex life. All institutions agree to add ‘genetic data’ to this list. The EP and Commission also want to add criminal convictions, but the Council wants to retain the current separate rule on this type of data. Furthermore, the EP wants to add sexual orientation, gender identity and biometric data to the list.

The ‘prohibition’ on processing such data is a legal fiction, since both the current rules and the proposed Regulation allow it to be processed on a number of grounds. In fact, the Council will likely agree to extend those grounds, to include social security and social protection, judicial activities, public health and archiving. The Council also wants to retain the current rule that consent by the data subject must be ‘explicit’, while the EP wants to add the possibility of processing based on a contract.

Finally, both the EP and the Council want to strengthen the current rule providing that the data controller is not obliged to obtain further data on the excuse that it has to identify the data subject in order to apply data protection law.

Comments

In summary, the Council’s likely version of the future Regulation would only differ from the current Regulation as regards: new principles of transparency and security; a new definition of consent; a largely cosmetic clause on children’s consent (since it refers back to national law); and a small extension of the list of sensitive data, coupled with a bigger list of exceptions to the prohibition on processing that data.

For its part, the EP would: add a new principle of effective exercise of rights; adjust the balance of interests between the data subject and data controller; limit incompatible further processing; curtail questionable contract terms; strengthen children’s rights; and widen the scope of the concept of sensitive data.

Despite all the fuss made over the proposed new legislation, the Council’s changes would amount to a very marginal change in the rules. (To be fair, though, there would be bigger changes in some other areas of data protection law, such as the new ‘one-stop-shop’ rules).  In particular, there are manifold protections for research-related activities in the Council version of the text: the end is clearly not as nigh for research as many advocates of it have been predicting. The key differences between the EP and the Council concern the balance between corporate interests and individual privacy rights, where it seems that companies have successfully lobbied the Council to make no significant changes, while privacy NGOs have convinced the EP to argue for modest improvements in individual rights. The forthcoming negotiations between the EP and the Council on the final version of the Regulation will determine whether the new rules will genuinely be different, or will merely amount to old cookies in new jars.  

 

Thứ Tư, 11 tháng 2, 2015

Bringing the Panopticon Home: the UK joins the Schengen Information System


 

Steve Peers

Over two hundred years ago, British philosopher Jeremy Bentham devised the concept of the ‘Panopticon’: a prison designed so that a jailer could in principle watch any prisoner at any time. His theory was that the mere possibility of constant surveillance would induce good behaviour in prison inmates. In recent years, his idea for a panopticon has become a form of shorthand for describing developments of mass surveillance and social control.

The EU’s forays in this area began with the creation of the Schengen Information System (SIS) in the 1990s. The SIS is a well-known EU-wide database containing enormous amounts of information used by policing, immigration and criminal law authorities.  

Until now, the UK has not had any access to the SIS. But this week, the EU Council finally approved the UK’s participation in the System, thereby linking the EU’s most iconic database with the intellectual home of the panopticon theory. What are the specific consequences and broader context of this decision?

Background

The main purpose of the Schengen system is to abolish internal border checks between EU Member States, as well as some associated non-EU States.  At the moment, the full Schengen rules apply to all EU Member States except the UK, Ireland, Cyprus, Romania, Bulgaria and Croatia. Those rules also apply to four associates: Norway, Iceland, Switzerland and Liechtenstein.

All of the Member States are obliged ultimately to become part of the Schengen system, except for the UK and Ireland. Those two Member States negotiated an exemption in the form of a special Protocol at the time when the Schengen rules (which originated in the Schengen Convention, ie a treaty drawn up outside the EU legal order) were integrated into the EU legal system, as part of the Treaty of Amsterdam (in force 1999).

The UK and Ireland are not entirely excluded from the Schengen system. In fact, they negotiated the option to apply to join only some of the Schengen rules if they wished. Their application has to be approved by the Council, acting unanimously. The UK and Ireland essentially chose to opt in to the Schengen rules concerning policing and criminal law, including the SIS, but not the rules concerning the abolition of internal border controls and the harmonisation of rules on external borders and short-term visas.

The UK’s application to this end was approved in 2000 (see Decision here), and Ireland’s was approved in 2002 (see Decision here). But in order to apply each Decision in practice, a separate subsequent Council decision was necessary, because the Schengen system cannot be extended before extensive checks to see whether the new participant is capable of applying the rules in practice.  On that basis, most of the Schengen rules which apply to the UK have applied from the start of 2005 (see Decision, after later amendments, here). The exception is the rules on the SIS, which the UK was not then ready to apply. After spending considerable sums trying to link to the SIS, the UK gave up trying to do so, on the basis that the EU was anyway planning to replace the SIS with a second-generation system (SIS II). There’s a lot of further background detail in the House of Lords report on the UK’s intention to join the SIS (see here), on which I was a special advisor. (Note that Ireland does not apply any of the Schengen rules in practice yet).

It took ages for the EU to get SIS II up and running, and it finally accomplished this task by April 2013 (see Decision here). The UK had planned to join SIS II shortly after it became operational, but this was complicated by the process of opting out of EU criminal law and policing measures adopted before the entry into force of the Treaty of Lisbon, and simultaneously opting back in to some of them again, on December 1st 2014 (see discussion of that process here). This included an opt back in to the SIS rules.

Once that particular piece of political theatre concluded its final act, the EU and the UK returned to the business of sorting out the UK’s opt in to SIS II in practice. This week’s decisioncompleted that process, giving the UK access to SIS II data starting from March 1st. The UK can actually use that data, and enter its own data into the SIS, from April 13th.

Consequences

What exactly does participation in the SIS entail? The details of the system are set out in the 2007 Decisionwhich regulates the use of SIS II for policing and criminal law purposes. There are also separate Regulations governing the use of SIS II for immigration purposes and giving access to SIS II data for authorities which register vehicles. The former Regulation provides for the storage of ‘alerts’ on non-EU citizens who should in principle be denied a visa or banned from entry into the EU, while the latter Regulation aims to ensure that vehicles stolen from one Member State are not registered in another one. The UK participates in the latter Regulation, but not the former, since it could only have access to Schengen immigration alerts if it fully participated in the Schengen rules on the abolition of internal border controls. On current plans, this will happen when hell freezes over.

The SIS II Decision provides for sharing ‘alerts’ on five main categories of persons or things: persons wanted for arrest for surrender or extradition purposes (mainly linked to the European Arrest Warrant); missing persons; persons sought to assist with a judicial procedure; persons and objects who should be subject to discreet checks or specific checks (ie police surveillance); and objects for seizure or use as evidence in criminal proceedings. There are also rules on the exchange of supplementary information between law enforcement authorities after a ‘hit’. For instance, if the UK authorities find that a European Arrest Warrant has been issued for a specific person, they could ask for further details from the authority which issued it.

On the other hand, the SIS does not, as is sometimes thought, provide for a basis for sharing criminal records or various other categories of criminal law data, although the EU has set up some other databases or information exchange systems dealing with such other types of data. (On criminal records in particular, see my earlier blog post here). The main point of setting up the second-generation system was to extend the SIS to new Member States (although in the end a new system wasn’t actually necessary for that purpose), and to provide for new functionalities such as storing fingerprints, which will likely be put into effect in the near future.

In practice, the UK’s participation in SIS II is likely to result in the Crown Prosecution Service receiving more European Arrest Warrants (EAWs) to process, and in more efficient processing of EAWs which the UK has issued to other Member States. It will also be easier, for instance, to check on whether a car or passport stolen in the UK has ended up on the continent, or vice versa.

Broader context

As noted already, while the UK is only now joining the SIS, the System has been around for many years, and has proved to be the precursor of many EU measures in this field. Indeed, as EU surveillance measures go, the SIS turned out to be a ‘gateway drug’: the friendly puff that led inexorably to the crack den of the data retention Directive.

Of course, interferences with the right to privacy can be justified on the basis of the public interest in enforcement of criminal law and ensuring public safety – if the interference is proportionate and in accordance with the law. Compared to (for instance) the data retention Directive and the planned passenger name records system, the SIS is highly targeted, focussing only on those individuals involved in the criminal law process, or police surveillance, or banned from entry from the EU’s territory. The legitimacy of the system therefore depends upon the accuracy and legality of the personal data placed in to it, and the connected data protection rules. On this point, the EU and national data protection supervisors have reported that many data subjects do not even know about the data held on them in SIS II, and they have produced a guide to help them with accessing their data in the system.

There’s an inevitable tension between the EU’s goal to set the world’s highest data protection standards, on the one hand, while also developing multiple huge databases, information exchange systems and surveillance laws, on the other.  It’s as if the brains of the utilitarian Jeremy Bentham and the libertarian John Stuart Mill were both battling for control of the same body – forcing it to draw up plans for the Panopticon at the same time as it was storming the Bastille. If this tension manifested itself in fiction, it would probably take the form of a comedy about a vegetarian butcher, or a virgin porn star. But the need to ensure that measures to protect our security do not remove all our liberty is not a laughing matter.

 

*This blog post is linked to ongoing research on the upcoming 4th edition of EU Justice and Home Affairs Law (forthcoming, OUP).

 

Image credit: nytimes.com

Barnard & Peers: chapter 25

Thứ Năm, 11 tháng 12, 2014

Bringing Data Protection Home? The CJEU rules on data protection law and home CCTV


 

Lorna Woods, Professor of Law, University of Essex

 
Does EU data protection law apply to home CCTV cameras? The CJEU addressed that issue yesterday in the judgment in Case C-212/13 Ryneš v. Úřad pro ochranuosobníchúdajů. In its judgment, the Fourth Chamber of the Court agrees with the Advocate-General's  opinion (discussed here), although it avoids some of the difficult questions hinted at in that opinion.

This judgment is significant in two ways. First, it has potentially broader application than just to fixed surveillance devices and could indicate the way data recording devices are used in public spaces even by private individuals.  Second, it forms part of a train of judgments highlighting the significance of data protection for individuals. This significance is perhaps reflected in the fact that eight member States made submissions before the court.
 

Facts

Mr Ryneš and his family had for several years been subjected to attacks by persons whom it had not been possible to identify and the windows of the family home had been broken on several occasions.  As a result, he installed CCTV cameras under the eaves of his house.  The camera was installed in a fixed position and could not turn; it recorded the entrance to his home, the public footpath and the entrance to the house opposite.  The images were recorded to hard drive, and subsequently over-written by new recordings.  A further attack took place but it was possible to identify the suspects because of the CCTV.  The recording was handed over to the police and relied on in the course of the subsequent criminal proceedings.  One of the suspects challenged the use of CCTV in this way: arguing that Mr Ryneš had not complied with the Czech rules implementing the EU Data Protection Directive (DPD). Mr Ryneš essentially argued that the matter did not come within the DPD because of the application of the ‘household exception’ in Article 3(2) DPD. It was the scope of that provision that was referred to the CJEU by the national court.
 

Judgment

The Court began by confirming that CCTV surveillance in principle constitutes the processing of personal data so far as it makes it possible to identify the person concerned [paras 22-25].  The Court then turned its attention to the question of whether the situation escaped the application of the DPD in so far as it is carried out ‘in the course of a purely personal or household activity’ for the purposes of the second indent of Article 3(2) DPD.

The Court emphasised that the purpose of the DPD is to ensure a high level of protection for personal data – seen as part of an individual’s privacy and in so doing referred to Google Spain and Google (C‑131/12), and that, following IPI (C‑473/12, para 39) and Digital Rights Ireland and Others(C‑293/12 and C‑594/12, para 52) restrictions on data protection must apply on so far as strictly necessary [para 28].  Further, the DPD must be construed in the light of the Charter. These factors meant that Article 3(2) DPD should be construed narrowly [para 29]. In the Court’s view this approach followed also from the wording of Article 3(2) in any event: the use of the word ‘purely’ indicates a narrow range of circumstances. Following the reasoning of the Advocate General, the Court held that:

‘To the extent that video surveillance such as that at issue in the main proceedings covers, even partially, a public space and is accordingly directed outwards from the private setting of the person processing the data in that manner, it cannot be regarded as an activity which is a purely ‘personal or household’ activity for the purposes of the second indent of Article 3(2) of Directive 95/46.’ [para 33]

While the DPD applies, the Court noted the possibility of the data controller’s legitimate interests and other possible exceptions in the Directive being taken into account [para 34] although the Court did not elaborate further on such balancing in this instance.
 

Comment

This case is not the first case that has considered the scope of the ‘household exception’: Lindqvist (C-101/01) was the first, which held that the ‘household exception’ did not apply to the posting of information on a web site. According to the Court then, the exception clearly did not apply because the making available of information to an indefinite number of people was not an activity carried out in the course of the private or family life of an individual.  The reasoning here is not clear, and is replete with assumptions (what is the position of an on-line personal diary, for example?). It is perhaps because of the lack of clarity that the Court here did not cite Lindqvist– a rather noticeable omission otherwise.  Rather it, like the Advocate-General before it, went back to first principles about the value and status of data protection. This is the beginning of a stream of data protection cases – arising in very different circumstances – in which the Court has repeatedly ascribed a high value to data protection and the protection of privacy. These cases then should be seen not as isolated, but as part of consistent body of rulings on this point.  What was clearer from the Opinion in this case was the fact that this high value ascribed to the protection of personal data applies as between individuals, as well as constraining the activities of the State.
 

While it might be standard practice to view exceptions as to be construed narrowly, the Court does not give us much information as to how to define this in practice. What we have instead is the assertion that something that impinges on a public space cannot be ‘purely’ private. Balancing of interests takes place as a consequence within the framework of the DPD, essentially by virtue of Article 7(f)DPD, which allows data processing to take place in the legitimate interests of the data controller (in this case, the homeowner interested in protecting his security), balanced against the interests of the data subject (the criminal suspects in this case), rather than by determining whether the DPD applies or not.  This approach probably allows for a more subtle approach to the question of respective interests, although as Article 29 Working Party (the advisory body made up of national data protection supervisors) have noted there is not much consistency across the Member States on how to interpret Article 7(f) DPD (Opinion 06/2014).  There has been concern that, given the openness of its wording, Article 7(f) could be used to undermine the effectiveness of data protection.  Here, presumably protection of private property would weigh heavily (the Article 29 Working Party give security as an example of a ‘legitimate interest’), though the balancing of interests might be different in the context of someone passing in the street and someone visiting the house opposite.
 

This then leads us to the question of when else the principles in Ryneš might apply.  The obvious example is devices capable of recording personal data in public spaces. In addition to CCTV, drones and body worn video used by local authorities and the police in the law enforcement context, we should think here about mobile phones with cameras and devices such as Google glass, which have already been flagged up as potentially problematic in regulatory terms. While Google may have taken steps to improve privacy by design in this device, this does not absolve users from responsibility under the data protection regime if it applies to them.  If we take the approach that even partial public use of a fixed CCTV system cannot benefit from the household exception, still less would a portable, possibly inconspicuous device the purpose of which is uncertain.  The reasoning seems stronger still if we consider the possible onward use of such data – via a website for example (though note the Article 29 Working Party’s view on social networking sites in Opinion 5/2009)– taking into account the view in Lindqvist.  Here it is less clear to see that the legitimate interests of the data controller (ie the person using the device to record and store personal data),assuming the processing were to be deemed ‘necessary’ to pursue that interest, would weigh heavily against a high level of protection for data protection even as between individuals (see views of Article 29 Working Party on freedom of expression arguments in this context).
 

How might this judgment apply to specific cases? A parent would have a legitimate interest in photographing or filming his or her children or friends, although there might be constraints (taking account of the Peck v UK judgment of the European Court of Human Rights, where Article 8 ECHR was breached after CCTV footage of an attempted suicide was shown on national television) on how much such footage might be shared in future. Indeed, broad sharing of those images (for example uploading to a website without privacy protection as in Lindqvist) could constitute an act of processing outside the household exception, which should therefore comply with DPD requirements too.  Photographs taken within the context of private and family life but then used by journalists presumably also fall within the scope of the Directive, although in that case the relevant provision would be the rather general clause which provides for balancing the right to privacy and the freedom of expression.
 

CCTV cameras which fully face public streets and areas open to the public like shopping malls are obviously covered by the Directive, so processing must comply with the requirements of Article 6 of the Directive unless any other exceptions are applicable. CCTV used in workplaces would obviously not fall within the scope of the household exception, so the requirements of the DPD regarding processing would apply. Depending on the nature of the footage there would be further limits on sharing that footage (images of hospital patients, for instance, would reveal sensitive data about their health). Finally, there might be hybrid locations which are both public and private (for instance, a care home is both a residence and a workplace). Given that the Court has emphasised the household exception arises only when the processing can be tied ‘purely’ to private and family life hybrid locations are unlikely to be considered within the household exception.  In the example of the care home, this is especially likely to be true given that the data controller is likely to be the operator of the care home using CCTV for operational reasons, rather than private ones. Of course, it would still be possible to justify the use of CCTV in such cases in accordance with the Directive.

 

Barnard & Peers: chapter 9

 

Thứ Ba, 25 tháng 11, 2014

The Domino Effect: how many EU treaties violate the rights to privacy and data protection?


 

Steve Peers

Earlier this year, the Court of Justice of the European Union (CJEU) ruled in the Digital Rights judgment against the validity of the EU’s data retention directive, on the grounds that it provided for mass surveillance without any effective safeguards. Subsequently it ruled against Google,in what has become known as the ‘right to be forgotten’ judgment.

What are the longer-term consequences of the Court’s ‘Privacy Spring’? An Irish court has already referred the ‘Europe v Facebook’ case (discussed here) to the CJEU, asking in effect whether the EU’s ‘Safe Harbour’ arrangement on data protection with the USA is compatible with the rights to privacy and data protection, in light of the Snowden revelations. Now the European Parliament (EP) has decided to refer the proposed EU/Canada agreement on passenger name record (PNR) data to the CJEU, asking if it is compatible with the rights to privacy and data protection in light of the Court’s recent case law. That judgment would implicitly determine whether the separate EU/USAand EU/Australia treaties on PNR data, and the proposed PNR Directive, violate those rights also. And if the PNR treaties breach the rights to privacy and data protection, it would then be more likely that the EU/USA treaty on banking data transfers also breaches those rights in turn.

So, are we at the start of a ‘domino effect’ of a series of EU laws and treaties being ruled in breach of the rights to privacy and data protection by the Court of Justice, all falling in sequence now that the data retention Directive has been overturned? Or are the features of the different measures different enough to avoid this?  

Background

There’s a little bit of déjà vu in today’s decision by the EP to ask the CJEU about the EU/Canada treaty on PNR. Back in 2004, it asked the Court to rule on the original EU/USA treaty on the same subject. The Advocate-General’s opinion in that case ruled against all of the EU’s arguments, including the right to privacy point. However, the Court’s 2006 judgment only ruled on one of the EP’s legal arguments – that the EU/USA treaty had the wrong ‘legal base’, and should have been approved by using a different procedure (relating to police cooperation, instead of the internal market). And that procedure meant that the EP had no role in the approval of the treaty, or any power to ask the Court of Justice about its compatibility with EU law.

Eight years later, the legal environment is quite different. Since the Treaty of Lisbon entered into force in 2009, the EP (or the Commission, Council or a Member State) can ask the CJEU for rulings on the compatibility with EU law of EU treaties with third States on police or criminal law cooperation. Indeed, this will be the first such ruling. And while waiting for the Court’s ruling, the EP can prevent the EU/Canada treaty from being concluded, since it now has the power of consent over such treaties (back in 2004, the Council circumvented a separate request by the EP for the CJEU to rule on the EU/USA PNR treaty by concluding that treaty without waiting for the Court’s opinion). Furthermore, the substantive legal environment has obviously been transformed by the Court’s ruling against mass surveillance earlier this year.

The CJEU had another chance to rule on the right to privacy in the international context when the Commission asked it to rule back in 2012 whether the international Anti-Counterfeiting Agreement (ACTA) violated EU law. However, the Commission left it too late to send its request to the Court, and the EP simply vetoed that proposed agreement before the Court could rule (the Commission then withdrew its case). So we should now get a long-awaited ruling from the Court on the compatibility of international data transfers with the EU rights to privacy and data protection – unless the EP can be talked into withdrawing its request to the Court.

The procedure which the EP has invoked today is a special process which allows the Court to rule on the compatibility with EU law of a draft treaty to be concluded by the EU (or by its Member States on behalf of the EU), before that treaty comes into force. (For Canadian readers: this process is broadly similar to sending a request to the Supreme Court to rule on the constitutionality of a draft law. The EU process only applies to treaties, though.) If the CJEU rules (probably in about 18 months’ time, unless the ruling is expedited) that the draft treaty is incompatible with EU law, either the draft treaty has to be amended to comply with the Court’s ruling, or (improbably) the EU Treaties themselves have to be amended to permit its ratification.

The EU/Canada PNR treaty is distinct from the EU/Canada treaty liberalising air transport (already in force), and the proposed EU/Canada free trade agreement (CETA) – although the latter treaty, along with the EU/USA free trade agreement now being negotiated, will be indirectly impacted by a pending case in which the EU Commission has asked the CJEU to rule on whether the EU/Singapore free trade agreement is compatible with EU law.

Comments

So does the EU/Canada PNR treaty violate the right to privacy? There’s a detailed analysis of the broader impact of the data retention judgment on other EU measures in a study by Boehm and Cole, published earlier this year. So this is only a short summary of the issues discussed further in that study. The starting point is how to interpret that judgment: does it rule out all mass surveillance, or just in cases where there are insufficient safeguards? In my view, it does indeed rule out all mass surveillance where it’s linked to EU law, and any draft treaty to which the EU is party would obviously be linked to EU law.

But there’s a prior question: when does a treaty with another State entail mass surveillance? The data retention case concerned collection of data on all phone and Internet use in the EU. This could be compared to the use of social media (in the pending Facebook case), or to international banking transfers, but it’s harder to argue that collection of data on all flights to a particular third country constitutes, by itself, mass surveillance. Having said that, the proposed PNR Directive, which would apply to all flights within the EU, would probably meet the criteria.

If (contrary to my interpretation) the Digital Rights judgment does permit mass surveillance, as long as there are sufficient safeguards, then what must these safeguards be? According to the judgment, there have to be: definitions of the ‘serious crimes’ or other purposes of the data exchange; rules on the subsequent access to the data; limits on the number of people who can access that data; independent control by a court or supervisory authority; strong rules on the data protection period; provisions on protecting data from unlawful access and use; and a requirement to retain the data within the EU only. Obviously, in the context of treaties with non-EU States, the latter requirement must be understood as an obligation to retain the data in the EU or that particular third country.

Do the EU’s treaties with third States meet these criteria? This has to be assessed on a case-by-case basis. At first sight, for example, the EU/Canada PNR treaty contains provisions addressing all of these safeguards issues except one: the transfer of PNR data to other countries, which is permitted (although subject to conditions). But it might be argued that in practice, the right to privacy and data protection is not protected as strongly under such treaties as it might first appear, due to inadequacies in national legislation or practice, such as NSA access to Facebook data or limitations on non-USA citizens claiming privacy rights in the courts.

Finally, there’s an important practical question here. Let’s imagine that the CJEU rules that the proposed EU/Canada treaty violates privacy and data protection rights; or that it approves that treaty, but its reasoning in that judgment casts doubt on the compatibility of other EU treaties with those rights. How can those other treaties be challenged, now that they are already in force?

Time has run out to bring annulment actions against those treaties, or to ask the CJEU for an advance ruling on their compatibility with EU law. But it is still possible for individuals to challenge the application of those treaties via the national courts (as in the Digital Rights and Facebook cases). Or the EP could argue that in order to secure effective protection of rights under the EU Charter of Fundamental Rights, the other EU institutions must take steps to denounce the treaties concerned. If they don’t do so, the EP can sue them for ‘failure to act’ as set out in the EU Treaties.

 
Barnard & Peers: chapter 9

Thứ Hai, 29 tháng 9, 2014

Questions for the would-be home affairs and justice Commissioners




Steve Peers, Emilio de Capitani and Henri Labayle

The would-be Commissioners for immigration and home affairs and Justice will shortly be questioned by Members of the European Parliament (MEPs) in hearings, to determine whether the EP should vote to confirm them in office. MEPs have already asked some written questions and the would-be Commissioners have replied. Since most of the written questions were not very searching (except for a couple of questions on data protection issues), the Commissioners did not reply in much detail.

However, the hearings are an opportunity for MEPs to ascertain the Commissioners’ plans, and to secure important political commitments, in these fields. To that end, we have therefore suggested a number of oral questions which MEPs should ask in the hearings. 

Immigration and asylum

The Commission consider that migration policy should be framed by the (non binding) objectives of the global approach to migration (GAMM) and relations with third countries should be dealt with by “Mobility Partnership” which are more diplomatic declarations than binding acts. Would you propose a binding legal basis for treaties with the countries concerned, grounded on Articles 77, 78 and 79 of the TFEU?

What actions will the Commission take to ensure that EU legislation in this field is fully and correctly implemented by the Member States?

Will the Commission propose an immediate amendment to the EU visa code, to confirm that Member States are obliged to give humanitarian visas to those who need them and who apply at Member States' consulates in third countries?

When will the Commission propose EU legislation to guarantee mutual recognition of Member States' decisions regarding international protection, including the transfer of protection?

When will the Commission make proposals for a framework for sharing responsibility for asylum-seekers and persons who have been granted international protection, starting with those who have applied outside the territory of the Member States?

Will the Commission propose an immigration code, and what will its main contents be?

The Court of Justice has recognised that search and rescue obligations are interlinked with external borders surveillance (Case C-355/10). The EU adopted rules in this field which governing only border control coordinated by Frontex. Do you intend to propose that such rules should apply to all Member States’ border controls as a general rule, by formally amending the Schengen Borders Code ?

What immediate and longer-term steps will the Commission take to address the death toll of migrants crossing the Mediterranean?

Will the Commission propose to amend the EU legislation on facilitation of unauthorised entry to confirm that anyone who saves migrants from death or injury during a border crossing, or who otherwise acts from humanitarian motives, is exempt from prosecution?

Internal Security and Police cooperation

Measures against terrorism and transnational crime were until now mainly taken under the vague framework of “operational cooperation”. Will the Commission propose a clear legal basis for the Internal Security Strategy and transforming the so called “Policy Cycle” in a transparent and legally binding framework where European and national interventions are clearly framed? Will you propose relevant amendments to the Europol legislative proposal which make reference to the policy cycle without framing it? Which initiatives will you take  to implement the principle of subsidiarity and proportionality as foreseen by the Treaty, and to ensure that the Charter must be taken in account also for police cooperation so that the European and national parliaments as well as the Court of Justice could verify that these principles have been complied with ?

According to Protocol 36 (the transitional protocol attached to the Treaty of Lisbon), all measures dealing with police cooperation adopted before the entry into force of that Treaty will fall under the jurisdiction of the Commission and of the Court from 1 December 2014. Some of them are outdated and should be repealed or substantially modified to take in account the post-Lisbon legal and institutional framework (role of the Charter, co-responsibility of the EP, role of the national Parliaments). In several cases where EU measures limit dramatically fundamental rights sunset clauses should be inserted in the basic acts. However nothing about this is written in your statement nor in the previous Commission’s REFIT exercise. Could it be a priority or do you believe that Lisbon Treaty did not change the situation in your domain of competence?

Will your legislative programme also be grounded on the Treaty legal basis of judicial cooperation in criminal matters ? If so, how will you frame the relations with the Commissioner in charge of these aspects ?

Schengen cooperation has been until now the most successful case of cooperation between the Member States and has been recently upgraded by launching SIS II and EUROSUR. The notion of integrated border management in Article 77 TFEU is progressively taking shape but no substantial improvement happens in the role of the European and National parliament. Other similar initiatives like PRUM and Swedish initiatives have been developed following the principle of availability. Do you plan further initiatives here?

For instance, in light of the recent UK case where a convicted murderer moved from one Member State to another, do you intend to propose the exchange of criminal records concerning the most serious crimes by a Member State’s nationals (murder, rape, grievous bodily harm) if those nationals are no longer imprisoned?

Will the Commission propose a police code that recasts EU legislation in this field?

When does the Commission intend to submit a legislative proposal implementing Article 75 of the TFEU dealing with freezing assets of terrorists ?

Justice Commissioner

According to CJEU (Melloni, Radu judgments) the principle of primacy of EU law covers also sensitive domains such as judicial cooperation in criminal matters. It is then important that the EU legislation is set at the highest possible standards of protection of fundamental rights so that by implementing the EU legislation the current level of protection at national level will not be lowered. Do you agree that all future EU legislative proposals on criminal law should make also reference to the possible impact on national law and always permit the possibility of higher national standards as referred to by art. 53 of the Charter ?

Will the Commission commit to propose to amend the Framework Decision on the European Arrest Warrant and other pre-Lisbon measures on mutual recognition in criminal matters, to ensure that there is the same level of protection of fundamental rights as guaranteed in the recent Directive on the European Investigation Order?

When will the Commission propose a measure to ensure adequate protection for suspects as regards pre-trial detention in criminal proceedings in the Member States?

Will the Commission submit further legislative measures to improve the suspect's procedural guarantees?

Fundamental rights protection is meaningless without effective ways to obtain a judicial redress at national or EU level. Will you submit a legislative proposal upgrading the 2013 Commission Recommendation on collective redress mechanisms so that citizens and companies can enforce the rights granted to them under EU law where these have been infringed?

How will the Commission act to ensure that Member States fully and correctly apply EU legislation on the protection of victims' and suspects' rights in criminal proceedings?

OLAF, EUROJUST and EPPO will deal under different perspectives with the problem of protection of EU financial interests. Has the time come to simplify the institutional machinery, for instance by merging OLAF with EPPO ?

Several EU measures such as the Framework decision on terrorism restrict individual freedoms. In these cases should the EU legislation (as well as delegated and implementing acts) should not embody sunset clauses, as it the case for the US legislation (see the Patriot Act)?

Will the Commission commit to propose to the Council that any EU treaty on sharing personal data with third countries will be suspended if, in the view of the European Parliament following an independent review, in practice there is no adequate level of protection of the relevant personal data in that third country?

According to the current and envisaged legislation it will be a Commission’s role to assess the adequacy of data protection in third countries. Do you agree that such evaluation should be done as delegated act as it requires a high level of discretion on the Commission side ?
DIGITAL AGENDA (together with Commissioner Oettinger and VP Ansip)

You will work with Candidate Commissioner Oettinger on the digital agenda who made reference to an ambitious legislative programme soon to be adopted to implement the European Digital Agenda. The EU Treaties offer several legal bases to accomplish such an objective even if the EU is still lacking a comprehensive and consistent legislative strategy which could give specific expression to fundamental rights as defined by the Charter of fundamental rights.

For this reason the Court of Justice has recently annulled the Directive on data retention. However the same fate could occur to other EU legislative measures planned or in negotiation which do not meet the high standards required by the Charter and to avoid challenges from national Courts.

To avoid these risks will you be available to design and implement with your other colleagues in the future Commission (Oettinger Timmermans, and Ansip) a legislative strategy which could become an European "Marco Civil" as the one recently adopted by Brazil ?

The Court of Justice has defined in its data retention ruling very strict criteria to be followed when collecting personal data for security purposes. Even the Council legal service seems to consider that the current EU-US agreements on TFTP and PNR do not fit with these criteria. What do you intend to do at the next Transatlantic summit? Will you notify the US authorities that the agreements should be profoundly revised?

When will the Commission respond to the CJEU ruling on the invalidity of the data retention Directive? Will it propose a new EU Directive which is compliant with the judgment? Does the Commission believe that the Directive still allows for mass surveillance? Will the Commission pursue infringement action against Member States whose legislation is not in compliance with the criteria set out in the judgment?


Barnard & Peers: chapter 25, chapter 26