Thứ Tư, 15 tháng 10, 2014

The proposed General Data Protection Regulation: suggested amendments to the definition of personal data


Douwe Korff, Professor of International Law
I.                    Background

In a recent judgment (discussed previously on this blog) the third chamber of the CJEU has ruled that the concept of "personal data" in the 1995 data protection (DP) directive is limited to data directly relating to a person, and does not include legal analyses in the file on the person, on which the state (NL) relied in taking its decisions in relation to that person (Joined Cases C-141/12 and C-372/12). I believe the Court’s restriction of the concept is wrong and contrary to the intended purpose of data protection; and should be corrected in the new General Data Protection Regulation.

First of all, the Court based itself on the, in my opinion erroneous, view that the 1995 EC DP Directive was solely aimed at protecting privacy. In particular, it felt that the right of data subjects to access to their personal data should not extend to a legal analysis of their case, contained in a file on them, because (in the Court’s view) such an analyses “is not in itself liable to be the subject of a check of its accuracy by [a data subject]”, and data subjects should not be able to use data protection to seek a rectification of such an analysis (cf. para. 44 of the judgment).

Secondly, the Court also relied on the fact that data of the kind at issue in the joined cases was administrative data held by a public authority and, drawing a parallel with EU regulations on privacy and access to documents, held that access to the legal analysis should be addressed under the latter rules rather than the former. This failed to take into account the fact that the EU rules referred to apply only to public (i.e., EU) bodies, whereas the 1995 DP Directive applies also, and in indeed especially, to private-sector bodies (in particular companies) that are not subject to public-sector rules on access to administrative data.

The Court’s judgment, in sum, seriously limits the concept of personal data and the right of access to one’s personal data, and thus seriously limits the application of the entire EU data protection regime. It leaves individuals with seriously less rights in respect of data on them (or relating to them, or used to take decisions on them, or that affect them) than was previously thought.

Specifically,the judgment runs directly counter to the authoritative 2007 Article 29 Working Party (WP) Opinion on the concept of personal data (Opinion 4/2007, WP136, of 20 June 2007). This first of all noted that the purpose of data protection is not limited to a narrow concept of privacy – as is indeed also clear from the fact that data protection is guaranteed in the Charter of Fundamental Rights (CFR) as a separate right, sui generis, from the right to private life/privacy (data protection is guaranteed in Article 8 CFR; Privacy in Article 7 CFR). Astonishingly, given that the WP29 is expressly charged with providing guidance on the interpretation and application of the 1995 DP Directive, the Court did not even mention either the Working Party or this specific opinion.

In the opinion, the Working Party discussed four elements of the definition, from which it deduces the appropriate criteria for determining whether data should be regarded as personal data within the meaning of the directive. They can be paraphrased as follows:

-                      The first element: “any information”:

The WP concludes that these words indicate that the concept of personal data should be interpreted broadly, and not limited to matters relating to a person’s private and family life stricto senso (as has wrongly been done in the UK under the Durant decision, and as appears to also underpin the Court’s judgment). It also covers information in any form, including documents, photographs, videos, audio and biometric data, body tissues and DNA.

-                      The second element: “relating to”:

In general terms, information can be considered to “relate” to an individual when it is about that individual. However, data about “things” can also be personal data, if the object in question is closely associated with a specific individual (e.g., mobile phone location data). This is of increasing importance in the era of the Internet of Things. Important in relation to the CJEU judgment, the WP29 adds the following consideration, with reference to an earlier opinion, on radio frequency identification (RFID) tags, WP105 of 19 January 2005 (original italics and bold; underlining added):

In the context of discussions on the data protection issues raised by RFID tags, the Working Party noted that "data relates to an individual if it refers to the identity, characteristics or behaviour of an individual or if such information is used to determine or influence the way in which that person is treated or evaluated."
...
[I]n order to consider that the data “relate” to an individual, a "content" element OR a "purpose" element OR a "result" element should be present.
The “content” element is present in those cases where - corresponding to the most obvious and common understanding in a society of the word "relate" - information is given about a particular person, regardless of any purpose on the side of the data controller or of a third party, or the impact of that information on the data subject.
...
Also a "purpose" element can be responsible for the fact that information "relates" to a certain person. That “purpose” element can be considered to exist when the data are used or are likely to be used, taking into account all the circumstances surrounding the precise case, with the purpose to evaluate, treat in a certain way or influence the status or behaviour of an individual.
...
A third kind of 'relating' to specific persons arises when a "result" element is present. Despite the absence of a "content" or "purpose" element, data can be considered to "relate" to an individual because their use is likely to have an impact on a certain person's rights and interests, taking into account all the circumstances surrounding the precise case. It should be noted that it is not necessary that the potential result be a major impact. It is sufficient if the individual may be treated differently from other persons as a result of the processing of such data.
...
These three elements (content, purpose, result) must be considered as alternative conditions, and not as cumulative ones. In particular, where the content element is present, there is no need for the other elements to be present to consider that the information relates to the individual. A corollary of this is that the same piece of information may relate to different individuals at the same time, depending on what element is present with regard to each one. The same information may relate to individual Titius because of the "content" element (the data is clearly about Titius), AND to Gaius because of the "purpose" element (it will be used in order to treat Gaius in a certain way) AND to Sempronius because of the "result" element (it is likely to have an impact on the rights and interests of Sempronius). This means also that it is not necessary that the data "focuses" on someone in order to consider that it relates to him. ...
The “legal analyses” that the CJEU ruled were not personal data are clearly covered by the above: they are the very basis on which the data subjects in questions (asylum seekers) were “treated” and “evaluated”. To apply the reasoning of the Working Party: they determine whether Titius should be treated the same way as Gaius or not; and they may also have an impact on the rights and interests of Sempronius.
This is also crucially important in relation to “profiles”. Under the judgment, states and companies could argue that individuals should also not have a right to challenge the accuracy of a profile, any more than the accuracy of a legal analysis; and that, indeed, they are not entitled to be provided on demand with the elements used in the creation of a profile. After all, a profile, by definition, is also based on an abstract analysis of facts and assumptions not specifically related to the data subject – although both are of course used in relation to the data subject, and determine the way he or she is treated.
In my opinion, the above is the most dangerous limitation flowing from the Court’s judgment.
-                      The third element: “identified or identifiable”:
Although this issue did not arise in the CJEU cases, it is still crucial, in particular in relation to the ever-increasing and ever-more-widely-available massive sets of “Big Data”. In the opinion of the WP, the core issue is whether a person is, or can be, singled out from the data, whether by name or not. A name sometimes suffices for this, but often not, while a photograph or an identity number often does allow such singling out even if no other details of the person are known. In relation to pseudonymised or supposedly anonymised data, the WP concluded (with reference to the recitals in the 1995 directive) that the central issue is whether the person can be identified (singled out), whether by the data controller or by any other person, “taking account of all the means likely reasonably to be used either by the controller or by any other person to identify that individual.
-                      The fourth element: “natural person”:
In principle, personal data are data relating to identified or identifiable living individuals. There are some issues relating to data on deceased persons and unborn children: these can often still (also) relate to living individuals, in the way discussed above, and would then still be personal data in relation to those latter individuals. Data on legal entities can sometimes also, similarly, relate to living individuals associated with those entities. Also, in some contexts some data protection rights are expressly extended to legal persons (companies etc.) per se, in particular under the so-called “e-Privacy Directive”. But that is a special case. This too, however, was not an issue relevant to the CJEU judgment.

Until the CJEU judgment, it could be assumed that as long as the General Data Protection Regulation used the same definition of personal data as the 1995 DP Directive, the above elements and criteria could simply be read into the new instrument.

However, the judgment could result in the definition in the GDPR being read in accordance with the Court’s restricted views, rather than in line with the WP29 guidance.

In my opinion, if the EU wishes to retain a strong European data protection framework, as is often asserted, it is essential that the GDPR expressly (if of course briefly) endorses the WP29 view of the issue, rather than the CJEU’s one.

Below, I suggest amendments to the definition of the concept of personal data in the GDPR that would achieve that (some further amendments should be made to the recitals).
II.                  Proposed amendments to the GDPR
As can be seen from the Annexes, with the different definitions of personal data and data subject in the Commission text of the GDPR and in the amended version of the Regulation adopted by the EP (and with the corresponding definitions in the current 1995 DP Directive), the definitions all say in essence that:

'personal data' means any information relating to a data subject (with ‘data subject’ then defined as “an identified or identifiable natural person”), or:
'personal data' means any information relating to an identified or identifiable natural person -
which comes to the same thing (and is in accordance with the current directive).

The EP text adds clarification on when a person can be regarded as “identifiable”, on the lines of the views of the Article 29 Working Party (drawing on a recital in the current directive); and more specific provisions on “pseudonymous data” and “encrypted data”.

However, neither text adds clarification on the question of when data can be said to “relate” to a (natural, living) persons – which is the issue so badly dealt with in the CJEU judgment.

I propose that the definition of “personal data” in the GDPR be expanded to expressly clarify the question of when data can be said to “relate” to a person, by drawing on the guidance of the Article 29 Working Party set out above; and by also expressly clarifying that “profiles” always “relate” to any person to whom they may be applied. Specifically, I propose that an additional paragraph be added to Article 2(2), spelling out that:

“data relate to a person if they are about that person, or about an object linked to that person; or if the data are used or are likely to be used for the purpose of evaluating that person, or to treat that person in a certain way or influence the status or behaviour of that person; or if the use of the data is likely to have an impact on that person's rights and interests. Profiles resulting from ‘profiling’ as defined in [Article 20 in the Commission text/Article 4(3a) of the EP text] by their nature relate to any person to whom they may be applied.”

The Annexes indicate more specifically how such an amendment could be incorporated into the current (Commission and EP) texts of the Regulation.


Annex I

PROPOSED AMENDMENTS TO ARTICLE 4 OF THE GENERAL DATA PROTECTION REGULATION:

(Added or amended text in bold)

The proposed amendments if applied to the Commission text:

(1)        'data subject' means an identified natural person or a natural person who can be identified, directly or indirectly, by means reasonably likely to be used by the controller or by any other natural or legal person, in particular by reference to an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;

(2)        'personal data' means any information relating to a data subject;

(2a)      data relate to a person if they are about that person, or about an object linked to that person; or if the data are used or are likely to be used for the purpose of evaluating that person, or to treat that person in a certain way or influence the status or behaviour of that person; or if the use of the data is likely to have an impact on that person's rights and interests. Profiles resulting from ‘profiling’ as defined in Article 20 by their nature relate to any person to whom they may be applied.

The proposed amendments if applied to the EP text:

(2)        'personal data' means any information relating to an identified or identifiable natural person ('data subject');

(2a)      an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, unique identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social or gender identity of that person;

(2b)     data relate to a person if they are about that person, or about an object linked to that person; or if the data are used or are likely to be used for the purpose of evaluating that person, or to treat that person in a certain way or influence the status or behaviour of that person; or if the use of the data is likely to have an impact on that person's rights and interests. Profiles resulting from ‘profiling’ as defined in paragraph (3a) by their nature relate to any person to whom they may be applied.

(2c) 'pseudonymous data' means personal data that cannot be attributed to a specific data subject without the use of additional information, as long as such additional information is kept separately and subject to technical and organisational measures to ensure non-attribution;

(2d)‘encrypted data’ means personal data, which through technological protection measures is rendered unintelligible to any person who is not authorised to access it;

NB: The actual Commission and EP texts are set out in Annex II


Annex II 

The definition of “personal data” in the original Commission text of the GDPR and in the amended version of the Regulation adopted by the European Parliament:

Text proposed by the Commission
Amendment
Definitions
Definitions
For the purposes of this Regulation:
For the purposes of this Regulation:
(1) 'data subject' means an identified natural person or a natural person who can be identified, directly or indirectly, by means reasonably likely to be used by the controller or by any other natural or legal person, in particular by reference to an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;

(2) 'personal data' means any information relating to a data subject;
(2) 'personal data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, unique identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social or gender identity of that person;

(2a) 'pseudonymous data' means personal data that cannot be attributed to a specific data subject without the use of additional information, as long as such additional information is kept separately and subject to technical and organisational measures to ensure non-attribution;

(2b) ‘encrypted data’ means personal data, which through technological protection measures is rendered unintelligible to any person who is not authorised to access it;

Cf. the following definition in the current 1995 DP Directive:
(a) 'personal data 'shall mean any information relating to an identified or identifiable natural person ('data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity;

Child abduction: a further extension of EU exclusive external powers




Steve Peers

It's every parent's worst nightmare: the abduction of their child. If the child is abducted by a stranger, there's obviously a grave threat to the child. But it's far more common for a child to be abducted by a parent who doesn't have custody of him or her, in the context of family law proceedings.

While it's fortunately much less likely that a parent is a threat to a child's welfare, such abductions are still problematic, since they are a breach of court decisions regarding custody. And if the child is taken to another country by the abducting parent, it is far harder for the parent with custodial rights to enforce them. Sometimes, the latter parent doesn't even get to see his or her children for years.

To address this problem, the Hague Conference (an international body) drew up an international treaty, the Hague Convention on the civil aspects of child abduction, back in 1980. All the EU Member States are party to this treaty. In fact, a total of 93 countries have ratified it. According to the latest available statistics, in 2008 the Convention was applied about 2300 times. Two-thirds of the parents taking children were the mothers, and the average age of the abducted children was six. 

Indeed, the very popularity of the Convention was at the heart of a dispute over the EU’s external power regarding it, which was resolved yesterday by the CJEU (Opinion 1/2013). This judgment concerned new States signing up to the Convention, which has an unusual rule on accession: it only applies to new States which ratify it to the extent that the existing signatories individually agree to this.

The EU is not itself a party to the treaty, and it can't be, since the treaty only permits States to be parties. But in the years since the treaty was drawn up, the EU has adopted legislation which addresses child abduction issues (Regulation 2201/2003). So arguably this means that the EU has external competence as regards the subject matter of the Convention, and Member States are only 'trustees' of that power.  In practice, that means that Member States cannot decide unilaterally whether to extend the Convention to new countries or not.

The Commission, believing that this interpretation was correct, proposed in 2011 that the Council adopt eight separate decisions permitting Member States to extend the Convention to third States, including Russia, Albania and Morocco. Most Member States disagreed. So the Commission invoked the special procedure set out in Article 218 TFEU, which allows the CJEU to decide on whether an envisaged international agreement would be in conformity with EU law.

Judgment

The CJEU had to address four arguments against the admissibility of this case.  First of all, the Court ruled that the decision on accession of a new State to the Convention was an 'agreement'. Secondly, it ruled that the impossibility of the EU itself becoming party to the Convention was irrelevant. As it had ruled before, it has jurisdiction under Article 218 TFEU even in 'trusteeship' cases.

Thirdly, the Court ruled that an agreement could still be considered as being 'envisaged' even if a large majority of the Member States in the Council were opposed to it, making its adoption improbable politically. Finally, the Court decided that it was irrelevant that a number of Member States had gone ahead and agreed to extend the Convention to the third States concerned. The possibility that the Commission could have sued those Member States for infringing EU law didn't stop the Commission from invoking the special jurisdiction of Article 218 TFEU.

As for the substance of the case, 19 Member States opposed the Commission view that the EU had external competence in this case. Only the European Parliament, along with Italy, supported the Commission. Nevertheless, the Court agreed with the Commission.

The Court began by noting that the EU has external competence not only when the Treaties expressly provide for it, but also when this is necessary to realise the internal objectives of the EU, even if the Treaties don't make express provision for this. Indeed, the Court stated that Article 216 TFEU now sets out this rule. In this case, the EU competence existed merely because Article 81(3) TFEU gives the EU internal power to adopt legislation on family law matters with cross-border implications.

However, the bigger issue is whether such competence is exclusive, or merely shared with the Member States. On this point, the Court reaffirmed that the EU would enjoy exclusive competence, as set out in its prior case-law and Article 3(2) TFEU, where an international treaty was liable to affect common EU rules or alter their scope. This was the case when the treaty fell within an area which was largely covered by the EU rules.

Applying that law to the facts, the main provisions of the Convention, dealing with return of the child and the right to visit a child, were also the subject of rules in the Regulation. There was a risk that patchwork extension of the treaty to third States by Member States would complicate application of the EU legislation, particularly where a dispute concerned a third State and two Member States, each of which had taken a different view on extending the treaty to the relevant third State. So it followed that the EU had exclusive external competence regarding the extension of the Convention to new countries. 

Comments

The Court’s judgment raises three issues: its impact upon child abduction in practice; the substantive scope of the EU’s external competence generally; and the process of litigating disputes about that competence.

On the first point, fortunately for the children concerned, the dispute regarding the EU’s external competence in this case doesn’t appear to have prevented Member States from extending the Convention to new countries in practice. However, since the new judgment resolves the issue, the Council now needs to move forward quickly to adopt the Commission’s earlier proposals (on family law issues, the Council votes unanimously, after consulting the European Parliament). Also, seven more States have ratified the Convention in the meantime, including Japan and Korea (see the full list of signatories here), so the Commission needs to propose further such measures straight away. A failure to act quickly will run the risk that a parent who has abducted a child to Russia (for example) might try to argue against the enforcement of a ruling issued by a Member State’s court on the return of a child, on the grounds that the Member State’s extension of the Convention to Russia was illegal.

The Court’s ruling also means that any amendment of the Convention in future will also fall within the scope of the EU’s exclusive external competence. This isn’t a purely hypothetical possibility, as there was some contemplation of a protocol to the Convention a few years ago (for the details, see here).  So it’s now clear that Member States will have to act together, or not at all, as regards any amendment to the Convention, and any extension of it to new countries.

As regards the EU’s external competence, there are two issues: the existence and nature of that competence. In fact, this is the first CJEU judgment since the entry into force of the Treaty of Lisbon which touched upon the existence of such competence. The Court’s judgment appears to assume that Article 216 TFEU simply reflects the prior case law; this issue had been debated in literature. And according to the Court, external competence exists where there is an internal legal base and the EU has adopted legislation on the subject in question. The Court didn’t rule on whether the existence of legislation on an issue was necessary before the EU could exercise its external competence. But on the facts of the case, it didn’t have to address that issue.

Moving on to the nature of the EU’s external competence, the Court’s ruling is not very surprising, following the pre-Lisbon judgment on the exclusivity of the EU’s external competence over civil jurisdiction issues (Opinion 1/03), and more recently the broadcasting rightsjudgment, confirming and elaborating a broad approach to finding that EU external competence is exclusive. In fact, EU exclusive competence as regards the child abduction Convention is more self-evident than as regards the planned broadcasters’ rights Convention, given that the two main aspects of the child abduction Convention clearly correspond to provisions of an EU Regulation, which moreover expressly incorporates or supplements some aspects of the Convention.

Finally, as regards the procedural aspects of this case, all four aspects of the Court’s ruling (the definitions of ‘agreement’ and ‘envisaged’, the application to ‘trusteeship’ cases and the relationship with infringement actions) take a broad approach to the scope of its jurisdiction pursuant to Article 218 TFEU. In effect, it’s now clear that all the Commission needs to do in order to trigger the possible use of Article 218 is to make a proposal for an external relations decision by (or on behalf of) the EU to the Council. Even if that proposal is ‘dead on arrival’ in the Council (as in this case), to the extent that Member States ignore the Commission’s proposal and begin ratifying the relevant treaty (or taking other external action) themselves, the Commission can still invoke the Court’s jurisdiction under Article 218. That special jurisdiction only ceases to apply if the Council approves the treaty concerned on the EU’s behalf, and the treaty then binds the EU. This precisely won’t ever be the case if the Council rejects the Commission’s proposal at the outset.

Having said that, the Court’s judgment does appear to draw a distinction between legaland political reasons for rejecting a Commission proposal, stating that in this case, the case was admissible because the Council’s reasons for rejection were purely legal. What if its objections were political – or both legal and political? And how can one tell the difference between those grounds?

Furthermore, does this reasoning also apply to the European Parliament? It has no veto right over family law treaties, but it does over most treaties concluded by the EU. The Commission passed up a chance to clarify this issue when it withdrew its request for a CJEU Article 218 ruling as regards the controversial Anti-Counterfeiting Trade Agreement, after the EP refused its consent to that treaty on political grounds. Arguably, the legal questions remain relevant even if a treaty has been rejected by either the Council or the EP on political grounds; but the Commission surely shows good judgment by accepting the political decision of either branch of the EU’s legislature and withdrawing applications for a Court ruling in such circumstances.


Barnard & Peers: chapter 24

Thứ Sáu, 10 tháng 10, 2014

Doktor U? The CJEU reconciles the right to a name with passport security



Steve Peers

Many people have a fluid sense of their personal identity. But this is anathema from the perspective of law enforcement bodies, who seek to fix individual identity in order to ensure certainty about each person they are collecting information on.

The CJEU had to reconcile these two conflicting principles in last week’s judgment in U. This was one of four separate CJEU judgments that week where the plaintiff was designated by a letter only (the others were E, Q and X). In my view, it’s long past time for the Court to borrow a good idea from journalism, and simply give the people in question assumed names. That’s because it’s harder to understand and recall a case which is designated by letters only, especially where the same letters are reused by the Court in other cases in the same field (such as asylum).

In particular, it’s confusing to use an initial only for the U case, because the whole point of the case is the designation of names. In fact, under German law Mr. U is also entitled to use ‘Doktor’ as part of his name. This makes it hard to resist the temptation to call him ‘Doktor U’. So I won’t resist it at all.
  
The judgment

Doktor U had the birth name ‘E’, but his official surname is now U. The German authorities placed in his passport that his name was ‘Dr. U, GEB E’. The ‘GEB’ stands for the German word ‘geboren’ (meaning ‘born’). In practice, this led to confusion about what his actual name was. So he challenged the authorities’ decision in the German courts, which asked the CJEU to interpret the EU’s passport security Regulation and the EU Charter of Rights.

According to the CJEU, first of all the EU legislation requires all passports to apply the recommendations of the ICAO on document security. This is an interesting example of EU law importing international soft law by reference (on the implications of this for EU external relations, see this week’s judgment in Germany v Council).

Secondly, the Court ruled that a Member State had flexibility to designate a person’s birth name as part of his name on a passport, even though the ICAO rules refer to national law, and the relevant German law on fixing of names (as distinct from the law on passports) does not include birth names as part of a person’s name. The rationale here was the interest of document security, which favoured the use of a fixed element (the name at birth).

Thirdly, the Court ruled that the birth name could not be included in the optional section of the passport. Finally, interpreting the Charter, it ruled that the right to a name, which forms part of the right to a private life set out in Article 7 of the Charter, means that any use of a birth name on a passport had to be clearly indicated. The abbreviation ‘GEB’ was not translated, so could not be comprehended by the authorities of other countries and was liable to lead to practical complications for the passport holder.  

Comments

It might be hard for some Germans to admit it, but their country’s enormous influence in the EU political system has not been accompanied by any predominance of the German language, either inside or outside the EU. So the insistence of a peculiar approach to inscribing names on passports, coupled with an absence of translation, will inevitably lead to complications for those German citizens whose name has changed since birth.

The CJEU goes some way to addressing that problem in this judgment, when it requires the German authorities to make it clear to the non-German speakers who make up most of the rest of the world that Doktor U’s birth name is just that, and that he now goes by a new name.  At least this will reduce the confusion about his name that the good Doktor experiences in practice.

But the Court could have gone much further. Doktor U didn’t merely want to reduce confusion about his current name; he wanted to be known only by his current identity. After all, his fictional namesake has not disclosed his Gallifreyan birth name in 50 years of screen time (or thousands of years in narrative time). And unlike that time-travelling Doctor, the real Doktor U has presumably not regenerated his body many times over, with consequent complications for using his passport.

While the Court was right to say that the EU legislation requires the application of ICAO soft law, it did not acknowledge the great ambiguity in those rules. Indeed, it is striking that the Advocate-General’s opinion arrives at precisely the opposite interpretation of them. The objective of ensuring passport security could still have been achieved by providing a precise record of Doktor U’s currentidentity. And the Court would have surely reached this conclusion if it had performed in this case – as it always ought to do – an assessment of whether the interference in Doktor U’s right to his private life was proportionate and necessary.



Barnard & Peers: chapter 9, chapter 26

Thứ Tư, 8 tháng 10, 2014

Denmark and EU Justice and Home Affairs Law: Really Opting Back In?





Steve Peers

Yesterday, the Danish Prime Minister made an announcement that Denmark would hold another referendum on EU matters in 2015. This was widely reported as a vote on whether Denmark would opt back in to EU Justice and Home Affairs (JHA) law. In fact, the government’s intention is to hold a vote on whether to replace a complete opt out with a selective opt-out. This blog post explains the detail of the issue, including a complete list of the measures which Denmark might opt back into if the Danish public approves the referendum proposal.

The Danish opt-out effectively dates back to the Danish referendum on the Maastricht Treaty in 1992. Following the initial Danish ‘no’ vote to that treaty, the EU’s Heads of State of Government adopted a Decision, which states that Denmark fully participates in EU JHA law. This was accompanied by a declaration stating that any transfer of powers to the European Community (as it then was) would be subject to a referendum in Denmark. This is generally regarded as the basis for Denmark’s opt-out on JHA matters.

This Decision is also often described as an opt-out on EU citizenship, although it is no such thing: it simply clarifies the relationship between Danish and EU citizenship. In fact, despite a widespread belief to the contrary, Denmark has no opt-out on EU citizenship at all.

The JHA opt-out was formalised as a Protocol to the Treaties at the time of the Treaty of Amsterdam (in force 1999), and was then revised at the time of the Treaty of Lisbon (in force 2009). It currently appears as Protocol 22 to the Treaties.

In a nutshell, the legal position is as follows.

First of all, Denmark is bound by the ‘Schengen’ rules abolishing border controls between most Member States, and measures building upon them, such as the Schengen Borders Code, the EU’s visa code, the Schengen Information System and the EU’s border control agency, Frontex. However, it is bound by these measures only as a matter of international law, not EU law. It could choose to opt out of new measures in this area, but there would be some unspecified retaliation if it did. It hasn’t done so in practice.

Secondly, Denmark is not bound by any other EU measures on immigration and asylum law, or civil cooperation, except for the measures on a standardised list of countries whose nationals do and don’t need visas to enter the EU. However,  for a few of these measures,  Denmark is bound instead by means of a treaty with the EU: the Dublin rules on asylum applications; the Brussels Regulation on civil and commercial jurisdiction; and the Regulation on service of documents. It’s also bound by the initial Rome Convention on conflicts of law in contract, but not by the Regulation replacing it.

Thirdly, Denmark is bound by EU measures on policing and criminal law adopted before the entry into force of the Treaty of Lisbon. This includes (as matters stand) the EU measures establishing Europol (the EU police agency), Eurojust (the EU prosecutors’ agency) and the European Arrest Warrant.

Fourthly, Denmark is conversely not bound by EU measures on policing and criminal law adopted after the entry into force of the Treaty of Lisbon. This includes particularly EU legislation on suspects’ rights, victims’ rights, and the European Investigation Order. In the near future, it will also not be bound by legislation re-establishing Europol, which will soon be the subject of final negotiations between the European Parliament and the Council (on the details of that negotiation, see the previous blog post). According to the Prime Minister, this is a particular reason for considering whether to exercise the opt-out.

The assumption behind her argument is that the pre-Lisbon measure establishing Europol will not be applicable to Denmark any longer once a new measure is adopted. In fact, Article 2 of Protocol 22 says as follows:

acts of the Union in the field of police cooperation and judicial cooperation in criminal matters adopted before the entry into force of the Treaty of Lisbon which are amended shall continue to be binding upon and applicable to Denmark unchanged.

However, in the specific case of EU agencies, it is hard to see in practice how Denmark could continue to be part of Europol as it was set up subject to a pre-Lisbon measure, while all of the other Member States (presuming that the UK and Ireland opt-in) are part of Europol as it was set up afresh by a post-Lisbon Regulation.

In fact, the same issue is likely to arise as regards Eurojust (the EU prosecutors’ agency) in the next year or so, since there is also a proposal to replace the pre-Lisbon Decision setting up that body with a post-Lisbon Regulation.

What are the consequences of the opt-in? Denmark has the power to denounce ‘all or part’ of the Protocol, which also includes an opt-out relating to EU defence policy, without a need for a Treaty amendment. (Note that Denmark’s opt-out from the obligation to adopt the EU’s single currency is set out in a separate Protocol).

However, Denmark also has another option available to it: to replace the current complete opt-out for post-Lisbon JHA measures not linked to the Schengen acquis with a selective opt-out, ie the power to opt in to JHA measures on a case-by-case basis. According to press reports, this is what the Prime Minister proposes. In light of this, it simply isn’t accurate to say that Denmark would be voting to ‘give up its JHA opt-out’.

If the public vote in favour, Denmark would have the same power that the UK and Ireland have to opt in to JHA measures on a case-by-case basis, either within three months after those measures are proposed or at any time after they are finally adopted. However, unlike the UK and Ireland, Denmark will continue to be fully bound by EU measures on visa lists (ie with no-opt-out possibility), and will also continue to participate in the Schengen rules (although those rules would then have the force of EU law, not international law, in Denmark).

It would be up to the Danish government and parliament to determine what arrangements apply to opting in, as a matter of national law. If national law permits, it is open to Denmark to provide, if it wishes, that its national parliament must approve every opt-in decision, possibly by a higher majority in some or all cases. The Danish government could also announce in advance which measures it would (and would not) seek to opt in to.

To clarify the potential impact of the decision, the Annex to this post contains a complete list of all current measures or proposals which Denmark could opt to participate in if the public chose to vote for a selective JHA opt-out in place of the current complete opt-out. Again, though, Denmark could choose to participate in only a small number of these measures if it wished.

While it is sometimes claimed that EU opt-outs are not really genuine, because Member States will face undue pressure to opt-in to EU measures regardless, the evidence of the last 15 years clearly refutes this assertion. In practice, Denmark and the UK have not been forced to adopt the single currency, and the UK and Ireland have opted out of a growing number of JHA measures.


Barnard & Peers: chapter 2, chapter 25, chapter 26


Annex

JHA measures which Denmark couldopt in to after adopting a selective opt-out

1) Adopted measures

Asylum

1. Directive 2001/55 on temporary protection (OJ 2001 L 212/12)
2. Regulation 439/2010 establishing a European Asylum Support Office (OJ 2010 L 132/11)
3. Recast Directive 2011/95 on qualification and content of international protection (OJ 2011 L 337/9)
4. Directive 2013/33 on reception conditions for asylum-seekers (OJ 2013 L 180/96)
5. Regulation 604/2013 on responsibility for asylum applications (OJ 2013 L 180/31) – nb applies to Denmark by means of treaty already
6. Directive 2013/32 on international protection procedures (OJ 2013 L 180/60)
7. Regulation 603/2013 on Eurodac (OJ 2013 L 180/1) – nb applies to Denmark by means of treaty already
8. Regulation establishing the asylum and migration Fund (OJ 2014 L 150/168)
9. Regulation laying down general provisions on the Asylum and Migration Fund and on the instrument for financial support for police cooperation, preventing and combating crime, and crisis management ((OJ 2014 L 150/112)

Irregular migration

1.Directive 2004/82 on transmitting passenger information by carriers (OJ 2004 L 261/24)
2.Decision on joint expulsion flights (OJ 2004 L 261/28)
3. Directive 2004/81 on residence permits for victims of trafficking or facilitation of irregular migration (OJ 2004 L 261/19)
4.Decision on an information and coordination network for Member States’ migration management services (OJ 2005 L 83/48)
5. Directive 2008/115 on common rules for expulsion – Returns Directive (OJ 2008 L 348/98) – nb applies to Denmark in part already
6. Directive 2009/52 on sanctions for employers of irregular migrants (OJ 2009 L 168/24)

Legal Migration

1. Directive 2003/86 on family reunion (OJ 2003 L 251/12)
2. Directive 2003/109 on the status of long-term resident third-country nationals (OJ 2004 L 16/44)
3. Directive 2004/114 on entry and residence of students, volunteers and others (OJ 2004 L 375/12)
4. Directive 2005/71 on admission of researchers (OJ 2005 L 289/15)
5. Decision on exchange of asylum and immigration information (OJ 2006 L 283/40)
6. Decision establishing Migration Network (OJ 2008 L 131/7)
7. Directive 2009/50 on the conditions of entry and residence of third-country nationals for the purposes of highly qualified employment (‘Blue Card Directive’) (OJ 2009 L 155/17)
8. Regulation 1231/2010 extending Regulation 883/2004 on social security for EU citizens to third-country nationals who move within the EU (OJ 2010 L 344/1)
9. Directive 2011/51 applying long-term residents’ Directive to refugees and beneficiaries of subsidiary protection (OJ 2011 L 132/1)
10. Directive 2011/98 (single permit Directive) (OJ 2011 L 343/1)
11. Directive 2014/36 on admission of seasonal workers (OJ 2014 L 94/375)
12. Directive 2014/66 on admission of intra-corporate transferees (OJ 2014 L 157/1)

Civil Cooperation

1. Regulation 1346/2000 on jurisdiction over and enforcement of insolvency proceedings (OJ 2000 L 160/1)
2. Regulation 1347/2000 on jurisdiction over and enforcement of matrimonial and custody judgments (OJ 2000 L 160/19)
3. Regulation 1206/2001 on cross-border taking of evidence in civil and commercial matters (OJ 2001 L 174/1)
4. Decision 2001/470 on European Judicial Network on civil and commercial matters (OJ 2001 L 174/25)
5.  Directive 2003/8 on legal aid (OJ 2003 L 26/41)
6. Regulation 2201/2003 on parental responsibility (OJ 2003 L 338/1)
7. Regulation 805/2004 on European enforcement order (OJ 2004 L 143/15)
8. Regulation 1896/2006 creating a European order for payment procedure (OJ 2006 L 399/1)
9. Regulation 861/2007 establishing a European small claims procedure (OJ 2007 L 199/1)
10. Regulation 864/2007 on the law applicable to non-contractual obligations ('Rome II') (OJ 2007 L 199/40)
11. Directive 2008/52 on mediation (OJ 2008 L 136/3)
12. Regulation 593/2008 on 'Rome I' (choice of law for contractual obligations) (OJ 2008 L 177/6)
13. Decision amending Decision on judicial network (OJ 2009 L 168/35)
14. Regulation 662/2009 on Member States’ negotiation and conclusion of external treaties relating to maintenance, divorce and parental responsibility (OJ 2009 L 200/25)
15. Regulation 664/2009 on Member States’ negotiation and conclusion of external treaties relating to conflict of laws as regards contractual and non-contractual obligations (OJ 2009 L 200/46)
16. ‘Rome III’ Regulation 1259/2010 on choice of law in divorce proceedings (OJ 2010 L 343/10)
17. Regulation 650/2012 on choice of law and jurisdiction in succession proceedings (OJ 2012 L 201/107)
18. Regulation 1215/2012 on civil and commercial jurisdiction (OJ 2012 L 351/1) - – nb applies to Denmark by means of treaty already
19. Regulation 606/2013 on civil law enforcement of protection orders (OJ 2013 L 181/4)
20. Regulation 542/1014 amending civil jurisdiction Regulation (OJ 2014 L 163/1) – nb applies to Denmark by means of treaty already
21. Regulation on European account preservation orders

Criminal law and policing

Directives

1. Directive 2010/64 on the right to interpretation and translation in the framework of criminal proceedings (OJ 2010 L 280/1)
2. Directive 2011/36 on trafficking in persons (OJ 2011 L 101/1)
3. Directive 2011/82 on exchange of information on traffic offences (OJ 2011 L 288/1)
4. Directive 2011/92 on sexual exploitation of children (OJ 2011 L 335/1)
5. Directive 2011/99 on European protection order (OJ 2011 L 338/2)
6. Directive 2012/13 on the right to information on criminal proceedings (OJ 2012 L 142/1)
7. Directive 2012/29 on crime victims’ rights (OJ 2012 L 315/57)
8. Directive 2013/40 on attacks on information systems (OJ 2013 L 218/8)
9. Directive 2013/48 on access to lawyer and communication rights (OJ 2013 L 294/1)
10. Directive 2014/41 on European investigation order (OJ 2014 L 130/1)
11. Directive 2014/42 on freezing and confiscation of criminal proceeds (OJ 2014 L 127/39)
12. Directive 2014/57 on criminal sanctions against market abuse
13. Directive 2014/62 on counterfeiting currency (OJ 2014 L 151/1)

Regulations

1. Regulation establishing a Justice Programme (OJ 2013 L 354/73)
2. Regulation on the instrument for financial support for police cooperation, preventing and combating crime, and crisis management (OJ 2014 L 150/93)
3. Regulation 543/2014 amending Decision on European Police College (OJ 2014 L 163/5)

2) Proposals

Immigration and asylum

1. Directive on admission of students, researchers and others (COM (2013) 151, 25 March 2013)
2. Regulation amending the Dublin III Regulation regarding unaccompanied minors (COM (2014) 382, 26 June 2014)

Civil cooperation

1. Commission invitation to Council to apply ‘co-decision’ procedure to the issue of maintenance obligations (COM (2005) 648, 15 Dec. 2005)
2. Commission proposal for Regulation on choice of law and jurisdiction on matrimonial property (COM (2011) 126, 16 Mar. 2011)
3. Commission proposal for Regulation on choice of law and jurisdiction on registered partnerships (COM (2011) 127, 16 Mar. 2011)
4. Commission proposal for Regulation amending insolvency Regulation (COM (2012) 744, 12 Dec. 2012)
5. Proposal for Regulation amending prior legislation regarding implementing measures (COM (2013) 452, 27 June 2013)
6. Proposal for Regulation amending small claims and order for payment Regulations (COM (2013) 794, 19 Nov. 2013)

Criminal law

1. Proposal for Directive on the right to interpretation and translation in the framework of criminal proceedings (COM (2010) 82, 9 March 2010)
2. Proposal for Directive on passenger name records (COM (2011) 32, 2 Feb. 2011)
3. Proposal for Directive on protection of EU financial interests (COM (2012) 363, 11 July 2012)
4. Proposal to amend Framework Decision on drug trafficking (COM (2013) 618, 17 Sep. 2013)
5. Proposal on presumption of innocence (COM (2013) 821, 27 Nov. 2013)
6. Proposal on childrens’ rights as suspects (COM (2013) 822, 27 Nov. 2013)
7. Proposal on provisional legal aid (COM (2013) 824, 27 Nov. 2013)
8. Regulation on Europol (COM (2013) 173, 27 March 2013)
9. Regulation on European Public Prosecutor’s Office (COM (2013) 534, 17 July 2013)
10. Regulation on Eurojust (COM (2013) 535, 17 July 2013)

Note: this list does not include measures which have expired or been replaced (or which will be replaced as of July 2015). It also does not include international treaties with third States, since at least in some cases, Denmark has parallel arrangements in place with the countries concerned. The most important treaties in question concern readmission, visa facilitation, the Hague Convention on maintenance and treaties on mutual assistance, extradition and exchange of police information.