European Commission Data Deals with U.S., from Statewatch

European Commission tells USA that demands for access to data on airline passengers breaches EU Data Protection Directive - but hints at a deal that would "fudge" the issue

- Commission option to reach bilateral agreement allowing for derogation from EU laws

- access to passenger data breaks EC Regulation on computer reservation systems (CRS) as well as 1995 Data Protection Directive

- Tom Ridge, US Secretary for Homeland Security, says on visit to Italy:

"Looking at this request beyond just a data protection issue but as a mutual security issue is something that can help us get closer to resolving our differences"
- correspondence reveals that USA is also asking for "Advance Passenger Information" to vet those flying


Update 15 September 2003

1. The US tried to impose a new deadline of 12 September for airlines flying there from within the EU to give access to personal passenger data (Passenger Name Record data, PNR). It is reported that Air France, British Airways and Iberia have been giving the USA access to this data since 5 March 2003. Indeed some airlines do not allow passengers to book tickets online unless they agree to personal data being handed over. Alitalia on the other hand have been banned from passing over any information that is not contained on a passport by their Data Protection Authority. Under US law airlines that fail to comply could be fined up to $6,000 a passenger and a loss of landing rights - passengers would be subject to checks on arrival. The European Commission has set a deadline of Christmas for trying to resolve the issue.

Tom Ridge, US Secretary for Homeland Security, said in Italy that there was still "some time to go to reconcile our differences" but stressed that the United States was firm in its intention to move aggressively on the issue. "Looking at this request beyond just a data protection issue but as a mutual security issue is something that can help us get closer to resolving our differences," he said.
sources: euobserver.com and AP.

2. The speech of Mr Bolkstein, the Commissioner for the Internal Market, to the European Parliament's Committee on Citizens' Freedoms and Rights on 9 September provided more insight into the issues involved.

"What has caused the problem", he told the Committee, "is a conflict of laws.. there is no avoiding the fact that the US has a different approach when it comes to the security of their homeland". He said "We must be realistic" because the USA is not the only country wanting to use PNR: "Canada and Australia have already made similar requests"

However, Mr Bolkstein fails to mention that these two countries have comprehensive data protection laws in place (see, Privacy International 2003).
He notes that there has been some progress, the US has agreed to "filter and delete.. sensitive data" - though of course they should not have access in the first place ("sensitive data" is defined in Article 8 of the 1995 EC Directive).

The Committee was told that there were four outstanding issues:

1) the USA does not want to restrict the use of PNR data to terrorism but want to cover "other serious crimes";

2) The Committee was told that:
"the US requires 39 different PNR elements, which it is hard to regard as proportionate to the purpose";

3) the US demand that data be kept for 50 years has come down to 6-7 years. Under Article 6.1.a. of the EC Regulation 2299/89 on computer reservations systems individual data has to be taken off-line within 72 hours of the completion of the booking (ie: flight arrival), can be archived for a maximum of three years and access to the data is "allowed only for billing-dispute reasons".

4) as the undertakings provided are not adequate, nor in a legal binding form, the EU is insisting "on an independent extra-judicial redress mechanism".
A fifth point considered essential by the Commission is that data is supplied by the airline reservation systems rather than US agencies having direct access to reservation databases.

The Commissioner told the Committee that he could envisage three options:

1) to continue negotiating until the USA position meets a standard of "adequacy" (see his letter below) - he is clearly not optimistic that the US is going to move sufficiently;

2) "to enforce the law" which would "ideally mean stopping data transfers" - under the 1995 Directive this is the job of the national data protection authorities. The Commission role is "to ensure that member states respect the Directive, not that the airlines do". However, the Commission has direct responsibility to enforce EU law under the 1989 EC Regulation on computer reservation systems as amended by the 1999 EC Regulation 323. The 1989 Regulation said in Article 6.d that: "personal information concerning a consumer and generated by a travel agent shall be made available to others not involved in the transaction only with the consent of the consumer."

This was greatly strengthened by the 1999 amendment to Article 6 which reflected the 1995 Data Protection Directive. In addition to saying that personal data can only be accessed for "billing-dispute purposes" - that is, it cannot be accessed for any other purpose as proposed by the USA - says that data: "shall include no identification, either directly or indirectly of personal information on a passenger"

Moreover, no users of the data shall "manipulate information" that leads it to "inaccurate, misleading or discriminatory presentation of that information" and the "consumer" has the right to be informed of the name and address of anyone using the information on them, "the purposes of the processing, the duration of the retention of individual data and the means available to the data subject of exercising their access rights [and].. access free of charge to their own data".

Extraordinarily, Mr Bolkstein states:
"At present, the Commission does not have clear-cut evidence of a breach, but is writing to the CRSs to obtain more information and to remind them of their obligations."

A number of airlines are on the public record that they are giving the US access to their passenger reservation database, at a hearing in the European Parliament on the issue back in March and in the presence of Commission officials several airlines declared that they were complying with US demands and online booking on the internet for a number of airlines does not allow ticket purchases unless a box is ticked agreeing to heir data being handed over.
The Commission's reasoning is that there is not agreement among the 15 EU governments, some member states back the Commission undertaking its legal and constitutional duties, others do not - which inevitably leads to the third option.

3) to "negotiate a bilateral agreement" between the USA and the EU. This would allow "narrowly targeted derogations to be made from the Data Protection Directive". This is a contradiction in terms - the EU law on computerised reservations system is perfectly clear as are the principles of the 1995 Data Protection, namely that information supplied by the citizen for one purpose cannot be used for another purpose, data supplied cannot be further "processed" for another purpose (ie: checked through US intelligence and security watch-lists and amended) and the data subject has a right to a copy of the information held on them and the right to correct it - none of these principles can be "derogated" from without abandoning data protection rights.

Mr Bolkstein presented the option of a bilateral agreement as a means to "bridge the gap between the two legal systems", but this not just about legal differences it is about the USA's determination to "aggressively" pursue their demands and the EU's lack of political will to maintain established law and protections for the citizens.

Full-text of Mr Bolkstein's speech in the European Parliament on 9 September 2003: Speech (pdf)
http://www.statewatch.org/news/2003/sep/Bolkestein-libe-9-09-03.pdf

Statewatch

For detailed information on this issue, please visit STATEWATCH, in our Links section or at:
http://www.statewatch.org