The Register® — Biting the hand that feeds IT

Feeds

Terror data handover seriously flawed

EU gives up bank data, for nothing in return

Agentless Backup is Not a Myth

Comment The European Union has redrafted its agreement with the US Treasury which requires Europe’s financial institutions to transfer details of global financial transactions to the US. The revised Draft Agreement is to be put to the European Parliament in July for approval, despite a text containing significant privacy defects and obvious areas of drafting in need of urgent attention.

The Draft Agreement (pdf) often refers to “terrorism or terrorist financing” without defining what “terrorism” is, or what makes a “terrorist”. There is a kind of unwritten assumption that everybody will recognise a terrorist when they see one, despite the adage that one person’s terrorist is another person’s freedom fighter.

However, the Agreement (in Article 2) does define a range of activities that most people would recognise as “terrorist”, but because these activities do not use the word “terrorism”, they can be interpreted with, how shall we put it, “a degree of flexibility”.

For example, Article 2 includes in its “activities” that allow transfer to the US “acts of a person that ... are ... dangerous to human life or create a risk of damage to property ... and are reasonably believed to be committed with the aim of ... coercing a government to act or abstain from acting”.

Can you recall the protracted UK fire-fighters strike in 2002 which involved thousands of fire-fighters? Did this strike “create a risk of damage to property”? Was the strike “dangerous to human life”? Was the strike called “with the aim of coercing a government to act” (in order to allow a large pay rise)? Well I think the answer to all three “terrorist” tests posited by the Agreement is “yes”.

Thus, the Agreement has the potential to transform law-abiding fire-fighters pursuing an industrial dispute into “terrorists” – and the same could apply in the case of the miners in the UK miners’ strike of 1984. Perhaps those organising comprehensive public sector strikes in Greece, France, Spain and Germany against those public sector cuts should be wary – this Agreement could easily assesses them as “terrorists”!

I am sure that the intent of this Draft Agreement is currently not to do this, but the fact is that it clearly has the potential to do so. I raise this prospect merely to show that “flexible drafting” increases the risk of unintended consequences at sometime in the future.

The Draft Agreement appears to be wholly unbalanced. Article 4 allows the US Treasury to obtain “data” on request. All the Treasury needs do is specify the categories of data it wants as being necessary in connection with terrorism, get the formal approval of fellow security officers in Europol, and then the personal data can be transferred.

Note there is no judicial warrant needed in relation to requests which could involve considerable amounts of personal data. However, when the EU wants data from the US, Article 10 requires them to identify “a person or entity that there is reason to believe has a nexus to terrorism or its financing”.

The difference between the two approaches is profound. The Draft Agreement allows the US to say to the EU, for example, “give us a range of data about transactions in a certain region” as we are investigating “terrorism” (whatever that is). By contrast, a Member State of the European Union has to say to the US something like “give us the data on this known entity or specific individual” in relation to “terrorism”.

Put in these terms, it is easy to see that the US can make general requests for “data” whereas the EU has to make specific targeted requests about individuals or entities

That is why the Agreement is unbalanced and will result in a one-way data traffic flow – from EU financial institutions to the US. No explanation has been given as to why the US cannot follow the EU States and make targeted requests for personal data.

Article 12 of the Agreement establishes monitoring safeguards and controls. It states that there is to be an “independent person” appointed by the European Commission to police the data protection safeguards. Note that the Draft Agreement could easily have said that a European Data Protection Commissioner, or an ex-Commissioner, or the European Data Protection Supervisor (the natural choice I would argue) would be appointed to monitor these safeguards - but it doesn’t.

So it follows that the “independent person” is not necessarily a Data Protection Commissioner or someone who has a track record in regulating the difficult area of privacy protection versus law enforcement. Of course the various DP Commissioners will be able to huff and puff on the sidelines, but make no mistake: Europe’s privacy regulators are deliberately being positioned on the periphery of this Agreement. My blog of 14/04/2010 explains one possible reason why the EU Commission has decided on this course of action.

This raises a serious issue. If the purpose of this Article is to ensure that privacy safeguards are properly established and supervised, then the suspicion raised by its text is that the Commission wants to appoint an ex-Chief of Police or some other kind of “security apparatchik”. If such an outcome were to occur, it is not going to reassure anyone. In short, this Article could easily produce a supervisory outcome that lacks credibility.

The Agreement provides for no effective mechanism to challenge a particular data transfer before it happens. For instance, if a Bank or individual or organisation formed the view that a particular exchange would not be in accordance with the Agreement, it could go to Court to challenge the matter. In practice, such a complainant would fail because the complainant, at best, would most likely possess “suspicions of a problem”. By contrast if the Courts are to rule on an issue they need actual evidence of a problem – mere suspicion is not enough.

What should happen is that the Agreement should provide for a complainant procedure via the Independent Supervisor who should then, assuming the complaint is not vexatious or trivial, be required to investigate fully. By contrast, under the current arrangements in the Agreement, a complainant could invite the Supervisor to investigate, and hope that the Supervisor might investigate.

However, this makes the system of supervision and privacy protection, especially prior to transfer, depend on “hope” and "might" – and “hope and might” are insecure foundations upon which to build any rigid system of protection. As everybody knows, I “hope” Barnsley FC "might" win the European Cup in the near future.

Article 13 establishes a yearly review of the Agreement to investigate how well it is working, and measure its effectiveness and the safeguards. Is this review undertaken by an independent body or the independent supervisor? Well the answer is “no” - this review is to be undertaken by appointees nominated by the Parties to the Agreement.

This Article thus contains another credibility gap (or chasm, in my view). It suggests a protective mechanism akin to that achieved by allowing Count Dracula to appoint one of his brides to investigate whether an agreement to supply blood works properly.

So to my conclusion? The EU and the US want wide-ranging powers to “follow the terrorist money trail” - most people support that objective. However, the absence of a definition of “terrorism”, the provision of a weak regulatory regime to act as a counter-balance to wide-ranging data sharing powers and the deliberate exclusion of Europe’s Data Protection Commissioners mean that this Agreement should not progress in its current form.

If the Agreement goes through, the UK has to choose whether to become a member. Most international agreements become law by the Royal Prerogative so there is a significant risk that there will be little Parliamentary scrutiny prior to implementation if the decision is taken to join the Agreement.

Originally published on Hawktalk, the blog of Amberhawk Training Ltd.

Cloud storage: Lower cost and increase uptime

Sir

Can you imagine the EU asking for banking details relating to specific US 'black ops' ? - I'm sure that would work.

Tell me, does the US also supply the vaseline - or do we have to pay for that ourselves too?

Starting to understand how the rest of the world feels about US foreign policy - it feels like we are on the periphery now rather than bosom buddies, and boy can you feel the difference.

Good article.

10
0

bah

1. Just because it doesn't apply to you doesn't mean you shouldn't care. Think of your friends and family or the possibility that faulty information is shared and your wrongly accused.

2. The writer was highlighting the lack of specificity in the definition of terrorism. The 3 rules (damage property OR risk life) AND (intended to coerce government to action or inaction) are way too broad and encompass things such as industrial action which nobody would reasonably consider terrorism. The definition is therefore wrong.

8
0

Spirit of the law?

No, the spirit of the law (any law) is irrelevant. The law is what the text of the law says. If the law as drafted says that the US can demand personal information on strikers then the US can do that.

This is fundamental. You can't tweak the meaning of a law to be what you want it to mean, you have to go by the specific text.

6
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA whistleblower to tech firms, Obama: 'Grow a pair!'
Ed Snowden: Email tracking grabs 'IPs, raw data, content, headers, attachments, everything'
NSA: We COULD track you by your phone ... if we WANTED to
Honestly, too much work, can't be bothered
Google flings another £1m at online child sex abuse vid CRACKDOWN
See, see, we're trying, ad giant tells Daily Mail UK.gov
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
 breaking news
Google mounts legal challenge to surveillance gag orders
Argues free speech trumps security secrecy