Abstract
The submission discusses the provisions in the EU–UK Trade and Cooperation Agreement on data protection as well as the consequences for the exchange of passenger name record data in the field of criminal and judicial cooperation. The author concludes that the impact of the Agreement will depend on the resolvement of the United Kingdom to uphold the standards of protection of personal data equivalent to the EU’s in order to reach an adequacy decision.
Introduction
Exchange of data is essential to the criminal and security cooperation between Member States. Due to the high volume of cross-border movements of goods, services and persons as well as the free flow of data and capital, those data that are necessary to prevent or prosecute crimes are often to be found in another Member State. Therefore, intelligence services and law enforcement heavily rely on data exchange among the Member States for investigations, threat analysis and the protection of security. This cooperation is also a basis for the mutual trust between the Member States. For example, by exchanging information on passengers, the free movement of persons cannot be disputed by Member States as endangering homeland security. The data provided should enable the receiving state to assess the threat of persons entering their state and if necessary, monitor these persons or prevent them from entering.
This exchange of data, often personal or sensitive data, between the Member States has been made possible by ensuring common standards for data protection. Protection of personal data and communication data is a highly regulated and contested area of EU law. Bolstering common standards among the Member States for the protection of these data is one of the main achievements of the European Union of the last decade. This is in the first place ensured by the General Data Protection Regulation (GDPR) 1 and, relevant to fighting crime, Directive (EU) 2016/680 (Police Directive). 2 These documents lay down the criteria and conditions for the processing of personal data by law enforcement. Second, the e-Privacy Directive 3 governs the guarantees and standards for the protection of communication data. Third, several legal initiatives for cross-border cooperation include safeguards for data protection.
The European Union has invested in instruments to facilitate the cooperation between the Member States on the exchange of data in the area of justice and security. For example, the European Investigation Order (EIO) provides for a swift cooperation between authorities for the exchange of identification data of communication. 4 Another example is the Passenger Name Record Directive (PNR Directive) that enables the exchange of data on passengers of cross-border movement between the Member States to fight terrorism and serious crime. 5 Also, the European Criminal Records Information System (ECRIS) allows for the Member States to exchange information on previous convictions. 6
However, several of these initiatives have been challenged before the Court of Justice of the European Union (CJEU) as being contrary to the mentioned data protection and privacy standards as well as the protection of personal data. This right is entrenched in Art 8 of the Charter of Fundamental Rights of the European Union (CFREU) 7 and stringently applied by the CJEU. Famously, the EU’s proposal for a common standard for retention of communication data was annulled by the ECJ as contrary to the right to protection of personal data. 8 Equally, the ECJ opposed EU initiatives broadening the scope of the Passenger Name Record (PNR) exchange to third countries (such as to Canada) if there was no guarantee for an equivalent protection of personal data. 9
In consequence, clear rules on future cooperation between the United Kingdom and EU on data protection in the field of justice and security are necessary if both intend to ensure an efficient exchange of personal data by law enforcement and judicial authorities. In the meantime, the European Commission has issued a draft decision on the adequacy of the UK data protection for the purpose of the Law enforcement directive. This should ensure further cooperation with the UK in the field of criminal matters.
Rules concerning data protection are included throughout the TCA. However, Title III stipulates specific provisions on data protection relevant to law enforcement and judicial cooperation in criminal matters.
Relevant new provisions
Title I provides for the general principles concerning data protection and exchange between the EU and United Kingdom in Art LAW.GEN.4. 10 It stipulates the criteria on the basis of which the equivalence of data protection, and thus exchange of personal data is to be examined.
The importance for common standards on data protection for the exchange of data between the United Kingdom and EU for judicial cooperation in criminal matters is again highlighted in Title XII. Art LAW.OTHER.137 provides for a suspension clause enabling the suspension of cooperation if the United Kingdom would fail to provide for an equivalent level of the protection of personal data.
Title III regulates the exchange of passenger data between the United Kingdom and the EU. It adopts as such a new PNR regulation that draws upon previous agreements, for example, as developed for the United States or Canada.
Summary of main changes
Adequacy decision required to safeguard data transfer
Art LAW.GEN.4 is a general provision setting the principled standard on data protection to assess whether data can be exchanged in the area of law enforcement and judicial cooperation in criminal matters. The provision stipulates that the cooperation and transfer of personal data for this purpose is based on the long-standing commitment of both parties to the protection of personal data.
As the United Kingdom has become a third party to the EU with regard to data protection and cooperation in the field of criminal justice, data transfers on a general basis will only be possible in so far as the EU agrees on an ‘adequacy decision’ following the procedure included in Art 36 Police Directive. 11 This follows from the Schrems decision in which the CJEU held that the transfer of personal data to a third country is possible only if such country ensures an ‘adequate level of protection’. 12 Therefore, the Commission will have to decide on an implementing act on data exchange with the United Kingdom after having reviewed the adequacy of the UK protection of personal data. 13 The adequacy of protection is to be reviewed every four years.
Mid February, the Commission proposed its draft adequacy decision that should ensure further exchange of personal data for the purpose of the GDPR and Law Enforcement Directive. The Commission finds that the UK provides similar safeguards as EU law on the protection of fundamental rights, including rules governing the oversight mechanisms and available remedies in case of access to data by UK public authorities. 14
The draft adequacy decision will have to be reviewed not only on the basis of the protection of privacy and personal data, but also on the basis of the criteria included in the TCA. Art LAW.GEN.4 stipulates the safeguards that both parties are to uphold when processing personal data in this field: 1. Lawful and fair processing in compliance with the principles of data minimisation, purpose limitation, accuracy and storage limitation; 2. Limiting the processing of special categories of personal data to the extent necessary and subject to appropriate safeguards; 3. An appropriate level of security to protect against data breaches; 4. Enforceable rights of access, rectification and erasure for data subjects; 5. Notification of data subjects in case of breach where this is likely to result in a high risk to the rights and freedoms of natural persons; 6. Rendering onward transfers to a third country subject to additional conditions and safeguards; 7. Supervision of compliance and enforcement of data protection by independent authorities; 8. Enforceable rights for data subjects to effective administrative and judicial redress in the event that data protection safeguards have been violated.
An independent authority is required to supervise compliance with and enforcement of data protection. This follows not only from the TCA but also from Art 36 Police Directive as it requires the EU to monitor the compliance of the data protection conditions by third countries, including a periodic review to reassess the adequacy decision. Therefore, Art LAW.GEN.4 stipulates that the Specialised Committee on Law Enforcement and Judicial Cooperation 15 or the supervisory authorities will be responsible for overseeing the data protection rules applicable to the cooperation under this Part III.
As to the last requirement, Art LAW.GEN.4 provides that the United Kingdom shall ensure that a domestic independent authority responsible for data protection will have the power to supervise compliance with and enforcement of data protection. The United Kingdom will inform the EU on the implementation and compliance.
Passenger data record exchange
Title III provides the relevant rules governing the transfer and processing of Passenger Name Record data (PNR data) between the EU and the United Kingdom.
Art 11 PNR Directive sets very strict conditions for transfer of these data to third countries. As such, without an additional agreement on PNR data exchange, the cooperation between the EU and United Kingdom exchanging these data would not only be limited but also slowed down. Previously, the EU already sought to gain leeway by concluding agreements with third countries to facilitate cooperation on PNR data. 16 Title III constitutes in fact such third-country agreement on PNR data exchange, stipulating the criteria, safeguards and functioning of the exchange mechanism.
The PNR Agreement with Canada 17 was met with a high level of scrutiny by the CJEU. The Court requires for these third countries to provide an adequate level of protection of personal data if further exchange of data beyond the provisions in Art 11 PNR Directive is intended. Title III as such incorporates both the requirements of the Police Directive as well as the additional criteria set forward by the CJEU in these decisions.
The use of PNR data by the United Kingdom is exhaustively regulated under Art LAW.PNR.20. They can only be processed in three circumstances. First, PNR data received pursuant to the TCA can be processed for preventing, detecting, investigating or prosecuting terrorism and ‘serious crime’ as well as for overseeing whether the data are processed within the terms of the TCA. Second, these data can be used exceptionally to protect vital interests of natural persons, such as in case of risk of death or serious injury or where a significant public health risk exists. The latter addition is a clear result of the COVID-19 pandemic. This provision would allow the United Kingdom to use PNR data to control whether passengers from the EU have complied with the national COVID-19 prevention measures. Third, PNR data can be processed on a case-by-case basis when the disclosure is compelled by a UK court or administrative tribunal in proceedings relating to prosecuting terrorism or other serious crime.
In return, Art LAW.PNR.22 determines the exchange of PNR data from the United Kingdom with the EU. The data are to be shared with Europol or Eurojust 18 or with the Passenger Information Units (PIUs) of the Member States. This exchange of data is allowed for the same purposes, namely, for the fight against terrorism and serious crime. This provision, in addition, provides for a cooperation clause providing that if the United Kingdom has shared data with the EU or vice versa, the competent authorities shall share the result of the processing of the data or the analytical information containing PNR data.
Having settled the scope of the exchange of PNR data, Title III further stipulates four basic principles to determine the adequacy of data protection by the United Kingdom: non-discrimination,
19
the prohibition of processing special categories of data,
20
data protection and integrity
21
and transparency.
22
1. Non-discrimination: One of the merits of the PNR regulation in the TCA is the inclusion of non-discrimination as a criterion for the adequacy of data protection. As racial profiling has been a major concern for PNR data analysis, this provision states that the PNR data processing applies to all natural persons on an equal basis without unlawful discrimination. 2. Special categories of data: The processing of particularly sensitive data as enumerated in Art 10 Police Directive
23
is prohibited under the PNR regulation in Title III. In consequence, any such data that may have been exchanged in the scope of the PNR data transfer should be deleted. 3. Data protection and integrity: To ensure the security of the PNR data, the United Kingdom must take all regulatory, procedural and technical measures to prevent accidental, unlawful or unauthorised access, processing or loss. To guarantee the integrity of the data, the United Kingdom must further ensure compliance verification and the protection, security, confidentiality and integrity of the data. The TCA highlights several measures to be implemented such as encryption of PNR data. 4. Transparency and notification: The United Kingdom must ensure that it is transparent to passengers whose data being processed. Under certain conditions, the individual whose data have been retained or processed must be notified individually.
Whereas some of these criteria are drafted as broad principles while others are more detailed, the added value is that not only these criteria guide the decision of adequacy but are also a solid basis for the UK independent data protection authority to assess the processing of PNR data.
Art LAW.PNR.27-33 further details the conditions and safeguards concerning the processing of the data, namely, the automated processing, 24 the retention, 25 the use, 26 the disclosure within and outside the United Kingdom 27 and the method and frequency of transfer of the PNR data. 28 In order to ensure that all conditions are met when processing these data, the competent authorities are required to log and document all processing of PNR data. 29
Suspension clauses
Art LAW.OTHER.137 provides for a suspension clause. It stipulates that the United Kingdom or EU may suspend the requirements under Part III of the TCA or any of the titles of this part in the event of serious and systemic deficiencies in the protection of fundamental rights or the rule of law.
In a second paragraph, the TCA emphasises that such suspension will also follow in case of a serious and systemic deficiency with regard to the protection of personal data, including where those deficiencies have led to a relevant adequacy decision ceasing to apply. The suspension of an adequacy decision on data protection may as such result in the suspension of those provisions of the TCA relevant to data exchange.
Temporal application
From 1 January 2021, has become a third country as to data protection. However, the TCA has provided for an interim period during which the United Kingdom will continue to be treated as a Member State for the exchange of personal and PNR data. This interim period should allow the Commission and the United Kingdom to agree on an adequacy decision. As mentioned above, this is necessary if both envisage to continue the swift exchange of personal data. The Commission already proposed a draft adequacy decision. After the opinion of the European Data Protection Board, the representatives of the Member States will decide on the draft in the so-called comitology procedure. If positive, the Commission can adopt the draft.
Pending this procedure, Art FINPROV.10A provides for a general interim provision for the transfer of personal data from the EU to the United Kingdom. For a specified period, the United Kingdom will not be considered a third party with regard to data exchange. This interim period ends with the conclusion of an adequacy decision or at the latest four months after the entry into force of the TCA. The latter period can be extended with two further months to six months unless one of the parties objects.
As to the provisions regulating the exchange of PNR data, the TCA provides for an even more generous interim period of a year extendable by another year during which the United Kingdom is provided time to comply with the requirements concerning the retention and processing of these data. As such, several of the provisions may only take effect in 2023.
Conclusion
It is safe to say that in the short term, little will change as to data exchange in the field of law enforcement and judicial cooperation, including PNR data. By including generous interim provisions, the negotiators have bought time to reach an adequacy decision. If the adequacy decision as proposed by the Commission is adopted, the further cooperation on the current schemes of data exchange such as ECRIS and even opt-in cooperation in future schemes is safeguarded. The only outstanding question is whether such an adequacy decision is a viable solution for the cooperation on data transfer between both partners.
Already during its membership, the United Kingdom developed increasingly privacy-intrusive data retention and surveillance legislation in the field of criminal investigations and intelligence. As a member of the Five Eyes, an alliance of Australia, Canada, New Zealand, the United Kingdom and the United States, the United Kingdom has relentlessly pushed for more leniency towards intrusive investigation methods, broadened surveillance and bulk retention of communication data.
The CJEU addressed the United Kingdom’s legislation on bulk retention of communication data and surveillance for intelligence reasons in the Watson 30 and in Privacy International cases, 31 respectively, and found it incompatible with EU law, in particular with the protection of personal data. In the Big Brother case, the European Court of Human Rights (ECtHR) highlighted structural deficiencies in the protection of privacy following from the British surveillance legislation. 32 Up until now, the United Kingdom only reluctantly adapted its legislation. As such, it could be expected that the United Kingdom will at least maintain its current measures and legislation, including the legislation recently found to violate EU law, or even implement more intrusive intelligence methods and broadened data retention after Brexit.
In the draft decision, the Commission easily comes to the conclusion that the UK upholds the same standards of protection. However, given the above it is not self-evident that this draft would pass the CJEU’s review under those circumstances. 33 Without an adequacy decision, the United Kingdom would be excluded from several of the existing initiatives of data exchange in the field of law enforcement and judicial cooperation. In this case, Member States will have to rely on other instruments for cooperation, in particular the 1959 MLA Convention and protocols, or other applicable international provisions, as determined by the TCA. 34 In consequence, exchange of personal data between the United Kingdom and individual Member States will be possible only on a case-by-case basis. A systematic exchange of personal data in the field of criminal justice would therefore be excluded.
Also, for the exchange of PNR data, an adequacy decision is required. The result is not evident either, given the already developed stringent case law of the CJEU in this field. However, the TCA is an upgrade with regard to the protection of personal data in comparison to previous PNR agreements with third parties. The TCA incorporates the case law of the CJEU, and the inclusion of a non-discrimination provision is a step forward. As always, the proof of the pudding is in the eating. Given the track record of the CJEU on thoroughly examining third-country agreements on data protection, the data exchange in the field of law enforcement and judicial cooperation will depend on the willingness of the United Kingdom to continue to comply with the EU’s standards of data protection.
Footnotes
Declaration of conflicting interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) received no financial support for the research, authorship, and/or publication of this article.
1.
European Parliament and Council Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC [2016] OJ L 119/1.
2.
European Parliament and Council Directive (EU) 2016/680 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA [2016] OJ L 119/89 (Police Directive).
3.
European Parliament and Council Directive 2002/58/EC of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector [2002] OJ L 201/37.
4.
European Parliament and Council Directive 2014/41/EU of 3 April 2014 regarding the European Investigation Order in criminal matters [2014] OJ L 130/1.
5.
European Parliament and Council Directive (EU) 2016/681 of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime [2016] OJ L 119/132.
6.
European Parliament and Council Directive (EU) 2019/884 of 17 April 2019 amending Council Framework Decision 2009/315/JHA, as regards the exchange of information on third-country nationals and as regards the European Criminal Records Information System (ECRIS) and replacing Council Decision 2009/316/JHA [2019] OJ L 151/143.
7.
Charter of Fundamental Rights of the European Union [2012] OJ C 326/02.
8.
European Parliament and Council Directive 2006/24/EC of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and amending Directive 2002/58/EC [2006] OJ L 105/54.
9.
Opinion 1/15 of the Court on EU-Canada Passenger Name Record [2017] ECLI:EU:C:2017:592.
10.
All provisions cited in this piece without further reference belong to the TCA.
11.
Art. 45 GDPR also provides of a procedure for adequacy decisions. However, agreements on the basis of this procedure do not include the exchange of data for law enforcement.
12.
Case C-362/14 Schrems v Data Protection Commissioner [2015] ECLI:EU:C:2015:650.
13.
The criteria for review include among others the review of the protection of the rule of law, respect for human rights and fundamental freedoms, relevant legislation, both general and sectoral, including concerning public security, defence, national security and criminal law and the access of public authorities to personal data, the existence and effective functioning of one or more independent supervisory authorities in the third country and the international commitments with other countries or international organisations to exchange data.
14.
European Commission, Commission implementing decision of 15 February 2021 pursuant to Directive (EU) 2016/680 of the European Parliament and of the Council on the adequate protection of personal data by the United Kingdom.
15.
On the Committee, see S. Schomburg, in this issue.
16.
Today, the EU already concluded adequacy decisions with Australia (agreement between the European Union and Australia on the processing and transfer of Passenger Name Record (PNR) data by air carriers to the Australian Customs and Border Protection Service, OJ L 186, [2012], 4–16), the United States (agreement between the United States of America and the European Union on the use and transfer of passenger name records to the United States Department of Homeland Security, OJ L 215, [2012], 5–14) and Canada (fn. 18). Currently, the EU is in negotiation with Japan and renegotiation with Canada after the annulment of the previous agreement by the ECJ.
17.
Agreement between Canada and the European Union on the transfer and processing of Passenger Name Record, OJ L 82, [2006], 14–19.
18.
On Europol and Eurojust, see Niblock, in this issue.
19.
Art LAW.PNR.23.
20.
Art LAW.PNR.24.
21.
Art LAW.PNR.25.
22.
Art LAW.PNR.26.
23.
Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. See Art 10 Police Directive.
24.
Art LAW.PNR.27.
25.
Art LAW.PNR.28.
26.
Art LAW.PNR.29.
27.
Art LAW.PNR.31–32.
28.
Art LAW.PNR.33–34
29.
Art LAW.PNR.30.
30.
Case C-203/15 Tele2 Sverige AB v Post- och telestyrelsen and Secretary of State for the Home Department v Tom Watson and Others [2016] ECLI:EU:C:2016:970. On this case, see I. Buono and A. Taylor, ‘Mass Surveillance in the CJEU: forging a European Consensus’ (2017) 76(2) Cambridge Law J 250; I. Cameron ‘Balancing data protection and law enforcement needs: Tele2 Sverige and Watson’ [2017] 54 CMLRev 1467; R. S. Waranch ‘Digital Rights Ireland Deja Vu: Why the Bulk Acquisition Warrant Provisions of the Investigatory Powers Act 2016 Are Incompatible with the Charter of Fundamental Rights of the European Union’ [2017] Geo. Wash. Int’l L. Rev. 50.
31.
Case C-623/17 Privacy International [2020] ECLI:EU:C:2020:790. On the impact of this decision on Brexit see L. Lloyd ‘Another EU court ruling leaves data adequacy in doubt after Brexit’ [2020], https://
accessed 22 January 2021.
32.
Big Brother Watch and others v the United Kingdom, App Nos 58170/13 and 24960/15 (ECtHR, 13 September 2018).
33.
34.
European Convention on Mutual Assistance in Criminal Matters, CoE [1959] European Treaty Series - No 30. On the topic of MLA under the TCE, please see Oehmichen and Keith, in this issue.
