Brussels, 26 May 2010
European Commission seeks high privacy standards in EU-US data protection agreement
The European Commission today adopted a draft mandate to negotiate a personal data protection agreement between the European Union and the United States when cooperating to fight terrorism or crime. The aim is to ensure a high level of protection of personal information like passenger data or financial information that is transferred as part of transatlantic cooperation in criminal matters. The agreement would enhance the right of citizens to access, rectify or delete data, where appropriate. EU citizens would receive a right to seek judicial redress in the US if their data is unlawfully processed. Independent public authorities would be given a stronger role in helping people exercise their privacy rights and in supervising transatlantic data transfers. The Council must approve the Commission's negotiating mandate before talks can begin. The European Parliament will be fully informed at all stages of the negotiations and will have to give its consent to the outcome of the negotiations.
"Fundamental rights must be protected and respected at all times. I want an EU-US agreement that protects personal data rights while fighting crime and terrorism," said Vice President Viviane Reding, the EU's Commissioner for Justice, Fundamental Rights and Citizenship. "I want to achieve an ambitious agreement, and I will associate the European Parliament very closely to the negotiations. I urge the Council to approve the mandate as soon as possible so we can swiftly proceed with negotiations on this and other important agreements between the EU and the US."
The EU Commissioner for Home Affairs, Cecilia Malmström, added: ''A solid agreement on personal data protection would benefit both sides of the Atlantic. By providing a high level of protection of personal data, it would give everyone – citizens, law enforcement authorities and other stakeholders – confidence that human rights are fully respected in the transatlantic fight against organised crime and terrorism."
Since 11 September 2001 and subsequent terrorist attacks in Europe, the EU and US have stepped up police and judicial cooperation in criminal matters. One important element is the transfer and processing of personal data if relevant for the prevention, investigation, detection or prosecution of crimes, including terrorism.
The EU and US are both committed to the protection of personal data and privacy. However, they still have different approaches in protecting data, leading to some controversy in the past when negotiating information exchange agreements (such as the Terrorist Finance Tracking Programme, so-called SWIFT agreement, or Passenger Name Records). The purpose of the agreement proposed by the Commission today is to address and overcome these differences.
Today's proposal would give the Commission a mandate to negotiate a new data protection agreement for personal data transferred to and processed by enforcement authorities in the EU and the US. It would also commit the Commission to keeping the European Parliament fully informed at all stages of the negotiations.
The Commission aims to establish legally binding and enforceable personal data protection standards that will ensure that individuals’ fundamental rights and freedoms are protected. Compliance with these standards would be controlled by independent public authorities on both sides of the Atlantic.
Under the Commission's proposal:
- The transfer or processing of personal data by EU or US authorities would only be permitted for specified, explicit and legitimate purposes in the framework of fighting crime and terrorism;
- There would be a right to access one's personal data and this would be enforceable in courts;
- There would be a right to have one's personal data corrected or erased if it is found to be inaccurate.
- There would be an individual right of administrative and judicial redress regardless of nationality or place of residence.
The agreement would not provide the legal basis for any specific transfers of personal data between the EU and the US. A specific legal basis for such data transfers would always be required, such as a data transfer agreement or a national law in an EU Member State. The new EU-US data protection agreement would then apply to these data transfers.
The protection of personal data is set out in Article 8 of the EU Charter of Fundamental Rights. The Charter is integrated into the Lisbon Treaty and is legally binding on the European Union and EU Member States when they implement EU law. The Lisbon Treaty (Article 16, Treaty on the Functioning of the EU) says that the EU can make rules on the protection of personal data processed by EU institutions, bodies, offices and agencies, and by the Member States when carrying out activities that fall within the scope of EU law.
The European Parliament, in a resolution on 26 March 2009, called for an EU-US agreement that ensures adequate protection of civil liberties and personal data protection. In December 2009, the European Council invited the Commission to propose a Recommendation "for the negotiation of a data protection and, where necessary, data sharing agreements for law enforcement purposes with the US."
For more information
Justice and Home Affairs Newsroom:
Homepage of Viviane Reding, Vice-President and Commissioner for Justice, Fundamental Rights and Citizenship: