Brussels, 20/04/2006 (Agence Europe) - The highly controversial directive on the retention of telecommunication data adopted for counter-terrorism purposes may be annulled, the European Data Protection Supervisor (EDPS) states. The directive, which was endorsed by the Ministers of the Interior during the JHA Council in February (EUROPE 9136), will make it an obligation for operators to keep telephone and e-mail communication data for up to two years. The use of such data proved essential in the inquiry to find the perpetrators of the bomb attacks in London in July 2005. Presenting his second annual report (2005) to the press on Wednesday, EDPS Director Peter Hustinx said he felt the legislation will be challenged before the Court of Justice and that there is a high risk of legal litigation. The directive lacks elements providing real data protection, especially concerning the duration of retention and the data to be stored, he explained, adding that it will be necessary to wait for the Court of Justice's decision before seeing whether such measures can be set in place. This will only happen, he said, if telecommunications operators feel they are injured by data storage costs, or if citizens feel it is detrimental to their privacy. Peter Hustinx considers, moreover, that the “balance” between the protection of privacy and the need for repressive authorities to have access to data for legal inquiry reasons is “often an excuse to go further than what is appropriate”. Concluding on this point, Mr Hustinx admits that people are “too naïve” when it comes to intrusion into their private life on the Internet and on mobile phones.
Whereas the year 2004 was devoted to setting up a new independent authority to protect personal data and privacy at the level of the European institutions and bodies, “2005 was focused on consolidation”, Peter Hustinx said, presenting his annual report. “Our three main activities are control, cooperation and the provision of advice, as confirmed in the institutional context, and our secretariat has seen a slight increase in the number of personnel and the establishment of our own press service”, Hustinx said, praising the work accomplished over the past two years. He went on to say: “The EU administration is progressing towards complying with its obligations and we are fostering the development of a data protection culture”. “Equally important”, Mr Hustinx said, “the EDPS advises the Commission the Council and the Parliament on proposals for new legislation that affects the privacy of citizens. However, much remains to be done in this important area”. In order to ensure that the European administration complies with the data retention obligations, EDPS has allowed for a learning period until spring 2007. Peter Hustinx pointed out that he has called on the EU institutions and bodies to present their prior control notifications by this date at the latest. In 2005, the EDPs allowed a number of tools to enable compliance, such as some 34 opinions on risky processing operations in the thematic priorities: medical files, staff appraisal, disciplinary procedures, social services and e-monitoring. At the end of 2005, 29 notifications were in process and many others were to follow. Other resources are available such as the reference document on the role of Data Protection Officers (DPO), who are compulsory in each institution or body, as well as advice and training for these officers. Peter Hustinx noted that their policy is all the more effective if these officers apply the recommendations.
By way of conclusion in its report, the EDPS foresees a series of priorities for 2006 including: - support of the DPO network to be completed by spring 2007 at latest; - continuation of prior checking; - e-monitoring and traffic data; - interventions in Court cases, raising data protection issues; - transfer of data to third countries. On this last point, Peter Hustinx was concerned by the EU/United States agreement on the transfer of air passenger data taken before the Court by the European Parliament (EUROPE 8759), considering that such an agreement violates the right to privacy.