Brussels, 11/10/2007 (Agence Europe) - European experts on data protection who make up the “Article 29 Working Party” will soon be delivering a generally positive message on the progress made by the American company, Swift (Society for Worldwide Interbank Financial Telecommunications), concerning respect of EU data protection rules.
In 2006, Swift, which is specialised in secure messaging systems in the banking sector, had been accused of transferring data to the American authorities for counter-terrorism purposes, in breach of European data protection rules. On average, Swift handles 12 million messages daily. In 2005, for example, the total volume of messages processed was 2.5 billion, including 1.6 billion for Europe. Responsible for data processing, Swift and the European financial institutions that use its services share a common responsibility, albeit on a different scale, for personal data processing. The European Central Bank (ECB) itself had called on European governments to work towards setting new rules in place to eliminate the uncertainties surrounding data protection in payment systems. It above all called on banks to ask for customers' consent before using Swift and to keep them informed in complete openness (EUROPE 9358). The Article 29 Working Party, entrusted with following up this matter, recently held a further discussion, the result of which was a generally “positive” message concerning the correcting measures taken by Swift, a European source confided to EUROPE. At the level of the member states and of their banks, “progress” has also been made but “not equally”, states a European source, which asserts, without giving names, that “some (states) have dropped considerably behind”.
The ball is now in the court of the Belgian committee on protection of privacy, this being the relevant body in this dossier as Swift must comply with Belgian law on privacy as it is based in Belgium. For its electronic operations, Swift has a server in the Netherlands and, for security reasons, a “twin server” in the United States. It is through the latter that data has apparently been examined by the CIA and the US Treasury Department, since September 11 2001. Called upon to act in response, Swift announced in early October that it will be setting up its second Operating Centre (OPC) or “mirror site” in Switzerland to ensure that intra-European banking messages remain in Europe. Although the choice of the site has not yet been determined, this new centre will allow Swift to process and store messages, which are internal to the European Economic Area or Switzerland, solely in its two European OPCs. The second Swift OPC is based in the Netherlands. In early July, the company pledged to sign up to the “Safe Harbour Principles”, which means that it undertakes to comply with a level of protection equivalent to that in force in the EU when importing data from European countries into the United States (EUROPE 9457). According to the Belgian committee responsible for the protection of privacy, the United States has obtained private data from Swift on 63 occasions between September 2001 and June 2006, when transfers were revealed by the American press. Data has been transferred six times since then. (bc)