Brussels, 07/01/2009 (Agence Europe) - The US authorities in charge of protecting privacy unveiled a report in mid-December, confirming the problems they are encountering in the strict application of the EU/US agreement, which was concluded in July 2007 on European Passenger Name Records PNR (EUROPE 9457).
In its report published on 18 December 2008, the head of the office in charge of privacy at the Department of Homeland Security - DHS, Hugo Teufel, concluded that PNR management by the DHS complied with US law and the EU-US agreement on processing and transferring PNR for passengers travelling to the US. The DHS is legally obliged to allow US citizens, EU residents and travellers to consult their PNR once they are collected. However, the conclusions reveal that the office for privacy and the investigations involving PNR data generally take more than a year to be processed. Answers to investigations are often unsatisfactory. When individuals asked the DHS for “all the data” affecting them, most of the time, they did not receive their PNR data. And even when the investigations explicitly focused on PNR data, the responses sent to the DHS are incomplete. The report stipulates that a large number of investigations remain unanswered due to the lack of staff. Given the contents of these conclusions, “Identity Project”, a US association that fights for free movement in the USA, considers that the “DHS has complied with neither the agreement with the EU, nor US law in its use of PNR data concerning US citizens as well as Europeans and other foreigners”. The association considers that Europeans should demand that transmission of PNR data to the US, and access by the DHS to PNR hosting systems that contain data collected in the EU, be stopped until there is a joint review. The European Parliament should immediatley respond and ask the European Commission where they are with the “joint review”, which should be carried out at regular intervals by the EU and DHS with regard to implementation of the agreement signed in 2007. Parliament should also ask the Commission whether the agreement should be reassessed in the context of the new framework decision on data protection in the third pillar, particularly Article 13, which requires appropriate levels of protection during data transfers to third countries. (B.C./transl.rh)