Tag Archives: data protection directive

Spying on the Europeans — PRISM repercussions as Obama heads to Europe

stasi 2.0

Michael J. Geary and I argue in The National Interest this morning that the repercussions of reports of the PRISM program within the U.S. National Security Agency mean that U.S. president Barack Obama will face tough questions when he goes to Europe for the G8 summit in Northern Ireland and additional meetings in Berlin. USflagEuropean_Union

At a time when Europeans are already concerned about the extent of their own governments’ intrusion into their private online lives, the revelations of the voluntary cooperation of service providers like Facebook and the like in allowing U.S. surveillance of foreign communications are already being met with skepticism from top U.S. allies at a crucial and ambitious time for the Obama administration’s European agenda:

The timing of the scandal could not have come at a worse time in EU-United States relations, with both sides set to embark on negotiations for what would be a landmark free-trade compact, the Transatlantic Trade and Investment Partnership (TTIP).

Above all, German chancellor Angela Merkel is expected to seek assurances from Obama in their one-on-one meetings in Berlin.  But with Germany having this week agreed to TTIP negotiations (leaving France as the remaining obstacle), and with the eurozone crisis still not fully over, certainly the Obama-Merkel meeting should have more important business than PRISM.

Ironically, the NSA gathered more pieces of intelligence within Germany during the month of March than any other EU country.  A spokesman for Merkel, the first chancellor from the former East Germany, where memories of Stasi surveillance are still fresh, said she would raise the issue with Obama. Her justice minister Sabine Leutheusser-Schnarrenberger stressed, “the suspicion of excessive surveillance of communication is so alarming that it cannot be ignored. For that reason, openness and clarification by the US administration itself is paramount at this point. All facts must be put on the table.”

Ultimately, the Obama administration and the NSA will be less vulnerable to the wrath of European regulators than the companies participating in PRISM themselves.

But Microsoft, Google and other service providers, including Facebook, YouTube, Apple and AOL, could face even more blowback than the U.S. government or the Obama administration. Their apparently voluntary participation in U.S. government’s PRISM program could open them to European lawsuits or otherwise subject them to additional regulatory scrutiny. Significant elements of their businesses are already subject to restrictions within Europe—Google faces strict restrictions on its StreetView program and Facebook’s facial-recognition capability is banned altogether. As PRISM continues to dominate world headlines, Facebook on Wednesday opened its first servers outside of the United States in northern Sweden—its presence there, which like much of Scandinavia is a bastion of government transparency and personal freedom, will come increasingly under the thumb of EU regulators.

I argued yesterday that Sweden is unlikely to come to the rescue anytime soon with respect to Facebook and PRISM.  More likely is that the European Parliament will work to pass the new data protection directive that it’s been considering for the past two years and that would place additional restrictions on the processing of personal data, though time is quickly running short with European elections set for May 2014.

Photo above is a popular graffiti slogan in Germany, showing former interior minister (and now finance minister) Wolfgang Schäuble — critics claimed Schäuble’s focus on counterterrorism measures approached levels of civil liberties intrusion similar to the East German secret police and intelligence force, the Stasi.

Can Sweden save the European Union from the NSA spooks?

facebook goes arctic

Even as the media continues to debate leaks revealing the secret surveillance program of the U.S. National Security Agency, code-named ‘PRISM,’ one of the chief private-sector actors in the PRISM scandal opened its first non-U.S. site on Wednesday, giving one European nation a key jurisdictional hook to regulate future data privacy.USflagEuropean_UnionSweden

According to news reports from The Guardian, Facebook, has been cooperating voluntarily with the NSA’s PRISM program since summer 2009, thereby exposing the private data of both U.S. and non-U.S. citizens alike to the purview of the NSA under the authority of the U.S. PATRIOT Act passed in the aftermath of the 2001 al Qaeda terrorist attacks on New York and Washington.

But Facebook also opened a new facility to host its servers in far northern Sweden on Wednesday (in part to use the chilly Arctic weather to more efficiently cool its European servers).  Despite the awkward timing, it is Facebook’s first server hall outside of the United States, and its opening comes when European Union leaders are pushing for answers on the extent to which NSA has been permitted access to private, personal data by Facebook, Google, YouTube, Apple, AOL and other service providers and while the European Parliament is considering a new data protection directive that would enhance protection of the personal data of EU citizens.  Assuming that the European Union cannot stop U.S. government agencies, it means that European regulators could target U.S. technology companies in greater measure — after all, the EU already places restrictions on Google’s StreetView program and has already banned the European use of Facebook’s face recognition software.

So does that give Sweden a unique opportunity to ensure that the private data of EU citizens is not caught up in the NSA snare?

After all, Sweden is virtually synonymous with good government, right?

According to Transparency International, it’s among the least corrupt countries is the world.  In the middle of the 18th century, Sweden essentially invented the concept of freedom of information with the Freedom of the Press Act of 1766, and its leaders over the past two decades championed a EU-wide freedom of information regime.

But a reputation for transparency doesn’t necessarily connote a reputation for protecting privacy.  Wikileaks founder Julian Assange was so worried that Swedish authorities would extradite him to the United States that he chose to hunker down in Ecuador’s London embassy instead of allowing British authorities to transfer him to Sweden for a trial on a sexual harassment charge.  Swedes have also raised concerns with EU policymakers that the push for more robust data protection could actually harm government transparency by limiting the Swedish government’s ability to provide open access to documents.

Moreover, the current center-right coalition headed by prime minister Fredrik Reinfeldt of the Moderata samlingspartiet (Moderate Party) has introduced greater levels of Swedish surveillance.  In 2009, it narrowly passed legislation that would allow the government’s Försvarets radioanstalt (the National Defence Radio Establishment) to wiretap and access all international telephone and internet traffic, even if all  ultimate parties in the traffic are Swedish.  Though the legislation, know as the ‘FRA law’ passed only narrowly by Sweden’s parliament, the law had its genesis in the prior center-left government of the Sveriges socialdemokratiska arbetareparti (Swedish Social Democratic Workers Party).  It essentially codified into Swedish national law much of what PRISM has been purported to do within the United States.

The law caused some amount of concern, especially in neighboring Finland because all of its Internet and phone traffic at the time routed through Sweden.

Sweden’s foreign minister Karl Bildt earlier this week protested that Swedish activities under the FRA law are not similar to what’s been reported PRISM, in part on the basis that the FRA law was debated publicly and enacted by a duly elected parliament.  In that regard, Bildt’s right — it was clear just what was at stake when the Swedish parliament adopted the FRA law; in contrast, Facebook wasn’t even developed until three years after the U.S. PATRIOT Act.  In addition, Bildt expressed a healthy hint of suspicion about other ‘certain states,’ presumably including the United States:

 

Continue reading Can Sweden save the European Union from the NSA spooks?