Tuesday, 8 April 2014

National legal challenges to the Data Retention Directive



Chris Jones, Researcher for Statewatch

This post, which examines the numerous legal challenges against the EU's Data Retention Directive at both national and EU level (not including today's judgment), is the third post in a series examining the EU's mandatory data retention legislation, which was struck down today by the Court of Justice of the European Union (CJEU). It is based on work undertaken by Statewatch as part of the SECILE project (Securing Europe through Counter-terrorism: Impact, Legitimacy and Effectiveness).

 EU Court of Justice legal basis challenge

The first legal challenge to the Data Retention Directive came when Ireland, supported by Slovakia, asked the EU Court of Justice to annul the Directive on the grounds that it had the wrong legal basis. They argued that the correct legal basis for data retention resided “in the provisions of the EU Treaty concerning police and judicial cooperation in criminal matters,” rather than those on the internal market. The ECJ dismissed the case in February 2009, stating that: “Directive 2006/24… regulates operations which are independent of the implementation of any police and judicial cooperation in criminal matters. It harmonises neither the issue of access to data by the competent national law-enforcement authorities nor that relating to the use and exchange of those data between those authorities… “It follows that the substantive content of Directive 2006/24 is directed essentially at the activities of the service provides in the relevant sector of the internal market, to the exclusion of State activities coming under Title VI of the EU Treaty".


Bulgaria


The first ruling on national laws transposing the Directive came from Bulgaria in proceedings launched by the NGO Access to Information Program. In December 2008 the country’s Supreme Administrative Court annulled an article of the transposing legislation permitting the Ministry of Interior “passive access through a computer terminal” to retained data, as well as providing access without judicial permission to “security services and other law enforcement bodies”. The court found that: “[T]he provision did not set any limitations with regard to the data access by a computer terminal and did not provide for any guarantees for the protection of the right to privacy stipulated by Art. 32, Para. 1 of the Bulgarian Constitution. No mechanism was established for the respect of the constitutionally granted right of protection against unlawful interference in one’s private or family affairs and against encroachments on one’s honour, dignity and reputation.” The court also found the legislation failed to make reference to other relevant laws – the Penal Procedure Code, the Special Surveillance Means Act and the Personal Data Protection Act – “which specify conditions under which access to personal data shall be granted.”


Hungary


In June 2008 the Hungarian Civil Liberties Union (HCLU or TASZ, Társaság a Szabadságjogkért) requested “the ex-post examination” by the Hungarian Constitutional Court of the amendment of Act C of 2003 on electronic communications, “for unconstitutionality and the annulment of the data retention provisions.” According to the HCLU, Act C “already comprised numerous restrictive data retention provisions prior to the directive. The only changes brought in by the amendments were the retention of Internet communications data and the elimination of the lax – but at least pre-defined – legal purposes of the data processing”. The HCLU argued that “the amendments completely disregarded the provisions of the directive [stating] that data should be ‘available for the purpose of investigation, detection and prosecution of serious crimes’.” Despite being filed in 2008, the case is yet to be heard. According to Fanny Hidvégi of the HCLU, this is because as of 1 January 2012 new restrictions were placed on submitting cases to the Constitutional Court, and “every pending case submitted by a person or institution which no longer has the right to do so were automatically terminated”. The HCLU has begun a new and lengthy procedure that requires the exhaustion of all other remedies before the Constitutional Court can examine the Hungarian data retention measures.


Romania


In October 2009, the Romanian Constitutional Court found that proposed national legislation implementing the Data Retention Directive violated Romanian constitutional provisions protecting freedom of movement; the right to intimate, private and family life; secrecy of correspondence; and freedom of expression. The court found that the government’s attempt to justify the mandatory retention of telecommunications data by invoking undefined “threats to national security” was unlawful. The Court also referred to the 1978 ECHR ruling in Klass v Germany, which stated that “taking surveillance measures without adequate and sufficient safeguards can lead to ‘destroying democracy on the ground of defending it’.”

 In October 2011 the European Commission asked the Romanian government to bring forward new laws transposing the Directive, issuing a “reasoned opinion” under Article 258 of the TFEU, which carries the threat of full infringement proceedings at the European Court of Justice if the request is not met. A new law was duly drafted, but was rejected by the Romanian Senate. The law was heavily criticised in the media prior to the vote and the country’s Data Protection Authority had refused to endorse it, claiming that articles relating to the security services were “still vague”. Civil society organisations also opposed it and even the government refused to sponsor it, leaving the Minister of Communications and Information Society to propose it in his role as MP rather than minister. Strong support from the Minister of European Affairs fuelled criticism that it was motivated solely by the need to escape sanction by the European Court of Justice.

Ultimately the Senate vote was not decisive and the law continued its journey to the Chamber of Deputies, where at the end of May 2012 it was adopted with 197 votes for and 18 against, with many abstentions amongst the 332 deputies. There was no substantive discussion of fundamental rights issues in the Chamber of Deputies or the main two committees that debated the law and critics have argued that the provisions on access to retained data are even more problematic than the original statute. On 21 February 2013 the European Commission withdrew the infringement procedure that it had opened in 2011.

Cyprus

In February 2011 the Supreme Court of Cyprus ruled that aspects of the national transposing legislation breached the Cypriot constitution and case law on surveillance. The case was brought by individuals whose telecommunications data had been disclosed to the police in accordance with District Court orders. They argued that the laws underlying the orders were based (Articles 4 and 5 of Law 183(I) 2007, that sought to harmonise Cypriot law with the Directive), and therefore the District Court orders themselves violated their rights to privacy and confidentiality of communications. The Supreme Court found that petitioners had indeed been subject to a violation of their rights and annulled provisions it said went beyond the requirements of the Data Retention Directive. However, the legality of the Directive itself was not called into question.


Germany


Legislation transposing the Data Retention Directive into the Telecommunication Act and Code of Criminal Procedure was passed by the Bundestag on 9 November 2007 and entered into force on 1 January 2008. The day before, 31 December 2007, 35,000 German citizens (represented by the NGO AK Vorrat) filed a complaint against the legislation at the Federal Constitutional Court. On 2 March 2010 the Court ruled that the transposing provisions were a disproportionate interference with Article 10 (confidentiality of communications) of the Basic Law (Grundgesetz), and contravened legal standards on purpose limitation, data security, transparency and legal remedies.

However, the Court made no ruling on the actual Directive, stating that data retention is in principle proportionate to the aim of investigating serious crime and preventing imminent threats against life, body, freedom of persons, and the existence and security of the Federal Republic or one of its states. The Court found that the new domestic law failed to comply with legal standards on purpose limitation (restrictions on use of the retained data), data security, transparency and legal remedies.

In January 2011 the Ministry of Justice (MoJ) presented a paper proposing an alternative to data retention – a “quick freeze” system of limited data preservation for criminal investigations. The police and/or public prosecutors would issue a “quick freeze” order seeking access to metadata already held by telecommunications providers, for example for billing purposes. To actually access the “frozen”’ data would require the approval of a judge. In addition, the MoJ proposed an obligation for ISPs to store internet traffic data for seven days, allowing criminal investigators to identify persons behind (already known) IP addresses in particular in cases of child pornography. Criminal investigators would request the traffic and communications data via service providers without having direct access to these traffic data. This paper reflected proposals made in June 2010 by the Federal Commissioner for Data Protection, as well as the suggestions of more pragmatic privacy advocates.

More radical activists claim that any mandatory storage of communications data should be prohibited. The Interior Ministry rejected these proposals and insisted on full implementation of the Directive, arguing that the Constitutional Court had already shown that it is possible to implement the Directive and ensure individual privacy through high data security standards, including encryption and the “four eyes principle” (approval by at least two people) as prerequisite for accessing data and log files; strict purpose limitation; and the protection of professions whose confidentiality must be ensured.

The MoJ produced a “quick freeze” bill in April 2012 but continued opposition from the Interior Ministry meant that it was never tabled in Parliament. The Interior Ministry was unhappy with the length of the proposed freezing periods, demanding three months instead of the one month suggested by the Ministry of Justice. Moreover, the Interior Ministry wanted to include crimes such as fraud and hacking. The controversy continues and no new legislation has yet been introduced.

By this time the European Commission had initiated infringement proceedings and took its case to the European Court of Justice in July 2012. The Commission is seeking to impose a daily fine of €315,000.

Czech Republic

On 13 March 2011 the Czech Republic's Constitutional Court declared national legislation implementing the Directive unconstitutional. It found that the retention period exceeded the requirements of the Directive, and that use of the data was not restricted to cases of serious crime and terrorism. “The national legislation lacked, according to the constitutional court, clear and detailed rules for the protection of personal data as well as the obligation to inform the person whose data has been requested.” As in Germany, the Court stated that it could not review the Directive itself, but noted there was nothing in principle preventing implementation in conformity with constitutional law.

A second Constitutional Court decision in December 2011 examined the procedures put in place for obtaining access to retained data and found the “procedure in question to be too vague, in breach of [the] proportionality rule (its second step) and thus unconstitutional due to interference with right to privacy and informational self-determination.” In the meantime the Czech government revised the implementing legislation with modifications that took account of the judgment.The NGO Iuridicum Remedium has lodged fresh proceedings against the revised legislation on the grounds that regulation remains inadequate and that the new decree could provide for the “monitoring of contents of Internet communications”.

Slovakia

In August 2012 a group of Slovakian MPs, supported by the European Information Society Institute, lodged a legal complaint against the legislation implementing the Data Directive. The complaint asks the Slovak Constitutional Court to examine whether the laws implementing the Directive and dealing with access by the authorities to retained data are compatible with constitutional provisions on proportionality, the rights to privacy and data protection, and the provision granting freedom of speech. It also argues that the measures infringe provisions guaranteeing privacy, data protection and freedom of expression in Slovakian human rights law, the European Convention on Human Rights and the Charter of Fundamental Rights of the European Union. The complaint has not yet been resolved.


Sweden


The European Commission has engaged in a lengthy battle to try to bring Sweden’s domestic legislation into line with the Directive. After the country missed the initial September 2007 deadline, the Commission brought infringement proceedings, with the European Court of Justice finding Sweden guilty of failing to fulfil its obligations in February 2010. A proposal for transposing legislation was put forward in December 2010 and adopted in March 2012. The new law should have taken effect in May 2012 but despite an overwhelming vote in favour of the new measures in the Swedish parliament (233 MPs voted in favour with 41 against and 19 abstaining), the Left Party and the Greens invoked a constitutional provision allowing the entry into force of new measures to be delayed by a motion of one sixth of the parliament's members.

In May 2013, the European Court of Justice ordered Sweden to pay a €3 million fine for its delay in implementing the legislation. The Court rejected Swedish pleas regarding the domestic controversy over the implementation of the law: “As the Court has repeatedly emphasised, a Member State cannot plead provisions, practices or situations prevailing in its domestic legal order to justify failure to observe obligations arising under European Union law... The same is true of a decision, such as the one made by the Swedish Parliament, to which paragraph 8 of this judgment makes reference, to postpone for a year the adoption of the draft bill intended to transpose that directive.”


The Court of Justice of the European Union (CJEU)


The most serious challenge to the implementation of the Data Retention Directive has come from joined cases brought by the NGO Digital Rights and the plaintiffs in a case referred from the Austrian Constitutional Court. The Advocate General's opinion on the case, published in December 2013 following a hearing in July, proposed that the Court declare the Directive as a whole incompatible with EU Charter articles 52(1) (limitations on rights “must be provided for by law and respect the essence of those rights and freedoms”) and 7 (right to privacy). The case focuses on the compatibility of the Directive with Articles 7 (respect for private and family life) and 8 (protection of personal data) of the European Union Charter of Fundamental Rights. At the hearing the representatives of those who brought the cases argued that the Directive is fundamentally incompatible with the Charter and that there is still no evidence to demonstrate that its necessity or proportionality.

On behalf of Austrian privacy group AK Vorrat, Edward Scheucher argued that: “[T]he cumulative effect of fundamental rights restrictions need to be taken into consideration when judging the legitimacy of a single measure. Given the revelations regarding PRISM, this cumulative effect now clearly provides a different result [than] at the time when the German [Constitutional] Court took its decision [to annul certain provisions of German transposing legislation]. Furthermore, he stated that the Austrian implementation of the directive clearly showed that a Charter-compatible national implementation of the Data Retention Directive is not possible. This argument is bolstered by the fact that the main author of the Austrian implementation is among the 11,139 Austrian plaintiffs who challenged data retention before the Austrian Constitutional Court."

In response to requests for evidence demonstrating the necessity of the Directive, the Austrian and Irish governments presented new statistics on the use of retained data at the hearing. Also arguing in favour of the Directive were representatives of Italy, Spain and the UK, as well as the Commission, the Council and the Parliament. However, the Directive’s advocates still “had to acknowledge a lack of statistical evidence”, with the UK admitting that “there was no ‘scientific data’ to underpin the need” for data retention. Judge Thomas von Danwitz, the Court’s main rapporteur for the hearing, asked for information that had led to the adoption of the Directive in 2006, given that “the Commission in 2008 claimed not to have enough information for a sound review”. The Council’s lawyers, meanwhile, “implored the Court not to take away instruments from law enforcement”.

 Ultimately, Advocate-General Cruz Villalón concluded that the Court answer the cases in the following way: “(1) Directive 2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and amending Directive 2002/58/EC is as a whole incompatible with Article 52(1) of the Charter of Fundamental Rights of the European Union, since the limitations on the exercise of fundamental rights which that directivecontains because of the obligation to retain data which it imposes are not accompanied by the necessary principles for governing the guarantees needed to regulate access to the data and their use. “(2) Article 6 of Directive 2006/24 is incompatible with Articles 7 and 52(1) of the Charter of Fundamental Rights of the European Union in that it requires Member States to ensure that the data specified in Article 5 of that directive are retained for a period whose upper limit is set at two years.”

Today's Grand Chamber judgment, which is analysed in Steve Peers' separate post, ultimately agreed with this recommendation. The EU has finally been forced to redraft its mandatory data retention rules.


 Barnard & Peers: chapter 9, chapter 25

Content and implementation of the Data Retention Directive



By Chris Jones, Statewatch researcher

This is the second in a series of posts examining the EU's Data Retention Directive, which is the subject of today's judgment of the Court of Justice of the European Union (CJEU). It is based on work undertaken by Statewatch as part of the SECILE project (Securing Europe through Counter-terrorism: Impact, Legitimacy and Effectiveness).

The post begins with an article-by-article examination of the Directive and subsequently examines the troubled national transposition and review process overseen by the European Commission. The first post examined the background to the Directive, and a subsequent, final post will look at national court cases challenging the implementation of the Directive.

The Directive, clause-by-clause

Article 1 sets out the subject matter and scope of the Directive, which covers all legal entities and: “[A]ims to harmonise Member States’ provisions concerning the obligations of the providers of publicly available electronic communications services or of public communications networks with respect to the retention of certain data which are generated or processed by them, in order to ensure that the data are available for the purpose of the investigation, detection and prosecution of serious crime, as defined by each Member State in its national law.”

Article 1(1) of the Directive states that serious crime is “as defined by each Member State in its national law”. Article 1(2) states that the Directive does not apply to the retention of the content of communications. However, it has long been argued that “retaining [internet] traffic data makes it possible to reveal… what websites people have visited”, indicating that certain content data can be retained under the Directive. The EU’s Article 29 Working Party on data protection issued an Opinion in 2008 making clear that the Directive is “not applicable to search engine providers”, as “search queries themselves would be considered content rather than traffic data and the Directive would therefore not justify their retention.”

Article 2 contains definitions. Article 3 outlines the obligation for telecoms providers to retain data, through derogation from a number of Articles (5, 6 and 9) of the e-Privacy Directive. Article 5 of that Directive obliges Member States to: “[E]nsure the confidentially of communications and the related traffic data by means of a public communications network and publicly available electronic communications services” through the prohibition, except when legally authorised, of “listening, tapping, storage or other kinds of interception or surveillance.” Article 6 of the e-Privacy Directive prohibits the retention by telecommunications providers of “traffic data relating to subscribers and users” except if necessary for billing or marketing and with the users' consent. Article 9 states that location data relating to users or subscribers “may only be processed when they are made anonymous, or with the consent of the users of subscribers to the extent and for the duration necessary for the provision of a value added service.”

Article 4 of the Data Retention Directive covers access by Member States’ competent authorities to retained data, which should only occur “in specific cases and in accordance with national law”. The phrase “competent authorities” is undefined in the Directive. Member States decide which of their agencies and institutions can request and access retained data. Member States also define the procedures authorities should follow to get access to retained data. This has led to wide divergence between Member States in which authorities can access retained data, and how they do so. The Directive also fails to stipulate that national law should include judicial scrutiny of requests for retained data, allowing Member States to establish self-regulatory systems that dispense with traditional surveillance “warrants”.

Article 5 lists in detail the data that must be retained by service providers:

The source of a communication;
The destination of a communication;
The date, time and duration of a communication;
The type of a communication;
Users’ communication equipment or what purports to be their equipment; and
The location of mobile communication equipment.

Article 6 covers periods of retention (“not less than six months and not more than two years from the date of the communication”). Article 7 outlines measures for the protection and security of retained data, compliance with which is to be supervised by “one or more public authorities” in accordance with Article 9.

Article 8 states that the storage of retained data must allow for its transmission to competent authorities, when requested, “without undue delay”. Article 10 obliges Member States to provide annual statistics to the Commission. Article 11 makes an amendment to Article 15 of the e-Privacy Directive, paragraph 1 of which permits Member States to enact their own data retention measures if they consider them: “[A] necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system.”

The Data Retention Directive supplemented this by stating that: “Paragraph 1 shall not apply to data specifically required by [the Data Retention Directive] to be retained for the purposes referred to in Article 1(1) of that Directive.” This legislative overlap has been problematic and the European Commission, which is reviewing the Data Retention and e-Privacy Directives in parallel, has suggested that: “Any revision of the Data Retention Directive should ensure that retained data will be used exclusively for the purposes foreseen in this Directive, and not for other purposes as currently allowed by the e-Privacy Directive.”

Article 12 permits Member States to extend retention for “a limited period” if they face “particular circumstances”, subject to the post-facto approval of the Commission. Article 13 obliges Member States to ensure that provisions of EU data protection law dealing with judicial remedies, liabilities and sanctions apply to Member States' transposing measures. It also requires the punishment by “penalties, including administrative or criminal penalties, that are effective, proportionate and dissuasive,” of any illegal access to or transfer of retained data.

Article 14 obliged the Commission to undertake “an evaluation of the application of this Directive and its impact on economic operators and consumers” and present it to the European Parliament and the Council (see further below). Article 14 also obliged the Commission to determine at this time “whether it is necessary to amend the provisions of this Directive”, a decision that the Commission has deferred, leaving no precise timetable for a new proposal. 

Articles 15-17 require Member States to transpose the Directive into national law by 15 September 2007. Article 15(3) allows Member States to “postpone application of this Directive to the retention of communications data relating to Internet Access, Internet telephony and Internet e-mail” for up to three years. Austria, Belgium, Cyprus, Czech Republic, Estonia, Finland, Germany, Greece, Latvia, Lithuania, Luxembourg, the Netherlands, Poland, Slovenia, Sweden and the UK all took up this option. The national legislation through which Member States transposed the Directive is listed in the EUR-Lex register.

Transposition and review

Nearly seven years after the deadline for implementation, the Directive has still not been implemented by all the states it covers and genuine “harmonisation” appears a remote prospect. Even with the extra room for manoeuvre on internet data retention, six Member States still found themselves subjected to infringement proceedings brought by the Commission after failing to implement national legislation on time.

The Commission brought proceedings against Austria, the Netherlands and Sweden in May 2009, Greece and Ireland in November 2009, and Germany in May 2012. Austria, Greece, the Netherlands, Ireland and Sweden subsequently adopted legislation; Germany has failed to do so and an infringement action is pending at the European Court of Justice. In Norway (obliged to implement the Directive through membership of the European Economic Area) legislation is yet to be agreed by parliament, and there is an on-going campaign by civil society organisations against it. The Commission recently demanded that Belgium “change its data retention laws to comply with the provisions of the European legislation”, and a draft bill aimed at ensuring full implementation was introduced into the Belgian Parliament in July 2013.

The Commission's evaluation of the Directive, due in September 2010, was eventually published in April 2011. It concluded that: “[D]ata retention is a valuable tool for criminal justice systems and for law enforcement in the EU. The contribution of the Directive to the harmonisation of data retention has been limited, in terms of, for example, purpose limitation and retention periods, and also in the area of reimbursement of costs incurred by operators, which is outside its scope.”

Retention period and scope

That the Directive failed to harmonise retention periods is hardly surprising – it allowed Member States to choose from anywhere between 6 and 24 months. The failure of the Directive to define “serious crime” also led to wide divergences across Member States: “Ten Member States (Bulgaria, Estonia, Ireland, Greece, Spain, Lithuania, Luxembourg, Hungary, Netherlands, Finland) have defined ‘serious crime’, with reference to a minimum prison sentence, to the possibility of a custodial sentence being imposed, or to a list of criminal offences defined elsewhere in national legislation. Eight Member States (Belgium, Denmark, France, Italy, Latvia, Poland, Slovakia, Slovenia) require data to be retained not only for investigation, detection and prosecution in relation to serious crime, but also in relation to all criminal offences and for crime prevention, or on general grounds of national or state and/or public security. The legislation of four Member States (Cyprus, Malta, Portugal, UK) refers to ‘serious crime’ or ‘serious offence’ without defining it.”

Most Member States also “allow the access and use of retained data for purposes going beyond those covered by the Directive, including preventing and combating crime generally and the risk of life and limb”.

Access to retained data

The authorities permitted to access retained data differ significantly from state to state. Every Member State allows police access and all except the UK and Ireland give access to prosecutors. 14 states provide access to security and intelligence agencies (only 12 are easily identifiable in the report – Bulgaria, Estonia, Spain, Latvia, Lithuania, Luxembourg, Hungary, Malta, Poland, Portugal, Slovenia and the UK). Six (Finland, Hungary, Ireland, Poland, Spain, UK) give access to tax and/or customs authorities; and four to border police (Estonia, Finland, Poland, Portugal). The UK allows other public authorities access to data retained if “authorised for specific purposes under secondary legislation.”

The type of authorisation required for access is also uneven: “Eleven Member States require judicial authorisation for each request for access to retained data. In three Member States judicial authorisation is required in most cases,” but the information provided in the report is not specific enough to allow identification of these states. A senior authority, but not a judge, must give authorisation in four other Member States (five Member States' information – Cyprus, France, Hungary, Italy, Poland – appears to fit this description). In two Member States, “the only condition appears to be that the request is made in writing,” although the information provided indicates that three states have such systems: Ireland, Malta and Slovakia.

Legitimacy and effectiveness

The Commission has acknowledged that many groups and individuals consider mandatory data retention “in principle… unjustified and unnecessary”. Nevertheless, EU Home Affairs Commissioner Cecilia Malmström has stated that “data retention is here to stay”. This has not allayed concerns about either the legitimacy or effectiveness of the Directive. In May 2011 the European Data Protection Supervisor issued a formal Opinion on the Commission’s evaluation report. Amongst other things, he said, the Commission needed to “invest in collecting further practical evidence from the Member States in order to demonstrate the necessity of data retention as a measure under EU law”, and that all those Member States in favour of data retention should prove “quantitative and qualitative evidence” demonstrating its necessity.

In December 2011 the European Commission wrote to the EU Council’s Working Party on Data Protection and Information Exchange (DAPIX) to inform Member States’ representatives of the results of the consultation that informed its April 2012 evaluation report. The Commission argued that it was necessary to “explain better the value of data retention” due to “a continued perception that there is little evidence at an EU and national level on the value of data retention in terms of public security and criminal justice”: “We have received strong views from law enforcement and the judiciary from all Member States that communications data are crucial for criminal investigations and trials, and that it was essential to guarantee that these data would be available if needed for at least 6 months or at least… 1 year. We have also received strong qualitative evidence of the value of historic communications data in specific cases of terrorism, serious crime and crimes using the internet or by telephone – but only from 11 out of 27 Member States.” Furthermore, “[t]he statistics required under Article 10 do not, as it is currently interpreted, enable evaluation of necessity and effectiveness”. Therefore, the Commission concluded, “all Member States – not just a minority – need to provide convincing evidence of the value of data retention of security and criminal justice”.

Member States’ delegations in DAPIX had already discussed the need for further evidence of the “necessity” of mandatory data retention at a meeting in May 2011. They concluded that retention: “[C]ould not be argued on the basis of statistical data… the gravity of the offences investigated thanks to traffic data, rather than the mere number of cases in which traffic data were used should receive due attention. Quantitative analysis should be complemented with qualitative assessment."

In March 2013 the Commission published a report that attempted to draw together “[e]vidence which has been supplied by Member States and Europol in order to demonstrate the value to criminal investigation and prosecution of communications data retained under Directive 2006/24/EC.” The report contains an overview of the ways in which communications data are used in criminal investigations and judicial proceedings; the sorts of cases in which retained data are important; the “consequences of absence of data retention”; and a section on statistics and quantitative data. This notes that 23 Member States have provided “some statistics since 2008”, but that they “interpret in different ways terms from the DRD such as ‘case’ and ‘request’, and statistics vary in format which limits their comparability”. However, what the statistics do show is massive variation in the extent that Member States are using their data retention powers, with total annual requests ranging from 23 (Portugal) to 777,040 (UK).

In November 2012 – six years after the adoption of the Directive – the Commission adopted and disseminated “more comprehensive guidance on provision of statistics under Article 10”. Such problems meant that the majority of the Commission's March 2013 report (20 of 30 pages) was given over to anecdotal evidence, including 91 reported cases from across Europe in which retained data assisted in finding the perpetrators of a variety of serious crime.

Alternative approaches

“Data preservation” regimes offer an alternative to data retention, by limiting retention of data to specific authorised investigations. In November 2012 the European Commission published a report it had commissioned on “current approaches to data preservation in EU Member States and third countries”. Data preservation was defined as the “expedited preservation of stored data or ‘quick freeze’” in: “[S]ituations where a person or organisation (which may be a communications service provider or any physical or legal person who has the possession or control of the specified computer data) is required by a state authority to preserve specified data from loss or modification for a specific period of time”.

The report explained that data preservation is already mandated by the Council of Europe Convention on Cybercrime (the Budapest Convention), which entered into force on 1 July 2004 and is open for worldwide signature. All EU Member States have signed the Convention although Greece, Ireland, Luxembourg, Poland and Sweden still need to ratify it (as of 7 April 2014). Under the Convention data may be preserved “for the purpose of specific criminal investigations or proceedings”.

The Convention, unlike the Data Retention Directive, explicitly permits the storage of communication content. While the German Ministry of Justice believes that data preservation is fundamentally an alternative to mandatory retention, the report concludes that: “[D]ata retention and data preservation are complementary rather than alternative instruments… data retention plays a role in ensuring that data is kept and that this is sometimes a prerequisite for data preservation, as data may have already been deleted before a data preservation order is issued.”

Revision of the Directive

Article 14 requires the European Commission to determine, on the basis of its review, whether it is necessary to amend the provisions of the Data Retention Directive. In August 2012 the Commission announced that it was postponing the revision of the Data Retention Directive with “no precise timetable” for a new proposal. The Commission spokesperson cited the need to review the “e-Privacy” Directive to “ensure that retained data will be used exclusively for the purposes foreseen in this Directive, and not for other purposes as currently allowed by the e-Privacy Directive.”

Before the revision of either of these two Directives takes place, the Commission wants to see its draft data protection package agreed by the Council and the Parliament. At present the two institutions disagree significantly on the proposal, with further disagreement amongst the Member States in the Council. However, more fundamental to the future of the Directive may be today's judgment of the European Court of Justice.


Barnard & Peers: chapter 9, chapter 25

Monday, 7 April 2014

Background to the EU Data Retention Directive



By Chris Jones, Researcher for Statewatch

As the fallout from the Snowden leaks rumbles on, the Court of Justice of the European Union (CJEU) will today decide a case (Digital Rights Ireland, Seitlinger and Others that could spell the end for the EU's Data Retention Directive in its current form. The Directive mandates the mass storage by private companies of individuals' telecommunications data, in case it is required by law enforcement authorities to investigate cases of serious crime or terrorism.

The judgment follows the handing down of a critical opinion by Advocate General Cruz Villalón in December 2013, which proposed that the Court declare the Directive as a whole incompatible with EU Charter articles 52(1) (limitations on rights “must be provided for by law and respect the essence of those rights and freedoms”) and 7 (right to privacy). This post, based on work undertaken by Statewatch as part of the SECILE project (Securing Europe through Counter-terrorism: Impact, Legitimacy and Effectiveness), outlines the history of the 2006 Data Retention Directive; the key points of the legislation; and its problematic national implementation, which has been the subject of legal challenges across Europe. Two further posts will examine the implementation of the Directive and the challenges to it.

The Data Retention Directive: a brief overview

The 2006 Data Retention Directive obliges Member States to ensure that telecommunications and Internet Service Providers (ISPs) retain various types of data generated by individuals through the use of landline phones, fax machines, mobile phones, and the internet, “in order to ensure that the data are available for the purpose of the investigation, detection and prosecution of serious crime”. The data that must be retained are:

The source of a communication;

The destination of a communication;

The date, time and duration of a communication;

The type of a communication;

Users’ communication equipment or what purports to be their equipment; and

The location of mobile communication equipment.

The retention period is a minimum of six months and a maximum of two years. Member States decide exact duration as well as the conditions under which it may be accessed.

The European Data Protection Supervisor has called the Directive “without doubt the most privacy-invasive instrument ever adopted by the EU in terms of scale and the number of people it affects,” and it ranks among the most controversial pieces of counter-terrorism legislation the EU has ever adopted. Fierce debate as to its legitimacy and effectiveness has raged since the earliest stages of its drafting to the present day.

The policy-making process

According to the preamble of the Data Retention Directive, the terrorist attacks in Madrid in March 2004 and in London in July 2005 “reaffirmed… the need to adopt common measures on the retention of telecommunications data as soon as possible.” However, law enforcement agencies had been seeking data retention legislation long before the destruction of the World Trade Centre on 11 September 2001, and the Directive does not limit data retention to combating terrorism.

Demands for data retention can be traced back to the “International Law Enforcement and Telecommunications Seminars” (ILETS) held at the FBI academy in Quantico, Virginia, which commenced in 1993 with the aim of developing global “interception requirements” – standards for telephone-tapping by police and security agencies to be provided in all telephone networks. Following the first ILETS meeting, the very first EU Council of Justice and Home Affairs (JHA) Ministers adopted a Resolution in November 1993 – which was not published – calling on experts to compare the needs of the EU vis-à-vis the interception of telecommunications “with those of the FBI”.

A second EU Resolution based on ILETS' work was adopted in January 1995 and introduced obligations on telecommunications companies to cooperate with law enforcement agencies in the “real-time” surveillance of their customers. This was never actually discussed by the Council of Ministers. It was adopted instead by “written procedure” (where legislative texts are circulated among ministries and adopted if there are no objections). The Resolution, which was not published in any form until November 1996, formed the basis of the provisions on the interception of telecommunications in the EU Convention on Mutual Legal Assistance of 2000. ILETS continued every year and in 1999 identified a new problem. Valuable “traffic data” – particularly mobile phone and internet usage records – were being erased by service providers after customers had been billed, a particularly acute issue in the EU because of the recently enacted EC Directive on privacy in telecommunications, which obliged service providers to delete traffic data after its use for billing purposes (usually within three months). ILETS thus introduced the principle of mandatory data retention regimes that would oblige service providers to keep data for much longer periods. This demand then surfaced in other intergovernmental fora concerned with police and judicial cooperation, such as the G8. The American Civil Liberties Union, Privacy International and Statewatch would later dub this process “policy laundering”: “the use by governments of foreign and international forums as an indirect means of pushing policies unlikely to win direct approval through the regular domestic political process.”

 In 2000 the EU decided to update the aforementioned 1997 Directive on privacy in telecommunications to take into account “new technologies” and proposed what would become known as the “e-Privacy” Directive. The draft Directive proposed scrapping the clause obliging service providers to delete traffic data after billing use. As a First Pillar matter (dealing with the functioning of the internal market), the European Parliament had what was then a rare vote on what was effectively a Justice and Home Affairs or Third Pillar issue (police surveillance). Following an extensive campaign by privacy advocates the proposal was rejected. However in 2002, with the events of 11 September 2001 providing a fresh justification, a left-right alliance of the European Socialist Party (PSE) and the European People’s Party (PPE) agreed the e-Privacy Directive and the “data retention amendment”, with the liberals, greens and left parties opposed. This paved the way for Member States to introduce their own optional national data retention regimes.

Yet no sooner was the ink dry on the e-Privacy Directive than a confidential draft Framework Decision on the compulsory retention of subscriber and traffic data for 12-24 months across the EU was circulated among Member States and leaked by Statewatch. Following widespread criticism of the proposal in European media, the then-Danish presidency of the EU was moved to issue a statement saying that the proposal was “not on the table”. If not ‘on the table’, the proposal appears to have remained close at hand – following the Madrid train bombings in March 2004, the 'EU Declaration on combating terrorism' endorsed the principle of mandatory data retention across the EU.

One month later the UK, France, Sweden and Ireland submitted a revised draft Framework Decision on data retention to the Council. By now, a majority of EU Member States had also introduced national data retention regimes. The EU proposal suffered another major setback when Statewatch published the confidential legal advice of the EU Council and Commission Legal Services, both of which had been withheld from MEPs and the public despite stating that the Framework Decision was unlawful because it had the wrong legal basis. Data retention, said the EU’s lawyers, was a First Pillar issue because it regulated the activities of service providers in the single market.

The European Commission, despite previously opposing data retention, redrafted the proposal as a Directive. This complicated things further. Whereas the European Parliament was only consulted on the draft Framework Decision, with the EU Council free to ignore its opinion, it would now enjoy full powers of “co-decision”. Moreover, during the consultation process on the Framework Decision, the Parliament had voted to reject mandatory data retention because it was “incompatible with Article 8” of the ECHR (protection of personal data).

However, between the defeat of the proposal for a Framework Decision and the publication of the proposal for a Directive, the July 2005 London tube bombings happened. These were used as a fresh justification for an EU data retention law, although the UK prime minister suggested at the time that “all the surveillance in the world” could not have prevented the attacks.

The UK then used its presidency of the EU Council to impose a deadline of the end of 2005 for the European Parliament to agree the measure, with Charles Clarke, UK Secretary of State, lecturing the EP on the need to adopt the proposal. Home Office officials were reported to have told MEPs in private that if parliament failed to do this they “would make sure the European Parliament would no longer have a say on any justice and home affairs matter.” Led by Privacy International and the European Digital Rights Initiative, 90 NGOs and 80 telecommunications service providers wrote to MEPs, imploring them to reject the measure. Despite their efforts, the EP finally agreed the measure on 14 December 2005, with another PSE-PPE alliance reversing the position on the draft Framework Decision that the parliament had taken just eight months earlier. The Directive completed its passage through parliament following a single reading, meeting the UK’s demands on the timeframe. The Council of the EU adopted the legislation by qualified majority, with Ireland and the Slovakia voting against, and the Directive passed into law in March 2006.

Two further observations are relevant to any substantive consideration of the policy-making process. The first concerns the role of the UK government, which took its attempts to enforce data retention to EU institutions after it had been prevented from a domestic mandatory data retention regime by the houses of parliament. In what appears to be a clear case of “policy laundering”, the subsequent EU Directive, championed by the UK government, was binding on the UK and implemented by statutory instrument, in the form of the Data Retention (EC Directive) Regulations 2007 and 2009.

The second observation concerns the role played by the US government in pushing for mandatory data retention in Europe, bilaterally in its discussions with the European Commission and EU Presidency, and in multilateral fora like the G8. This is noteworthy because at that time there were no corresponding powers in the USA, nor any intention to introduce them. In place of blanket “data retention”, US law enforcement and security agencies are obliged to seek “preservation orders” from special surveillance courts. However, recent leaks such as that of the FISA court order imposed on Verizon, demonstrate that US agencies and their special “surveillance court” have interpreted these principles so widely as to cover entire telephone networks and all of their users.

Nevertheless, a more principled implementation of such a regime would be more privacy-friendly than the EU's current blanket approach. Opposition to the Data Retention Directive in Europe included advocacy from civil society organisations for the development of this model as an alternative, with judicial supervision to try and ensure that access to private data is necessary and legitimate. This is still the preferred option of the Ministry of Justice in Germany, where implementation of the Directive has been highly controversial and the subject of a Constitutional Court ruling that demanded its redrafting.


Barnard & Peers: chapter 9

Friday, 4 April 2014

Family Reunion for Third-Country Nationals: Comments on the Commission’s new guidance



Steve Peers

Family life is a key part of the day-to-day lives of all residents of the EU (whether they are EU citizens or not). For non-EU citizens (third-country nationals), the issue is regulated by the EU Directive on family reunion for third-country nationals, which was adopted back in 2003. The Commission’s new guidance on this Directive raises new prospects for its effective enforcement and correct interpretation. While the guidance addresses a number of issues well, it could still be improved or clarified on a number of points.

 Background

In 2008, the Commission issued a report on the application of the Directive, which indicated that Member States had breached the Directive in dozens of ways. However, it did not bring any infringement actions against Member States. In 2011, it issued a Green Paper on possible reform of the Directive, but ultimately decided against proposing any amendments, seemingly due to fear that if any proposal were made, Member States would ultimately insist on dropping the degree of protection for family reunion, rather than raising it. So instead, the Commission has issued this guidance document – only 11 years after the Directive was initially adopted.

It should be noted that the Directive applies to 25 Member States, ie not the UK, Ireland or Denmark, which exercised their opt-outs.

General points

The Commission quite rightly relies upon the prior CJEU judgments relating to the Directive. In EP v Council, the Court upheld some provisions of the Directive which the European Parliament challenged for breach of human rights. However, the Court made clear that the exceptions in the Directive could not be applied automatically, but on a case-by-case basis. In Chakroun, the CJEU stated that the conditions and exceptions in the Directive had to be interpreted narrowly, so as not to frustrate the main purpose of facilitating family reunion. The concepts in the Directive that made no reference to national law had to be interpreted uniformly; the Directive had to be interpreted in accordance with human rights (the right to family life, in the ECHR and the EU Charter of Fundamental Rights); and Member States could not use their discretion to undercut the objectives of the Directive.

Personal scope

Several issues arise as regards the personal scope of the Directive. First of all, it does not apply to EU citizens who seek family reunion with their third-country national family members, as confirmed by the CJEU in Dereci. However, the CJEU also made clear in the 2012 S and O judgment that in the case of ‘mixed nationality’ families, ie where a parent is a third-country national and a child is an EU citizen, the parent can rely upon the Directive. But it is also possible that the sponsor is a dual citizen of both the EU and a third State, and the Commission does not expressly comment on what happens in that case. It should be noted that the CJEU has ruled, in the Kahveci case, that the EU/Turkey rules on Turkish workers’ family members still apply to dual citizens of Turkey and a Member State. So it is arguable that, by analogy, the same rule applies to the family reunion Directive. The issue is only relevant, of course, as regards dual EU/third-country citizens who live in their own Member State, because EU citizens who move to other Member States can rely upon the more generous family reunion rules in the EU’s citizens’ Directive. Those EU citizens who live in their own Member State can rely on EU family reunion rules only if they have moved to other Member States and returned, or exercise some activity, in another Member State, as recently clarified by the CJEU.

Another important question is how to interpret the rule that the sponsor must have a ‘reasonable prospect’ of permanent residence. The Commission lays great stress on national discretion here. While it makes some good points about the limits to that discretion, the better argument is that this is a uniform concept of EU law (in the absence of any reference to national law). Furthermore, the guidance should have mentioned the possibility that other EU laws could be relevant to determining whether such a prospect exists, in particular the EU/Turkey association rules and EU legislation on long-term residents, refugee qualification, researchers and highly-skilled migrants.

Family members

 The Commission makes a good case that the concept of dependency, which is crucial where a child is not the joint child of the sponsor and his or her spouse, should be determined by analogy with the EU citizens’ Directive. However, it does not mention Reyes, the most recent judgment on this issue, which established the important points that the reasons for the support of a family member do not matter (the existence of remittances is enough to show that dependence exists), and that the possibility of the family member getting a job in the host State are irrelevant.

As for the possibility of requiring the spouse to be a minimum age before admission (no older than 21), the Commission makes the sound point that this rule must be applied on a case-by-case basis, for instance exempting spouses from this requirement if there is no doubt that there is no forced marriage. It also rightly argues that it is sufficient that the spouse meets the age requirement at the time of admission, not the time of the application. The latter issue will be decided by the CJEU in the pending case of Noorzia.

 Conditions for admission

The Commission states that Member States have wide leeway to accept in-country admissions from family members in certain cases. In fact, since the entire Directive sets minimum standards (Article 3(5)), Member States should be free to accept in-country applications in all cases.

As for fees to be charged for family reunion applications, the new guidance makes some good points on the limits imposed by the principle of proportionality, in accordance with CJEU case law on the long-term residence Directive.

While the Commission argues implicitly that the ‘public health’ requirement in the Directive can be interpreted by analogy with the citizens’ Directive, it states that the public policy and public security rules in the latter directive are only relevant by way of background. Arguably the latter rules also apply by analogy, since the drafters of the family reunion directive chose to use the same terms as those in the citizens’ Directive.

The Commission makes some good points about the accommodation requirement. In particular, it should be sufficient that the sponsor will be able to satisfy that requirement at the time of admission of family members, not at the time of application. It would be disproportionate for a person who is de facto single to have to rent or buy family accommodation for months or even two years before his or her family members are admitted.

This brings us to the integration requirement. The permissibility of a language requirement has been raised in the pending case of Dogan, although that case also raises the interesting question of whether the standstill clause in the EU/Turkey association precludes the application of a new requirement of this nature. More broadly, the Commission makes a strong argument that any integration requirement must be proportionate and applied on a case-by-case basis, taking account of individual circumstances and the limited access of females to education in some developing countries. There is a very recent case referred to the CJEU (for details, see the annex below; many thanks to Jeremy Bierbach for this information) that will clarify this point.

Next, the Commission rightly states that the waiting period of up to two years must include any ‘legal stay’ of the sponsor even before the sponsor met the conditions for family reunion under the Directive. It also suggests some sound guidance relating to continuity of residence.

Refugees

The Commission’s discussion regarding the special rules for refugees gives the unfortunate impression that all of these rules can be disapplied if the refugee had ‘special links’ with a third State, or did not apply within three months. In fact, only the special rules relating to waiving the conditions in Article 7 are subject to these possible waivers.

However, the Commission does make good points about the high threshold needed to show that a refugee had ‘special links’ with a third State, and the burden of proof which falls on a Member State which wishes to apply this rule. It also rightly states that Member States which require the family member to make an application for family reunion should take account of the particular issues relating to refugees.

Legal challenges

Finally, the Commission makes the sound points that in light of Article 47 of the EU Charter, legal challenges to family reunion decisions must apply to all decisions made pursuant to the Directive, must permit access to a court, and must consider all issues of fact and law, including a review of the merits of decisions.

Conclusions

The Commission’s guidance is largely welcome, subject to the criticisms made above. But it is also rather overdue. One can only hope that it proves useful to national courts and administrations, and that the Commission does not hesitate to bring infringement actions to back up its convictions about the correct interpretation of these key rules facilitating the right to family life of third-country nationals.


 Barnard & Peers: Chapter 26

 Annex – new pending case on integration measures: translation and notes by Jeremy Bierbach

  Preliminary reference from the Council of State of 1 April 2013, cases 201211916/1/V2 and 201300404/1/V2, K. and A. vs. Minister van Buitenlandse Zaken:

 1.a Can the term 'integration conditions' - contained in Art. 7(2) of Directive 2003/86/EC of the Council of the European Union of 22 December 2003 concerning the right to family reunification (PB 2003 L 251, with rectification in PB 2012 L 71) - be interpreted in such a way that the competent national authorities of the member states can require of the family member of a third-country national [Dutch: lit. "family unifier"] that the family member shows that he or she possesses knowledge of the official language of the member state at a level corresponding to level A1 of the Common European Framework of Reference for languages, as well as knowledge at a basic level of the society of the member state, before these authorities grant this family member permission for entry and residence?

 1.b For the answer to this question, is it of importance that, i.a. in the context of the proportionality test as described in the European Commission's Green Paper of 15 November 2011 concerning the right to family reunification, according to national regulations imposing the condition mentioned in 1.a, the application for permission for entry and residence, barring the circumstance that the family member has demonstrated that he or she is durably incapable of taking the integration exam due to a psychological or physical disability, will only not be rejected if a combination of very special individual circumstances are present that justify the assumption that the family member is durably incapable of satisfying the integration conditions?

 2. Does the goal of Directive 2003/86/EC, and in particular Art. 7(2) of it, preclude that the examination to test whether the family member satisfies the aforementioned integration conditions costs €350 for every time that the examination is taken, and that the one-time cost of the study materials to prepare for the examination is €110?

 The basic details of the case: K. is a national of Azerbaijan who applied for a preliminary visa at the Dutch embassy in Ankara for the purpose of applying for a residence permit for stay with her husband (nationality not provided). She submitted a medical statement that she suffers from diabetes, hypertension, coronary disease, hypercholesteremia and morbid obesity, which makes her, in her claim, incapable of taking the Dutch consular integration exam. A. is a national of Nigeria who applied for the same type of preliminary visa at the Dutch embassy in Abuja. She submitted medical documents showing that she suffers from a psychological disorder for which she has to take medication. In both cases, the Deputy Minister of Justice (the political head of the Dutch immigration authority IND, which takes decisions on visas on behalf of the Minister of Foreign Affairs, the formal defendant in this case) denied that the disabilities demonstrated were sufficient to warrant exemption from the consular integration exam. Moreover, the Deputy Minister went on: the consular integration exam does not violate the Directive.

Wednesday, 2 April 2014

In defence of the EU Charter of Fundamental Rights



Steve Peers

The House of Commons European Scrutiny committee recommended today that the UK pass an Act of Parliament to disapply the EU’s Charter of Fundamental Rights in the UK. There are three fundamental problems with this suggestion.

First of all, it would not solve the uncertainty regarding the Charter that they refer to; rather it would further complicate the application of human rights rules in the UK.

Secondly, the suggestion could possibly lead to large fines being applied against the UK, for breach of EU law, as interpreted in light of the Charter.

Thirdly, the committee’s recommendation is essentially dishonest. If the UK disagrees with the legal obligations which it has accepted as regards EU law, then the honest response would be to seek to renegotiate the terms of our membership, or to withdraw from the EU. The idea that we remain a member, but flout key EU law rules, is fundamentally unprincipled.

This post first of all summarises the committee’s analysis, then elaborates upon the three points made above.

The committee’s analysis

The committee first of all concludes that the special ‘Protocol 30’ relating to the British (and Polish) application of the Charter, adopted at the time of the Treaty of Lisbon, is not an opt-out from the Charter. This opinion was supported by the chief drafter of the Protocol (Lord Goldsmith), and was confirmed by the Court of Justice of the European Union (CJEU) in the NS judgment, concerning the removal of asylum-seekers to Greece. It was also the widespread academic view, as discussed by Professor Anthony Arnull in his analysis of the Protocol in the Commentary on the EU Charter of Fundamental Rights.

Furthermore, the committee notes that the prior committee had reached the same conclusion back in 2007. But it states that there was some confusion about the issue because of contradictory government statements. In fact, the only evidence it gives for this assertion is a statement by Tony Blair as Prime Minister, just after agreement upon the Treaty of Lisbon, in the final few days of his mandate. Subsequent governments have not taken this position. Indeed, when David Cameron set out the Conservative party’s revised EU policy in November 2009, following the ratification of the Treaty of Lisbon, he stated that the UK did not have an opt-out from the Charter, and that he would seek a Treaty amendment to change that. Whether one agrees with his objective to renegotiate the Treaty or not, his statement of the current legal position was clear and accurate.

The committee also gives examples of judicial confusion, namely the contrasting views of the higher and lower courts in the NS litigation. But disagreement between different courts on the correct interpretation of legal rules is hardly new.

Next, the committee correctly sets out the legal effect of the Charter, as a mechanism for the interpretation and validity of EU law in light of human rights. As regards national law, the Charter applies only where there is a link to EU law. As the CJEU stated in the Fransson judgment last year, this means that the Charter applies not only where Member States implement EU law, but where their actions fall within the scope of EU law – a somewhat nebulous concept.

The committee notes that the supremacy of EU law means that any national law in breach of the Charter must be set aside by (any) national court. So the Charter has a stronger legal effect than the UK’s Human Rights Act, but a narrower scope. The committee then states that the Charter does not include new rights. In fact, from the perspective of EU law, this was confirmed by the CJEU in its NS judgment, in which it stated that the Charter did not contain any additional rights beyond those recognised previously in EU law, in the form of the ‘general principles of law’.

Next, the committee reaches the conclusion that the Charter does not create new economic and social rights, and that those Charter rules which create ‘principles’, rather than ‘rights’, are not justiciable. In the absence of CJEU case law on these points, it is not yet clear if this is correct, although the Court’s judgment in January in the AMS case (discussed in a previous blog post) has begun to clarify the law on these issues, at least via the indirect route of indicating which Charter rights are not precise enough to be enforceable directly. A further case on this issue, Fennoll, has recently been heard by the CJEU, and so will be decided soon.

On the other hand, the committee is undoubtedly correct to say that the Charter does not give the EU new competences. This is expressly set out in Article 51 of the Charter, and has been confirmed many times by the CJEU. But despite this, the committee states that the Charter could possibly affect the way in which the CJEU interprets EU law.

The committee then objects to the lack of legal clarity as regards aspects of the Charter, namely as regards five points: the distinction between rights and principles; the overlap with the pre-existing general principles; the scope of application of the Charter; its consistency with the ECHR; and its horizontal application.

This brings us to the committee’s recommendations. It argues that the UK government should set out its legal position as regards the correct interpretation of the Charter. While the UK government is planning to intervene in cases concerning the Charter, in order to clarify its scope of application in particular, the committee does not believe that this is likely to be successful. So to avoid the ever-increasing jurisdiction of the CJEU, the committee recommends that the UK pass a new Act of Parliament to disapply the Charter in the UK.

Problems with the recommendation

As I set out at the outset, there are three fundamental problems with the recommendation: it would lead to more legal uncertainty, not less; it could result in large fines being applied to the UK; and it is essentially unprincipled.

Legal certainty

First of all, as regards legal uncertainty, the committee raised five specific points, as listed above. On four of these five issues, the committee definitely has a point; but the conclusions which it draws from this are not convincing.

Taking these four points in turn, the distinction between rights and principles is unclear, but as noted above, the CJEU is beginning to clarify this issue. Next, as regards the scope of application of the Charter (the committee’s main reason for recommending an Act of Parliament to block the Charter’s application in the UK), the Fransson judgment certainly at first sight takes a broad approach to this issue. However, other judgments point the other way. A more recent case, Siragusa, as discussed in a recent post on this blog, takes a much narrower approach. The CJEU has also, quite unjustifiably, refused to rule on whether various national austerity measures demanded in return for EU-organised bailouts are in breach of the Charter. So the committee’s assumption that the Court’s jurisdiction regarding the Charter will apply to ‘an ever wider field with increasingly unintended consequences’ is contradicted by the facts.

 As regards the consistency between the Charter and the ECHR, the committee raises two points. First of all, arguably the Charter itself sets higher standards than the ECHR, in at least some cases where the two overlap. In fact, as I discuss in detail in my analysis of Article 52 of the Charter in the Commentary, it is not clear if this interpretation is correct. So far, the CJEU has not clarified the issue expressly, but has implicitly refused to set higher standards, even when the issue was crucial in the case (see, for instance, the Melloni judgment).

 Secondly, the EU can set higher standards than the ECHR, in its secondary legislation. This is undoubtedly true. But the examples which the committee offers are hugely inappropriate. They object specifically to the recent proposals on legal aid and the presumption of innocence. But regards of the merits of their objections, the UK has opted out of these proposals. More broadly, the committee objects to ‘unwarranted interference in matters of pre-eminent significance in terms of the constitutional settlement of the UK’. But as far as criminal justice is concerned, this is simply bombast: the UK can opt out of any proposals that it wishes to, so there is no ‘interference’ at all.

And even beyond this, the committee’s objection here is misconceived, since the EU’s power to adopt secondary legislation setting higher standards than ECHR rights is not derived from the Charter. The Charter simply confirms the existence of such a possibility. So disapplying the Charter in the UK will change nothing in this regard.

As for the horizontal application of the Charter, this point overlaps with the distinction between ‘rights’ and ‘principles’. On this point, the AMS judgment more expressly clarifies the case law on this issue, and as noted above, more clarification can be expected soon.

This brings us to the committee’s weakest point: the overlap between the Charter and the pre-existing general principles. It does not acknowledge that in the NS judgment, the CJEU stated that the Charter went no further than the general principles, and that in the Fransson judgment, the Court stated that the scope of the two sources of law is the same. So to some extent the overlap has been clarified.

But the problems with the committee’s reasoning go much deeper than that. Its recommendation is to disapply the Charter in the UK, but not the general principles. So they would continue to apply. But not only do they contain all of the rights in the Charter (as confirmed in NS), they also raise again many of the same objections regarding legal uncertainty: the scope of the general principles has been disputed; their relationship with the ECHR is unclear; and their horizontal effect has been confirmed by the CJEU in the Kucukdeveci case. In fact, since the general principles do not take the form of a formal legal text, if anything their interpretation is even less certain than that of the Charter. And if the general principles apply in the UK, but the Charter does not, there could be a need for additional litigation to confirm whether CJEU case law relating to the Charter is also applicable to the general principles.

Of course, it could be argued that the UK should disapply both the Charter and the general principles as a matter of domestic law. But as the committee itself notes, a key aspect of the Charter (and, prior to the Treaty of Lisbon, the general principles) is the requirement to interpret EU secondary legislation in light of it. It is hard to see how that secondary legislation could be interpreted in light of the Charter and general principles in most Member States, while disapplying consideration of those aspects in the UK. There could also be cases where the CJEU rules that an EU measure is invalid because it breaches the Charter, and the question would obviously arise whether that measure is still valid in the UK. It can only be concluded that the committee’s suggestions are in fact a recipe for creating the maximum possible legal uncertainty.

Financial liability

If the UK (like any other Member State) fails to apply EU law which is binding upon it, the Commission can ask the CJEU to impose fines upon the UK. Because of the UK’s generally high degree of respect for EU law, the Commission has never done this.

 But if the UK disapplies the Charter as a matter of national law, then this may result in such proceedings. This is because, due to the obligation to interpret secondary EU law in light of the Charter, this might well result in the UK not applying EU law correctly. There is therefore a possible significant financial cost to the committee’s proposal.

Lack of principle

The EU’s fiercest critics in the UK either want the UK to leave the EU altogether, or to renegotiate the terms of its membership. Either position, whether we agree with it or not, is fundamentally an honest one. In particular, David Cameron’s pledge (which was ultimately frustrated when the Conservative party did not get a majority of seats in 2010) to renegotiate the Treaties to disapply the Charter to the UK entirely was honest. It would have caused great legal uncertainty, for the reasons described above, but that’s a different issue.

In contrast, the idea that the UK should remain an EU Member State, but not fully comply with the obligations which it has accepted, is not honest. It’s certainly legal as a matter of domestic law, since under the British constitution the authority of EU law in this country derives from Acts of Parliament. But the Charter is part of our obligations as an EU Member State, and as long as we are a Member State bound by the Charter, the principle of the rule of law demands that our national law provides for it to be given effect. Furthermore, disapplying it in our national law would hardly help the position of British citizens and British businesses seeking to rely on EU law to vindicate their legal rights in other Member States.

Conclusions

For the reasons set out here – legal certainty, financial liability and principle – the idea that an Act of Parliament should disapply the Charter in the UK should be roundly rejected. But as a final point, we cannot forget the intrinsic value of human rights, and the importance of the Charter as a means to uphold them, within the scope of EU law. While the EU has not – despite the claims of its most deranged critics – committed atrocities equal to or worse than those of Nazi Germany, neither can it be claimed that no serious human rights abuses occur within the scope of its law.

To take just one example, the subject of the NS case, it was established in the European Court of Human Rights, in the judgment in MSS v Belgium and Greece, that asylum-seekers sent to Greece are subject systematically to appalling conditions, both in and out of detention, for instance resorting to drinking out of toilets after they were refused water. The Charter has an important part to play in addressing such abuses, and the committee’s suggestions to disable it in the UK should be rejected for that reason alone.


 Barnard & Peers: chapter 9

Tuesday, 1 April 2014

Simplifying applications for Schengen visas for third-country national family members of EU citizens: do the new proposals go far enough?



Steve Peers

For many EU citizens whose family members are third-country nationals, particularly if those family members are citizens of an Asian, African or Caribbean country, free movement isn’t as free as it is for others. Unless they are travelling between Schengen countries (as explained below), those EU citizens who wish to visit another Member State with their third-country national family members may have to obtain a visa for their family members first, which can complicate their travel significantly.

This situation would be ameliorated somewhat, if the two proposals regarding visas issued today by the Commission are adopted. One of these proposals would amend the existing rules relating to ‘Schengen visas’, which allow for travel to all Schengen states for a period of three months (ie the EU’s ‘visa code’). The second proposal would create a new ‘touring visa’ for travel for up to one year to Schengen countries. While the proposals have of course not yet been adopted, and may be amended (or not adopted at all) as they go through the EU’s legislative process, they are significant enough to merit some analysis at this early stage.

In fact, these proposals are complex and important enough to merit four separate posts. This first post examines the proposed new rules for third-country national family members of EU citizens. The other three will examine: the visa code proposal; the touring visa proposal; and the important issue which isn’t addressed in these proposals: a protection visa for those fleeing persecution or serious harm.

EU free movement and Schengen compared

First of all, it’s necessary to reiterate which countries are covered by EU free movement law, on the one hand, and Schengen on the other.

The free movement rules, as set out in Directive 2004/38 (the ‘citizens’ Directive’) apply to all Member States, in the context of the citizenship of the EU. They also apply to Norway, Iceland and Liechtenstein, since the citizens’ Directive was extended to those countries pursuant to the treaty establishing a European Economic Area (EEA). The EU also has an agreement on free movement of persons with Switzerland, but that treaty does not apply the citizens’ Directive as such to Switzerland.

The Schengen rules, which abolish internal border checks between the signatories and introduce common rules on external border control and short-term visas, currently apply to 22 Member States, along with Norway, Iceland, Liechtenstein and Switzerland (the ‘Schengen associates’).

The Member States not applying the Schengen rules fall into two categories. On the one hand, the UK and Ireland do not apply Schengen at all (except for a number of flanking rules relating to police cooperation). On the other hand, Romania, Bulgaria, Cyprus and Croatia are obliged to apply all Schengen rules in principle, and do apply some of them (such as the external border rules and the common list of States whose nationals do or don’t need a visa), but do not yet apply all of them. More precisely, the Schengen rules on abolition of internal border controls, including the rules on Schengen visas, will not apply until the other Schengen States unanimously agree that Schengen should be extended to each of these countries.

It should be noted that the UK and Ireland won’t have any vote on the Commission’s new proposals, while the other four States not yet applying the Schengen rules will (given that they will have to apply those rules eventually). For simplicity’s sake, I’ll refer to the latter group of four States as ‘Romania, et al’, and to all six States not currently applying Schengen as ‘non-Schengen States’.

The cross-over between these two regimes is particularly important as regards third-country national (ie, non-EU) family members of EU citizens. They have the right to move and reside freely with their EU citizen family members in other Member States. As regards short-term visa requirements, though, it matters a great deal whether they are living and travelling within the Schengen states or not. Within the Schengen area, they do not need a visa to travel, even if they are not travelling with the EU citizen whom they are related to, because Schengen rules allow any third-country nationals with a residence permit or long-stay visa to travel between Member States. However, if they are travelling from Schengen States to non-Schengen states, or vice versa, or between non-Schengen States, they are subject to rules on visas and border controls.

There are, of course, special rules as regards travel between the UK and Ireland, known as the Common Travel Area, but there’s no need to consider those rules here. Also, since the Commission’s new proposals only relate to Schengen visas, there’s no need to consider here the issues relating to border controls.

 If the third-country national family members of EU citizens seek to enter the UK and Ireland, they are subject to national law, along with the citizens’ Directive. If they seek to enter the Schengen area, they are subject to both the Schengen rules and the citizens’ Directive. If they seek to enter Romania et al, they are subject to national law, subject to the citizens’ Directive and certain aspects of the Schengen rules (the common rules on border controls and visa lists – but not the Schengen visa rules).

All Member States are subject to the citizens’ Directive, so it’s important to examine its provisions first. First of all, in principle third-country national family members of EU citizens have the right to enter the territory with their EU citizen family member (Article 5(1)). They might, however, need a visa (Article 5(2)). Whether they need one or not is determined by national law (as regards the UK and Ireland) or by the EU visa list (as regards the other Member States, including Romania et al). So if a British citizen wishes to visit the Schengen area with her American husband, the husband will not need a visa, because the USA is on the Schengen ‘whitelist’ of states whose nationals don’t need visas. But conversely, if an Irish citizen wishes to visit the Schengen area with his Indian wife, she will need one.

Next, Member States must also exempt from the visa requirement those third-country national family members of EU citizens who hold a special ‘residence card’ issued by another Member State. The exact interpretation of this rule is at issue in the pending McCarthy case, which the CJEU recently heard.

However, the issue affected by today’s proposals is not whether a visa is necessary or not in the first place, but the process which applies in the event that it is. On that point, the citizens’ Directive also states that the family members concerned must have ‘every facility’ to obtain such visas, which shall be ‘free of charge’ and issued on the basis of an ‘accelerated procedure’. There is no further explanation of these concepts in the Directive, but the Commission has now sought to clarify them in the proposal to amend to visa code – to which we now turn.

The visa code proposal

As a general point, the Commission suggests an important clarification of the rules, to specify throughout that the ‘family members’ of EU citizens covered by the visa code are all family members referred to in Article 3 of the citizens’ Directive. This would confirm that these rules would apply not only to the ‘core’ family members (essentially spouses, formal partners, children and parents) referred to in Article 3(1), but also to extended family members referred to in Article 3(2).

This clarifies a point which is ambiguous in the citizens’ Directive: whether the rules on visas (and, in fact, most of the other rules in the Directive) apply to extended family members as well as core family members. True, there is no absolute obligation to admit extended family members, but that does not necessarily mean that they cannot benefit from the rules in the Directive (such as access to employment) if they are admitted, in the same way as core family members. Indeed, in the Commentary on the EU Citizenship Directive, my co-authors and I have argued in detail that they do. At least as regards visas for admission into the Schengen area, this point would be clear.

Substantively, the first rule in the proposal regarding third-country national family members of EU citizens is that they cannot be subject to the requirement to hold a transit visa (Article 3(8); all Article numbers refer to the proposal, not the current version of the visa code). Actually, this provision isn’t new, as it already appears in the current visa code.

The second rule in the proposal is new: it concerns appointments at consulates. Third-country national family members of EU citizens would not need a prior appointment, or could get an immediate appointment (Article 8(4)). Next, there is a simplified rule for the presentation of documents relating to third-country national family members of EU citizens (Article 13(3)). The proposal would also expressly waive the visa application fee for such persons (Article 14(3)), although this simply repeats the wording of the citizens’ Directive. Finally, there are faster deadlines (5 days, with a 10-day maximum) to decide upon the applications of such persons.

However, it should be noted that not all rules are waived or relaxed. Third-country national family members of EU citizens will not be exempt from the fingerprinting requirement, or from having their names and personal data entered into the EU’s Visa Information System. The Commission does not suggest that they should be entitled to a multiple-entry visa as such (Article 21), although that would go a long way toward simplifying their travel to other Member States, which is the essence of free movement. It is arguable that being a family member of an EU citizen would help to satisfy the criteria for obtaining a multiple-entry visa, but it would have been better to provide for this automatically, in all cases, subject to the condition that the person concerned is accompanying an EU citizen.

Even more problematically, the proposal does not expressly exempt the third-country national family members of EU citizens from the substantive rules on the criteria for issuing a visa (Article 19). This is surprising given that the Commission’s own report on the application of that Directive stated that some Member States were wrongly applying the general rules in the visa code to visa applications by third-country national family members of EU citizens. While of course the rules in the citizens’ Directive take precedence, it would be better to refer to them expressly to ensure correct application, just as the proposal expressly includes that Directive’s rules on visa application fee exemptions.

Nor is there any express rule allowing for the issue of a visa at the border (Article 32) – even though this directly contradicts the judgment of the CJEU in the MRAX case.

EU free movement law and ‘touring visas’

The separate proposal on ‘touring visas’ contains no express rules for third-country national family members of EU citizens, other than the general reference to the priority of the free movement rules (Article 1). From one point of view, this is sufficient, since those third-country national family members of EU citizens who wish to visit a series of other Member States (whether those States are Schengen States are not) are entitled to do so if they are accompanying or joining their EU citizen family member, and indeed to do so indefinitely (not for a one-year maximum), as long as they meet the liberal conditions of the citizens’ Directive. From another point of view, however, it would be useful to clarify, for the sake of legal certainty, that those family members cannot be subject to work permit requirements as referred to in the proposal, given that Article 23 of the citizens’ Directive gives the third-country national family members of EU citizens the right to work in any Member State in which they are accompanying or joining their family member.

General points

First of all, there might be an argument over the ‘legal base’ of these proposals, as regards the inclusion of specific rules on third-country national family members of EU citizens. In the Metock judgment, the CJEU said expressly that the Treaty provisions on EU free movement law constituted the correct legal base for regulating the position of third-country national family members of EU citizens. It might possibly be arguable, however, that the EU competence relating to visas could be used to provide for additional detailed rules on this issue, as long as they do not conflict with the rules adopted on the basis of EU free movement law.

Secondly, the inclusion of specific rules on these issues in the visa code risks an a contrario argument being made in the non-Schengen states, to the effect that they are not bound by these rules, since they are not bound by the visa code. But they are certainly bound by the specific obligation to waive visa fees, and by the more general obligation to expedite applications by third-country national family members of EU citizens, since those obligations appear in the citizens’ Directive.


Barnard & Peers: chapter 26