Tuesday, 14 June 2016

Net Neutrality: New EU Regulatory Guidelines



Professor Lorna Woods, University of Essex

After a long legislative process, a new EU regulation amending the EU telecommunications package was agreed last Autumn and came into force in April 2016. It contained rules relating to roaming and to universal service. These latter rules are the EU’s provisions on net neutrality and they aim ‘to establish common rules to safeguard equal and non-discriminatory treatment of traffic in the provision of internet access services and related end-users’ rights. The intention is ‘to protect end-users and simultaneously to guarantee the continued functioning of the internet ecosystem as an engine of innovation’ (point 1 in the preamble). 

At the time, there was debate as to whether these rules were good, bad or just ugly.  The Commission at that stage made big claims about the achievement.  Indeed, according to point 9 in the preamble:

[w]hen providing internet access services, providers of those services should treat all traffic equally, without discrimination, restriction or interference, independently of its sender or receiver, content, application or service, or terminal equipment. According to general principles of Union law and settled case-law, comparable situations should not be treated differently and different situations should not be treated in the same way unless such treatment is objectively justified. 

The rights of end-users are found in Art. 3 of the Regulation.  Art. 3(1) contains the rights of end-users to access and use the Internet.  Subsequent sub-provisions deal with possible exceptions.  Due to the open-textured nature of the drafting in the Regulation, and the inclusion of certain exceptions to the basic principle, the level of protection to end-users as well as the scope of providers’ activities in practice were uncertain. 

BEREC, the Body of European Regulators of Electronic Communications, was then tasked with producing guidelines to cut down on some of these uncertainties.  BEREC launched a public consultation on the Guidelines on 6th June 2016 which will run until 18th July. In the Guidelines, as with the Regulation, there are three problematic issues: zero-rating, traffic management and ‘specialised services’.

Zero-rating

The Issue: Zero-rating is the practice whereby traffic from certain sources does not count towards a subscriber’s monthly data cap.  Essentially this allows providers to charge different rates in respect of comparable services.  Zero rating makes ‘free’ sources more attractive to subscribers and potentially has an impact on the actual content consumed.  There are concerns that a provider will prioritise content it, or a linked company, provides; or provides only a ‘walled garden’. There are questions here about the impact on diversity of platforms (particularly where we are looking at vertically integrated conglomerates) and diversity of content, as well as the impact on the ability of users to use strong end-to-end encryption.

The Regulation: does not prohibit zero-rating

The Guidelines: BEREC notes that different forms of zero rating may have different consequences.  In determining the acceptability of a given form of zero rating, it takes a case-by-case approach based on criteria developed from the terms of the Regulation and set down in the Guidelines.

Circumvention of general aims of Regulation (see Art. 1, Rec 7)
Market position of ISPs and content and application providers involved (Rec 7)
Any effects on end-user rights of consumers/businesses
Any effects on end-user rights of content and application providers
The scale of the practice and availability of alternative offers
Any effects on freedom of expression and media pluralism (rec 13). 

We could suggest that this is a middle ground, allowing regulators to assess the threats to diversity in the specific instance. There are however questions as to whether practice will provide an adequate safeguard given that BEREC reiterates that the impact on users must be material, and be sufficiently predictable.  Predictability may be particularly problematic for start-ups. In such a circumstance, it could be that providers would be tempted to push the limits of the permissible, at least adversely affecting diversity of platform and content. It should be noted that zero rating in particular has been seen as especially problematic in competition law terms, and has even been banned in some countries.

Traffic Management

The Issue: Historically, transfer of data has been carried out on a ‘best efforts’ basis, with all traffic in principle treated equally. Traffic management is the way operators prioritise or restrict the flows of data on the network.  It is envisaged as a way of dealing with congestion, or in ensuring that time sensitive applications work (consider the differential impact with regards an ‘Internet of Things’ (IoT) health device, the function of which is disrupted by comparison with spam email). The problem is that slowing down some services can make them less attractive, so a telecoms provider might have an incentive to slow down (throttle) an OTT voice chat service. It is difficult to assess if services have objectively different requirements.   As the Regulation noted, ‘a significant number of end-users are affected by traffic management practices which block or slow down specific applications or services’ (recital 3 in the preamble). 

The Regulation: permits traffic management, but subject to certain safeguards.  So, the Regulation allows ‘reasonable traffic management’ which may be used to differentiate between ‘categories of traffic’.  There are three additional exceptions in Art. 3(3) which are allowed for the following reasons: a) compliance with other laws; b) preservation of integrity and security; and c) congestion management measures (see also Rec. 13, 14 and 15).

The Guidelines: in principle support the idea that traffic management should be service neutral, reiterating the Regulation on this issue.  At para 74 it lists traffic management practices that (subject to Art. 3(3) of the Regulation) are not permitted.  The guidance and limitations on reasonable traffic management focus on application-agnostic traffic management, specifically not allowing an operator to manage specific application traffic as part of their traffic management policies. Note, however, that non-discrimination does not mean that the quality of service is the same, provided application-agnostic traffic management can be shown.  Following the requirements of the Regulation,

[i]n order to be deemed to be reasonable, such measures shall be transparent, non-discriminatory and proportionate, and shall not be based on commercial considerations but on objectively different technical quality of service requirements of specific categories of traffic. Such measures shall not monitor the specific content and shall not be maintained for longer than necessary.

Nonetheless according to para 63, operators are permitted to distinguish between different classes, even when the network is not congested: an operator can differentiate between ‘objectively different’ categories of traffic – such as video, gaming, web browsing – as long as the purpose is to optimize the overall quality and user experience ‘based on technical quality of service requirements (for example, in terms of latency, jitter, packet loss, and bandwidth) of the specific categories of traffic’. An ISP must be able to detail the traffic management rationale when implemented to the national regulatory authorities (NRAs), and be transparent to the end user. The rationale seems to be to allow the network providers to optimize their networks, thereby putting off the day when the networks need to be upgraded. The issue of who should pay for the ultimate upgrade (or in what proportions) is hotly debated, reflecting concerns of the broadcasting ‘must carry’ debate.

‘Specialised services’

The Issue: the term, which is not in the Regulation, refers to those services which require special treatment (think about some IoT health apps) as an exception to the principle that paid prioritisation of certain content is not permissible.  BEREC suggests that ‘specialised services’ is a shorthand for the terminology in Art. 3(5) of the Regulation. In effect, ‘specialised services’ would not fall within the net neutrality rules. The question was how wide would this exceptional class be? In effect, would this open up the possibility of a ‘fast lane’ for those prepared to pay the toll?

The Regulation: the definition was open to interpretation, though there were some safeguards provided.  Specifically, the provision of specialised services should not be detrimental to regular Internet services and may only be offered if the provider has sufficient capacity.  Essentially this requires a test of necessity and capacity.

The Guidelines: BEREC has opted for a narrower perspective on these services. ‘Specialised services’ have to be new services that cannot function over the open Internet, so the extra speed must be ‘objectively required’ thus closing down the possibility of a two-tiered internet generally.  The Guidelines give examples: high-quality voice calling on mobile networks; live television delivered over the internet; and remote surgery but national regulatory authorities will be free to assess this on a case by case basis.  The justification for this was the inability to predict what new services will develop, especially in the context of the IoT. There are some concerns.

It seems that BEREC has decided that the provision of specialised services which will require some of the relevant subscriber’s own bandwidth for ‘normal’ Internet use will be acceptable, provided that there is no impact on the quality of other users’ experience (para 118).  This is the choice of the user in BEREC’s view.  Further, the Guidelines seem to envisage that it will be the service wanting to be designated as specialised that will ‘objectively determine’ whether the criteria are satisfied. Does this risk undermining the safeguards? BEREC seems to be aware of the risk: it suggests that the NRAs should monitor these services closely to check that the reasons given are plausible and not just about circumventing the rules.

It remains to be seen how open to movement BEREC is in terms of changes to the draft.  While the net neutrality campaigners have expressed concern about threats to the open Internet, equally the operators have voiced concern about the balance achieved in the draft as can be seen from ETNO’s response.  While the competition and pluralism issues are significant, underpinning this significant divide is the issue of where we expect the money to come from for network infrastructure and its development. There are a number of competing sectors in the mix: infrastructure, access, platforms/intermediaries, content providers and aggregators as well as the end-users – but who should pay and how should that payment be assessed and structured?

Photo credit: www.dontcomply.com

Sunday, 12 June 2016

EU Referendum Briefing 2: How could Brexit affect young people?



Steve Peers

If British voters decide to Leave the EU in the upcoming referendum, how would that affect young people? I’ll look at that from three perspectives: education, travel and the economy.

Education

The EU doesn’t regulate the content of education, or issues like tuition fees. These limits on the EU’s role are set out in Article 165 of the Treaty on the Functioning of the EU:

The Union shall contribute to the development of quality education by encouraging cooperation between Member States and, if necessary, by supporting and supplementing their action, while fully respecting the responsibility of the Member States for the content of teaching and the organisation of education systems and their cultural and linguistic diversity.

So tuition fees differ across the EU – just as they do within the UK. Instead, the EU is involved in the cross-border aspects of education. Article 165 goes on to list these, including:

– encouraging mobility of students and teachers, by encouraging inter alia, the academic recognition of diplomas and periods of study,
– encouraging the development of youth exchanges…

This takes the form of the Erasmus programme. It’s sometimes suggested that the Erasmus programme is nothing to do with the EU. That’s clearly not true: the Erasmus programme is based on an EU law, first adopted in 1987. The most recent EU law on Erasmus dates from 2013. While the Erasmus programme is best known for exchanges of university students, it also provides for exchanges of school pupils, apprentices and college students.

Could the UK still participate in the Erasmus programme after Brexit? The current EU law (see Article 24) lists the five categories of countries which participate: a) EU Member States; b) Norway, Iceland and Liechtenstein, on the basis of a free movement treaty; c) Switzerland; d) countries applying to join the EU; and e) neighbourhood countries, like Ukraine.

Also, some of the non-EU countries don’t fully participate in Erasmus: only Norway, Iceland and Liechtenstein, along with Turkey and Macedonia, are full participants (‘programme countries’). The others are ‘partner countries’, who have only ‘limited access’ to the student exchanges (see page 34 of the Erasmus Programme Guide). Similarly, 75% of the money for youth and volunteer exchanges is spent on the programme countries (see page 75 of the guide).

So could the UK become a programme country after Brexit, to retain full participation in Erasmus? It wouldn’t be a current or candidate Member State. It wouldn’t be a ‘neighbourhood country’ either: that term applies to the countries on the EU’s eastern and southern borders (the purple and darker yellow states on this map):



The other countries fully participating in Erasmus are countries with a deal on the free movement of persons: Norway, et al and Switzerland. It’s striking that when the Swiss decided to end their treaty with the EU on free movement of persons, the EU decided that because the link with free movement was now broken, Switzerland could no longer be a programme country. It also suspended Swiss participation in research funding.

So currently, full participation in Erasmus extends only to countries which have applied to join the EU or which have a free movement agreement with it. The official position of the Vote Leave side is that the UK should not participate in the free movement of people or the single market (ie the ‘Norway option’) after Brexit. Therefore the UK will not qualify for full participation in Erasmus. The EU could agree to change the rules – but there are no guarantees of that. Moreover, the example of Switzerland suggests that it won’t.

A Brexit would have other impacts on British students who want to study in the EU – whether they participate in Erasmus or not. First of all, the EU rule that students pay the same tuition fees as locals – which enables British students to pay the same low fees as most local students in EU universities – would no longer apply. (Even under the ‘Norway option’, this rule doesn’t apply). UK students in EU universities would therefore pay foreign fees, unless the UK government was able to negotiate reciprocal deals with each country to avoid this.

Secondly, unless the UK still signs up to the free movement of persons, the EU rules on recognition of qualifications will not apply. So British employers will not be obliged to recognise qualifications from universities in the EU – and EU employers will not be obliged to recognise British qualifications either. They might still choose to do so, or to apply some non-EU rules on recognition, but overall there will be fewer legal guarantees of recognition.

Thirdly, it will be more difficult for students to move to an EU country for more than three months.  (Again, this assumes that – as Vote Leave says – the UK would not still sign up to the free movement of persons). The EU has rules on the admission of non-EU students (the UK, Ireland and Denmark have an opt-out), which were recently amended (see discussion here). They will not simply be able to jump on a plane to move to another Member State, but will have to apply for a residence permit up to three months in advance and pay a fee for that application. If they wish to stay after study there may be complications – to which we now turn.
    
Travel

Many young people are used to travelling to Amsterdam or Barcelona for the weekend. Most likely such short-term trips will be equally easy to make after Brexit, because as long as the UK does not impose a need to get a short-term visa (for visits of less than three months) on any EU countries, the EU will not demand that British citizens will need a visa to travel to the EU. That’s the EU policy of visa reciprocity. (Note that Ireland, like the UK, has opted out of this policy, so trips to Ireland shouldn’t be affected by Brexit).

However, there is some risk that weekend visits or longer holidays will be disrupted. A prominent Vote Leave campaigner, the justice minister Dominic Raab, has suggested that the UK should impose a visa requirement on EU citizens after Brexit, and accepted that this will mean that UK citizens would be subject to visa requirements to visit the EU. That’s because the EU visa reciprocity policy works both ways.

What would this visa requirement mean in practical terms? I have discussed the impact in detail here, but I’ll summarise the main points again. The EU rules on short-term visas for non-EU citizens are set out in a ‘visa code’, so we know exactly what would happen.

There would be a €60 application fee for every individual over 18, for every visit. Usually there would be an additional fee to pay to a private service provider to handle the documents. Visits to the EU couldn’t be very spontaneous, since applicants would have to wait several days for their visa to be approved. Without the visa stamped in their passports, airlines and ferry companies wouldn’t allow them to travel. Not everyone would get a visa either: young people who haven’t got a job yet are more likely to be turned down. Any refusal of a visa application would be recorded on an EU-wide database for several years, increasing the chance of further refusals.

What about stays of longer than three months? Unless the UK agrees to continue with the free movement of people to and from the EU, any young (or indeed not-so-young) people wishing to stay for longer than three months in an EU country to work or study, or to join a family member, will no longer have the right to do so after Brexit. Instead, they will be subject to far more restrictive national immigration laws (partly harmonised by the EU), as discussed in detail here.  

Economy

How could Brexit affect young Britons’ economic prospects? Economic forecasts of the effect of Brexit aren’t certainties. The negative predictions about leaving the EU made by many economists and international institutions could turn out to be wholly incorrect, or at least overstated.

But in Martin Lewis’ objective assessment, there are more economic risks to a Leave vote. And even the pro-Brexit economist Andrew Lilico predicts that there will be a negative economic effect to Brexit in the short-term, with a positive impact starting in 2030:


If this forecast is correct, less economic growth means fewer jobs. And young people looking for work after school or graduation are looking for their first job now, or in the next few years – not in 2030. Indeed, one economic analysis predicts that younger people would face the biggest negative impact on the job market.

Conclusion

Nigel Farage recently said he was ‘shocked’ that British students would want to study in the EU – referring to the rest of the world instead. But it’s possible to want to visit Rome as well as Rio, or study in Madrid instead of Mumbai.

We can’t be certain of the impact of Brexit upon young people in advance. But the evidence suggests that access to the Erasmus scheme may be under threat. And it will certainly be harder to move to an EU country for any reason if the UK is no longer participating in the free movement of persons – as Farage and the official Vote Leave camp suggest. Moreover, if there are negative economic effects, at least in the short-term, that would affect every young person in the UK looking for work in the next few years.  


Photo credit: The Guardian

Saturday, 11 June 2016

EU Referendum Briefing 1: Can the UK control the EU’s future if it stays a member?




Steve Peers

During the EU referendum campaign, a number of arguments have been made that staying in the EU is risky, because of possible future developments of the EU itself. While there will always be someone somewhere who says they would like to see an EU army, or some development related to the single currency, such an expression of opinion is meaningless by itself.  The fundamental issue is whether the UK could control such developments – either by vetoing them or opting out.

So what’s the worst that can happen? In this post, I’ll examine in turn the main alleged risks to staying in the EU. As we’ll see, in every single case the UK has control, either by an opt-out or a veto. In other words, none of these things can happen without the British government’s consent. Nearly all of them would also need our Parliament’s consent. And the large majority – all the fundamental possible changes to the EU that many are concerned about – would actually need the consent of the British public in another referendum. (Anyway, there's nothing to stop the UK holding another referendum on EU membership in future, if it wanted to).

All of these safeguards for UK control of further developments of the EU exist in the current law of the EU – as I will show in detail. None of them are first created by the renegotiation of EU membership agreed this February.

I’ll look at seven issues where the UK has control over future EU developments:

a) defence;
b) transfers of power;
c) new Member States, including Turkey;
d) taxation;
e) non-EU immigration, asylum and criminal law;
f) the single currency; and
g) the EU budget, including the UK rebate.

There's also an earlier blog post on the controversial issue of the planned EU/US trade deal (TTIP) and the NHS. 

a)      EU Defence and foreign policy

The UK has control over EU defence and foreign policy measures because they are in principle taken by unanimous vote, with only limited exceptions. On foreign policy in general, Article 31 TEU says:

Decisions under this Chapter shall be taken by the European Council and the Council acting unanimously, except where this Chapter provides otherwise.

The exceptions are where there has been a prior act or request of EU Presidents and Prime Ministers (who act by consensus), or where the EU is implementing a prior act already agreed by unanimity, or where the EU appoints a ‘special representative’. However, there is a kind of ‘emergency brake’ in all these cases:

If a member of the Council [ie a Member State government] declares that, for vital and stated reasons of national policy, it intends to oppose the adoption of a decision to be taken by qualified majority, a vote shall not be taken.

Also the majority voting ‘shall not apply to decisions having military or defence implications’. It’s also possible to apply majority voting to funding issues, but again there’s a military and defence exception (Article 41 TEU), and also there’s an exception for a Member State which chose to abstain on a proposal. The bottom line is that the UK is in control of whether it has to contribute to EU foreign policy funding.

So whether EU foreign policy relating to Ukraine or Russia (for instance) is a good idea or not, it has not been imposed on the UK government. Rather the government is in control, because it could have vetoed it. This means that if EU Member States can’t agree on an issue, there is no EU foreign policy on that issue, and they do as they like – as in the case of the Iraq War, for instance.

Some have raised the issue of the UK’s permanent seat on the United Nations Security Council. In fact Article 34(2) TEU refers to Member  States’ seats on the Security Council, not to any EU seat. The UK has control here, because it could veto any EU decision that required it to give up its Security Council seat, as part of its veto over any foreign policy matters. It’s suggested that the European Parliament wants that to happen, but the European Parliament has no role in EU foreign policy: Article 36 TEU says that it’s only consulted.

Anyway, a change to the UK’s Security Council veto  could only happen by means of a change to the UN Charter, and the UK has control over that: a veto, according to Article 108 of the Charter:

Amendments to the present Charter shall come into force for all Members of the United Nations when they have been adopted by a vote of two thirds of the members of the General Assembly and ratified in accordance with their respective constitutional processes by two thirds of the Members of the United Nations, including all the permanent members of the Security Council.

As for defence, can there be an EU army? Article 42(2) TEU says:

2. The common security and defence policy shall include the progressive framing of a common Union defence policy. This will lead to a common defence, when the European Council, acting unanimously, so decides. It shall in that case recommend to the Member States the adoption of such a decision in accordance with their respective constitutional requirements.

So the UK has control over any possible ‘common defence’, by means of its veto. And there’s more: the ‘constitutional requirements’ that would apply in the UK are not only parliamentary approval, but also a referendum, according to the European Union Act 2011. In general this law sets out a ‘referendum lock’ on further transfers of power to the EU, putting the British public in control over any future transfers. I’ll refer to this law again several times, since it sets many other limits on the development of the EU in future. It also requires a referendum before any British veto over foreign policy or defence is given up. 

b) Treaty amendments and transfers of power

It’s sometimes suggested that there might be future transfers of power from Member States to the EU, as part of the developing single currency project (perhaps following the so-called ‘Five Presidents Report’ on this issue) or for some other reason. This is sometimes presented as a 'superstate', or as an inevitable outcome of the EU's 'ever closer union' clause. However, the UK has control over these developments. First of all, the UK has an opt-out from the single currency, as discussed below. Secondly, it also has a veto over future Treaty amendments.

There are several ways to amend the EU Treaties, as set out in Article 48 TEU. They have two things in common: (a) the UK government has a veto over all of them (which it used in 2011, for instance); and (b) the British Parliament would have to approve each of them, either by voting in favour or deciding not to vote against.

But there’s more. The European Union Act 2011, first mentioned above, also gives control to the British public over any significant Treaty amendment, by means of a referendum. This would apply where the UK would drop nearly any veto. It would also apply to other transfers of powers to the EU from the UK, defined in detail as including:

a)      ‘the extension of the objectives of the EU’;
b)      any ‘conferring’ or ‘extension’ of any EU competences, including over ‘the co-ordination of economic and employment policies’ (an issue in the Five Presidents’ Report); or
c)       giving any EU ‘institution or body’ any power to give orders or impose sanctions upon the UK.
  
It’s been suggested that the UK gave up a veto relating to single currency and banking issues as part of the renegotiation deal. This isn’t true, as the deal didn’t amend the Treaties and Parliament has not amended the 2011 Act.

So the control over any transfer of power from the UK to the EU is threefold: the UK government, UK Parliament and the British public.

c)       New Member States

The rules on accession of a new Member State are set out in Article 49 TEU, as follows:

Any European State which respects the values referred to in Article 2 and is committed to promoting them may apply to become a member of the Union. The European Parliament and national Parliaments shall be notified of this application. The applicant State shall address its application to the Council, which shall act unanimously after consulting the Commission and after receiving the assent of the European Parliament, which shall act by an absolute majority of its component members. The conditions of admission and the adjustments to the Treaties on which the Union is founded, which such admission entails, shall be the subject of an agreement between the Member States and the applicant State. This agreement shall be submitted for ratification by all the contracting States in accordance with their respective constitutional requirements. The conditions of eligibility agreed upon by the European Council shall be taken into account.

So the UK controls whether a new country joins the EU, by means of a veto. The ‘constitutional requirements’ are an Act of Parliament in favour.

There has been some concern about new Member States joining the EU in future, but in order to join each new State must negotiate 35 chapters of detail about EU law. In 11 years’ of negotiations, Turkey has only agreed one out of those 35 chapters. It has not even opened many of them:



Moreover, the ‘conditions of eligibility’ include human rights standards, which Turkey doesn’t now meet. Cyprus would veto Turkish membership unless there’s a deal on the future of the island. The other countries applying to join have not agreed many chapters either.

In any event, the current Member States can insist on a long waiting period before the free movement of persons fully applies to new Member States. The majority of the Member States which joined the EEC/EU after it was founded (14 out of 22) have been subject to seven-year waiting periods before full free movement of people, and longer periods could be applied in future.

The UK veto over enlargement could only be dropped by a Treaty amendment, approved by the government, parliament and public under the European Union Act 2011.

d)      Taxation

The main taxes harmonised at EU level are VAT and excise taxes. EU law sets a minimum rate for these taxes: it’s 15% for VAT, subject to exemptions. It also defines their scope. The UK has VAT exemptions on things like books, basic foodstuffs and children’s clothes.

While VAT is sometimes depicted as if it is imposed by the EU upon the UK, in fact the UK has consented to all VAT laws, since law-making in this area is subject to unanimity. The rule currently appears in Article 113 of the Treaty on the Functioning of the European Union:

The Council shall, acting unanimously in accordance with a special legislative procedure and after consulting the European Parliament and the Economic and Social Committee, adopt provisions for the harmonisation of legislation concerning turnover taxes, excise duties and other forms of indirect taxation.

So the UK has control in this area, since it has consented to every VAT obligation and excise tax obligation set by EU law. It’s the UK’s own decision to set the rate of tax for VAT and excise taxes (taxes on alcohol, tobacco and petroleum) above the minimum level. Many people would like to see further exemptions from VAT, such as on tampons or environmental services; but it was the UK government that agreed to commit itself not to lower these rates. Actually, the UK government recently agreed to a renewal of the 15% minimum rate. In any event, the EU has recently agreed to a more flexible approach, which will allow VAT to be dropped on tampons and possibly a broader range of other products and services.

It follows from the existence of the veto that the UK has control over any future amendment to EU tax law in these areas, including any removal of any exemption, by means of its veto.

What about other taxes? There is little EU involvement in other areas of tax law. So, for instance, the UK is entirely free to set rates of personal income tax, National Insurance contributions, corporate taxation, council tax and many more. However, there is some limited EU involvement in cross-border aspects of corporate tax, such as the recent law which aims to tackle cross-border tax evasion.

The EU adopts these laws on the different legal basis of Article 115 TFEU:

Without prejudice to Article 114, the Council shall, acting unanimously in accordance with a special legislative procedure and after consulting the European Parliament and the Economic and Social Committee, issue directives for the approximation of such laws, regulations or administrative provisions of the Member States as directly affect the establishment or functioning of the internal market.

Again it can be seen that unanimity is the rule. So the UK has a veto. This veto is further protected by Article 114(2) TFEU, which says that the majority voting that normally applies to EU single market law does not apply to ‘fiscal provisions’.

Therefore the UK has control over any new EU tax that might possibly be proposed to fund refugee and migration costs, or upon pensions, or upon anything else. We can simply veto it.

Can these vetoes be removed? As discussed above, due to the European Union Act 2011, they can only be removed (in whole or part) if the Treaty is amended with the consent of the UK government and parliament, and the British public in a referendum.

e)      Asylum, non-EU migration and criminal law

The UK has an opt-out over EU laws on non-EU migration, criminal law and policing. This is set out in Protocol 21 to the Treaties.

As regards immigration and asylum, the UK opted out of most non-EU immigration laws, but opted in to the first phase of asylum laws from 2003-2005, using the veto which it had at the time to ensure that these laws did not require any change in UK asylum law. The only substantive EU asylum laws which the UK has opted in to since 2005 are the Dublin III Regulation (on returning asylum-seekers back to another Member State where they first entered) and the Eurodac Regulation (on fingerprinting asylum-seekers to that end). The UK opted out of recent EU laws on relocating asylum-seekers from Italy and Greece to other Member States.

The UK also has an opt-out from the Schengen system of open borders between Member States, and harmonised external border controls (see Protocols 19 and 20). This includes an opt-out from the EU laws on short-term visas (which concern stays of three months’ maximum). So the UK will not be covered by the proposed laws on waiving the short-term visa requirement for Turkish citizens, or for other countries (Ukraine, Georgia, Kosovo).

For the same reason, the UK will also not be covered by the proposed law on a European Border Guard. While this law originally provided for the border force to enter a Member State without its consent, that idea was dropped during negotiations. That would anyway not have applied to the UK; and in fact the EU court has ruled that the UK could not opt in to the EU law creating a border agency (the precursor to the proposed Border Guard law) even if it wanted to, without signing up to the whole of the Schengen system.

In the areas of criminal law and policing (which will be the subject of a separate blog post with more detail), the UK had a veto until 2009, when the Treaty of Lisbon came into force. Since that date, it has had an opt-out, which it has frequently used. In particular, it has opted out of the proposal for a European Public Prosecutor. Note that the EU’s police agency, Europol, is not a ‘federal police force’: the Treaty rules out ‘coercive powers’ for it, so it cannot arrest, question or detain people. Its main role is the analysis of police investigation data.

The abolition of the opt-outs on immigration and asylum, Schengen and criminal law would require a Treaty amendment subject to approval of the government and Parliament. The abolition of the Schengen opt-out would also require a national referendum, under the European Union Act 2011. So would participation in the European Public Prosecutor.

f) The Single Currency

The UK’s opt-out from the single currency appears in Protocol 15 to the Treaties. Point 1 reads:

1. Unless the United Kingdom notifies the Council that it intends to adopt the euro, it shall be under no obligation to do so.

This protocol does not expire at some point, as is sometimes suggested. Neither are ‘all Member States obliged to join the euro by 2020’. So the opt-out is valid for an unlimited period.

The protocol goes on to disapply the various EU law rules relating to the single currency. This has a number of implications. Due to the single currency opt-out the UK cannot be subject to austerity measures imposed by the ‘Troika’ that oversees bail-outs to Eurozone countries, since this only applies to states which adopt the single currency. Austerity policy in the UK is solely a decision made by our own government.

Furthermore the UK is exempt from some EU banking laws. Most notably it is not obliged to participate in the permanent bail-outs of Eurozone states. Only Eurozone states are involved in that, on the basis of a separate treaty. In fact the EU as such cannot adopt laws on permanent bail-outs, according to the EU court.

The UK could potentially be part of solely temporary bail-outs. But here the law was amended to provide a guarantee that the UK would get its money back in the event of any default.

g)      The EU budget – and the UK rebate

Of the money the UK in principle sends to the EU, there are two key features: a) a rebate, meaning some of that contribution is never sent at all; and b) some EU spending back in the UK. (For an overview, see here).



It’s often suggested that the rebate is not legally secure, and that the UK has no control over spending by the EU. Both suggestions are false.

The rebate is set out in the EU’s Own Resources Decision. This does not (as some suggest) have an expiry date (other Member States’ rebates will expire in 2020, but the UK rebate, and the law as a whole, will not). If the EU wants to amend this law, Article 311 TFEU applies:

The Council, acting in accordance with a special legislative procedure, shall unanimously and after consulting the European Parliament adopt a decision laying down the provisions relating to the system of own resources of the Union. In this context it may establish new categories of own resources or abolish an existing category. That decision shall not enter into force until it is approved by the Member States in accordance with their respective constitutional requirements.

It’s clear that the UK government can control the future of the rebate by means of a veto. Furthermore, so can Parliament, since the ‘constitutional requirements’ for the UK referred to mean that an Act of Parliament has to be passed for any amendment to the Own Resources Decision. These constraints have meant that the veto has stayed in place for over 30 years – although the UK government and parliament have agreed to some reduction in it over that time.

It’s clear that this rebate is not ‘conditional’, as is sometimes suggested. The UK has full control over the rebate money and can do entirely what it likes with it.

What about EU spending back in the EU? The basic rules on what the EU spends money on are set out in the law on the ‘Multi-Annual Financial Framework’. The latest such law is here. The UK does have control over the basic features of this law, because it has a veto over it, according to Article 312(2) TFEU:

2. The Council, acting in accordance with a special legislative procedure, shall adopt a regulation laying down the multiannual financial framework. The Council shall act unanimously after obtaining the consent of the European Parliament, which shall be given by a majority of its component members.

It’s also useful to put the EU budget contribution into broader perspective. It’s less than 1% of UK spending (the small red section of the graph below). So if the UK no longer paid the contribution, it would be like getting a pay increase from £400 to £404. The average taxpayer is paying 12p a day toward the EU.



Conclusion

As we have seen:

a)      The UK cannot be required to join an EU army without consent of the UK government, parliament and public;

b)      Treaty amendments require the consent of the UK government and parliament, and (if there’s any transfer of powers) the public;

c)       Accession of new Member States requires the consent of the UK government and parliament; it is a long way off for Turkey in particular and if it ever happens, will be subject to long periods of transition for workers to be admitted;

d)      The UK has a veto on tax issues; the UK government, parliament, and public would have to consent to dropping it;

e)      The UK has an opt-out from EU law on asylum, non-EU migration and criminal law; the UK government and parliament would have to consent to dropping it, and the public would have to agree to join Schengen or the European Public Prosecutor;

f)       The UK has an opt out from the single currency and other related issues, and could only join after the consent of the UK government, parliament and public;

g)      The UK has a veto over the basic EU budget revenue and spending rules, including the UK budget rebate; the veto could only be dropped with the consent of the UK government, parliament and public.

Of course, there are many other possible criticisms of the European Union. Some may be valid, and some not. But the argument that the UK government could be forced into any of the measures listed above is quite clearly false and scaremongering. All of the above possible developments are subject to the control of the UK government, and usually our Parliament and the general public besides.


Art: ‘The Scream’, Edvard Munch

Monday, 30 May 2016

Money laundering, customer due diligence and data protection: the CJEU's judgment in Safe Interenvios




Marcin Kotula, Legal Officer at the European Commission

The views expressed are purely those of the author and may not in any circumstances be regarded as stating an official position of the European Commission

Background

The recent judgment of the CJEU in the case of Safe Interenvios was triggered by a preliminary reference from the Provincial Court in Barcelona (Audiencia Provincial). The Court in Barcelona submitted to the CJEU a number of questions related to the interpretation of the third Anti-Money Laundering Directive 2005/60/EC (AML Directive, since replaced by the fourth money laundering Directive, discussed here).

In the case in question, Safe, a company which falls under the definition of a "financial institution" within the meaning of the AML Directive and of a "payment institution" within the meaning of the Payment Services Directive 2007/64 (PSD) has been transferring the funds of its customers abroad through the accounts it held with 3 banks, BBVA, Sabadell and Liberbank. The transfers were to be carried out by agents who were accordingly authorised by Safe and verified by the Bank of Spain (Banco de España). After discovering irregularities regarding Safe's agents the banks, acting under Spanish Law 10/2010 on the prevention of money laundering and terrorist financing[1] which transposes the AML Directive in Spain requested various information from Safe. When Safe did not provide them with the requested information the banks closed its accounts. Before closing Safe's account BBVA informed SEPBLAC[2] that Safe might be involved in money laundering activities.

Safe challenged the closure of its accounts before the Commercial Court in Barcelona (Juzgado de lo Mercantil) arguing that the banks have also been transferring funds abroad and that insofar they have been competing with Safe on the same market. In consequence, according to Safe, the closure of accounts was an act of unfair competition. Safe argued further that the information requested by the banks which related to Safe's customers as well as to the origin and destination of the funds could not have been provided without breaching the data protection legislation.

Safe's challenge was largely unsuccessful as the Commercial Court in Barcelona did not find a specific infringement of competition law by none of the banks. It concluded that BBVA closed Safe's account on the basis of checks which showed that nearly a quarter of transactions were not carried out by agents authorised by Safe and verified by the Bank of Spain. As for the closure of accounts by Sabadell and Liberbank, the court in Barcelona partly ruled in Safe's favour concluding that these two banks failed to properly set out the reasons for their closures.

Subsequently Safe, Sabadell and Liberbank appealed against that judgment to the Provincial Court in Barcelona which submitted the preliminary questions to the CJEU. 

The CJEU was asked, first, whether customer due diligence measures, laid down in the AML Directive to respond to the risks of money laundering and terrorist financing, could be applied by a credit institution (in the case at hand, a bank) to a financial/payment institution such as Safe, given that financial/payment institutions are already subject to supervision by competent authorities under the PSD and the AML Directive. The CJEU was then additionally asked what type of customer due diligence measures (standard, simplified or enhanced) could be applied in such a scenario and which circumstances could trigger the application of those measures. Finally, the national court asked if the measures and the provision of certain information requested by the banks from Safe are in line with EU competition law (Safe claimed that the banks compete with it on the payment services market) and with EU data protection law (according to Safe, the banks requested the identification data of its customers and of the recipients of the funds which Safe transferred).

The AML Directive sets out the legal framework for measures aimed at preventing and combatting money laundering and terrorist financing. Its provisions are to a great extent inspired by the recommendations of the Financial Action Task Force (FATF), the main international body in the area of combatting money laundering and terrorist financing.  Article 3 of the AML Directive defines which institutions and professions are to apply the anti-money laundering measures. The list in Article 3 includes credit institutions such as banks and financial institutions such as Safe. Chapter II of the AML Directive, which deals with customer due diligence, distinguishes between 3 types of such diligence, i.e. simplified, standard and enhanced.

As far as standard due diligence is concerned, Articles 7 and 8 of the AML Directive describe in which circumstances due diligence should be applied and what measures this might involve. The latter provision underlines that the extent the due diligence measures can be determined on a risk-sensitive basis depending on the type of customer, business relationship, product or transaction.

Article 9 of the AML Directive specifies the checks that need to be undertaken before the establishment of a business relationship or the carrying-out of a transaction. It also indicates when a business relationship must be terminated or a transaction cannot be carried out.

Article 11 sets out the simplified customer due diligence measures which inter alia apply in situations where the customers are credit institutions or financial institutions. Such customers are already covered by the scope of Article 2 of the AML Directive and need to apply due diligence measures towards their own customers. Enhanced customer due diligence is dealt with in Article 13.

Pursuant to Article 37 of the AML Directive the compliance with the requirements of the Directive by the institutions and persons that need to apply it is supervised by competent authorities. Credit institutions and payment institutions are also covered by the PSD.

Payment institutions get authorised to provide payment services by competent authorities designated by the Member States. These authorities are also empowered to supervise the compliance with the requirements that are applicable to payment service providers.

The CJEU's analysis

The CJEU first dealt with the question if financial institutions such as Safe can be the addressees of standard or enhanced customer due diligence measures despite the derogation in Article 11 of the AML Directive which foresees the application of simplified due diligence measures towards financial institutions.

The Court underlined that Article 11 of the AML Directive does not derogate from Article 7(c) under which standard customer diligence measures must be applied when there is a suspicion of money laundering or terrorist financing. Thus, a national provision which authorises the application of standard due diligence measures vis-à-vis financial institutions in such circumstances of suspicion is compatible with the Directive.

In a similar vein, Article 11 of the AML Directive does not derogate from Article 13 thereof. The latter requires enhanced customer due diligence measures to be applied in situations where the risk of money laundering or terrorist financing is higher. Paragraphs (2) to (4) of Article 13 contain a non-exhaustive list of such situations which by their nature present a higher risk. Whilst this list does not include the transfer of funds abroad the Member States have a margin of discretion in applying a risk-based approach and identifying other situations which are, by their nature, associated with a greater risk of money laundering or terrorist financing. In the case at hand, the transfer of funds abroad was included by the Spanish legislator in Law 10/2010 (Article 11) as one of the higher-risk situations which trigger enhanced customer due diligence.

The CJEU then dealt with Article 9 of Spanish Law 10/2010 which on the one hand allows the non-application of standard customer due diligence towards financial institutions but on the other hand empowers the Minister of Economic Affairs and Finance to exclude the application of simplified due diligence towards certain customers. On this point, the CJEU noted that the AML Directive only lays down the minimum level of EU harmonisation with Article 5 of the Directive envisaging the possibility of adopting or retaining in force stricter provisions in the EU Member States. This conclusion was supported by an earlier CJEU judgment in Jyske Bank Gibraltar. The stricter provisions which can apply in the Member States need to serve the purpose of strengthening the fight against money laundering and terrorist financing. They may thus also relate to additional situations which, according to the Member State, present a risk of money laundering or terrorist financing  even if the AML Directive does not prescribe any type of customer due diligence for those situations.

The second group of questions before the CJEU related to the extent of powers which credit institutions may exercise in the context of customer due diligence and to the relation between those powers and the powers of the supervisory authorities under Article 37 of the AML Directive and under Article 21 of the PSD. Here, the Court noted that an institution covered by the AML Directive cannot establish a business relationship or carry out a transaction through its account or must terminate an existing business relationship when it is unable to obtain the various items of information that are defined  in Article 8 of the Directive. These items include the verification of the customer's and the beneficial owner's identity (in the latter case pursuant to a risk-based approach) as well as the information on the purpose and intended nature of the business relationship. The inability of the institution to obtain these types of information might be due to the customers' refusal to cooperate (as in the case at hand) or to other factors.

The CJEU went on to identify the limitations that need to be applied when taking a measure such as the termination of a business relationship or the refusal to carry out a transaction through the bank account. The measure must be proportionate to the risk of money laundering or terrorist financing and thus cannot be taken in the absence of sufficient information which point out to that risk.

The Court then stated that the powers exercised in the context of customer due diligence and the supervisory powers of the competent authorities under the AML Directive and the PSD are rather to be seen as separate and complementary. In consequence, a credit institution may take account of the due diligence measures which its customer had to apply towards its own customers but the extent of the credit institution's due diligence measures in such a scenario must be appropriate to the risk of money laundering and terrorist financing. In addition, a credit institution must in that case neither compromise the supervisory tasks of the competent institutions under the PSD nor replace those supervisory authorities.

Next, the CJEU spelled out the conditions in which the national legislation can authorise or require standard or enhanced customer due diligence measures towards a financial institution. The CJEU's reply to the first group of questions indicated already that such measures can be applied vis-à-vis financial institutions pursuant to Article 13 of the AML Directive (enhanced due diligence) and Article 5 (stricter provisions). In this part of the judgment however the Court examined how the Member States (when prescribing such measures) or the credit institutions (when authorised by the Member State to apply such measures) can exercise the powers under Article 5 and 13.

The CJEU started by recalling its case-law on the freedom to provide services and on the permissible restrictions of that freedom (Art. 56 TFEU). It reminded that in Jyske Bank Gibraltar the prevention of and fight against money laundering and terrorist financing was recognised as a legitimate public interest objective which could justify a barrier to the freedom to provide services. It then turned to the question if Article 11 of Spanish Law 10/2010 which identifies the transfer of money abroad as a situation which always presents a higher risk of money laundering and terrorist financing (and in consequence triggers enhanced customer due diligence) is appropriate for attaining this legitimate public interest objective. In that regard, the Court stressed that both the national legislator (when prescribing standard or enhanced due diligence measures towards a financial institution) and the credit institutions (when authorised by the Member State to apply such measures) must carry out a complete risk assessment prior to deciding on the measures to take. Such measures must furthermore be proportionate to the risk so identified. The final element of this part of the CJEU's judgment was thus dedicated to the proportionality of Article 11 of Spanish Law 10/2010. Here, the Court concluded that the restriction of the freedom to provide services laid down in Article 11 would be proportionate if no less restrictive means were available and if the restriction was compatible with the fundamental rights and freedoms under the Treaties and the Charter e.g. with the right to protection of personal data (Article 8 of the Charter) and with the principle of free competition. Whilst, in principle, leaving the protection of personal data aspects for the last part of the judgment the Court found that a less restrictive measure was available in this case. In the case at hand the Spanish legislator generally presumed that all transfers of money abroad present a higher risk of money laundering and terrorist financing whereas it could have provided a possibility of rebutting that presumption in individual cases which objectively do not present such a risk.

The last group of preliminary questions put before the CJEU focussed on the compatibility of the enhanced due diligence measures with the EU data protection law, as set out in the Data Protection Directive (Directive 95/46). The Provincial Court in Barcelona asked if Safe can be obliged to provide the banks with the identification data of its customers and in particular those from whom the transferred funds originated as well as with the identification data of the recipients of the funds. In the reply to the previous group of questions the CJEU has already indicated that the due diligence measures taken pursuant to Articles 5 and 13 of the AML Directive need to be compatible with Article 8 of the Charter, i.e. with the right to the protection of personal data. The reply to the last group of questions could have thus elaborated on this statement and clarified which personal data of the customers and recipients can be validly requested by credit institutions. However, in the case at hand BBVA denied that it requested the identification data of Safe's customers and of the recipients of the funds. It merely requested the identification data of Safe's agents who used BBVA's accounts. Moreover, the CJEU found the last group of questions not to be sufficiently precise because they only referred generally to the Data Protection Directive without specifying any of its provisions which could be relevant in this context. The part of the preliminary questions which related to the Data Protection Directive was therefore considered inadmissible.  

Comments

The replies of the CJEU to the preliminary questions point out in the direction of giving a certain degree of flexibility to the national legislators and to the institutions and persons which apply customer due diligence measures. On the other hand, the measures prescribed or authorised by the national authorities and the measures applied in individual cases by banks and other institutions and persons covered by the AML Directive need to be preceded by comprehensive risk assessments. Those risk assessments should lead to the definition of measures which are appropriate to the identified level of risk. The measures can vary depending on the type of customer, business relationship, product or transaction.

This kind of well-balanced approach seems in line with the objectives of the AML Directive and with the CJEU's case-law which recognised preventing and combatting money laundering and terrorist financing as an overriding reason in the public interest.

The CJEU added a further safeguard at the later stages of the judgment: the proportionality of the customer due diligence measures depends not only on the results of the risk assessment but also on their compliance with the fundamental rights and freedoms and general principles of law. The Court specifically mentions the principle of free competition and the right to the protection of personal data enshrined in Article 8 of the Charter.

In Safe the CJEU did not however provide any specific indications on the issue which personal data can be requested from the customer in the context of due diligence measures and in which circumstances. This was so because the last group of preliminary questions was based on facts which were disputed in the proceedings and eventually this last group was declared inadmissible by the Court.

The AML Directive does not really address the matter how the measures it designs relate to the protection of personal data. In fact, there is only one point in the text of the Directive which touches upon that issue. It is Recital 33 which refers to the applicability of national data protection laws and of the international transfers rules of the Data Protection Directive in the context of the transmission of information to the Financial Intelligence Units (FIUs) and the disclosure of information about such a transmission.

On the other hand, the new fourth Anti-Money Laundering Directive 2015/849 is much more outspoken in this respect. Its Chapter V implicitly states that Article 7(e) of the Data Protection Directive constitutes the legal basis for processing personal data for the purpose of the prevention of money laundering and terrorist financing by recognising, in Article 43, that such processing is a matter of public interest. The same Chapter deals also with the issue of the information that needs to be provided to the customer before establishing a business relationship or carrying out an occasional transaction. Finally, it lays down more precise indications with regard to the transmission of information to FIUs and to the disclosure of that fact to the customers. According to Article 41(4) this issue should be regulated in national laws which must strike the balance between the access of the customer to the personal data and the interests of the proper functioning of the anti-money laundering procedures and investigations.

The provisions on the different kinds of customer due diligence are also more precise in the new Directive. There is no longer a derogation from standard due diligence for financial institutions. The Directive is now accompanied by three annexes. The first of these annexes contains a non-exhaustive list of risk variables that shall be taken into account when determining the extent of customer due diligence measures. The second annex includes a non-exhaustive list of factors which point out to a potentially lower risk of money laundering and terrorist financing, i.e. the degree of risk that might trigger the application of simplified customer due diligence. Finally, the third annex is a non-exhaustive list of factors suggesting a higher degree of risk which requires the application of enhanced customer due diligence. Generally speaking, the factors included in the three annexes relate to types of customers, geographic areas, and particular products, services, transactions or delivery channels. In addition, Articles 17 and 18 of Directive 2015/849 envisage guidelines on the risk factors and the measures to be taken in situations of simplified customer due diligence and enhanced customer due diligence respectively. Such guidelines shall be issued by ESAs, i.e. the European Supervisory Authorities (EBA, EIOPA and ESMA) by 26 June 2017.

Photo credit: gfintegrity.org



[1] Ley 10/2010 de prevención del blanqueo de capitales y de la financiación del terrorismo.
[2] The Executive Service of the Commission for the Prevention of Money Laundering and Financial Crime of the Bank of Spain - Servicio Ejecutivo de la Comisión de Prevención de Blanqueo de Capitales e Infracciones Monetarias del Banco de España.