EU data watchdog to Europol: You've helped yourself to too much data
- Reference: 1641901670
- News link: https://www.theregister.co.uk/2022/01/11/eu_data_watchdog_to_europol/
- Source link:
EDPS says it probed Europol's collection of large datasets for strategic and operational analysis from April 2019 until September 2020. The investigation concluded the law enforcement agency needed to up its game when it came to data minimisation and retention and encouraged Europol to make necessary changes and then let the EDPS know of its action plan.
According to regulations, "personal data should be adequate, relevant, and limited to what is necessary in relation to the purposes for which this data is processed," and "personal data processed by Europol shall be kept in a form which permits identification of data subjects for no longer than necessary for the purposes for which the personal data are processed."
[1]
Which, to be fair, is a vague directive allowing for multiple interpretations.
[2]
[3]
Indeed the EDPS found Europol's interpretation and subsequent actions to correct the data management inadequate, despite the pan-Europe police body implementing technical measures to separate and secure datasets to minimize chances of data misuse.
One beef the EDPS had was that Europol didn't specify a time limit for its extraction process or a maximum retention period on datasets that didn't include data subject categories. Europol [4]cited [PDF] the nature of long-running criminal investigations as its reason for needing longer retention periods.
[5]Canon: Chip supplies are so bad that our ink cartridges will look as though they're fakes
[6]The James Webb Space Telescope has only gone and deployed its primary mirror
[7]BeOS rebuild / Haiku has a new feature / that runs Windows apps
EDPS appointee Wojciech Wiewiórowski [8]said in a canned statement:
Europol has dealt with several of the data protection risks identified in the EDPS' initial inquiry. However, there has been no significant progress to address the core concern that Europol continually stores personal data about individuals when it has not established that the processing complies with the limits laid down in the Europol Regulation.
On January 3rd, after some back and forth between the parties, the watchdog [9]narrowed the room for Europol's interpretation on regulations via directives.
The supervisor said:
…the EDPS has decided to use its corrective powers and to impose a 6-month retention period (to filter and to extract the personal data). Datasets older than 6 months that have not undergone this Data Subject Categorisation must be erased.
This means that Europol will no longer be permitted to retain data about people who have not been linked to a crime or a criminal activity for long periods with no set deadline. The EDPS has granted a 12-month period for Europol to comply with the Decision for the datasets already received before this decision was notified to Europol.
Europol is also going to have to provide implementation reports every three months for one year. Argh paperwork, right?
The database is an aggregate of several sources of information, both public and private, and includes a swath of information ranging from biometrics to data relating to an individual's work and travel.
[10]
"Without putting in place the safeguards provided in the Europol Regulation, individuals run the risk of being wrongfully linked to a criminal activity across the EU, with all the potential damage to their private and professional lives that this entails," said the EDPS in a [11]document . ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yd23uVE0v@LuY2uEWjBb@QAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yd23uVE0v@LuY2uEWjBb@QAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yd23uVE0v@LuY2uEWjBb@QAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://edps.europa.eu/system/files/2022-01/22-01-10-edps-decision-europol_en.pdf
[5] https://www.theregister.com/2022/01/10/canon_ink_chip_supplies/
[6] https://www.theregister.com/2022/01/10/james_webb_space_telescope/
[7] https://www.theregister.com/2022/01/10/haiku_linux_wine/
[8] https://edps.europa.eu/press-publications/press-news/press-releases/2022/edps-orders-europol-erase-data-concerning_en
[9] https://edps.europa.eu/data-protection/our-work/publications/other-documents/europol-order-and-faq_en
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yd23uVE0v@LuY2uEWjBb@QAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://edps.europa.eu/system/files/2022-01/22-01-10-europol-order_faqs_en.pdf
[12] https://whitepapers.theregister.com/
Re: Rule of Law
I came here to post the Guardian article too. One of the TL;DR aspects seem to be that Europol trying to kick the can down the road in order for some potential legislation to get through the EU parliament that absolves them of a lot of the Privacy requirements.
I hope EDCP comes down hard on them. Spooks gonna spook otherwise. Rozzers gonna rozzer.
I hope EDPS won't bend under the political pressure that will be high. Cops have files on politicians.
"Deleted" nudge nudge wink wink
(EDPS) has ordered European Union law enforcement agency Europol to delete any data it has on individuals that's over six months old, provided there's no link to criminal activity.
I zapped the data
But I did not zap the backup drive
(Apologies to Bob Marley)
Rule of Law
Data collection on private citizens seems to be quite the thing after GCHQ was recently criticised.
https://www.theregister.com/2022/01/10/ipco_report_2020/
See also:
https://www.theguardian.com/world/2022/jan/10/a-data-black-hole-europol-ordered-to-delete-vast-store-of-personal-data
Looks like every 'law enforcement' organisation really wants to be above the law themselves. trouble is, when Robert Mark was appointed to a senior position in the Metropolitan Police he sated that the Palin-clothes division of the Met was "the most corrupt organisation in London". So these agencies really do need to consider how a corrupt officer or employee might behave with access to all that data, and how to reduce the chances of internal corruption (not holding my breath).