Air passengers entering or leaving the European Union could soon have their personal details stored and shared among EU countries, after lawmakers voted Wednesday to move forward with the proposal.
The creation of the passenger name record (PNR) system, recording such details as who flew where, when, and how they booked, is intended to help law enforcers fight terrorism and serious crime, but civil rights groups say it is disproportionate and undermines fundamental privacy rights.
The European Parliament's Civil Liberties, Justice and Home Affairs Committee (LIBE) quickly dealt with almost 900 amendments filed on the proposal, including two calling for its outright rejection, before agreeing to enter negotiations on a final text with the European Commission and the Council of the EU, composed of representatives of national governments.
Under the committee's proposal, PNR data would be retained in national databases for an initial period of 30 days, after which all data used to identify a passenger would be "masked out" and then stored for up to four years in serious transnational crime cases and five years for terrorism ones. After that period, the data should be deleted unless authorities need it for specific criminal investigations or prosecutions.
The proposed rules would apply to air carriers and companies like travel agencies and tour operators that handle international flights to and from the EU. The rules would not apply to flights between EU member states.
The data could be processed "only for the purposes of prevention, detection, investigation and prosecution of terrorist offences and certain types of serious transnational crime," Parliament representatives said in a news release. The offenses covered by the proposal include drug trafficking, sexual exploitation of children, money laundering and cybercrime.
EU countries would also be required to share data with each other and with Europol under conditions that still need to be determined. They would use Europol's Secure Information Exchange Network Application system to do so.
The committee proposed to let the data be handled by national "passenger information units" (PIUs). They would have to appoint a data protection officer to monitor data processing. Passengers would also have to be clearly and precisely informed about their rights. The committee also backed provisions that prohibit the use of sensitive data and the transfer of data to private parties.
The Commission first proposed a PNR system in 2007, mirroring an agreement already in place to send U.S. authorities details of passengers flying there from the EU. The Commission reiterated its proposal in 2011, and EU member states approved a version of the text in 2012. The following year, however, Parliament's LIBE committee rejected the proposal out of concern that it would violate fundamental privacy rights.
After terrorist attacks in Paris and Copenhagen earlier this year, the member states' calls for the databases became louder, and the Commission has been working on a compromise to convince the Parliament to go ahead with the plan, promising better privacy protection.
With Wednesday's vote in the LIBE committee, the Commission appears to have succeeded.
However, the victory may be short-lived: Opponents of the databases warn that they may be illegal.
European digital rights groups EDRi and Access Now warn that the EU risks making exactly the same mistake it made when it adopted the Data Retention Directive obliging telecommunications operators to retain data about customers' communications and location and provide it to law enforcers. The Court of Justice of the European Union (CJEU) invalidated the directive last year because it interfered with fundamental privacy rights.
"The Commission has still not produced evidence for the necessity and proportionality of an EU PNR scheme," said Member of the European Parliament Jan-Philipp Albrecht. This means that "terrorists will be able to enter the EU easily by train or car as we put all money into blanket PNR collection," Albrecht added.
EDRi and Access Now say it is not proven that creating a blanket surveillance measure like the PNR databases will work to prevent terrorism and serious crimes.
The EU has already signed bilateral PNR Agreements with the U.S., Canada and Australia, and on Wednesday the Commission started negotiations for an EU-Mexico PNR agreement. Some EU countries such as the U.K. already have a PNR system while others have either enacted legislation or are currently testing PNR data systems, according to the Parliament's website.
The Parliament hopes to end negotiations on the PNR system before the end of the year.
Loek is Amsterdam Correspondent and covers online privacy, intellectual property, online payment issues as well as EU technology policy and regulation for the IDG News Service. Follow him on Twitter at @loekessers or email tips and comments to email@example.com
Join the CIO New Zealand group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.