{"id":17903,"date":"2019-08-09T00:00:00","date_gmt":"2019-08-08T22:00:00","guid":{"rendered":"https:\/\/bezbednost.org\/publikacija\/model-laws-on-security-and-defence\/"},"modified":"2023-04-04T15:54:21","modified_gmt":"2023-04-04T13:54:21","slug":"personal-data-protection-defends-individual-freedom-in-the-era-of-mass-surveillance","status":"publish","type":"publikacija","link":"https:\/\/bezbednost.org\/en\/publication\/personal-data-protection-defends-individual-freedom-in-the-era-of-mass-surveillance\/","title":{"rendered":"Personal Data Protection Defends Individual Freedom in the Era of Mass Surveillance"},"content":{"rendered":"<p>Mr. Sajfert participated in the creation of the so-called Police Directive or\u00a0<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=uriserv%3AOJ.L_.2016.119.01.0089.01.ENG\">Law Enforcement Directive <\/a>(LED), counterpart of\u00a0the General Data Protection Regulation (<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\">GDPR<\/a>)\u00a0for the law enforcement authorities.\u00a0The LED regulates the protection of personal data collected and processed by the competent authorities for the purpose of preventing, detecting and investigating criminal offenses, prosecuting offenders, as well as for the purpose of executing criminal sanctions.\u00a0Sajfert is employed by the European Commission, but has given this interview in his personal capacity, so the views and\u00a0opinions expressed in the interview do not in any way reflect the official opinion of the European Commission.<\/p>\n<p><strong>As the European Union act itself has a name that is too long and is rarely mentioned in its entirety, the most commonly used term is the Police Directive.\u00a0However, is it a fitting name, since the Directive neither covers every police action nor it is limited to the police alone?<\/strong><\/p>\n<p>That is not the most appropriate term.\u00a0It was often used when it was proposed as part of legislative negotiations.\u00a0However, when the Directive was enacted and started to get transposed into national law, and has now been in force for a year after its transposition, most participants realized that it was better to use the term\u00a0Law Enforcement Directive (LED)\u00a0. Because it doesn&#8217;t just cover the police.\u00a0Of course, police are a big part of its application, but the Directive covers the prosecution, criminal courts and prisons, and some other bodies that, in certain situations, may be part of law enforcement because they have certain jobs of that type.\u00a0So today the term Law Enforcement Directive\u00a0(LED) is used more than the\u00a0Police Directive,\u00a0as it used to be.<\/p>\n<p><strong>We are now waiting for the acronym LED to be incorporated, as is the case with GDPR, which is a much more familiar part of the EU&#8217;s personal data protection package.\u00a0Why are two separate regimes necessary for security authorities and for everyone else?\u00a0Is it a consequence of different EU competences in the former first and third pillars, or are there also fundamental differences that explain why the rules are different?<\/strong><\/p>\n<p>There is actually both reasons.\u00a0The architecture of the two separate acts, GDPR and LED, carries certain problems and the distinction between them is not always clear.\u00a0One is a regulation that is applied directly, the other is a directive that must be transposed into national law, so I don&#8217;t think the best solution is to regulate the whole field this way.<\/p>\n<p>I think there are also many historical reasons.\u00a0In the area covered by LED, which is the former third pillar &#8211; police and judicial cooperation in criminal matters,\u00a0member states are used to having more autonomy, a\u00a0more pronounced voice and stronger decision-making power, than in the area covered by GDPR, where the European parliament also has something to say.\u00a0After the Treaty of Lisbon, when we no longer have these pillars, the differences disappear, but a historical sense of member states that they\u00a0have more autonomy\u00a0in this\u00a0than in other areas remains.\u00a0That is why I think LED was proposed, because it leaves more freedom to states to decide how will it be transposed, while GDPR doesn\u2019t leave much space.<\/p>\n<p>From a legal point of view, the Treaty of Lisbon has Declaration 21, which states that the\u00a0specifics of the\u00a0rules on personal data protection in law enforcement\u00a0should be taken into account.\u00a0Law enforcement has its own characteristics that are reflected in the LED,\u00a0but not in\u00a0GDPR, which is the more specific part of the story.\u00a0I think there\u00a0is a\u00a0combination of practical and legal reasons, on the one hand, and political and historical reasons, on the other.<\/p>\n<h4>Private and State Mass Surveillance Are Equally Dangerous<\/h4>\n<p><strong>What is more dangerous, that huge companies have massive databases about us, or that the state has?\u00a0I suspect that the state has a greater volume of diverse information about us, in different public authorities.<\/strong><\/p>\n<p>That is a very good question, on which there are differing opinions.\u00a0Some people think &#8211; I don&#8217;t care what\u00a0Facebook\u00a0has<em>,\u00a0<\/em>how has it profiled me, but I&#8217;m more concerned with what the state is doing.\u00a0Others say &#8211; what the state is doing is fine, because I know that they will\u00a0not do something that they should not, or\u00a0use their authority inappropriately, so I do not care. I trust them, but I do not trust\u00a0these large companies.\u00a0Such\u00a0opinions can\u00a0often be\u00a0found in Northern Europe.\u00a0What people think depends a lot on the local context,\u00a0historical circumstances, and\u00a0whether there is a culture of trust or distrust towards the state, and this culture is different from state to state.<\/p>\n<p>Personally,\u00a0I have a problem with both, so I can&#8217;t draw a line what is more or less important.\u00a0I have a problem\u00a0with what is happening in the private\u00a0sector, as well as with all the\u00a0means that law enforcement can use\u00a0under the guise of security,\u00a0in order to put the population\u00a0under mass control: the\u00a0potential for misuse has especially increased\u00a0after\u00a02015,\u00a0in the context of\u00a0the fight against terrorism.<\/p>\n<p>Both\u00a0can be\u00a0mass surveillance, only for different purposes.\u00a0State\u00a0control\u00a0can be carried out\u00a0in order to control the population, and private for the purpose of directing the population towards products which can provide better earnings.\u00a0I can\u2019t establish a hierarchy of what&#8217;s worse.<\/p>\n<p>Trends\u00a0in the private sector\u00a0lead to the\u00a0confiscation of\u00a0the\u00a0free will of individuals and directing\u00a0the\u00a0individual\u00a0to what they think they want\u00a0&#8211;\u00a0there is more and more manipulation.<\/p>\n<p>Law enforcement\u00a0can also exert\u00a0mass surveillance on the population, which ultimately leads to the loss of individual autonomy and freedom, as we have seen throughout history in some repressive regimes, such as East Germany.\u00a0These are not new things, just new methods enabled by the technology of today.<\/p>\n<h4>Individual Rights Are One of the Main Differences between GDPR and the LED<\/h4>\n<p><strong>What are the most significant differences between the\u00a0GDPR\u00a0and the\u00a0LED, or the general regime of personal data protection and that of the security authorities?<\/strong><\/p>\n<p>If we go through both texts that have the same structure, we can see already in the section on principles that we have significant differences between GDPR and LED.\u00a0The LED does not know the principle of transparency, and the GDPR places great emphasis on this principle.\u00a0The principle of minimizing the data is much stricter in GDPR than in the LED, which leaves more freedom in deciding what information to collect, retain etc.<\/p>\n<p>There are\u00a0specific provisions\u00a0in the LED\u00a0that we will not find equivalent to in the GDPR.\u00a0For example,\u00a0there is an\u00a0obligation to keep data on different categories of persons separate,\u00a0and\u00a0to prescribe time periods for data retention or for periodic review of whether\u00a0data\u00a0should\u00a0be retained further.\u00a0The LED also prescribes the obligation to\u00a0keep records, the so-called\u00a0logs, which means that all databases of personal data maintained by law enforcement must be accompanied by logs showing when and why someone consulted those databases, and whether they have further shared those data.<\/p>\n<p>There is a\u00a0significant difference in the rights of persons that the data relates to.\u00a0For example, the right to information as the obligation of the data handler in GDPR is much stronger than in the LED.\u00a0Some rights from GDPR do not exist in the LED, but the LED, on the other hand, has a mechanism for indirectly exercising the rights of the persons concerned through a supervisory authority, which does not exist in GDPR.\u00a0It is also one institute that only the LED recognizes.\u00a0Basically, there are significant differences in the rights of the data subject.<\/p>\n<p>And there are also big differences in the transfer of data to third states.\u00a0As a rule, law enforcement can only send data to their equivalents in third states, and the whole architecture is different.<\/p>\n<p><strong>Can it then be stated clearly that the data protection standards are higher or lower in the LED, or are they just different from the GDPR?<\/strong><\/p>\n<p>I would say that, in\u00a0principle, the level of protection is lower and the degree of flexibility for operators is higher in the LED than in GDPR.\u00a0But there are some elements where the standards are higher in the LED.\u00a0There is\u00a0an indirect exercise of the rights of the persons concerned through the supervisory authority, which does not exist in\u00a0GDPR, for example.\u00a0This provides one additional safeguard that\u00a0GDPR\u00a0doesn\u2019t recognize.<\/p>\n<p><strong>Is there a danger that the scope of the LED is being interpreted too broadly, to the detriment of GDPR?<\/strong><\/p>\n<p>Yes, and that is something that will be a big topic in the coming years.\u00a0Often this does not depend at all on the legislative text of a member state, but on how that text is interpreted.\u00a0Of course, there are legal solutions that are dubious in themselves.\u00a0The\u00a0problem of demarcation, namely the too broad field of application of the LED, occurs in the interpretation of national law that transposes the LED &#8211; what it is applied to, when it is applied and in which situations.<\/p>\n<p>The LED is intended to be an instrument applied only by classic law enforcement bodies such as the police, prosecution, criminal courts and prisons, and only for the purpose of preventing, investigating and prosecuting criminal offenses.\u00a0That is the intended scope of the LED, and everything else should be regulated by the\u00a0GDPR.\u00a0However, many states want to make it easier for the police,\u00a0and then they try to interpret the law so that everything the police do is regulated by a single law on personal data protection.<\/p>\n<p>Another problem is that in some states, too many authorities are considered to be repressive, which then fall under the scope of the LED rather than GDPR.\u00a0It\u2019s is quite an important issue, but\u00a0it is more practical\u00a0than\u00a0it concerns\u00a0the text of the law that transposes the LED.<\/p>\n<h4>Synchronization Is Important for Serbia because of EU Accession and Effective Data Exchange<\/h4>\n<p><strong>The LED is an act of the European Union.\u00a0Why should non-member states, and especially those aspiring to EU membership like Serbia, be familiar with the standards of this directive?<\/strong><\/p>\n<p>I think for Serbia, the\u00a0so-called\u00a0LED is\u00a0important for two reasons.\u00a0One is to align Serbia&#8217;s legislation with European regulations within the accession process, and to bring\u00a0Serbia&#8217;s legislative framework and practice\u00a0closer\u00a0to what exists in Europe.\u00a0The second reason is, I suppose, the interest of the Serbian law enforcement in cooperation and exchange of personal data with European equivalents.\u00a0In order for this exchange to flow smoothly, it is essential that rules, levels of protection and supervisory mechanisms are similar\u00a0to those\u00a0existing in the European Union.<\/p>\n<p><strong>Police and other law enforcement authorities in Serbia are already exchanging information with authorities within the European Union.\u00a0On what basis is this exchange made?\u00a0Does this mean that Serbia is sufficiently aligned with EU regulations in the field of personal data protection?<\/strong><\/p>\n<p>I think that the most are relying on the provision of Article 37 of the LED, which allows law enforcement authorities in the EU to carry out self-assessment of whether there are\u00a0sufficient\u00a0safeguards that data can be exchanged on a regular basis in Serbia.<\/p>\n<p>I believe\u00a0that\u00a0the\u00a0majority of bodies that regularly exchange information with Serbia are\u00a0familiar with the legislation\u00a0in the field of data\u00a0protection.\u00a0So they were able to\u00a0conclude that Serbia is a member of\u00a0<a href=\"https:\/\/rm.coe.int\/16806c1abc\">the Convention 108 of the Council of Europe<\/a>,\u00a0that it has a legislative framework that\u00a0includes\u00a0law enforcement authorities,\u00a0that there is\u00a0<a href=\"http:\/\/www.pravno-informacioni-sistem.rs\/SlGlasnikPortal\/eli\/rep\/sgrs\/skupstina\/zakon\/2018\/87\/13\/reg\">a new law<\/a>\u00a0that has yet to start being enacted, that\u00a0the supervisory authority has some powers over law enforcement, that there is no discrimination whether the data subject is a Serbian citizen or not.\u00a0On that basis it could be concluded that there are certain safeguard mechanisms that allow for regular data exchange. I suppose that most of them rely on this.<\/p>\n<p><strong>Is this a satisfactory solution?\u00a0What would make the transfer even faster and easier?<\/strong><\/p>\n<p>It would be best for Serbia to get Adequacy decision of the European Commission, because then for all data transfers Serbia would be treated as if it were a member state.\u00a0Then the data flow could\u00a0 be completely free.\u00a0However, that decision is hard to acquire.\u00a0I don\u2019t know if\u00a0the\u00a0legislative framework\u00a0and practice in\u00a0Serbia are at that level.\u00a0I think that Serbia should\u00a0certainly\u00a0express interest\u00a0in this decision and start negotiations\u00a0with the Commission, considering that\u00a0a number of conditions exist, at least on paper.<\/p>\n<h4><em>Read soon what are the main points of dispute in the design and implementation of the\u00a0so-called Law Enforcement Directive of the EU, what provisions have to be substantially specified in national laws, and what are good examples of laws of EU Member States, in the next part of the interview.<\/em><\/h4>\n<p><em>The interview was conducted as a part of the project \u201c<a href=\"http:\/\/bezbednost.org\/All-projects\/7065\/Defending-the-Right-to-Access-to-Information-in.shtml\">Defending the Right of Access to Information<\/a>,\u201d which is supported by the Open Society Foundation in Serbia.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How security authorities need to protect the personal data they handle, why they need special rules, and why European regulations in this area are important for Serbia, BCSP researcher Jelena Pejic asked Juraj Sajfert, a lawyer and European expert in the area of personal data protection.<\/p>\n","protected":false},"author":27,"featured_media":12814,"comment_status":"open","ping_status":"open","template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[8615,8613],"tags":[264,8541,7870,8545,5799,7884,7886,7813,8544,3844,8543,8525,3843,7640,7642,7555,8439,8542,4991,7461,7469,7111],"vrsta":[9441],"pdfpub":[],"coauthors":[150],"class_list":["post-17903","publikacija","type-publikacija","status-publish","has-post-thumbnail","hentry","category-eu-en","category-foreign-policy","tag-264","tag-asked","tag-authorities","tag-defends","tag-european","tag-expert","tag-freedom","tag-important","tag-individual","tag-jelena","tag-juraj","tag-lawyer","tag-pejic","tag-personal","tag-protection","tag-researcher","tag-rules","tag-sajfert","tag-security","tag-serbia","tag-special","tag-surveillance","vrsta-analysis"],"acf":[],"_links":{"self":[{"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/publikacija\/17903","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/publikacija"}],"about":[{"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/types\/publikacija"}],"author":[{"embeddable":true,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/comments?post=17903"}],"version-history":[{"count":1,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/publikacija\/17903\/revisions"}],"predecessor-version":[{"id":31835,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/publikacija\/17903\/revisions\/31835"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/media\/12814"}],"wp:attachment":[{"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/media?parent=17903"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/categories?post=17903"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/tags?post=17903"},{"taxonomy":"vrsta","embeddable":true,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/vrsta?post=17903"},{"taxonomy":"pdfpub","embeddable":true,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/pdfpub?post=17903"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/bezbednost.org\/en\/wp-json\/wp\/v2\/coauthors?post=17903"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}