European data protection authorities, including that of Malta, are in the process of harmonising their efforts to address the recent findings and recommendations of an EU working party looking into the Swift financial data scandal.
The Malta Data Protection Commission has also met with and updated Maltese financial institutions on the latest developments.
The scandal has seen millions of European, including Maltese, personal and financial records being compromised when they were, since 2001 and ostensibly as part of global counter-terrorism efforts, secretly passed over to US intelligence agencies, specifically the US Treasury Department (UST) and the Central Intelligence Agency.
The Belgium-based Society for Worldwide Interbank Financial Telecommunication (SWIFT) is a worldwide financial messaging service that handles the majority of international fund transfers.
The so-called “Article 29” EU working party investigating the scandal has found that Swift’s actions “represent a serious breach” of EU data protection laws.
It adds in its findings: “All financial institutions in the EU using the Swift service, including the Central Banks, have to make sure that their clients are properly informed about how their personal data are processed and which rights the data subjects have.”
The working party, of which Malta’s data protection commissioner Paul Mifsud Cremona is a member, found that all European banks using the Swift service must also inform clients that US authorities could be given access to their personal and financial data as a result.
“Data protection supervisory authorities will enforce these requirements in order to guarantee that they are met by all financial institutions on a European level and they will cooperate on harmonised information notices,” the working party added.
The Malta DPC, which has investigated the Swift situation at local level and participated with the other European authorities at central level, is in complete concurrence with the working party’s findings.
Asked for its reaction to the report, the DPC informed The Malta Independent on Sunday: “The Malta Data Protection Commissioner is one of the members of the Article 29 Working Party. The Commissioner does not only agree, but participated in the drafting of the Opinion published on 22 November 2006.”
Moreover, action on the harmonised notices is in hand. “The efforts of the European Data Protection Authorities are being harmonised to adopt a common approach to the matter with the US authorities,” Malta’s DPC added.
Swift, meanwhile, is to present a way forward to secure compliance with the EU’s Data Protection Directive by the end of January. The DPC referred to a meeting held last week between the Belgian Data Protection Authority, an Article 29 representative, the European Data Protection Supervisor and Swift.
At the meeting, which was described as cordial, it was decided that by the end of January, Swift will be presenting a way forward to secure compliance with the Data Protection Directive.
In its long-awaited report on the issue, the working party concluded at the end of last month that “the hidden, systematic, massive and long-term transfer of personal data by Swift to the UST in a confidential, non-transparent and systematic manner for years without effective legal grounds and without the possibility of independent control by public data protection supervisory authorities, constitutes a violation of fundamental European principles as regards data protection and is not in accordance with Belgian and European law”.
It concluded that the lack of transparency and adequate, effective control mechanisms surrounding the entire process of transferring personal data first to the US and then to the UST, “represents a serious breach in light of the Directive. In addition, the guarantees for the transfer of data to a third country as defined by the Directive and the principles of proportionality and necessity are violated.”