DAVID LINDSAY
The Malta Data Protection Commission is in discussions with local banks regarding a requirement to inform clients making international financial transactions through the SWIFT system that their personal data could be passed on to US authorities.
Contacted by The Malta Independent on Sunday, Maltese Data Protection Commissioner Paul Mifsud-Cremona said that while discussions are still underway, “I must say that all the local bankers have been very cooperative on this matter.”
Another matter of concern is the fact that Maltese banks sometimes use the SWIFT system for communicating between themselves, given the efficiency and cost-effectiveness of the system.
Such transactions although undertaken strictly within Malta, nevertheless end up on SWIFT’s databases and as such have been at risk of being handed over to US authorities. There are, however, a number of other such systems that can be used toward the same end – another matter discussions are thought to be focusing on.
Meanwhile, the scandal over the transfer of Europeans’ personal data by European Union companies to the United States authorities, such as the Central Intelligence Agency and the Treasury Department, after 9/11 now appears even more serious that initially thought.
First was last year’s debacle when it was revealed that SWIFT – the Belgium-based Society for Worldwide Interbank Financial Telecommunication – had handed over millions of European personal data contained in financial transaction records, among them many Maltese records, to the US authorities since 2001. Next was the outcry over European Passenger Name Records being passed over to US authorities by airlines.
Now the European Parliament has called on the European Commission to look, as a “matter of urgency”, into similar instances in which European personal data have been handed over, by means of US subpoenas for ongoing terrorism investigations – issued under the Safe Harbour agreement – by other companies operating in financial services, insurance and telecommunications.
Safe Harbour is a framework negotiated by the EU and US in 2000 to provide a way for companies in Europe, with operations in the US, to conform to EU data privacy regulations.
In a recent communiqué on the matter, the European Parliament noted it “is concerned over the fact that EU companies and sectors with operations in the US not covered by the Safe Harbour agreement may currently be forced to make personal data available to US authorities, in particular US branches of European banks, insurance companies, social security institutions and providers of telecoms services” and called on the Commission “to investigate this as a matter of urgency”.
Mr Mifsud-Cremona, himself a member of the Article 29 Working Party looking into the SWIFT data protection issue, noted that SWIFT is moving toward compliance with EU data protections laws by means of, for example, looking to enter the Safe Harbour framework.
He added, “However, the information is still being passed to the US authorities.”
SWIFT has taken steps to enhance its compliance with EU rules, the society told a plenary meeting held on 17 and 18 April with the Article 29 Working Party, which Mr Mifsud-Cremona attended.
Among steps being taken by SWIFT is a bid to increase transparency toward its customers on policies and processes applicable in case of mandatory data requests for data. To this end, a data privacy-working group is redrafting SWIFT’s Data Retrieval Policy.
The policy is to make a fundamental distinction between personal data collected by SWIFT for purposes related to services and personal data supplied by customers as part of the society’s services – such as the personal data contained in SWIFT message data. The data privacy group is due to report back to the SWIFT board by mid-June.
SWIFT has also undertaken to adhere to the Safe Harbour framework and in February obtained confirmation of its membership to the framework. SWIFT’s board approved the initiative in March.
A good deal of technical and legal work still needs to be done to finalise SWIFT’s Safe Harbour membership, work expected to be concluded by the third quarter of this year. By adhering to the framework, SWIFT has confirmed that customer data located in the US are protected under similar data privacy principles as in Europe.
Discussions between the EU and the US with a view to hammering out a solution to compliance with US subpoenas, while also providing legal certainty for the financial services industry and SWIFT, are currently underway.