Is Data Privacy really safe seen through Commissioner’s PRISM?

Eric Holder, Alan Shatter and Viviane Reding in the EU/US Justice Ministerial Meeting (from left to right) (EC Audiovisual Services)

Eric Holder, Alan Shatter and Viviane Reding in the EU/US Justice Ministerial Meeting (from left to right) (EC Audiovisual Services)

It was last Friday that the European Commissioner for Justice, Viviane Reding, had a ministerial meeting in Dublin with Mr Eric Holder, U.S. Attorney General. The topic of the meeting would have normally been the ongoing discussion on the transatlantic data privacy agreement. That would have been effectively the 15th round of negotiations to bridge the gap between the two world powers and everyone was waiting for a conclusive step forward.

However, the interest of that ministerial meeting under the gloomy weather of Dublin was monopolized by the biggest state surveillance scandal in the US political history, that only broke out at the beginning of this month.  I am talking of course about the infamous leak concerning PRISM, the up till now covert National Security Agency’s (NSA) programme of the USA that has divided citizens and policy makers in both continents.

The PRISM Scandal

The scandal came to the surface after an IT consultant, who also happens to be a former CIA agent, suddenly decided to put his name in the American history as one of the most famous whistleblowers together with Daniel Ellsberg (Pentagon Papers on Vietnam War) and Bradley Manning (Wikileaks). The 29-year old, Edward Snowden, current employee of the defense contractor Booz Allen Hamilton, in the beginning had trusted a 41-slide PowerPoint presentation, classified as top secret by NSA, to the Washington Post and the Guardian. They both published a part of the presentation that was allegedly used for training purposes to NSA agents participating at the notorious PRISM spying programme on the 6th and 7th of June respectively.

Slide of PRISM Programme Presentation (source: The Guardian)

Slide of PRISM Programme Presentation (source: The Guardian)

The PRISM, until recently secret, programme is part of the Foreign Intelligence Surveillance Act (FISA) that was first signed into law in 1978. After 9/11 it underwent continuous amendments though. In October 2011 President Obama signed an extension of FISA. This is the Section 702 and according to the Director of National Intelligence, Mr James Clapper, who after the revelations had to eventually accept the existence of the PRISM, this Section is its legal basis.

Slide of PRISM Programme Presentation (source: The Guardian)

Slide of PRISM Programme Presentation (source: The Guardian)

Let’s see now what the notorious PRISM is about. As described in the slides that have seen the light of publicity, this programme is something like a contract between the National Security Agency of the USA and 9 big American software/Internet companies: Microsoft, Google, Yahoo, Facebook, PalTalk, Youtube, Skype, AOL and Apple. The slides define that the NSA can have direct access to the servers of those companies and gain access to emails, Chats, Videos, Photos, Stored data, VoIP, File transfers, Video Conferencing, Logins, Social Networks and “Special Requests”. If the above slide cannot make you lose your sleep at night, then words have lost their meaning.

Slide of PRISM Programme Presentation (source: The Guardian)

Slide of PRISM Programme Presentation (source: The Guardian)

On top of that, another slide gives away the age of the Prism programme and the exact time that each of the 9 American companies joined it. Microsoft was the first in 2007 to join, followed by Yahoo in 2008, Google, Facebok and PalTalk in 2009, Youtube in 2010, Skype and AOL in 2011. Apple seems to have resisted the most until they finally conceded with this outrageous Private Data bazaar and only joined the PRISM at the end of 2012.

No privacy seen through the PRISM

That the NSA reserves the right to request from companies specific access to private data from their users is not something new. The National Security Agency of the USA even has the right to ask for a court order that will grant the agency access to the data required. However, it seems that the American Government regarded this as a time consuming and painful task, especially when they had to fight in court with true Internet Giants like Google or Facebook. The NSA would not afford that and most of all would not afford the publicity of a legal adventure like that.

Hence, they invented the PRISM, which according to the reportage of the Guardian gives direct access to the servers of the 9 companies mentioned above, without the need for polite requests or court orders. Obviously the PRISM is nothing but an open backdoor to your emails and my facebook profile together with the skype calls of potential Al Qaeda members in Afghanistan.

Everyone is Innocent

What is astonishing, though, despite how clearly the top secret slides indicate the way PRISM functions, is that all those 9 companies unanimously after the scandal came out to claim that it is the first time they find out about the PRISM and how it operates. Google replied to Guardian’s invitation for comment that: “Google cares deeply about the security of our users’ data. We disclose user data to government in accordance with the law, and we review all such requests carefully. From time to time, people allege that we have created a government ‘back door’ into our systems, but Google does not have a back door for the government to access private user data.”… “If they are doing this, they are doing it without our knowledge”. What is more, an Apple spokesman stated:  “We have never heard of PRISM. We do not provide any government agency with direct access to our servers, and any government agency requesting customer data must get a court order.”

Moreover, Mark Zuckerberg posted a message on his Facebook account concerning this issue: “Facebook is not and has never been part of any programme to give the US or any other government direct access to our servers,” he maintained. “We have never received a blanket request or court order from any government agency asking for information or metadata in bulk, like the one Verizon reportedly received. And if we did, we would fight it aggressively. We hadn’t even heard of PRISM before yesterday.” Microsoft also denied any relation to the PRISM: “We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don’t participate in it.”

AOL did not omit to comment on this either: “We do not have any knowledge of the Prism programme. We do not disclose user information to government agencies without a court order, subpoena or formal legal process, nor do we provide any government agency with access to our servers.” Last, but not least, the online video chat room PalTalk made also a similar announcement: “We have not heard of PRISM. Paltalk exercises extreme care to protect and secure users’ data, only responding to court orders as required to by law. Paltalk does not provide any government agency with direct access to its servers.”

Numerous requests but none for American citizens?

At the same time, after the revelations companies admitted that they have indeed received data surveillance requests by the NSA. Microsoft stated that it has received around 6.000 to 7.000 requests from US government agencies that affect anything between 31.000 and 32.000 customer accounts. Moreover, Facebook announced that they have received 9.000 to 10.000 requests that concern 18.000 to 19.000 accounts. Google in its turn accepted that in 2012 only they have received from 1 to 999 data requests. Apple, allegedly the last company to join the PRISM, admitted that they have received from December 2012 to May 2013 requests that link to around 9.000 to 10.000 accounts. Last, but not least, Yahoo said that they have received in 2013 more than 12.000 data requests. It seems that the American companies accept the fact that they receive enormous amounts of data requests from the US Government but they all deny any knowledge about the infamous PRISM programme.

Right after the publication of the information on the PRISM, Mr Clapper, Director of National Intelligence, came to state that the PRISM is dedicated to acquire “foreign intelligence information” of only non-US citizens outside the USA. Mr Clapper argues later in his Press Release that “Information collected under this program is among the most important and valuable foreign intelligence information we collect, and is used to protect our nation from a wide variety of threats”. Mr Clapper concludes by saying that the PRISM is an “entirely legal” programme. What we clearly see here is that companies deny the existence of the PRISM while the NSA accepts it. Isn’t that at least suspicious?

Slide of PRISM Programme Presentation (source: The Washington Post)

Slide of PRISM Programme Presentation (source: The Washington Post)

Seeing through the European PRISM

Mrs Viviane Reding, Vice President of the European Commission, having seen this last slide cited above where the bandwith of information between Europe and the USA has the lion’s share, felt the urge to take up this matter immediately with Mr Holder, US Attorney General. Hence, at the beginning of last week, only days before their meeting in Dublin on the 14th, she wrote a letter to Mr Holder with the “European questions and worries” about the PRISM issue:

  • “Are they only aimed at gathering the data of US citizens and residents, or are they also – or even primarily – targeting non-US nationals, including EU citizens?
  • Is the data collection limited to specific and individual cases and, if so, what criteria is applied?
  • How regularly is the data of individuals collected or processed in bulk?
  • What is the scope of Prism and other such programmes? Is it limited to national security and foreign intelligence, and if so how are such terms defined?
  • How might companies in the US and EU challenge the efforts to access and analyse the data?
  • What ways might EU citizens find out if they have been affected? How is this different to the situation for US citizens and residents?
  • How might EU citizens and companies challenge any effort to access and process their personal data? How does this compare to the rights offered to US citizens and residents?”

Europe is nodding along

Despite the numerous questions by Mrs Reding and by the European citizen, that she needed to represent in Dublin, it seems that Mr Holder did not have any particular difficulty to convince the Vice President of the European Commission that everything is just fine for the data privacy of European citizen. The only thing that the US Attorney General had to do basically was to repeat what he had stated during his Press Released issued before the ministerial meeting.

Mrs Reding, however, turning a blind eye on the horrible and obvious breach of data privacy for the European citizen because of the PRISM, she appeared reassured and convinced that the PRISM is not “invasive” either “overall spying”. In fact she repeated like a parrot almost exact excerpts from Mr Holder’s press release: “It is about foreign intelligence, targeted at non-US citizens under investigation on terrorism and cyber crime. So it’s not bulk collection but individuals and groups [targeted] and is the basis of a court order and congressional oversight”. She concluded by stating “I have been given answers and assurances. For me, this is the beginning of a dialog.” Is that so?

It is more than evident that the PRISM scandal has tremendous repercussions for the data privacy of the European citizen, because since 2007 the NSA had open access to your emails, his skype calls and later my Facetime. This is rather unacceptable. But what is more unacceptable is to see the Vice President of the European Commission not challenging even a bit the US Attorney General on this one. This was probably for Mr Holder one of the easiest ministerial meetings he ever had in his career. Instead of asking about the fortune of specific data from European citizens that the PRISM stored and elaborated, Mrs Reding was apparently nodding during the whole meeting. Was it because the Vice President of the Commission is rather a naïve and innately kind-hearted individual?

Without regulation Europe will be always the victim

I am afraid Mrs Reding realized from the very first moment that she was truly unarmed in this battle. While the US have been constantly upgrading their FISAs like a new app version for Android, the EU is unreasonably stuck in that old 1995 Data Protection Directive that is supposed to protect Europeans’ data privacy with standards of an era when the Internet was nothing else but an ambitious idea. Consequently, it is unfortunately well expected that the EU has nothing to do or say on this issue. The USA are so much ahead on data privacy or better “data privacy violation” that by the time we finally upgrade our data privacy regulation they will be inventing PRISM Version 15.

Mr Joe McNamee, executive director of European Digital Rights stated at Bloomberg BNA last Friday that before the EU reaches any agreement with the USA on data privacy protection, Brussels needs to finalize first its own directive.

It is clear that last week it was not only Mrs Reding that was unarmed and truly unprotected, but most of all the European consumer.

You may watch here the discussed exclusive interview of the PRISM whistleblower, Edward Snowden, to Glenn Greenwald from The Guardian:

Advertising

Advertising

Advertising

Advertising

Advertising

Advertising

the sting Milestone

Featured Stings

Can we feed everyone without unleashing disaster? Read on

These campaigners want to give a quarter of the UK back to nature

How to build a more resilient and inclusive global system

Stopping antimicrobial resistance would cost just USD 2 per person a year

The digital revolution will transform the steel industry

This fascinating map shows how food moves around the US

EU Budget 2020 deal: Investing more in climate action, youth and research

The clothes of the future could be made from pineapples and bananas

UN will do ‘utmost to prevent and mitigate any risk of violence’ in DR Congo, pledges Mission chief

Brussels to point the finger to Washington for lack of commitment over TTIP

Migration crisis update: Greece could probably say goodbye to Schengen really soon

European Commission determined to conclude EU-Mercosur trade deal this year despite French concerns

UN chief urges emergency fund support as one of the ‘most effective investments’ in humanitarian action

The success story of a Chinese investment in the Greek port of Piraeus

COP24: green, gender focus, as UN’s crucial climate change conference gets underway

Thursday’s Daily Brief: Climate emergency, call to support breastfeeding, rising political heat and new investigation board for Syria

World Population Day: ‘A matter of human rights’ says UN

5 ways cities can use emerging technologies to fight climate change

Climate change: Parliament’s blueprint for long-term CO2 cuts

What is adversarial artificial intelligence and why does it matter?

FROM THE FIELD: Children in warzones denied right to education

5 technologies that will forever change global trade

Impressions of China

‘Counter and reject’ leaders who seek to ‘exploit differences’ between us, urges Guterres at historic mosque in Cairo

Promoting rule of law and fundamental rights in the EU

If we can build the International Space Station, ‘we can do anything’ – UN Champion for Space

Migration crisis: how big a security threat it is?

Human health – litmus paper for the climate change?

Amid continued suffering in Yemen, UN envoy welcomes reports of reduced violence

IQ scores have been falling for decades, new study finds

‘Ticking bomb’ health warning over deteriorating conditions facing Cyclone Idai victims

Yemen war: UN chief urges good faith as ‘milestone’ talks get underway in Sweden

Disease slashing global meat output, cereals boom, bananas under watch: FAO

European Parliament the most trusted EU institution

Autumn Fiscal Package: Commission adopts Opinions on euro area Draft Budgetary Plans

Sign language protects ‘linguistic identity and cultural diversity’ of all users, says UN chief

Trump ostracized by his party and world elites but still remains in course; how can he do it?

Biblioburro: The amazing donkey libraries of Colombia

Charlotte in Ghana

Tiny Iceland teaches the West how to treat bankers

High-flyers: China is on top of the world for skyscraper construction

What people want – ignore at your peril

Eliminating hepatitis calls for ‘bold political leadership, with investments to match,’ UN health chief says

Violence against women a barrier to peaceful future for all

Greece’s future solely in the hands of Tsipras; he can direct the poor country any way he likes

Global climate change: consequences for human health in Brazilian cities

Greenhouse gas emissions have already peaked in 30 major cities

Unemployment and exclusion brings EU cities to boiling point

May led Britain to chaos, now looks for way out with unpredictable DUP

European Business Summit 2014: Sting Report, Day I

How to bring precision medicine into the doctor’s office

Turkey to let EU alone struggle with the migrant crisis while enhancing its economic ties with Russia instead?

How to get ageing populations to invest in their health

Russia accepts what the EU has to offer and settles to negotiate with Ukraine

Scotland “shows the way” to separatist movements as Catalonia calls a vote on independence

Parlamentarians to “break up” with reality in the Google antitrust case

More unemployment and lower wages to make European workers competitive?

8 amazing facts to help you understand China today

Hate speech exacerbating societal, racial tensions with ‘deadly consequences around the world’, say UN experts

How tomorrow’s buildings will make you – and the planet – healthier

More billions needed to help Eurozone recover; ECB sidesteps German objections about QE


Re-thinking citizenship education: bringing young people back to the ballot box

EU and Japan select first Erasmus Mundus Joint Master Programmes

OECD Steel Committee concerned about excess capacity in steel sector

More Stings?

Comments

  1. Hey I know this is off topic but I was wondering if you knew of any widgets I could add to my blog that automatically tweet my newest twitter updates.
    I’ve been looking for a plug-in like this for quite some time
    and was hoping maybe you would have some experience with
    something like this. Please let me know if you run into anything.

    I truly enjoy reading your blog and I look forward to your new
    updates.

Speak your Mind Here

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s