European Information Systems and Data Protection as Elements of the European Administrative Union (2/3) – The Right to Privacy in the Light of Media Convergence –

Since the secondary law also contains a number of data protection provi-
sions, matters become even more complicated: A rst layer consists of general
EU data protection rules contained either in the EU data protection directive
95/46 which regulates data processing by member states and which is
currently under reform or in the EU regulation on the protection of indivi-
duals with regard to the processing of personal data by EU institutions (reg.
45/2001). These acts are complemented by the Convention 108 of Council of
Europe concerning the Protection of Individuals with regard to Automatic
Processing of Personal Data, an act of international law which is referred to by
a number of EU legal acts within the framework of the area of freedom, security
and justice like for instance the Convention for implementing the Schengen
Agreement, i.e. the legal basis of the Schengen Information System SIS. Finally,
a number of sector-specic provisions on data protection have to be taken into
So what Wolfgang Homann-Riem (a former judge responsible for data
protection cases within the German Federal Constitutional Court) once said
about German data protection law also holds true for data protection law on the
European level: Since even experts have a hard time understanding and apply-
ing it, laymen have even a harder time adhering to it. Due to the number and
inconsistencies of data protection provisions, data protection law at least par-
tially fails to achieve its goals.
This is a thought I am going to pick up later.
C. The Schengen Information System and new
legal arrangements for integrated data bases
Though it would be possible to address the aforementioned questions on an
abstract level, I have chosen a more empirical approach here. Thus, I am going
to present two case studies which show how an adequate level of data protection
can be reached in praxis.
My rst example for this will be the Schengen Information System (SIS). In
order to present some innovative legal arrangements governing intensively inte-
grated information systems, I am going to focus on the systems function in the
European migration administration.
The SIS enables the participating national
agencies to issue alerts for the purposes of refusing entry for migrants to the
Schengen area. Such an alert has a trans-national eect:
Someone who is subject
to an alert entered into the SIS will be unable to obtain a Schengen-visa from any
Schengen state and thus will not be allowed to enter and/or stay in the Schengen-
area (Art. 5 (1) lit. d, 15 Convention implementing the Schengen Agreement).
I. Trans-national representative action and substitutional
This leads to the question of how such an alert can be legally challenged. Take
the example of a Tunisian businessman whose application for a Schengen-visa is
refused in France due to an erroneous alert eventually based on a confusion of
names with a criminal issued by German authorities.
The rules on information management and remedies within the SIS combine
decentralized and intensively integrated structures. Although only the state
issuing an alert can change, amend or remove the entry to the SIS (Art. 106 (1)
Convention implementing the Schengen Agreement), a blacklisted individual
may sue for rectication, deletion or disclosure of information (and also for
damages) any member state using the SIS (Art. 111 (1) Convention implementing
the Schengen Agreement).
I would like to call this special legal arrangement
trans-national representative action [transnationale Prozessstandschaft].
So the
ctional Tunisian businessman mentioned above could sue in France in the
language he probably is more familiar with. The resulting judgment would also
be binding on (and would have to be enforced mutually by French and) German
authorities (Art. 111 (2) Convention implementing the Schengen Agreement).
Unfortunately, until today it is unclear how this mutual enforcement is supposed
to work in practice.
No such enforcement problems apply to claims for damages caused by a
wrongful alert. Art. 116 Convention implementing the Schengen Agreement
provides that any member state is directly liable to a damaged person. If the state
against which an action is brought is not the state issuing the alert, the latter
shall be required to reimburse, on request, the sums paid out as compensation
unless the data were used by the requested state in breach of the Convention. I
term this special legal arrangement substitutional liability [Stellvertreterhaftung].
II. Administrative duties to control quality of data entered into
the SIS
The rights of blacklisted individuals (at least those falling under the principle of
the freedom of movement e.g. our Tunisian businessman only if he is married to
an EU Citizen) were bolstered by the ECJ in a judgment from 2006 which seriously
limited the trans-national binding eect of SIS alerts.
In this judgment, the ECJ
established an administrative duty to control quality of data entered into the SIS
[Picht zu einer interadministrativ nachvollziehenden Amtsermittlung
So even though the member states may still treat an alert in the SIS as
evidence during the visa proceedings, they may not rely on it blindly. The ECJ
ruled that since an institutional structure exists capable of providing background
information on alerts on short notice (the so-called SIRENE-agencies)
, the
members states are obligated to assess applications for Schengen-visa by them-
selves without solely referring in their decisions to the alerts issued by other
member states.
This shows that EU information systems must not only be considered as
threats to the protection of an individuals personal data, but can also provide
an infrastructure strengthening individual rights and tightening administrative
duties to improve the quality of the data used for their decisions.
D. Privacy by design in European information
systems: the case of the Internal Market
Information System (IMI)
My second case study will present the concept of privacy by design and its
implementation in the Internal Market Information System (IMI). Since this
information system links many government agencies on dierent administrative
levels (including local trade control agencies as well as governmental ministries)
and connects them to an information exchange system spanning the whole EU,
the IMI is to be considered as an especially comprehensive information system.
In contrast to the SIS, the IMI currently isnt designed to serve mainly as a
comprehensive database containing long-term information,
but as a mechan-
ism enabling national authorities to exchange information with limited maxi-
mum storage time.
It also allows direct access to a common database only in a
very limited eld of application. Thus the IMI is not to be categorized as an
information system strictu sensu but as an intensied informational arrange-
ment (information system in a wide sense).
One of its central features is the ability to alleviate the cross-border (and
cross-language) information exchange between national agencies by providing
not only a multilingual interface with pre-translated standardized questions
(and answers) in every language used in the EU, but also by enabling an agency
to monitor the status of its inquiries (tracking mechanism).
This example shows that information systems can also contribute to the
eectiveness of administrative processes by addressing seemingly trivial issues
(like language issues). But how the use of standardized question/answer patterns
(and the use automatic translation systems for non-standard questions)
inuence the rationality and the error rate of administrative decisions is rather
European Information Systems and Data Protection