BETA

Activities of Hugues BAYET related to 2011/0023(COD)

Plenary speeches (2)

Use of Passenger Name Record data (EU PNR) (A8-0248/2015 - Timothy Kirkhope) FR
2016/11/22
Dossiers: 2011/0023(COD)
Use of Passenger Name Record data (EU PNR) (debate) FR
2016/11/22
Dossiers: 2011/0023(COD)

Amendments (21)

Amendment 65 #
Proposal for a directive
Recital 2 a (new)
(2a) Recent events have highlighted the need for a more effective response to the security threats facing the Union. Any additional procedures in this area must of course be consistent with fundamental rights, prove their effectiveness and be proportionate to the objectives to be achieved.
2015/04/20
Committee: LIBE
Amendment 66 #
Proposal for a directive
Recital 2 b (new)
(2b) If the fight against terrorism is to be stepped up, it is essential above all that the most effective possible use should be made of existing tools (e.g. SIS II) in the context of external border checks and exchanges of information between Member States. It is essential, therefore, that the relevant Member State services should make full information available at all times and that Member States’ police and intelligence services should work closely together.
2015/04/20
Committee: LIBE
Amendment 242 #
Proposal for a directive
Article 1 – paragraph 2 – introductory part
2. The PNR data collected in accordance with this Directive may be processed only for the following purposes: (a) The prevention, detection, investigation and prosecution of terrorist offences and serious crime according to Article 4(2)(b) and (c); and (b) The prevention, detection, investigation and prosecution of terrorist offences and serious transnational crimecertain types of serious transnational crime as defined in point (i) of Article 2 and according to Article 4(2)(a) and (d).. deleted deleted
2015/04/20
Committee: LIBE
Amendment 329 #
Proposal for a directive
Article 3 a (new)
Article 3a Data Protection Officer 1. Member States shall provide that the head of the public authority responsible for monitoring the application of the provisions adopted pursuant to this Directive and for contributing to their consistent application throughout the Union, appoints a Data Protection Officer within the Passenger Information Unit. 2. Member States shall provide that the data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and ability to fulfil the tasks referred to in this Directive. 3. Member States shall provide that the Data Protection Officer shall be responsible: (a) to raise awareness, to inform and advise the members of the Passenger Information Unit of their obligations in accordance with the data protection provisions adopted pursuant to this Directive, in particular with regard to technical and organisational measures and procedures; (b) to monitor the implementation and application of the policies in relation to the protection of personal data, including the assignment of responsibilities, the training of staff involved in the processing operations and the related audits; (c) to monitor the implementation and application of the data protection provisions adopted pursuant to this Directive, in particular as to the requirements related to data protection by design, data protection by default and data security and to the information of data subjects and their requests in exercising their rights under the provisions adopted pursuant to this Directive; (d) to ensure compliance with the data protection provisions adopted pursuant to this Directive, in particular, through conducting random sampling of data processing operations; (e) to ensure that the documentation referred to in Articles 11f (new) and 11g (new) is maintained; (f) to monitor the documentation, notification and communication of personal data breaches pursuant to Articles 11l (new) and 11m (new); (g) to monitor the response to requests from the supervisory authority, and to co- operate with the supervisory authority at the latter's request or on his/her own initiative, especially on matters relating to data transfers to other Member States or to third countries; (h) to act as the contact point for the supervisory authority on issues related to the processing of PNR data and to consult with the supervisory authority, if appropriate, on his/her own initiative. 4. Member States shall provide that the data protection officer is properly and in a timely manner involved in all issues which relate to the protection of personal data within the Passenger Information Unit. 5. Member States shall ensure that the data protection officer is provided with the means to perform his/her duties and tasks referred to in this Article effectively and independently, and does not receive any instructions as regards to the exercise of the function. 6. Member States shall provide that any other professional duties of the data protection officer are compatible with that person's tasks and duties as data protection officer and do not result in a conflict of interests. 7. Member States shall provide the data subject with the right to contact the data protection officer, as a single point of contact, on all issues related to the processing of his or her PNR data. 8. Member States shall provide that the name and contact details of the data protection officer are communicated to the supervisory authority and to the public.
2015/04/20
Committee: LIBE
Amendment 345 #
Proposal for a directive
Article 4 – paragraph 2 – point a
(a) carrying out an assessment of the passengers prior to their scheduled arrival or departure from the Member State in order to identify any persons who may be involved in a terrorist offence or a certain type of serious transnational crime and who require further examination by the competent authorities referred to in Article 5. In carrying out such an assessment, the Passenger Information Unit may process PNR data against pre-determined criteria in line with the requirement set out in paragraph 3. Member States shall ensure that any positive match resulting from such automated processing is individually reviewed by non-automated meansand subject to human intervention by a member of the Passenger Information Unit in order to verify whether the competent authority referred to in Article 5 needs to take action;
2015/04/20
Committee: LIBE
Amendment 377 #
Proposal for a directive
Article 4 – paragraph 3
3. The assessment of the passengers prior to their scheduled arrival or departure from the Member State referred to in point (a) of paragraph 2 shall be carried out in a non- discriminatory manner on the basis of assessment criteria established by its Passenger Information Unit. These assessment criteria must be targeted, specific, justified, proportionate and fact- based. Member States shall ensure that the assessment criteria are set by the Passenger Information Units, in cooperation with the competent authorities referred to in Article 5 and regularly reviewed. The regular review shall involve the Data Protection Officer and ensure that the assessment criteria remain targeted, specific, justified, proportionate and fact-based. The assessment criteria shall in no circumstances be based on data revealing a person's race or ethnic origin, political opinions, religiousn or philosophical beliefs, political opinion, trade union membership, health or sexual life. sexual orientation or gender identity, trade union membership and activities, and the processing of biometric data or of data concerning, health or sex life. The assessment shall in any case not be based solely on automated processing and allow for human intervention on every criteria.
2015/04/20
Committee: LIBE
Amendment 463 #
Proposal for a directive
Article 6 – paragraph 2 – point a – introductory part
(a) once 24 to 48 hours before the scheduled time for flight departure;
2015/04/20
Committee: LIBE
Amendment 467 #
Proposal for a directive
Article 6 – paragraph 2 – point b
(b) once immediately after flight closure, that is once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for further passengers to board.
2015/04/20
Committee: LIBE
Amendment 486 #
Proposal for a directive
Article 7 – paragraph 1
1. Member States shall ensure that, with regard to persons identified by a Passenger Information Unit in accordance with Article 4(2)(a) and (b), the result of the processing of PNR data is transmitted without delay by that Passenger Information Unit to the Passenger Information Units of other Member States where the former Passenger Information Unit considers such transfer to be necessaryrelevant for the prevention, detection, investigation or prosecution of terrorist offences or seriouscertain types of serious transnational crime. The Passenger Information Units of the receiving Member States shall transmit such PNR data or the result of the processing of PNR data to their relevant competent authorities. Where appropriate, an alert shall be entered in accordance with Article 36 of the Schengen Information System.
2015/04/20
Committee: LIBE
Amendment 719 #
Proposal for a directive
Article 11 a (new)
Article 11a Processing of special categories of data 1. Member States shall prohibit the processing of PNR data revealing race or ethnic origin, political opinions, religion or philosophical beliefs, sexual orientation or gender identity, trade-union membership or activities, and the processing of biometric data or of data concerning health or sex life. 2. In the event that PNR data revealing such information are received by the Passenger Information Unit, they shall be deleted without delay. To that end, upon the receipt of PNR data from air carriers, Member States shall apply automated and manual controls to identify and delete sensitive data from PNR data obtained. 3. In order to identify and delete any sensitive data from PNR data retained, members of the Passenger Information Unit shall undertake manual checks before any further manual processing and prior to any transfer of PNR data to competent authorities in accordance with Article 4(2), to the Passenger Information Unit or another Member State in accordance with Article 7, or to a third country in accordance with Article 8.
2015/04/20
Committee: LIBE
Amendment 724 #
Proposal for a directive
Article 11 c (new)
Article 11c Right of access for the data subject Member States shall provide for the right of the data subject to obtain from the Passenger Information Unit a copy of the PNR data undergoing processing. Where the data subject makes the request in electronic form, the information shall be provided in electronic form, unless otherwise requested by the data subject.
2015/04/20
Committee: LIBE
Amendment 726 #
Proposal for a directive
Article 11 d (new)
Article 11d Right to rectification and completion 1. Member States shall provide for the right of the data subject to obtain from the Passenger Information Unit the rectification or the completion of personal data relating to him or her which are inaccurate or incomplete, in particular by way of a completing or corrective statement. 2. Member States shall provide that the Passenger Information Unit informs the data subject in writing, with a reasoned justification, of any refusal of rectification or completion, on the reasons for the refusal and on the possibilities of lodging a complaint with the supervisory authority and seeking a judicial remedy. 3. Member States shall provide that the Passenger Information Unit shall communicate any rectification carried out to each recipient to whom the data have been disclosed, unless to do so proves impossible or involves a disproportionate effort. 4. Member States shall provide that the Passenger Information Unit communicates the rectification of inaccurate personal data to the third party from whom the inaccurate personal data originate.
2015/04/20
Committee: LIBE
Amendment 727 #
Proposal for a directive
Article 11 e (new)
Article 11e Right to erasure 1. Member States shall provide for the right of the data subject to obtain from the Passenger Information Unit the erasure of personal data relating to him or her where the processing does not comply with the provisions adopted pursuant to Article 4 of this Directive. 2. The Passenger Information Unit shall carry out the erasure without delay. The Passenger Information Unit shall also abstain from further dissemination of such data. 3. Instead of erasure, the Passenger Information Unit shall restrict the processing of the personal data where: (a) their accuracy is contested by the data subject, for a period enabling the Passenger Information Unit to verify the accuracy of the data; (b) the personal data have to be maintained for purposes of proof or for the protection of vital interests of the data subject or another person. 4. Member States shall provide that the Passenger Information Unit informs the data subject in writing, with a reasoned justification, of any refusal of erasure or restriction of the processing, on reasons for the refusal and on the possibilities of lodging a complaint with the supervisory authority and seeking a judicial remedy. 5. Member States shall provide that the Passenger Information Unit notifies recipients to whom those data have been sent of any erasure or restriction made pursuant to paragraph 1, unless to do so proves impossible or involves a disproportionate effort.
2015/04/20
Committee: LIBE
Amendment 728 #
Proposal for a directive
Article 11 f (new)
Article 11f Documentation 1. Member States shall provide that the Passenger Information Unit maintains documentation of all processing systems and procedures under their responsibility. 2. The documentation shall contain at least the following information: (a) the name and contact details of the organisation and personnel in the Passenger Information Unit entrusted with the processing of PNR data, the different levels of access authorisation and the personnel having such authorisations; (b) a description of the category or categories of data subjects and of the data or categories of data relating to them; (c) the recipients of the personal data; (d) all transfers of data to a third country, including the identification of that third country and the legal grounds on which the data are transferred, a substantive explanation shall be given when a transfer is based on Article 8a (new) of this Directive; (e) the time limits for retention and erasure of the different categories of data; (f) the results of the verifications of the measures that the processing of PNR data is performed in compliance with applicable data protection provisions; (g) an indication of the legal basis of the processing operation for which the data are intended. 3. The Passenger Information Unit shall make all documentation available, on request, to the supervisory authority.
2015/04/20
Committee: LIBE
Amendment 729 #
Proposal for a directive
Article 11 g (new)
Article 11g Keeping of records 1. Member States shall ensure that records are kept of at least the following processing operations: collection, alteration, consultation, disclosure, combination or erasure. The records of consultation and disclosure shall show in particular the purpose, date and time of such operations and as far as possible the identification of the person who consulted or disclosed PNR data, and the identity of the recipients of such data. 2. The records shall be used solely for the purposes of verification of the lawfulness of the data processing, self-monitoring and for ensuring data integrity and data security, or for purposes of auditing, either by the Data Protection Officer or by the supervisory authority. 3. The Member State shall ensure that the Passenger Information Unit shall make the records available, on request, to the supervisory authority.
2015/04/20
Committee: LIBE
Amendment 730 #
Proposal for a directive
Article 11 h (new)
Article 11h Security of processing 1. Member States shall provide that the Passenger Information Unit implements appropriate technical and organisational measures and procedures to ensure a high level of security appropriate to the risks represented by the processing and the nature of the PNR data to be protected, having regard to the state of the art and the cost of their implementation. 2. In respect of automated data processing, each Member State shall provide that the Passenger Information Unit, following an evaluation of the risks, implements measures designed to: (a) deny unauthorised persons access to data-processing equipment used for processing PNR data (equipment access control); (b) prevent the unauthorised reading, copying, modification or removal of data media (data media control); (c) prevent the unauthorised input of data and the unauthorised inspection, modification or deletion of stored PNR data (storage control); (d) prevent the use of automated data- processing systems by unauthorised persons using data communication equipment (user control); (e) ensure that persons authorised to use an automated data-processing system only have access to the data covered by their access authorisation (data access control); (f) ensure that it is possible to verify and establish to which bodies PNR data have been or may be transmitted or made available using data communication equipment (communication control); (g) ensure that it is subsequently possible to verify and establish which PNR data have been input into automated data- processing systems and when and by whom the data were input (input control); (h) prevent the unauthorised reading, copying, modification or deletion of PNR data during transfers of the data or during transportation of the data media (transport control); (i) ensure that installed systems may, in case of interruption, be restored (recovery); (j) ensure that the functions of the system perform, that the appearance of faults in the functions is reported (reliability) and that stored PNR data cannot be corrupted by means of a malfunctioning of the system (integrity). 3. Member States shall provide that the Passenger Information Unit observes the requisite technical and organisational measures under paragraph 1.
2015/04/20
Committee: LIBE
Amendment 731 #
Proposal for a directive
Article 11 i (new)
Article 11i Right to judicial remedy 1. Without prejudice to any available administrative remedy, including the right to lodge a complaint with a supervisory authority, Member States shall provide for the right of every natural person to a judicial remedy if they consider that that their rights laid down in provisions adopted pursuant to this Directive have been infringed as a result of the processing of their personal data in non- compliance with these provisions. 2. Member States shall ensure that final decisions by the court referred to in this Article will be enforced.
2015/04/20
Committee: LIBE
Amendment 732 #
Proposal for a directive
Article 11 j (new)
Article 11j Liability and the right to compensation Member States shall provide that any person who has suffered damage, including non-pecuniary damage, as a result of an unlawful processing operation or of an action incompatible with the provisions adopted pursuant to this Directive shall have the right to claim compensation for the damage suffered.
2015/04/20
Committee: LIBE
Amendment 733 #
Proposal for a directive
Article 11 k (new)
Article 11k Penalties for non-compliance Member States shall lay down the rules on penalties, applicable to infringements of the provisions adopted pursuant to this Directive and shall take all measures necessary to ensure that they are implemented. The penalties provided for must be effective, proportionate and dissuasive.
2015/04/20
Committee: LIBE
Amendment 734 #
Proposal for a directive
Article 11 l (new)
Article 11l Notification of a personal data breach to the supervisory authority 1. Member States shall provide that in the case of a personal data breach, the Passenger Information Unit, without undue delay and, where feasible, not later than 24 hours, the personal data breach to the supervisory authority. The Passenger Information Unit shall provide, on request, to the supervisory authority a reasoned justification in cases of any delay. 2. The notification referred to in paragraph 1 shall at least: (a) describe the nature of the personal data breach including the categories and number of data subjects concerned and the categories and number of data records concerned; (b) communicate the identity and contact details of the Data Protection Officer referred to in Article 3a (new) or other contact point where more information can be obtained; (c) recommend measures to mitigate the possible adverse effects of the personal data breach; (d) describe the possible consequences of the personal data breach; (e) describe the measures proposed or taken by the Passenger Information Unit to address the personal data breach and mitigate its effects. In case all information cannot be provided without undue delay, the Passenger Information Unit can complete the notification in a second phase. 4. Member States shall provide that the Passenger Information Unit documents any personal data breaches, comprising the facts surrounding the breach, its effects and the remedial action taken. This documentation must be sufficient to enable the supervisory authority to verify compliance with this Article. The documentation shall only include the information necessary for that purpose. 5. The supervisory authority shall keep a public register of the types of breaches notified.
2015/04/20
Committee: LIBE
Amendment 735 #
Proposal for a directive
Article 11 m (new)
Article 11m Communication of a personal data breach to the data subject 1. Member States shall provide that when the personal data breach is likely to adversely affect the protection of the personal data and/or the privacy of the data subject, the Passenger Information Unit shall, after the notification referred to in Article 11l (new), communicate the personal data breach to the data subject without undue delay. 2. The communication to the data subject referred to in paragraph 1 shall be comprehensive and use clear and plain language. It shall describe the nature of the personal data breach and contain at least the information and the recommendations provided for in points (b), (c) and (d) of Article 11l (new) and information about the rights of the data subject, including redress. 3. The communication of a personal data breach to the data subject shall not be required if the Passenger Information Unit demonstrates to the satisfaction of the supervisory authority that it has implemented appropriate technological protection measures, and that those measures were applied to the PNR data concerned by the personal data breach. Such technological protection measures shall render the data unintelligible to any person who is not authorised to access it. 4. The communication to the data subject may be delayed or restricted, in a specific case, to the extent that such a delay or restriction constitutes a necessary and proportionate measure: (a) to avoid obstructing official or legal inquiries, investigations or procedures; (b) to protect public security; (c) to protect the rights and freedoms of others.
2015/04/20
Committee: LIBE