Sunday

28th Nov 2021

Investigation

UK unlawfully copying data from EU police system

  • UK not part of Schengen, but its abuse of Schengen systems put people at risk, report said (Photo: Khairil Zhafri)

The United Kingdom has been illegally copying classified personal information from a database reserved for members of the passport-free Schengen travel zone.

It has shared the information with US companies and it is demanding to keep access to the database after it leaves the EU next year.

Read and decide

Join EUobserver today

Become an expert on Europe

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

  • Travellers at risk of being targeted over bogus and illegal information (Photo: Curt Smith)

An internal EU document, seen by EUobserver, listed years of violations by British authorities following restricted access to the Schengen Information System (SIS), an EU-run database used by police to track down undocumented migrants, missing people, stolen property, or suspected criminals.

The UK never joined the Schengen area, which includes 26 other European countries most of whom are EU members, but has been given some access to SIS since 2015.

British mismanagement and manipulation of the Schengen system also meant that "persons sought for arrest for instance even for terrorism related activities by Schengen Associated Countries cannot be detected upon entry to the UK," said the "restricted" EU document.

The British authorities copied the data and handed it over to border police despite the fact that some of the information contained was not only incorrect but entirely out of date, it added.

That meant that innocent people visiting or living in the UK run the risk of being flagged for violations they never committed from data that was unlawfully copied.

The 29-page document, drafted by Schengen experts from EU states and from the European Commission, said the UK violations "constitute serious and immediate risks to the integrity and security of SIS data as well as for the data subjects."

The UK also ignored alerts issued by other EU states, it said, so that "vehicles stolen on the territory of another member state and located in the UK are not seized."

A team of Schengen experts warned the UK already in 2015 to curb its abuses, but it did not comply.

At the same time, the British government is demanding use of the database following the UK's exit from the European Union next year.

Spot checks by the same team of Schengen experts composed from various member states and the European Commission documented the full range of violations in early November last year after visiting government offices, police stations, and airports in places like Warrington, Heathrow, Hampshire, Southampton and Kent.

Around half the checks were surprise visits.

They found, among other things, "that some major deficiencies in the legal, operational, and technical implementation of SIS identified during the evaluation of 2015 were not effectively remedied and still persist."

Examples abounded.

The UK has made numerous full and partial copies of SIS, increasing the risk of data breach and of having it unlawfully shared with other authorities around the world.

SIS contains information on nearly 500,000 non-EU citizens denied entry into Europe, as well as over 100,000 missing people, and some 36,000 criminal suspects. The Brits alone are said to have run some 539 million SIS checks last year.

Some of these copies were unlawfully stored on back-up laptops at airports and ports. Other copies were held at government offices. Other still were held by private contractors like CGI, a US-Canadian company, as well as IBM and ATOS, which were hired by the UK government to run the systems.

CGI now manages a SIS copy that included photographs, fingerprints and European Arrest Warrants. IBM manages a copy used by the UK's national border targeting centre as a service for the UK Home Office, which it then stores at a data centre owned by ATOS.

"Entrusting the management of the SIS technical copies to private contractors poses increased risks in terms of physical and logical data security, especially since the private contractors in the UK are not only hosting the systems but also implement changes to the system," the EU experts' report noted.

US companies holding such sensitive data may also be required to hand it over to the US government given demands by the USA Patriot Act, warned the EU document.

Meanwhile, the UK was using partial SIS data with a variety of national systems.

These included the Warning Index, which cross-references incoming travellers against national lists of known criminals and terrorists.

The Warning Index is held and managed by Fujitsu, a private contractor, on behalf of the UK Home Office, and is running at six UK airports.

The index is also one of the biggest violators of the SIS data and "constitutes an unlawful copying of SIS data", the EU report said.

Flagged alerts for arrests were not made available at the UK borders, complicating efforts by its own border guards from spotting returning foreign terrorist fighters.

Semaphore, a system used to capture inbound and outbound passenger information supplied by airlines and shipping companies, also has access to SIS as does the UK's central national database known as IDENT1.

IDENTI1 contains information like fingerprints and palm prints from people arrested by the British police. Those prints are then matched against records held by SIS.

IT security system threatens EU rights

EU commission wants to link up all information systems on security, border, and migration, drawing a rebuke from own rights agency.

Exclusive

Balkan spies 'feed' EU's police database via Czechs

Western Balkan secret services have handed over more the 250 alerts on suspected foreign terrorist fighters since last summer - fed into the EU's police database by the Czech Republic, according to a confidential document seen by EUobserver.

Exclusive

Breton's firm hosted unlawful copy of EU police data

France's Thierry Breton is set to become the next European Commissioner for industrial policy. While he was CEO of IT giant Atos, the firm hosted unlawful partial copies of EU police data on behalf of the United Kingdom.

UK taking 'steps' after illegal copying of EU Schengen data

According to a classified report, the UK made illegal copies of EU security data, and its disregard for EU rules on handling such data was a "serious and immediate risk". The Commission now says "practical steps" have since been taken.

News in Brief

  1. Covid variant: EU to block travel from southern Africa
  2. France and UK seek EU help on Channel migrants
  3. New Swedish PM who resigned after 7 hours gets second chance
  4. Belgium to decide on Friday on Covid measures
  5. UK rings alarm on new Covid strain in South Africa
  6. Turkish police use tear gas at women's rights march
  7. Poland calls for more Nato troops
  8. Ex-Navalny aide leaves Russia

Feature

Covid-hit homeless find Xmas relief at Brussels food centre

The Kamiano food distribution centre in Brussels is expecting 20 people every half hour on Christmas Day. For many, Kamiano is also more than that - a support system for those made homeless or impoverished.

Top court finds Hungary and Poland broke EU rules

EU tribunal said Hungary's legislation made it "virtually impossible" to make an asylum application. Restricting access to international protection procedure is a violation of EU rules.

Stakeholders' Highlights

  1. Nordic Council of MinistersNew report reveals bad environmental habits
  2. Nordic Council of MinistersImproving the integration of young refugees
  3. Nordic Council of MinistersNATO Secretary General guest at the Session of the Nordic Council
  4. Nordic Council of MinistersCan you love whoever you want in care homes?
  5. Nordic Council of MinistersNineteen demands by Nordic young people to save biodiversity
  6. Nordic Council of MinistersSustainable public procurement is an effective way to achieve global goals

Latest News

  1. Belgium goes into three-week 'lockdown light'
  2. MEPs list crimes of 'Kremlin proxy' mercenaries
  3. EU to open up 'black box' of political ads
  4. Can the ECB solve climate change and inflation on its own?
  5. EU set to limit vaccine certificate to nine months
  6. Surprise coalition in Romania without former Renew's Ciolos
  7. This 'Black Friday' is a turning point in corporate accountability
  8. West struggling to show strength on Ukraine

Join EUobserver

Support quality EU news

Join us