Mostrando postagens com marcador Europa. Mostrar todas as postagens
Mostrando postagens com marcador Europa. Mostrar todas as postagens

quinta-feira, 17 de janeiro de 2013

Cerco legal de la UE al blanqueo de dinero en el juego online

Expansion.com 17/01/2013

[foto de la noticia]

La Comisión Europea ha publicado un plan de acción para tratar de acabar con el fraude en las apuestas en línea. A estas directrices se unirán en breve recomendaciones para proteger al consumidor.

 

El mundo de las apuestas online es un sector joven, pero que ha demostrado generar grandes beneficios en muy poco tiempo: unos ingresos anuales de 13.000 millones de euros estimados en 2015 y un crecimiento anual del 15%. Por esta razón, la Unión Europea (UE) ha preparado un plan de acción para animar a los Estados miembros a prevenir el fraude y el blanqueo de dinero, impedir los amaños de resultados en eventos deportivos, así como potenciar la protección de los menores y los ludópatas frente a este tipo de actividades.

Aunque los Estados miembros son libres de fijar los objetivos de sus políticas en materia de juego online, la Comisión adoptará próximamente tres recomendaciones dirigidas a los 27 países sobre la protección común de los consumidores, la publicidad responsable del juego y la lucha contra el amaño de partidos debido a las apuestas. Además, otras medidas prevén la ampliación del ámbito de aplicación de la directiva sobre el blanqueo de capitales.

Entre el resto de recomendaciones, la UE insta a los países miembros a fomentar la formación de los jueces sobre el fraude y el blanqueo de capitales mediante las apuestas online y a recoger datos sobre las ludopatías.

"La UE quiere fijar unas bases claras para que sus miembros regulen el juego online y se fijen en los problemas más importantes a los que hay que hacer frente, como el tratamiento de datos personales, así como las garantías de protección del jugador. Sin embargo, no creo que la Comisión pretenda crear una directiva europea centrada en este tipo de servicios de ocio. Cada país es diferente y tiene una tradición frente al mundo de las apuestas", comenta Francisco Pérez Bes, responsable de seguimiento normativo de LB Apuestas y vicepresidente de Enatic.

El sector del juego en España no es nuevo, pero su vertiente online es más reciente. Sin embargo, y según el primer balance realizado por la Dirección General de Ordenación del Juego (DGOJ), en 2012 el Estado recaudó 140 millones de euros en impuestos, frente a los 100 millones que había presupuestado. Esta cifra significa el doble de lo recaudado en 2011, cuando los juegos en línea vivían una situación de alegalidad.

Este sector, que se rige por la norma ley 13/2011 de 27 de mayo, otorgó las primeras licencias provisionales de operadores a mediados del año pasado y, en febrero, la DGOJ concederá las licencias definitivas a todos los que hayan superado las pruebas técnicas que exige la ley.

Uno de los objetivos de esta norma ha sido la lucha contra el fraude imponiendo los dominios .es para poder actuar en España. "Mediante este sistema, el Estado puede hacer frente a los problemas de blanqueo mediante investigaciones dentro del país –antes había que contar con la cooperación internacional y había cruce de legislaciones–, llevar a cabo un control fiscal de los operadores y obligarles a tributar en España, así como auditar los sistemas técnicos para asegurar la seguridad de los datos personales cedidos por los jugadores", comenta Pérez Bes.

Según este experto, la legislación española –que se basa en la italiana y la británica– es buena, aunque tendrá que seguir la evolución del sector e ir adaptándose a la realidad. "Ya hemos visto un cambio sustancial, ya que el Estado ha aceptado que los jugadores puedan deducir sus pérdidas de juego al tiempo que tributan por sus ganancias", concluye el vicepresidente de Enatic.

Apoyo legislativo de la Comunidad de Madrid a Eurovegas
El pleno de la Asamblea de la Comunidad de Madrid aprobó el pasado 27 de diciembre diversos cambios que afectan a la Ley del Juego de Madrid. Estas variaciones iban encaminadas a apoyar el macroproyecto Eurovegas del magnate Sheldon Adelson. Por un lado, se creó la figura de Centro Integral de Desarrollo, que, según la norma, será un lugar "que tenga por objeto la prestación integrada de actividades industriales, turísticas, de ocio, espectáculos, juego".

Eurovegas, actualmente el único Centro Integral de Desarrollo, se beneficiaría de bonificaciones fiscales en los impuestos por trabajador contratado, una deducción anual para compra de material e inversiones para las instalaciones que se construyan, así como una rebaja del 95% sobre la cuota que resulte de operaciones sujetas al impuesto sobre transmisiones patrimoniales y actos jurídicos documentados. Además, la Comunidad de Madrid aprobó que tendrán un régimen jurídico específico del juego, adaptado a las características propias de estos complejos y del turismo que promueven.

Sin embargo, la mayor y más polémica ventaja adoptada por la Asamblea de Madrid ha sido la rebaja de la tributación de los ingresos procedentes del juego. Habitualmente, los casinos pagan entre un 45% y un 60%. Pero la nueva normativa lleva este porcentaje del 45% hasta el 10%. Este cambio debería haber sido bien recibido por todos los casinos, pero esta disminución sólo empezará a aplicarse cuando empiecen a funcionar las instalaciones de Eurovegas.

Este aspecto es para los expertos una clara discriminación hacia el resto de casinos de la comunidad que podrían beneficiarse de esta mejora durante los próximos años, mientras que se construye definitivamente el macrocomplejo.

Todos os direitos reservados: Expansion.com

sexta-feira, 4 de janeiro de 2013

Vatican Goes ‘Cash Only’ Because of Lack of Money-Laundering Controls

By HARVEY MORRIS JANUARY 4, 2013, 7:27 AM

LONDON — If you’re planning a trip to the Vatican, be sure to take cash.

Since Wednesday, museums and businesses in the Holy See have been declining credit card and debit card purchases following a decision by the Bank of Italy that is reportedly linked to concerns over inadequate money-laundering controls.

Cash machines have also been shut down after the Italian central bank refused authorization for Deutsche Bank’s Italian unit to continue operating services it provided within the Vatican’s walls.

An Italian treasury official said last month that the Vatican could no longer use the services of Italian-based banks in the light of new rules against money laundering, according to Vatican Radio.

“The Bank of Italy could not give the authorization because the Vatican, apart from not respecting money-laundering regulation, did not have the legal prerequisites,” Reuters reported, quoting a source close to the Bank of Italy.

The banking freeze, which has prompted the move to cash-only transactions, and which Vatican officials have tersely dismissed as a technical problem, has prompted speculation in the Italian press that a fresh scandal is about to erupt involving the ministate’s still-shadowy finances.

Pope Benedict XVI has pledged to throw light on the Holy See’s finances and on its ultrasecretive Institute for Works of Religion, otherwise known as the Vatican Bank. He has even hired a Swiss expert in money laundering controls, René Brülhart, to oversee the process.

A report by Moneyval, an official European financial watchdog, reported last year that the Vatican was failing in almost half the criteria required to meet standards of financial transparency. The Holy See had come a long way in a short time, the report said. However, the Vatican Bank continued to lack independent supervision.

Mr. Brülhart’s brief involves getting the Vatican included in a “white list” of territories judged to comply with international standards on combating financial crime.

The Vatican’s efforts to shake off a reputation for shadowy finances date back to 1982 and the collapse of the Banco Ambrosiano, in which the Vatican Bank was a major shareholder.

At the height of that scandal, the body of Roberto Calvi, the Ambrosiano chairman known as “God’s banker” for his Vatican ties, was found hanging beneath Blackfriars Bridge in London.

The Ambrosiano affair was not the last of the Vatican’s troubles, however.

Just last May, the Vatican Bank fired Ettore Gotti Tedeschi, its chairman, after a three-year tenure marred by financial scandal. In 2010, Italian prosecutors seized the equivalent of $29 million from a Rome bank account registered to the Vatican Bank, amid suspicions of money-laundering violations.

As the current ban on credit cards suggests, the Vatican’s efforts to clean up its finances have only been partially successful.

The Rev. Federico Lombardi, the Vatican spokesman, said contacts were under way with other operators to resume normal banking services and the suspension would be “short-lived.”

In the meantime, at the Vatican’s museums and souvenir stores, it’s cash only, please.

quinta-feira, 27 de dezembro de 2012

Caen colombianos involucrados de lavado de dinero en España

EL País Por: Elpais.com.co I EFEJueves, Diciembre 27, 2012 - 8:30 a.m

Los delincuentes tenían una compleja red de locutorios por medio de la cual hacían llegar las ganancias del narcotráfico a Colombia.

La Policía española desmanteló una red de locutorios que contrataban organizaciones de narcotraficantes para hacer llegar a Colombia los beneficios de la venta de drogas en España, método con el que supuestamente llegaron a blanquear más de 30 millones de euros.

Según informó la Policía, en la operación fueron detenidas 49 personas en Madrid, Barcelona y Albacete (centro) , entre ellos el presunto líder del grupo y los responsables de los locutorios.

La organización desarticulada usaba doce locutorios abiertos al público pero sin apenas actividad comercial, con los que podían lavar una media de 50.000 euros diarios.

El origen del caso se remonta a octubre de 2010, cuando se detuvo a 41 personas relacionadas con el blanqueo de más de 200 millones de euros procedentes del narcotráfico.

Investigaciones posteriores revelaron que formaban parte de otro entramado dedicado al blanqueo dirigido por un colombiano.

El jefe de esta organización recibía grandes sumas de dinero de narcotraficantes que operaban en España para enviarlas a Colombia.

Para ello utilizaba una red de locutorios situados en su mayoría en Madrid, que "camuflaban" las operaciones de blanqueo bajo la apariencia de remesas de dinero remitidas por ciudadanos extranjeros residentes en España a sus países de origen.

quarta-feira, 19 de dezembro de 2012

Corporate Governance – Do amor e do ódio

Jorge Brito Pereira | 19 de Dezembro de 2012 hrs. Portugal

300px-Checkmate2Quando a Comissão Europeia acaba de aprovar o Plano de Acção em que são delineadas as futuras iniciativas em matéria de Direito das Sociedades e de Corporate Governance (Action Plan: European company law and Corporate governance de 12 de Dezembro) e num momento em que, deste modo, se encerra mais um processo de reflexão nesta matéria, é interessante olhar para a montanha russa que, nesta matéria, têm sido os últimos 20 anos.
Tendo as sensibilidades despertado para o Corporate Governance nos anos 80, logo foi o tema invadido pelos ares de desregulamentação dos anos 90. Já há mais de uma década que a regulamentação do sector financeiro era criticada do outro lado do Atlântico e rapidamente se percebeu que, com a abertura do sistema jurídico Inglês a bancos estrangeiros, os americanos realizavam em Inglaterra operações que, nos Estados Unidos, não eram possíveis graças às restrições do Glass-Steagall Act, sobretudo no que respeitava à possibilidade de utilizarem depósitos para operações por conta própria. Se o capitalismo triunfava e o muro de Berlim caía, restava liberalizar, revogar restrições, promover centros financeiros e entrar na concorrência pela desregulamentação. O flirt foi correspondido – a partir do segundo trimestre de 1991, a economia norte-americana entrou no mais longo período de expansão do pós-guerra, com o PIB a crescer por 37 trimestres consecutivos até ao segundo trimestre de 2000.
No dealbar do novo século, logo o processo se inverteu com a falência da Enron, WorldCom, Andersen e outras que tais, com o indiscreto rebentar da bolha tecnológica e das bolsas de valores e, sobretudo, com a perda de confiança dos investidores das principais praças nas demonstrações financeiras das sociedades cotadas. Este foi o momento em que as exigências de Corporate Governance  mais se acentuaram, ao mesmo tempo que os reguladores foram ganhando papel central em todos os sistemas.
Mas a coisa passou. Com o processo de queda de juros, de direccionamento de capitais para o sector imobiliário, com a potenciada expansão do mercado de crédito e a popularização de novos e atípicos produtos financeiros, voltou a desregulamentação e o mero cumprimento formal das exigências impostas, sem que isso significasse que o Corporate Governance era atribuída importância material.
E de novo o processo de inverteu com o subprime, a crise financeira, a desalavancagem do mercado de crédito e as novas exigência deste mundo em que vivemos. É a este mundo – ao último – que o Plano de Acção da Comissão Europeia pretende responder. A ver vamos se não é afundado por mais uma onda qualquer que venha em sentido contrário.

 

sexta-feira, 14 de dezembro de 2012

Patriot Act can "obtain" data in Europe, researchers say

By ZACK WHITTAKER / CBS NEWS/ December 4, 2012, 3:59 PM

US-Dept-of-Homeland-Security-610x343LONDON - European data stored in the "cloud" could be acquired and inspected by U.S. law enforcement and intelligence agencies, despite Europe's strong data protection laws, university researchers have suggested.

The research paper, titled "Cloud Computing in Higher Education and Research Institutions and the USA Patriot Act," written by legal experts at the University of Amsterdam's Institute for Information Law, support previous reports that the anti-terror Patriot Act could be theoretically used by U.S. law enforcement to bypass strict European privacy laws to acquire citizen data within the European Union.

The Patriot Act, signed into law in 2001, granted some new powers to U.S. authorities, but it was mainly a "framework law" that amended and strengthened a variety of older laws, such as the Foreign Intelligence Services Act (FISA) and the Electronic Communications Privacy Act (ECPA).

"Most cloud providers, and certainly the market leaders, fall within the U.S. jurisdiction either because they are U.S. companies or conduct systematic business in the U.S.," Axel Arnbak, one of the authors of the research paper, told CBS News.

Play VIDEO

Obama signs extension of Patriot Act

"In particular, the Foreign Intelligence Surveillance Amendments (FISA) Act makes it easy for U.S. authorities to circumvent local government institutions and mandate direct and easy access to cloud data belonging to non-Americans living outside the U.S., with little or no transparency obligations for such practices -- not even the number of actual requests."

This holds true for requests targeted at non-U.S. individuals and for entire business records, he added.

Dutch vice-chair of the European Parliament's civil liberties committee Sophie in 't Veld welcomed the research, adding that it "provided further evidence" to support the theory.

She told CBS News, however, that the European Commission's proposals for new data protection rules will not solve the potential conflicts posed by third country law and the lengthy period of time in which EU laws become ratified, "would not be a reason to let the situation be for several years to come."

Information security, privacy and data protection lawyer Bryan Cunningham, who worked under both democratic and republican administrations, most recently as deputy legal advisor to former U.S. National Security Advisor Condoleezza Rice under President George W. Bush, told CBS News that this "important report" should "help correct a widespread post-9/11 misconception," that the Patriot Act and related legislation, "provided vast new powers for the U.S. government to gain access to sensitive communications and data of non-U.S. persons."

The research resurfaces questions about the security and sovereignty of citizen and government data in an ever-connected global and borderless online world. It also supports a ZDNET report that European data protection rules do not protect EU citizens' data against extra-territorial third country law, such as that of the United States.

Months after the research was published, Microsoft U.K. managing director Gordon Frazer was the first to publicly admit that the software giant could not guarantee that European citizen data stored in EU-based data centers would not leave the European Union under any circumstances, including under a Patriot Act request.

"Neither can any other company," Frazer noted.

Frazer's disclosure triggered outrage among politicians in the European Parliament. Subsequently a number of European member state governments began to question their own cloud service provisions, and in some cases banned U.S. providers from offering IT and computing services in their countries.

U.K.-based defense giant BAE Systems in the past year reneged on plans to adopt Microsoft's cloud-based services, citing fears that critical national defense secrets could land in U.S. hands.

The Dutch government is also investigating a potential conflict with third country law in regards to personal citizen passport data. Dutch social-liberal party D66raised questions in the country's parliament after suspicions arose that U.S. authorities could potentially access Dutch fingerprint and facial scans for passports because the North Holland-based company Morpho is owned by parent company Safran, which conducts systematic business in the U.S."

U.S. jurisdiction "extends to companies"

Cloud computing is the storing of documents, photos, music and files online. Governments, in possession of citizen data along with their own national security secrets, are increasingly utilizing cloud services for internal government communications, hosting documents and enabling the sharing of vast amounts of data between government departments.

Companies, schools and universities that wish to keep their data in their home jurisdiction -- governments, most of all -- the cloud poses a new set of risks.

Because most major cloud providers, such as Apple, Amazon, Google and Microsoft, are based in the U.S., the study was focused on the provisions under U.S. law, particularly in reference to the Patriot Act, signed in 2001, and the Foreign Surveillance Intelligence Act (FISA), originally signed into law in 1978 and last amended in 2008 by Congress.

Facebook is, basically, a giant cloud-based service, that can store your photos, videos, and other content, which is available from almost any device in the world.

/ AP PHOTO/TOBY TALBOT

The researchers explain that businesses, schools and universities located outside the United States -- including foreign governments -- which use cloud services offered by a company that conducts business in the U.S., could be forced by U.S. law enforcement to transfer data to U.S. territory for inspection by law enforcement agencies.

"In the U.S. legal framework, there is a legal doctrine called 'extra-territorial jurisdiction'. This implies that cloud providers operating anywhere in the EU, or anywhere in the world for that matter, have to comply with data requests from U.S. authorities as soon as they fall under U.S. laws," said Arnbak.

"These laws, including the Patriot Act, apply as soon as a cloud service conducts systematic business in the United States. It's a widely held misconception that data actually has to be stored on servers physically located in the U.S."

If they are forced to hand over EU-stored data back to the U.S., the company could be found in breach of EU law, even if is covered by both EU and U.S. legal jurisdictions.

"The key criterion in this respect is whether the cloud provider conducts systematic business in the United States, for example because it is based there or is a subsidiary of a U.S.-based company that controls the data in question," the researchers write.

Because non-U.S. residents are not protected from unwarranted searches under the Fourth Amendment, the researchers warn that this "gives the U.S. government entities concerned the statutory power to gather data on a large scale about non-U.S. citizens located abroad. And, legal protection under specific U.S. laws applies primarily to U.S. citizens and residents."

However, under FISA -- amended by the Patriot Act in October 2001, just a month after the September 11 terrorist attacks -- foreigners were not the only group immune to unwarranted searches, the Fourth Amendment notwithstanding.

"The Bush administration had intercepted the communications of Americans without obtaining a judicial warrant. The New York Times had carried reports on this from late 2005," the researchers write.

The Patriot Act also added powers to FISA which, "enables the FBI to request access to business records for an investigation into espionage and terrorism involving both U.S. and non-U.S. persons."

However, while the researchers warn that U.S. law extends beyond the reach of its borders, figures relating to requests do not exist in the public domain.

The common misconception, according to the researchers,  is that FISA gives the U.S. "unrestricted" or "unprecedented" access to data outside the country. FISA warrants do go through a "special court known as the Foreign Intelligence Surveillance Court (FISC)." The role of the court is to, "review the acquisition of intelligence information in this way if U.S. government entities require the assistance of electronic communication service providers for this purpose."

This keeps highly sensitive requests for foreign data, under the premise of keeping terrorism-scale investigations secret, out of the public eye. Because FISA courts hold national security secrets and details of ongoing terrorism investigations, the researchers say the data can't and shouldn't be published.

"Given the nature of intelligence work, it is not possible to gain insight into actual requests for information by the U.S. authorities, other than a description of the general legal framework," the researchers write.

EU citizens "at risk" from FISA, Patriot Act

While most Americans are aware of the Patriot Act and its wide-ranging provisions for domestic security, its role outside the U.S. border remains widely unknown.

While the researchers focused their efforts on the data protection of cloud users in higher education in the Netherlands, in speaking to CBS News, Arnbak warned that the concern over the ability of third countries accessing data stored in the European Union was not limited to the Netherlands, but that it "certainly" extends to the 27 member state bloc, and even outside the European Union.

"The risk of data access by U.S. authorities to cloud data is realistic, and should form an integral part in any decision making process to move data into the cloud," he said.

Because the Netherlands is a member of the European Union, the country's data protection laws originally stemmed from a wider directive from the European Commission.

Ratified in 1995, the EU Data Protection Directive must have been subsequently implemented into the legal systems of all member states by 1998. Therefore, every EU member state has the same foundation framework for data protection and privacy as each other, giving member state governments to expand upon the base principles and allowing data to freely flow across member states' borders, just as EU citizens have the right to do.

Play VIDEO

Audit Raps FBI On Privacy

"This concerns anyone with an interest in autonomy and control over access to data -- governments, businesses, non-profits and consumers alike. That's why the current debate on electronic heath records in The Netherlands is both fascinating and very serious. It appears that nobody has looked into this risk, before investing millions of taxpayers money to build these systems," Arnbak said.

He noted that businesses and governments alike, despite the additional costs, should consider in-house solutions instead of moving to the cloud. "If data is processed in-house, institutions will at the very least know of such investigations at an early stage."

Cunningham says, "There remains no credible way -- short, perhaps, of end-to-end encryption with the data provider holding the only key -- to assure confidentiality and security for cloud-stored data, whether stored in the United States or elsewhere."

"Governments and institutions seeking such privacy and security protections should, at least for now, stick to storing their own data or, perhaps, implementing national cloud solutions with robust privacy and security protections."

Because the U.S. government has "ample possibilities to request data from foreign (in this case Dutch) users of the cloud," the researchers claim, "it grants [authorities] to retrieve information on a large scale, including access to complete data sets."

"In other words, these agencies may obtain information not only about a student who could pose a threat to U.S. national security but also about a student who makes an appointment in good faith through email with a person suspected by U.S. authorities of drug trafficking," the researchers assert.

But this also extends outside the Netherlands to countries both in and outside the European Union. "From the U.S. legal perspective, Dutch users of cloud-based computing services therefore enjoy the same degree of [U.S.] constitutional protection as North Koreans," the study says.

However, the U.S. is not alone with laws reminiscent of FISA or the Patriot Act. The researchers note that such wide-ranging provisions able to access cloud-stored data outside of their respective jurisdictions are not limited to the U.S. And continue to say, "Other nation states, including the Netherlands, have comparable provisions in place for access to data in the context of law enforcement and national security."

For instance, the report notes the Dutch Intelligence and Security Services Act, which give the Dutch security and intelligence services, "the power to process the personal data of a wide range of persons." One of the sections of the law specifically carries FISA-like provisions in the Netherlands, which, "authorizes them to carry out, using a technical aid, targeted tapping, reception, recording and interception of any form of conversation, telecommunication or data transfer by means of an automated activity, irrespective of where this takes place."

Similarly, the Canadian Anti-Terrorism Act "replicates" much of the provisions in the U.S.' Patriot Act. Ontario's Information and Privacy Commissioner Ann Cavoukian said in a recent report that the Act's provisions are part of the normal data-sharing process between governments.

"You can outsource services, but you cannot outsource accountability," Cavoukian says.

"Legal provisions regulating data access for intelligence and law enforcement purposes will exist in all democracies," Arnbak says.

Cunningham warns that large, multinational, private cloud companies could pose a greater risk to private and sensitive citizen data than governments.

"Many intelligence services around the world, particularly in non-democratic countries, have no effective legal restrictions whatsoever, and are aggressively collecting massive amounts of sensitive personal, government, and commercially valuable information around the world," Cunningham says.

"Particularly with the rise of large, lightly-regulated cloud data storage providers, private, multinational companies actually may have more access to sensitive, personal data than national governments." Cunningham continues to say, such firms "assert far more authority to combine and data-mine such data for their own purposes than would the government be permitted under U.S. law."

"And, whether or not such companies would intend to misuse such data, they are far from immune from ill-motivated insiders and external hacking activities, by individuals, criminal groups, and foreign governments."

As a result, many countries can also theoretically acquire data stored by companies in another country without a mutual legal assistance request -- used by governments to request help in obtaining evidence from another jurisdiction to assist in investigations in another -- if the company is required by that country's domestic law to assist, in spite of any protection offered by a third country's legal system.

This could include cloud-stored medical data, financial information provided by banks, and business documents or corporate secrets, all the way down to an ordinary user's cloud-stored iTunes music collection or the cloud-stored photos taken on a recent vacation.

Because the U.S. is home to the global powerhouses that run major cloud services -- not limited to Apple, Amazon, Google and Microsoft -- the research increases the scope of relevance to cloud users. Conversely, the report notes that the company may not have to be headquartered in the U.S. to be supposedly susceptible to a data access request.

"If a company has a subsidiary or branch in the United States, it may be assumed that such jurisdiction exists, but jurisdiction may also exist in other more complex cases," the researchers assert.

Authorities, however, are more likely to be interested in the electronic communications between two or more persons, rather than a citizen's recent holiday photos.

In the case of cloud-stored email, which many businesses, schools, universities and ordinary citizens use, this can be hosted by an EU-based subsidiary of a U.S.-based parent company. U.S. residents enjoy not only Fourth Amendment protection from unwarranted searches, but also additional protection from the Electronic Communications Privacy Act (ECPA) and the Stored Communications Act (SCA), which regulates the U.S. government's access to electronically stored data, such as email, in criminal investigations.

Play VIDEO

Petraeus scandal developments

One of the strongest legal protections, the researchers note, under the SCA is the provision that requires U.S. authorities to request a search warrant from a judge, based on grounds of reasonable suspicion, if email is less than 180 days old. This law recently came to light after the recent resignation of Gen. David Petraeus, the former director of the Central Intelligence Agency. A warrant from only a federal prosecutor is required to acquire emails that are older than six months.

However, if U.S. federal authorities requested foreign citizen data, they would not receive protection under the Fourth Amendment, nor would the receive any protection from the ECPA or the SCA, because, "the position remains that if a person whose records have been requested is not a U.S. person and is not located in the United States, he cannot invoke the protection of the Fourth Amendment," the research states.

The academics warn that, while in some cases, contracts can be offered to cloud customers; these do not override judicial requests by third countries. "The possibility that foreign governments request information is a risk that cannot be eliminated by contractual guarantees."

Did EU laws ever protect against third country snooping?

The EU's Data Protection Directive 1995 states that EU personal data may only be transferred outside the 27 member state bloc if that country provides guarantees that the data will be given an adequate level of protection.

Data stored in the European Union freely flows to the U.S. so long as the company or government department receiving the data adheres to the EU's Safe Harbor Principles, which were set up between the U.S. government and the European Union after the EU data and privacy laws were first ratified in 1995. The rules help U.S. recipients of EU observe basis EU data protection rules in order to prevent data loss or accidental data disclosure by U.S. companies receiving EU data.

However, the Patriot Act, signed into law in 2001, granted some new powers to U.S. authorities, but it was mainly a 'framework law' that amended and strengthened a variety of older laws, such as FISA and ECPA. The 2001 Act has since been amended numerous times to extend its powers. FISA, which provides authorities to acquire cloud-stored data in foreign countries and jurisdictions, was first signed into law in 1978, and has also been amended numerous times to keep up to date with current technological trends.

While suggesting that the Patriot Act's bypassed the protection of European data by the EU Data Protection Directive, allowing data to be potentially transferred outside the EU via a U.S.-based company, one former U.S. government lawyer noted that the Patriot Act did not substantially change how the U.S. government acquires data for intelligence purposes.

ZDNET's report suggests that the Patriot Act's "negated" the protection of European data by the EU Data Protection Directive, allowing data to be potentially transferred outside the EU via a U.S.-based company.  Politicians in the European Union raised questions over laws that may affect their own nation's legal system.

Cunningham told CBS News that with appropriate judicial or other government procedures, "U.S. law enforcement and security authorities remain, as they were before the Patriot Act, able to lawfully collect both the substance of electronic communications and telephone toll, e-mail, and other business records, both of U.S. persons and those of other countries, without resort to mutual legal assistance or other international agreements and procedures."

"This is particularly true when such data is held by companies physically located in, or with substantial business connections to, the United States," he continues.

U.K., Netherlands raise concerns over cloud legal issues

There are already existing agreements and data-sharing arrangements between EU member states and non-member states, such as the U.S., the issues relating FISA and the Patriot Act notwithstanding. Without it, most Europeans would not even be allowed to step on an airplane bound for the U.S.

Mutual legal assistance (MLA) agreements exist between various nations, which conform with EU data protection and privacy laws, in order assist nations outside both within and outside the 27 member state bloc in criminal investigations. For instance, the U.S., Australia, or any other country with an MLA agreement with the Netherlands can request data on a Dutch citizen data, just as the Netherlands can in return.

Apple's cloud services allows you to access your documents from any Apple device or computer with an Internet connection.

/DONALD BELL/CNET

"If U.S. government agencies have no jurisdiction over an entity operating in the Netherlands, they may submit a request for mutual assistance under such agreements," the researchers state.

"But in the borderless cloud, in which activities are in the U.S., there is "no clear obligation under U.S. law for the U.S. government to rely on such agreements when seeking access to data on non-U.S. persons."

Also, passenger name record (PNR) data sharing agreements between the EU and Australia, Canada and the U.S., not only allow citizens to travel between those countries, but also help those authorities fight transnational crime.

PNR data includes personal and sensitive citizen data, such as their name, gender, date of birth and nationality. It can also include "racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership or concerning the health or sex life," according to the European Commission, but notes that PNR data "rarely contain sensitive data of this kind."

When the EU-U.S. PNR agreement came up for renewal, in 't Veld was appointed the "rapporteur," or the person chosen by the European Parliament to investigate the agreement. After many months of negotiations, with the previously debated EU-Australia PNR agreement set as an "acceptable" agreement, in her words, in 't Veld ultimately recommended that the European Parliament reject the EU-U.S. PNR deal citing privacy fears relating to the disclosure of EU citizen data to U.S. authorities.

The U.S.-EU PNR agreement passed with a significant minority opposing the deal, but by the she had distanced herself from the report that she recommended should be rejected.

"The U.S. may also use the data for other, less-explicitly defined purposes such as immigration and border controls," she warned in her findings.

"The decision of the European Parliament does not reflect my recommendation. Therefore I choose to distance myself from it." If the agreement was not signed, it may have meant "the visa privileges for European travellers to the U.S. fell," in 't Veld noted, or the disallowing of EU citizens to travel to the U.S.

Play VIDEO

Lawmakers On NSA Controversy

Beyond the European Parliament, other EU member states are warning their respective parliaments and governments that the reach of third country laws could extend beyond their reach as a result of the borderless "cloud."

The U.K. parliament recently outlined its plans to move to the cloud, but worries regarding the Patriot Act spurred on two opposition members of Parliament to question the proposals.

John Thurso, chair of the U.K. Parliament's Finance and Services Committee, suggested in a recent debate in the U.K.'s House of Commons discussing the cost-efficiency of Parliament, that all parliamentary members should "move to a more cloud-based system." (The full video can be found on the BBC's Democracy Live Web site.)

However, another politician interjected, who mentioned that committee members are currently using iPads, stated that they "cannot put information on the cloud on the basis that servers for Apple products are based in the U.S. and therefore covered by the Patriot Act."

Thurso retorted: "The committee is not yet engaged on the Patriot Act." Former minister under the previous Labour government Angela Eagle, who was responsible for the early planning of the 2011 census, also questioned Thurso to "ensure when we do get a cloud finally, its storage will be in the U.K."

In the Netherlands, the government is under increasing scrutiny over unrest surrounding the country's electronic patient records system.

The patient records are operated by a Dutch subsidiary of U.S. parent company CSC, though the data is stored on servers in the Netherlands. However, VZVZ director Edwin Velzel, whose company is behind the setting up of the system, told Dutch television earlier this month that unless CSC can give assurances that it is not subject to the Patriot Act, the contract will be withdrawn.

Arnbak highlighted possible problems with the Dutch passport system. He told CBS News in an email: "In order to obtain a passport, all Dutch citizens need to provide fingerprints to the government. Morpho, a company that falls under U.S. jurisdiction, was contracted to process these fingerprints, which are thus stored somewhere in the cloud and within reach of U.S. authorities under the Patriot and FISA Acts."

"When this hit the news in the Netherlands, it logically caused considerable social unrest," he said.

Dutch Home Affairs minister Liesbeth Spies said in a briefing to members of the Dutch parliament that she could not rule out U.S. authorities accessing Morpho's database of passport data.

In 't Veld told CBS News that the governments who have been confronted such issues "tend to deny the problem, or -- when they can no longer deny it -- just duck the issue by making vague promises about 'speaking to the U.S. authorities.'"

"Frankly, I wouldn't know what there is to discuss. The only relevant question is: do European and [member state] authorities feel responsible for enforcing EU law on EU territory, and protecting EU citizens, or do they not?"

Europe's next steps: Secure the European cloud

The potential conflicts between U.S. anti-terror laws and EU data protection law, as described by the researchers at the University of Amsterdam could be solved with the upcoming EU Data Protection Regulation, which was proposed by the European Commission in January.

Speaking in the European Parliament's upper house chamber earlier this year, EU Justice Commissioner Viviane Reding noted there was not enough clarity in the existing data protection and privacy laws, and that the final any international disputes regarding the impact of third country legislation on EU laws would be up to the International Court of Justice, the so-called "World Court," in The Hague.

Viviane Reding, EU Justice Commissioner, who is overseeing the new EU data protection laws.

/ THE COUNCIL OF THE EUROPEAN UNION

But, she said, she was confident that the draft Data Protection Regulation, published earlier this year in January, would "bring further legal clarity."

Some members of the European Union's upper house, the European Parliament remain skeptical that the new "one-size-fits-all" law will not offer sufficient protections against U.S. or any other third country law.

In 't Veld, who has been particularly vocal in the European Parliament regarding data protection and concerns of third country law impacting European citizens, told CBS News that the European Commission continues to deny the potential conflict between the two continents.

"I do not think it will lead to a change in policies in the short term. The problem is not that governments and the Commission are not aware of the problem. We have brought it to their attention ad nauseam. The real problem is they have no interest in addressing it."

In 't Veld noted in a 2011 letter to Reding that, "EU based companies are currently facing U.S. subpoenas under the Patriot Act." She added: "They are obliged to submit data stored in Europe to U.S. authorities, thereby probably violating EU laws." Because these firms have operations in the U.S., she described it as "very difficult" for them to refuse to comply with a U.S. subpoena.

"I really wonder if the authorities will be just as lax when they realize other countries can and will do the same -- China, for example. The passivity of Commission and [member state] governments sets a very bad precedent. They are failing their citizens."

A European Commission spokesperson told CBS News in an emailed statement: "The high standards which we give to our citizens must also be transferred when there is an exchange of data with third countries."

"We in the Commission take this question very seriously, because the Commission believes and supports the principle that, in international public law, a legal act which is enacted by a third country cannot be directly and automatically applied in the territory of the EU unless -- exceptionally -- Union law or Member State law explicitly recognises the facts of such an act in their respective jurisdiction."

The Commission also explained that existing legal channels -- such as mutual legal assistance requests -- must be used:

"No legal acts of a third country as such can legally overrule the relevant EU legislation or Member State legislation, and this includes data protection rules. Any processing of personal data in the EU has to respect the applicable EU data protection law. If, for example, a U.S. law enforcement authority requires information from companies operating in the European Union, whatever the nationality of those companies, they have to use existing channels of cooperation and mutual legal assistance agreements."

"This issue also applies when personal data are transferred by an EU company to a company in the U.S. and when the data are subsequently processed for law enforcement purposes."

Arnbak argues that a real solution to the concern over third country laws can only be found at an international legal and political stage.

"It is important to realize that government access to cloud data is not a data protection issue," Arnbak says. "Having to comply with a data access request from the government is not something that you can exclude yourself from in a legal contract: you either comply as a cloud provider, or you face prosecution."

"The fact that the important cloud providers of today will have to comply with U.S. legal requirements, while non-Americans living outside the U.S. cannot claim the legal protection that their domestic law provides for, constitutes a gap in legal protection that can only be solved by governments engaging with each other at the international level."

Arnbak resonated in 't Veld's concerns about the cloud. He said that the European Commission should be, "open and frank about the wide gap in legal protection for Europeans in the U.S. cloud and either demand that these concerns are addressed through an EU-U.S. approximation of laws, or stimulate alternatives that lower the dependency of European customers on U.S. entities."

Related Posts Plugin for WordPress, Blogger...