Access for consultation of the Visa Information System (VIS) by designated authorities of Member States and by Europol

2005/0232(CNS)

OPINION OF THE EUROPEAN DATA PROTECTION SUPERVISOR

The European Data Protection Supervisor (EDPS) was asked by the Commission to give its opinion on the Proposal for a Council Decision concerning access for consultation of the Visa Information System (VIS) by the authorities of Member States responsible for internal security and by Europol for the purposes of the prevention, detection and investigation of terrorist offences and of other serious criminal offences.

The EDPS deems it important to deliver an opinion on this sensitive subject because this proposal follows directly from the establishment of the VIS, which will be subject to his supervision.

Overall, the Data Protection Supervisor underlines the crucial importance of granting access to authorities in charge of internal security and Europol, only on a case by case basis, and under strict safeguards. This aim is achieved by the proposal in a globally satisfactory way, although some improvements can be made, as proposed in this opinion:

  • it should be a condition for access to the VIS according to Article 5 that consultation will ‘substantially’ contribute to the prevention, detection or investigation of a serious crime, and the records required in Article 10 should allow an evaluation of this condition in each individual case;
  • two search keys for access in the VIS mentioned in Article 5(2), namely ‘purpose of travel’ and ‘photographs’, should be reconsidered and made available as supplementary information in the case of a hit;
  • the level of data protection applying beyond consultation should be equivalent, regardless of the authorities consulting the VIS data. Article 8 and 10 should also apply to Member States to which the VIS Regulation does not apply;
  • a coordinated approach to supervision should be ensured, also with regard to access to the VIS as envis aged in this proposal;
  • provisions on monitoring systems should also ensure self auditing of compliance with data protection requirements.