The European Data Protection Supervisor (EDPS) suggested on Thursday that Frontex (the European Coast Guard Agency) is breaching data protection rights and laws by not handling migrant data properly when processing debriefing interviews before handing over the data of Europol (the EU’s police agency).
The EDPS published a report based on an audit carried out in October 2022 that identified 36 findings, including Frontex using discursive interviews to collect personal data that would allow the interviewee to be identified. Frontex claims the interviews are anonymous and voluntary in order to gather information on migration routes and prevent smuggling and trafficking. However, the EDPS claims that individuals can be identified when this information is requested, along with their personal data.
The EDPS also questions whether the processing of personal data is adequate, necessary or subject to the necessary risk analysis before it is transferred to Europol. The report also described that some migrants were detained or imprisoned, which may have made them feel they had to provide more personal data – more than what Europol required. Additional serious compliance issues were also raised in the report against Frontex. This violates several EU data protection rules as well as Frontex rules.
In response to the EDPS report, Frontex sent an email to several media outlets explaining that they want to continuously ensure that their activities comply with data protection and fundamental rights regulations – and are ready to consider changes to their current work. However, Frontex is still heavily monitored by the EDPS, the EU and the ECtHR, especially after previous allegations that the agency was involved in turning away illegal migrants along the coast, which led to full-scale human rights investigations.
The EDPS has given Frontex until the end of 2023 to resolve the data regulation, storage and protection issues.