EDPS Opinion on EU Cyber Security Strategy

June 18, 2013

Credible cyber security strategy in the EU needs to be built on privacy and trust, says the European Data Protection Supervisor, Peter Hustinx. He made the simple point that cyber security is not an excuse for the unlimited monitoring and analysis of the personal information of individuals following the publication of his opinion on the EU’s strategy on cyber security, Cyber Security Strategy of the European Union: an Open, Safe and Secure Cyberspace.

The EDPS Opinion states that, while the strategy document includes a welcome acknowledgement of the importance of data protection principles for a robust cyber security policy, the strategy is not clear on how these principles will be applied in practice to reinforce the security of individuals, industry, governments and other organisations. 

Peter Hustinx said:

There is no security without privacy. So I am delighted that the EU strategy recognises that it is not a case of privacy versus cyber security but rather privacy and data protection are guiding principles for it. However, the ambitions of the strategy are not reflected in how it will be implemented. We acknowledge that cyber security issues have to be addressed at an international level through international standards and cooperation. Nevertheless, if the EU wants to cooperate with other countries, including the USA, on cyber security, it must necessarily be on the basis of mutual trust and respect for fundamental rights, a foundation which currently appears compromised’. 

The EDPS acknowledges that the overall aim of the EU strategy is to make the use of the internet (and any network and information system connected to it) safer by enabling organisations in the EU to prevent and respond to cyber disruptions and attacks. The intended result is to foster trust in individuals and organisations using the internet. However, the EDPS considers that the Commission Communication fails to take due account of the role of data protection law and of current EU proposals in promoting cyber security, such as the proposed Data Protection Regulation and the eTrust Regulation, among others. It also does not take into account the importance of factoring in protection at the inception of any system that contributes to cyber security – privacy by design – as a foundation for building trust. The result is that the strategy is not as effective and comprehensive as the Commission intends it to be.

While measures to ensure cyber security may require the analysis of some personal information of individuals, for instance IP addresses that can be traced back to specific individuals, the EDPS believes that cyber security can play a fundamental role in ensuring the protection of privacy and data protection rights in the online environment, provided the processing of this data is proportionate, necessary and lawful.

The EDPS highlights the fact that national data protection authorities (DPAs) play a significant role in ensuring that an appropriate level of security is applied to the processing of personal information, including on the internet and through network and information systems, and in raising awareness of the rules that apply to individuals and organisations in EU countries. Moreover, DPAs must be notified of any new operation by an organisation that involves the processing of personal information and of data breaches. Agencies such as Europol, ENISA and others listed in the strategy also need to liaise with them in the performance of their tasks. Although this is not reflected in the strategy, the EDPS believes that their role in contributing to cyber security must be acknowledged.

Background information

On 7 February 2013, the Commission and the High Representative of the European Union for Foreign Affairs and Security Policy adopted a Joint Communication to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions on a “Cyber Security Strategy of the European Union: an Open, Safe and Secure Cyberspace”. On the same date, the Commission adopted a proposal for a Directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security across the Union. This Proposal was sent to the EDPS for consultation on 7 February 2013.