UPDATE 2013-11-27: here (.pdf, Nov 27) is the EU Report on the Findings by the EU Co-chairs of the ad hoc EU-US Working Group on Data Protection — i.e., the EU-US expert group established in response to the revelations about NSA-related activities on European territory that is referred to in the post below.
On November 15th, the Dutch Minister of the Interior and Kingdom Relations, Ronald Plasterk, sent a letter (in Dutch) to the Dutch Senate. The letter addresses questions concerning the impact of the Snowden revelations on ongoing TAFTA negotiations and EU Data Protection negotiations, and mentions SWIFT. Below is my translation. Parts in [] are mine.
WARNING: this is an unofficial translation.
Date: November 15th 2013 Subject: NSA, privacy and (economic) espionage
1. Did the revelations of Mr. Snowden come as a surprise to the government?
2. Has the government thoroughly informed itself about the significance of the revelations of Mr. Snowden for the constitutional protection of the privacy of citizens?Yes. The government is committed to careful and adequate protection of personal data. This is a point of attention in the bilateral discussions currently taking place with the U.S. government in response to the revelations about the NSA. The Minister of Foreign Affair already expressed his concerns about the NSA’s activities to his American colleague Kerry, and I spoke with the director of the NSA. The Netherlands also assesses the initiative of Germany and France to reach agreements with the Americans as positive, has contacted with both countries, and will make an active contribution where possible.
An EU-US expert group exists that is deliberating on protecting the privacy and electronic data of citizens. The aim of this expert group is to gain insight into each other’s programs and how they are anchored in the rule of law.
Also, the State Secretary of Security and Justice and I are actively involved in the negotiations on the new EU legislation on the protection of privacy. The significance of the revelations of Mr. Snowden will be included in this.
During the JHA Councils of July and from October 2013 an – always informal – exchange of views took place on the consequences that could be associated with the revelations. Decisions have not been made on these matters. I refer the Parliament to the reports on the council meetings.
On September 16th, is a “Friends of the Presidency”-meeting (an informal meeting where no formal decisions are made) was held dedicated to two proposals to amend Chapter V of the EU Data Protection Regulation. This chapter covers the transfer of personal data from the EU to third countries. For a report of that discussion, I refer to the report on the negotiations relating to the Q3/2013. The discussion on Chapter V of the Regulation will be continued. The outcome of the ongoing discussions between the EU and the U.S. on the collection of data and the underlying legislation will be taken into account.
In addition to the Council, the European Parliament is also deliberating on the legislation. The European Parliament pays specific attention to the transfer of personal data from the EU to the authorities of third countries. It goes without saying that the issue will be explicitly addressed in due course in the trialogue between the Commission, Council and European Parliament.
The government believes it is still important that we shortly come to an ambitious and comprehensive agreement with the United States. It is the Netherlands itself that has a lot to gain: in addition to a expected structural growth of the Dutch GDP by 4 billion a year, the agreement also provides new jobs and lower prices. The government makes no connection between EU standards regarding privacy and the free-trade agreement.
I can not confirm the accuracy of the messages on the interception of SWIFT by the NSA. I am aware that Commissioner Malmström, following the media reports of the tapping of SWIFT by the NSA on September 12th, has asked the U.S. authorities to clarify this issue and that this topic is part of the discussions between the U.S. and the EU. See also the answer to the questions posed by the MP’s Koolmees and Schouw (both D66) on the media reports that the servers of the Society for Worldwide Interbank Financial Telecommunication (SWIFT) may be tapped by the NSA (publication date October 16th, 2013, reference: 2013D41109).
The government has no insight into the quantitative economic damage that businesses suffer from theft of confidential data. However, there are several qualitative insights into the economic loss due to theft of confidential information and industrial espionage. In a study from 2011 that was commissioned by the British government [0], the annual economic loss in the United Kingdom due to cybercrime was estimated at 27 billion pounds. This is a conservative estimate, the amount is probably higher and increases every year. Industrial espionage takes 28% (7.6 billion pounds) and identity theft accounted for 6.3% (1.7 billion pounds). It is estimated that the industry contributes 75% of the damage. TNO has projected these findings to the Dutch situation and estimates the total national damage caused by cybercrime, with digital espionage as part of it, to be at least 10 billion euros [1]. Industrial espionage accounts for approximately 2 billion. These are estimates, the exact damage is difficult to determine or can not be determined.
The Dutch government is focusing on several areas to avoid digital espionage and combat theft of confidential data:
- The AIVD and MIVD provide briefings to create awareness among government entities and industry about the threat of cyber espionage, and give advice on information security.
- Within the National Cyber Security Center (NCSC), an active information exchange exists between government services and the private sector – for instance the vital sectors – on (direct) threats and vulnerabilities.
- In the Second National Cyber Security Strategy (NCSS2) that the government has recently presented to the Parliament, an action is taken to develop a detection and response network. This partnership between public and private parties will be an important step to make the Netherlands digitally more secure and resilient.
- The government commissioned the development of the Vulnerability Analysis Espionage (KWAS) and an associated manual and e-learning module. The Espionage Vulnerability Assessment Manual helps companies and organizations to investigate the risks of espionage themselves.
- Hardware and software are vulnerable to cyber crime; computer infected with malware are also used for espionage. Besides awareness programs, a quality mark is being developed for secure software.
- The Minister of Security and Justice, being the coordinating minister for cyber security, has sent the new government-wide National Cyber Security Strategy to the Parliament. This includes extensive coverage of measures to increase the overall resilience in the digital domain.
Also see the answer to the questions posed by the MP’s Schouw and Sjoerdsma (both D66) on media reports that Russian spies are very active in the Netherlands (publication date May 23, 2013rd, reference: 2013D20939).
7. What steps has the government taken to counter the ongoing privacy breaches?See the answer to question 2.
The government considers any action outside the framework of the Dutch law to not be acceptable. This includes espionage for economic reasons by foreign powers in the Netherlands. The AIVD and MIVD therefore carry out structural investigation of espionage by foreign powers in the Netherlands. If such espionage is detected, measures always follow, both diplomatically and in other areas.
See the answers to question 2 and 8.
