Crime (Overseas Production Orders) Bill [HL] Debate

Full Debate: Read Full Debate
Department: Department for International Development
Lord Rosser Portrait Lord Rosser
- Hansard - - - Excerpts

In the other direction, would an order made in an American court against a British provider that is not complied with lead to contempt proceedings in a United States court, and how would that court enforce it against a British provider?

Lord Paddick Portrait Lord Paddick (LD)
- Hansard - -

While we are waiting, am I right in thinking that in the recent Facebook case it was not that the service provider did not want to provide the information that would be of use to UK law enforcement but that domestic law in America did not allow it to provide that information, and that in the overwhelming majority of cases to which this legislation would apply we anticipate that the service provider would be more than keen to provide the data, provided it can be done lawfully, and that this mechanism provides the lawful means of doing that?

Baroness Williams of Trafford Portrait Baroness Williams of Trafford
- Hansard - - - Excerpts

I think the noble Lord is probably quite right. It goes back to what I was saying at the beginning of my response. If there were doubts about compliance, or that began to become apparent, MLA would be the process that we would revert to if this was not forthcoming. Ditto, the American side would probably institute the MLA process to ensure compliance.

--- Later in debate ---
Moved by
39: After Clause 16, insert the following new Clause—
“Priority
In the event of any conflict between this Act and the Data Protection Act 2018 (“the DPA”) or the General Data Protection Regulation 2018 (“the GDPR”), the provisions of the DPA or the GDPR shall prevail.”
Lord Paddick Portrait Lord Paddick
- Hansard - -

My Lords, Amendment 39 is in my name and that of my noble friend Lady Hamwee. I am grateful for the briefing from techUK, which raises concerns about how this legislation might affect a deal between the EU and the UK on adequacy should the UK leave the European Union. We are unsure how to address those concerns and this amendment is very unlikely to be the means by which to do so, but at this stage it is a means of raising them. It is a bit of a Second Reading amendment, if noble Lords get my drift.

Throughout our debates it has been emphasised that the sole purpose of this legislation is to enable UK law enforcement agencies to find a faster legal means to secure data held overseas that may contain vital evidence in serious criminal cases being prosecuted in the UK than the current mutual legal assistance treaty process. Data handled in the UK is subject to the protections of the Data Protection Act 2018 and the EU general data protection regulations. Indeed, the Data Protection Act ensures that the GDPR continues to have effect, even if the UK does leave the EU.

Throughout our debates on this legislation we have expressed our concerns that the designated international co-operation arrangements that enable overseas production orders to have effect in the target state will give as much right to overseas law enforcement agencies to demand data from UK service providers as the right this legislation will give UK law enforcement agencies to demand data from a service provider in a foreign state. Those foreign states, such as the United States of America, are not bound by the Data Protection Act or the GDPR.

For a third country to exchange data with the EU it must persuade the EU that it has adequate protections for personal data equivalent to or exceeding the standards that EU countries have to comply with under the GDPR. Indeed, EU states are not bound by EU regulation relating to data used for national security purposes, but third-party states are. For the first time, if we leave the EU, the EU will scrutinise the way we handle data in relation to national security because we will become a third-party country, involving more scrutiny than currently takes place. I think that is called “taking back control”. Whether in relation to national security or not—we have already debated the weaker safeguards proposed in relation to terrorism offences—such arrangements could result in personal data from an EU country and shared with a UK service provider being passed to a law enforcement agency in a state that falls short of the protections provided by the GDPR.

In summary, our concern is that, by entering into international co-operation agreements enabling overseas law enforcement agencies directly to access personal data held in the UK by UK service providers, sensitive personal data will be accessed by overseas law enforcement agencies whose standards fall below those set out in the Data Protection Act and the GDPR, thereby jeopardising the EU granting the UK an adequacy certificate. Could the Minister explain what discussions have taken place with the EU on this issue and how the UK’s adequacy status will be protected? I beg to move.

Lord Kennedy of Southwark Portrait Lord Kennedy of Southwark
- Hansard - - - Excerpts

My Lords, I fully support the amendment moved by the noble Lord. I recall our debates in the Chamber on the GDPR and how important it is to get the adequacy certificate to make sure that we are compliant with all these regulations, and we cannot put that at risk in subsequent legislation. I am looking for the Minister to address that point. The noble Lord has raised a very valid point. We need to get this right before this legislation reaches the statute book.

--- Later in debate ---
Baroness Hamwee Portrait Baroness Hamwee
- Hansard - - - Excerpts

My Lords, as the Minister is responding, it seems that this falls into a similar category to a point we raised last week about how one balances the different public interests involved. I think the Minister is saying that there is a public interest in the application of the Data Protection Act and the GDPR, which takes us back to the clause about assessing public interest. The Minister is nodding at that. Perhaps, before Report, we should go back and look at how that might apply in this context as well.

Lord Paddick Portrait Lord Paddick
- Hansard - -

My Lords, I am grateful to the Minister, and to other noble Lords, for their contributions. In essence, my question is: if the EU has to assess whether we are safeguarding its data, yet we are entering into agreements to give away that data to another country, will the EU need to be satisfied that that other country also has standards of data protection equivalent to or better than the GDPR? If not, we might be putting the adequacy judgments at risk. That is the essence of the amendment. I would be grateful for an opportunity to discuss this further with the Minister in the meetings between now and Report but, at this stage, I beg leave to withdraw the amendment.

Amendment 39 withdrawn.