FOR PREVIEWING & TESTING PURPOSES ONLY.
This notification will disappear once the page will be published.
This link is available for less than 30 minutes.
  • Easy to read
  • Text size

You have a complaint against an EU institution or body?

Current language: 
  • English
Available languages: 

Decision on how the European Commission dealt with a request for public access to documents concerning surveillance and security systems and equipment at migrant centres in Greece (case 507/2023/PVV)

The case concerned a request for public access to documents held by the European Commission concerning surveillance and security systems and equipment at migrant centres in Greece. The Commission identified eighteen documents as falling within the scope of the request and, after consulting the Greek authorities, denied access to all of them. In doing so, it invoked exceptions under the EU legislation on public access to documents, arguing that disclosure could undermine the public interest as regards public security and the commercial interests of a contractor. The complainant asked the Commission to review its decision (by making a 'confirmatory application').

As the Commission failed to reply within the applicable time limits, and incurred a considerable delay, the complainant turned to the Ombudsman.

The Ombudsman opened an inquiry and her inquiry team inspected the documents in question. She took the view that the Commission should grant wide access to the documents, in light of the suggestions made in the context of an earlier inquiry into how the Commission ensures respect for fundamental rights in EU-funded migration management facilities in Greece and given that some of the documents appeared to be public or to contain information that is public. The Ombudsman therefore made a proposal for a solution to the Commission, asking it to reconsider its position with a view to granting the widest possible access to the documents.

In reply, the Commission agreed to grant wide access to the documents at issue.

The Ombudsman welcomed the Commission’s positive response to her solution proposal. Whilst she considered that this resolved the complaint, she noted the significant delay incurred by the Commission in this case of public interest. She thus closed the case, reminding the Commission that it should urgently address the major issue of delays in its processing of requests for public access to documents.

Background to the complaint

1. Multi-Purpose Reception and Identification Centres (MPRICs) are migrant reception centres set up on the Greek islands. The MPRICs are EU-funded and deal with the identification, first reception and pre-removal detention of asylum seekers. The European Commission is tasked with ensuring that Greece uses the EU funds covering the MPRICs in compliance with EU law.[1] That includes the surveillance and security systems and equipment that are used in the MPRICs. Such surveillance and security technologies are supported through the Internal Security Fund[2] and the Recovery and Resilience Facility[3].

2. The complainant, a journalist, referred to criticism of the surveillance and security systems and equipment at issue by various organisations and experts. In addition, the Greek Data Protection Authority opened an own-initiative investigation into these systems in 2022. In April 2024, the Greek Data Protection Authority concluded its investigation and imposed a large administrative fine on the Greek Ministry of Migration and Asylum “for the breaches found in relation to the cooperation with the Authority and the impact assessments”.[4] It also ordered the Ministry[5] to ensure compliance with the EU General Data Protection Regulation (GDPR)[6].  

3. The complainant submitted three access to documents requests to the Commission in this context.[7] The second request - covered by this inquiry  - was submitted in August 2022 and concerned the ‘Centaur’[8] security system and other surveillance and security systems and equipment at migrant centres in Greece in particular (GESTDEM 2022/4534).

4. In October 2022, the Commission sent the complainant its initial reply. The Commission identified eighteen documents as falling within the scope of the request and denied access to all of them in their entirety. The documents identified at initial stage were correspondence, documents, inquiries, contracts and documentation related to the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA) of the IT systems established by the Greek authorities in the MPRICs.

5. The complainant asked the Commission to review its decision (by making a ‘confirmatory application’) on 31 October 2022. Due to a clerical error, the complainant’s confirmatory application was not registered until 23 November 2022. The Commission extended the deadline for its reply to 13 January 2023. Following several reminders from the complainant, the Commission informed the complainant on 16 February 2023 that it could not commit to a specific date for a final decision.

6. Dissatisfied with how the Commission handled their request, the complainant turned to the Ombudsman on 23 February 2023.

The inquiry

7. The Ombudsman opened an inquiry into how the Commission handled the complainant’s request for public access.

8. Although the inquiry initially focused on securing a final decision on the complainant’s access request, the Ombudsman inquiry team inspected the eighteen documents identified at initial stage in light of the persisting delay. Following a review of the documents, the Ombudsman made a proposal for a solution that the Commission grant the widest possible access to the documents at issue.

9. The Commission replied, after a very significant delay, to the complainant’s confirmatory application and, a few months later, to the Ombudsman’s proposal for a solution. The complainant informed the Ombudsman inquiry team that they are satisfied with the access granted.

The Ombudsman's proposal for a solution

10. As the documents at issue originate from a Member State, the Commission referred, in its initial reply, to its consultations of the competent national authorities in accordance with Article 4(4) and (5) of Regulation 1049/2001.[9] The Greek Ministry of Migration and Asylum, as the originator of the documents, objected to the documents’ disclosure based on the protection of the public interest as regards public security (Article 4(1)(a), first indent of Regulation 1049/2001) and the protection of the commercial interests of the beneficiary of the contract for the “Centaur” project (Article 4(2), first indent of Regulation 1049/2001).

11. In her proposal for a solution of November 2023[10], the Ombudsman stressed that although an institution is not required to carry out an exhaustive assessment of a Member State’s decision to object to disclosure, it must check whether the explanations given by the Member State appear to it, prima facie, well founded.[11] Based on her inquiry team’s inspection of the eighteen documents concerned and the documentation pertaining to the consultation of the Greek authorities, the Ombudsman was not convinced that the Greek authorities had given proper reasons to object to the disclosure of the documents in order to protect public security and commercial interests.

12. For the documents related to the Data Protection Impact Assessments (DPIAs) and the Fundamental Rights Impact Assessment (FRIA), the Ombudsman reminded the Commission of the findings in her inquiry OI/3/2022/MHZ into how the Commission ensures respect for fundamental rights in EU-funded migration management facilities in Greece. Granting access to these documents would be in line with the Ombudsman’s view on proactive transparency regarding surveillance and security systems in the MPRICs, and with the Commission’s commitment to suggest to the Greek authorities to embrace such transparency in reply to the Ombudsman’s suggestion for improvement in the context of OI/3/2022/MHZ. Moreover, the Ombudsman noted that the review of these documents showed that they contain information that appears generic in nature and the ‘specific and actual risk’ for the protection of the public interest as regards public security was thus not readily clear.

13.  For the other documents identified, the Ombudsman pointed out that they appear to be public or appear to contain information that is public. For instance, one of those documents provides an overview of Greek, European and international legislation on data protection and the use of video surveillance systems. Other documents appear to be addressed to migrants arriving or residing in the MPRICs, and the requested ‘Data Protection Officer Contract’ is available on the Greek public procurement contracts repository.

14. The Ombudsman therefore proposed that the Commission reconsider its decision on this public access request, with a view to disclosing the documents concerned to the widest extent possible.

15. Following the Ombudsman’s solution proposal, the Commission replied to the complainant’s confirmatory application in February 2024. The Commission granted wide access to all eighteen documents identified at initial stage, with redactions of personal data only. In addition, it identified two further documents (email threads) as falling within the scope of the complainant’s access request. The latter two documents were partially disclosed, relying on the need to protect personal data and the public interest as regards public security.

16. In May 2024, the Commission replied to the Ombudsman’s proposal for a solution.[12] It explained that the delay in replying to the complainant’s access request was due to “the need to assess additionally identified documents and to consult the Member State on the disclosure of the documents originating from that Member State”. More specifically, “following several exchanges”, the Greek authorities agreed (explicitly for most and tacitly for two documents) to disclosure of the documents identified at initial stage. As for the email exchanges identified at confirmatory stage, the Commission and the Greek authorities considered that some redactions were needed to protect the public interest as regards public security given that the documents contain information concerning “the development and progress of the Hyperion project and the functionalities as well as equipment installation locations in relation to Centaur project”.  

17. Finally, the Commission indicated that it granted access to all documents related to the DPIAs and the FRIA, for which the Commission had suggested their publication to the Greek authorities following the Ombudsman’s inquiry OI/3/2022/MHZ. 

18. The complainant informed the Ombudsman inquiry team that they are satisfied with the access now granted.  

The Ombudsman's assessment after the proposal for a solution

19. The Ombudsman welcomes the Commission’s positive response to her solution proposal and the wide access the Commission has now given to the documents at issue.

20. Given that the complainant did not put forward any reasons as to why they would need access to the personal data, the Commission’s decision to redact these data is justified. In addition, the complainant did not take issue with the redactions for the protection of the public interest as regards public security in the email exchanges identified at confirmatory stage. Consequently, the Ombudsman considers that the Commission’s confirmatory decision and its reply to her proposal for a solution have resolved the complaint.

21. That said, the Ombudsman notes the egregious delay incurred by the Commission in this case. According to Regulation 1049/2001, an EU institution should, within 15 working days from registration of the confirmatory application, either grant access to the document requested or, in a written reply, state the reasons for the total or partial refusal. The time limit of 15 working days may be extended by a further 15 working days in exceptional circumstances.[13]

22. In this case, the Commission took over a year to take a decision on the complainant’s confirmatory application, while the initial access request dates back to August 2022. In its reply to the Ombudsman’s proposal for a solution, the Commission referred to its dialogue with the Greek authorities in this regard. Although the Ombudsman appreciates that a dialogue with a Member State makes it less likely that the Commission has to overrule a Member State’s opposition to disclosure, such a dialogue must be conducted whilst respecting the applicable time limits.[14]

23. This case is thus another example of the significant and systemic delays the Commission encounters in dealing with confirmatory applications, which the Ombudsman considered to amount to maladministration[15]. Following a Special Report of the Ombudsman to the European Parliament on the matter, the European Parliament urged the Commission to correct its systematic and significant delays in processing requests for public access to documents.[16]

24. The Commission’s delay in replying to the complainant’s public access request in this case is particularly regrettable in light of the significant public interest attached to ensuring respect for fundamental rights in migrant reception centres. Given that the Commission is responsible for ensuring that surveillance technologies that receive EU funding comply with the applicable rules, timely transparency on the relevant impact assessments was warranted and the Ombudsman already called for their publication in June 2023[17]. Concerns of the Greek Data Protection Authority and civil society only heightened this need for transparency. Indeed, in April 2024, the Greek Data Protection Authority considered the DPIA’s to be “substantially incomplete and limited in scope”.[18]

25. The Ombudsman thus profoundly regrets the delay incurred by the Commission in replying to the complainant’s request.

Conclusions

Based on the inquiry, the Ombudsman closes this case with the following conclusions:

The Commission has accepted the Ombudsman’s proposal for a solution and provided the complainant with wide access to the requested documents.

The Ombudsman profoundly regrets the delay incurred by the Commission in replying to the complainant’s request. She insists that failure to comply with the time limits established by the legislature in Regulation 1049/2001 cannot be good administration. She again urges the Commission to improve its handling of public access requests as a matter of priority, and refers it to the recommendation in her strategic inquiry OI/2/2022/OAM.

The complainant and the European Commission will be informed of this decision.

 

Emily O'Reilly
European Ombudsman


Strasbourg, 02/08/2024

 

[1] In 2022, the Ombudsman opened an own-initiative inquiry (OI/3/2022/MHZ) on how the European Commission ensures respect for fundamental rights in these new EU-funded migration management facilities in Greece. The Ombudsman made suggestions to address a number of issues identified. Information on the inquiry can be found at: https://www.ombudsman.europa.eu/en/case/en/62000.

[2] More information: https://home-affairs.ec.europa.eu/funding/borders-and-visa-funds/internal-security-fund-borders-and-visa-2014-2020_en and https://home-affairs.ec.europa.eu/funding/internal-security-funds/internal-security-fund-2021-2027_en.

[3] More information: https://commission.europa.eu/business-economy-euro/economic-recovery/recovery-and-resilience-facility_en. See also the Commission’s reply to a Parliamentary question on this topic: https://www.europarl.europa.eu/doceo/document/E-9-2022-003094-ASW_EN.html#ref2.  

[4] See: https://www.dpa.gr/en/enimerwtiko/press-releases/ministry-migration-and-asylum-receives-administrative-fine-and-gdpr.

[5] Ibid.

[6] Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data: https://eur-lex.europa.eu/eli/reg/2016/679/oj.

[7] GESTDEM 2022/4531 - complaint 380/2023/PVV with the Ombudsman; GESTDEM 2022/4534 - complaint 507/2023/PVV with the Ombudsman and GESTDEM 2022/4621 - complaint 508/2023/PVV with the Ombudsman. Available at: https://www.ombudsman.europa.eu/en/opening-summary/en/167614.

[8] A digital management system for electronic and physical security around and within the facilities, using cameras and motion analysis algorithms (Artificial Intelligence Behavioural Analytics), more information: https://digitalstrategy.gov.gr/project/kentayros.

[9] Regulation 1049/2001 regarding public access to European Parliament, Council and Commission documents: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32001R1049.

[10] The full text of the Ombudsman’s proposal for a solution is available at: https://www.ombudsman.europa.eu/solution/189092.

[11] Judgments of 5 April 2017, France v Commission, T-344/15, paragraph 54 (https://curia.europa.eu/juris/document/document.jsf?text=&docid=189616&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=376000) and of 8 February 2018, POA v Commission, T-74/16, paragraph 57 (https://curia.europa.eu/juris/document/document.jsf?text=&docid=199205&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=5365996).

[12] The Commission’s reply is available at: https://www.ombudsman.europa.eu/doc/correspondence/189093.

[13] Article 8 of Regulation 1049/2001.

[14] See points 41-44 of the Ombudsman’s Recommendation on the time the European Commission takes to deal with requests for public access to documents (strategic inquiry OI/2/2022/OAM), available at: https://www.ombudsman.europa.eu/en/recommendation/en/167661.

[15] Recommendation on the time the European Commission takes to deal with requests for public access to documents (strategic inquiry OI/2/2022/OAM).

[16] See https://www.europarl.europa.eu/doceo/document/TA-9-2024-0172_EN.html.

[17] In the context of her own-initiative inquiry (OI/3/2022/MHZ) on how the European Commission ensures respect for fundamental rights in these new EU-funded migration management facilities in Greece.

[18] See: https://www.dpa.gr/en/enimerwtiko/press-releases/ministry-migration-and-asylum-receives-administrative-fine-and-gdpr.