FOR PREVIEWING & TESTING PURPOSES ONLY.
This notification will disappear once the page will be published.
This link is available for less than 30 minutes.
  • Easy to read
  • Text size

You have a complaint against an EU institution or body?

Current language: 
  • English
Available languages: 

Decision on how the European Border and Coast Guard Agency (Frontex) dealt with a request for public access to documents concerning social media monitoring related to migration routes (case 344/2023/PVV)

The complainant asked the European Border and Coast Guard Agency (Frontex) to grant public access to documents concerning social media monitoring related to migration routes, including documents concerning potential cooperation between Frontex and the EU Agency for Law Enforcement Cooperation (Europol).

Frontex identified 55 documents as falling under the scope of the request. It granted access to parts of 32 of the documents and refused access to 23 documents. In doing so, Frontex argued that full or wider disclosure would undermine the protection of the public interest as regards public security and international relations, the protection of legal advice, the purpose of an ongoing investigation and an ongoing decision-making process. It also stated that it would constitute a disproportionate administrative burden to review and apply redactions to disclose parts of the documents, and that partial disclosure would be meaningless.

Based on the inspection of the documents, the Ombudsman considered that Frontex did not demonstrate why the exceptions it invoked should apply and why the documents should not be disclosed, at least partially. She also did not find that reviewing and redacting parts of the documents would pose a disproportionate administrative burden or that redactions would make the documents meaningless.

As such the Ombudsman proposed as a solution that Frontex review its position on the request with a view to granting wider partial access to the documents concerned. In doing so, Frontex should take account of the time that has passed since it adopted its confirmatory decision. She also proposed that, when reviewing its position, Frontex should provide a list of documents it identified as falling within the scope of the complainant’s request, unless disclosing such a list would undermine the interest(s) Frontex claims should be protected in this case.

In reply to the Ombudsman’s proposal for a solution, Frontex granted wider partial access to the documents at issue and agreed to share a list of documents with the complainant. The Ombudsman welcomed the wider partial access that Frontex has now granted to the documents. While she identified a number of shortcomings in how Frontex had handled the matter, also by way of reply to her solution proposal, overall she considered that her solution has been partially accepted and closed the case. She stressed the importance for the future of providing sufficient reasoning for withholding access, mainly as regards the exception for the protection of an ongoing decision-making process.

 

Background to the complaint

1. In 2017, the European Union Agency for Asylum (EUAA)[1] started conducting social media monitoring (SMM). The purpose of these SMM activities was to draft reports on shifts in migration routes, offers made by smugglers and discourse on social media regarding key related issues such as the EU’s asylum system.[2] In 2018, the European Data Protection Supervisor (EDPS) was formally consulted on these social media monitoring reports. The EDPS noted that SMM amounts to processing of personal data that can undermine individuals’ ability to exercise control over their personal data and thus requires strong safeguards.[3] The EDPS concluded that the EUAA’s mandate did not include an explicit legal basis for such processing activities and imposed a temporary ban on the EUAA’s SMM activities in 2019.

2. Following this ban, in 2020, the European Commission consulted the EDPS on the possibility that the European Border and Coast Guard Agency (Frontex) could develop a SMM capacity in accordance with its extended mandate.[4] It was suggested that Frontex would add SMM to its existing surveillance tools and establish a link with the European Union Agency for Law Enforcement Cooperation (Europol) which coordinates criminal investigations. Europol’s ‘EU Internet Referral Unit’ (EU IRU) has been investigating malicious content on the internet and in social media since 2015.[5] In 2019, Frontex and Europol also signed a Joint Action Plan[6] providing for a structured exchange of information between the two agencies.

3. In 2021, in its Communication on ‘a renewed EU action plan against migrant smuggling (2021-2025)’[7], the Commission noted that SMM is “necessary for the continuous development of a clear, real time picture of migrant smuggling dynamics”. It allows for the collection and analysis of information from social media on the activities of criminal networks and general developments in partner countries. [8] The Commission considered that “Frontex should deploy its monitoring capabilities in social media to improve risk analysis regarding future irregular migratory movements whilst taking into account data protection considerations”.[9] The Commission further considered that Europol’s IRU should provide support in disrupting these migrant smuggling networks.[10]

4. Frontex, like all European institutions, bodies, offices and agencies, has to comply with the EU rules on the processing of personal data.[11] To this end, Frontex adopted in December 2021 two Management Board (MB) Decisions (68/2021[12] and 69/2021[13]) on processing personal data. In June 2022, the EDPS, in its supervisory capacity, issued two negative opinions concerning these two MB Decisions.[14] It considered that these MB Decisions had several shortcomings, in particular concerning the legal basis for processing special categories of personal data.[15] The EDPS recalled that any activity by Frontex in relation to the “prevention, detection and investigation of criminal offences is [...] secondary and should be carried out primarily as a form of support to Europol, Eurojust and Member States’ competent authorities”.[16] In October 2022, the EDPS also conducted a data protection audit of Frontex.[17] To implement the EDPS’s findings in its opinions and audit, Frontex started redrafting MB Decisions 68/2021 and 69/2021 and in the meantime suspended the related SMM project.

5. In September 2022, the complainant asked for public access to documents[18] concerning SMM for the period from 1 January 2021 to 27 September 2022. In particular, the complainant requested access to (i) meeting minutes and correspondence between Frontex and Europol, and (ii) Frontex’s internal documents concerning SMM. In its initial reply, Frontex identified five documents concerning the first aspect of the complainant’s request but stated that it did not hold any documents concerning the second aspect. It refused access to the five documents it identified in their entirety, arguing that their disclosure would undermine the protection of the public interest as regards international relations[19] and public security[20], and would seriously undermine an ongoing decision-making process[21].

6. The complainant asked Frontex to review its decision (by making a ‘confirmatory application’), arguing that Frontex’s reliance on the exceptions set out in Article 4 of the EU legislation on access to documents (Regulation 1049/2001) was excessive, disproportionate and contrary to the spirit and the letter of the regulation and the applicable case-law. The complainant considered that Frontex failed to disclose even basic information about the documents. The complainant did not object to the redaction of personal data. However, the complainant deemed it “highly improbable” that there were no internal documents falling within the scope of the second element of the request and asked Frontex to conduct another search.

7. In its confirmatory decision, Frontex identified 50 additional documents as falling within the scope of the complainant’s request. It granted partial access to 32 of these documents and refused access to the remaining 23 documents (including the five documents it had identified at the initial stage) in their entirety. In doing so, Frontex argued that full or wider disclosure would undermine the protection of the public interest as regards public security and international relations, the protection of legal advice[22], the purpose of an ongoing investigation[23] and an ongoing decision-making process.

8. Dissatisfied with how Frontex handled their request, the complainant turned to the Ombudsman on 17 February 2023.

The inquiry

9. The Ombudsman opened an inquiry into how Frontex handled the complainant’s request for public access to documents.

10. In the course of the inquiry, the Ombudsman inquiry team inspected the documents at issue and reviewed the additional views[24] that Frontex had provided. The Ombudsman inquiry team also met with the relevant representatives of Frontex with a view to obtaining clarifications on how Frontex had handled the complainant’s public access request. The Ombudsman then shared with the complainant Frontex’s additional views, the report on the meeting[25] and Frontex’s written reply[26] to the questions the Ombudsman had set out in her meeting request. The complainant provided comments.

11. Based on the information provided by the complainant and Frontex throughout the inquiry, the Ombudsman made a proposal for a solution[27] as set out below.  

12. In reply to the Ombudsman’s proposal for a solution[28], Frontex granted wider partial access to the documents concerned[29]. It gave partial access to 18 out of 23 previously non-disclosed documents and wider access to seven out of 32[30] already partially disclosed documents. In addition, it provided the complainant with a list of documents identified. The Ombudsman also received the complainant’s comments on the Ombudsman’s proposal for a solution and Frontex’s reply.  

The Ombudsman's assessment after the proposal for a solution

The application of the exceptions under Regulation 1049/2001

Public security and international relations (Article 4(1)(a) Regulation 1049/2001)

13. Frontex enjoys a wide margin of discretion when determining whether disclosing a document would undermine the protection of the public interest as regards public security and international relations. However, it is still required to demonstrate a ‘specific and actual risk’ that is reasonably foreseeable and not purely hypothetical.[31] Leaving aside Frontex’s justified application of the public security exception in relation to four documents (security alerts)[32], the Ombudsman noted in her proposal for a solution that the inspection of the documents at issue in this case showed that some of the information contained therein is of a general nature and in some cases already publicly available[33]. It was thus not readily clear how disclosure of parts of some of the documents could actually and specifically undermine that protected interest.

14. Following the Ombudsman’s solution proposal, Frontex granted further partial access to some of the documents, including the SMM concept note[34], for which it had invoked the public security exception. While the Ombudsman regrets that Frontex did not disclose these parts of the documents at issue in a more timely way, she welcomes Frontex’s engagement with her proposal for a solution and considers that there is no manifest error in Frontex’s application of the exception for the remaining redactions.

15. In her proposal for a solution, the Ombudsman also noted that Frontex applied the exception for the protection of the public interest as regards international relations too broadly. Following the Ombudsman’s solution proposal, Frontex reconsidered the application of this exception and it no longer relies on it to justify the remaining redactions.

16. The Ombudsman thus welcomes Frontex’s positive response to her solution proposal in relation to the application of the public security and international relations exceptions.

Decision-making process (Article 4(3) Regulation 1049/2001)

17. In her proposal for a solution, the Ombudsman stressed that to refuse public access, Frontex has to show that disclosure would seriously undermine its decision-making process. The mere fact that the decision-making is still ongoing[35], or the fact that the deliberations are of a preliminary nature[36] are not sufficient. Rather, Frontex must show, with tangible elements, that access is likely to concretely and effectively bring serious harm to the decision-making process in a reasonably foreseeable and non-hypothetical way.[37]

18. Frontex argued that the decision-making process at issue (namely, the redrafting of the two MB Decisions and the SMM project) was very sensitive and that it was the subject of intense media interest and attempts to unduly influence the procedure. Notwithstanding these arguments, the Ombudsman had taken the view that Frontex did not put forward tangible elements that would show that disclosure of the requested documents or parts thereof[38] would seriously undermine its decision-making process in relation to either the SMM project, or the redrafting of the MB Decisions.  

19. When reviewing its position in reply to the Ombudsman’s proposal for a solution, Frontex granted wider access to some of the documents, such as the SMM concept note, that it considered to be covered by the exception for the protection of its decision-making process at the confirmatory stage. In doing so, Frontex took into account the changed circumstances and the fact that it has, in the meantime, redrafted and adopted the two MB Decisions.[39]

20. Frontex however continues to rely on this exception for some of the remaining redactions. In its reply to the Ombudsman’s proposal for a solution, the agency indicates that “the SMM project’s preparatory work is currently pending, with certain sections of the documents at issue containing nascent proposals prepared by the leading business units, which have not been fully consulted and endorsed by all relevant Frontex entities and the executive management”. In light of “the relevance of these activities not least for criminal networks”, Frontex argues that “divulging these limited sections would deprive Frontex of its space to think and jeopardize the ongoing negotiations taking place between Frontex, the European Commission and other Justice and Home Affairs agencies”.

21. In their final comments, the complainant takes issue with Frontex’s continued application of the exception for its internal decision-making process. In particular, the complainant criticises Frontex’s refusal to grant public access “to crucial details as regards the scope of its planned SMM activities” by, for instance, heavily redacting the SMM concept note. Frontex would have presented the planned SMM project as “an almost innocuous information-gathering activity” whilst it appears, from the further disclosed documents “that the intention was to go much farther”. According to the complainant, “it is highly likely that at least some of these activities will form an integral part of the Agency’s SMM programme in the future”. Frontex however “effectively arrogates to itself the right to develop and enact its SMM programme with minimal public scrutiny”.

22. The Ombudsman maintains her view that Frontex has applied the decision-making protection exception under Regulation 1049/2001 too broadly. More specifically, as required by EU case-law[40] and stressed by the Ombudsman in a recent inquiry[41], targeted external pressure may constitute a legitimate ground for restricting access to documents relating to an ongoing decision-making process only where the reality of such external pressure can be established with certainty. Evidence must also be adduced to show that there was a reasonably foreseeable risk that that process would be substantially affected owing to that external pressure[42]. The Ombudsman remains unconvinced that Frontex’s general references to its space to think and its ongoing negotiations with the Commission and other agencies constitute such evidence. In addition, the Ombudsman repeats that the fact that deliberations are of a preliminary nature does not suffice to invoke the exception.

23. The Ombudsman’s inquiry has, however, resulted in the public availability of significantly more information on Frontex’s envisaged SMM activities.

24. Moreover, the Ombudsman’s review of the SMM concept note and Frontex’s explanations during the inquiry have shown that part of the remaining redactions in this note comes within the scope of the exception for the protection of the public interest as regards public security[43]. Indeed, Frontex’s reference to “the relevance of these activities not least for criminal networks” would seem rather to concern the protection of the public interest as regards public security than Frontex’s internal decision-making process.

25. Overall, as already stated, the Ombudsman welcomes Frontex’s further disclosure of the documents at issue. For the future, the Ombudsman invites Frontex to ensure it provides sufficient reasoning if it deems it necessary to withhold access based on this exception.

Purpose of investigations (Article 4(2), third indent, Regulation 1049/2001)

26. In her proposal for a solution, the Ombudsman noted that the documents at issue were not themselves subject to the EDPS’s supervisory opinions or audit and that it was therefore not readily clear how their disclosure[44] would have undermined the purpose of the EDPS’s investigations. More specifically, the Ombudsman considered that Frontex had not put forward convincing arguments that disclosure, at the time of the confirmatory decision, would have endangered the EDPS’s supervisory opinions or audit.

27. In reply to the Ombudsman’s proposal for a solution, Frontex took into account that it has, in the meantime, redrafted and adopted the two MB Decisions and it no longer relies on this exception. Whilst the Ombudsman regrets that Frontex did not disclose the relevant parts of the documents at the time of its confirmatory decision, she welcomes that Frontex no longer invokes this exception.

Legal advice (Article 4(2), second indent, Regulation 1049/2001)

28. Frontex refused to grant access to (parts of) two documents[45] because their disclosure would undermine the protection of legal advice. One of the two documents in question contains two answers, a long version and a short version, to a written question from a Member of the European Parliament. In her proposal for a solution, the Ombudsman noted that the short version was already publicly available and that there are only minimal additions in the long version that are not already public. Concerning the second document for which Frontex invoked this exception, the one sentence in question is a factual statement. The Ombudsman therefore concluded that it was not readily clear how disclosure would undermine Frontex’s interest in seeking and receiving frank, objective and comprehensive legal advice.

29. Following the Ombudsman’s proposal for a solution, Frontex granted full access to the answers prepared for the Member of the European Parliament and no longer relies on the exception for the protection of legal advice in relation to the other document.

Overriding public interest

30. As regards the possible existence of an overriding public interest, the Ombudsman emphasised, in her proposal for a solution, that concerns as to whether an EU body complies with EU law, as invoked by the complainant in their confirmatory application, are not a purely private concern but a public one. Furthermore, the Ombudsman was not convinced that the information contained in the documents at issue continued to be so sensitive that the interest in its protection would outweigh the specific public interest put forward by the complainant. On the contrary, the level of public scrutiny, in addition to the EDPS’s concerns in relation to the lawfulness of Frontex’s personal data processing activities, shows the importance of transparency on the topic of SMM by Frontex.[46] This is particularly the case given that the concerns relate to the protection of personal data, which is a fundamental right.[47]

31. In its reply to the Ombudsman’s proposal for a solution, Frontex maintains its view that “the general assertions made by the complainant cannot provide an appropriate basis for establishing that the principle of transparency is especially pressing and capable of prevailing over the reasons justifying the refusal to disclose the remaining elements in question”.

32. The complainant, in their final comments, notes that it is “highly concerning” that Frontex continues to reject the existence of an overriding public interest in disclosure. Frontex would be “arrogating to itself a mantle of secrecy more akin to a national security or intelligence agency, rather than a civilian border management agency, with only auxiliary law enforcement functions as stipulated by its legal mandate”.

33. The Ombudsman regrets that Frontex did not take into account her views as regards the existence of an overriding public interest and emphasises the need to ensure transparency on compliance with fundamental rights.  

Procedural issues

Partial access

34. In its confirmatory decision, Frontex considered that the administrative burden of redacting the parts that may not be disclosed was particularly heavy and that disclosure of highly fragmented parts of the requested documents would not be in line with the principle of partial access.

35. The Ombudsman’s proposal for a solution set out that, according to EU case-law, EU institutions and agencies can, in exceptional cases, refuse to grant partial access if the administrative burden of blanking out the parts covered by the exceptions would be excessive[48] or if the remaining parts of the documents would be meaningless[49]. Where an institution seeks to rely on a claim of proportionality to limit the exercise of a fundamental right[50], this must be clearly demonstrated. In terms of meaningful partial access, EU case-law also clarifies that it is not for the institution or agency to determine what is or is not useful for the applicant.[51] Given that the inspection of the documents had shown that the majority are not covered in their entirety by one (or more) of the exceptions set out under Article 4 of Regulation 1049/2001, the Ombudsman considered that partial access is possible and that Frontex had not substantiated why this case is exceptional.

36. In its reply to the Ombudsman’s proposal for a solution, Frontex referred to the “inappropriate administrative burden” as regards the five documents which were not further disclosed[52]. The Ombudsman’s review of these documents has shown that these documents are indeed (almost) fully covered by the exception for the protection of the public interest as regards public security. Consequently, Frontex was justified in holding that redacting the sensitive information in these five documents would have made them largely unintelligible. The Ombudsman therefore considers that Frontex’s reply to her proposal for a solution has resolved the complaint in relation to this aspect of the inquiry.

List of documents

37. In line with her recommendation in case 1129/2023/OAM[53], the Ombudsman also proposed that, when reviewing its position, Frontex should provide a list of documents it identified as falling within the scope of the complainant’s request, unless the very disclosure of the list undermines the interest(s) to be protected in this case.

38. In reply to the Ombudsman’s proposal for a solution, Frontex agreed to share a list of documents with the complainant. For the identified security alerts, Frontex removed the sensitive operational information from the title of these documents, to protect the public interest as regards public security. The Ombudsman therefore commends Frontex for its positive response and trusts that Frontex continues this practice as a matter of good administration.

Identification of additional documents

39. The complainant was concerned that Frontex identified only five documents at the initial stage and identified 50 more at the confirmatory stage.

40. During the meeting with the Ombudsman inquiry team, Frontex said that it was very rare that additional documents are identified at the confirmatory stage. It considered, however, that this showed that Frontex conducted a renewed search and full review following the complainant’s confirmatory application. Frontex explained that the ownership of the SMM project had changed and that some of the documents were stored in the previous project manager’s individual email account, to which Frontex did not have access. This made the identification of documents more difficult. Frontex said that, at the confirmatory stage, more actors were involved in the identification of documents which led to the identification of the additional 50 documents from other units. Frontex stated that it has put in place a records management policy which ensures continuity by storing documents more centrally. It added that discussions are ongoing on how to ensure that all documents are identified. These discussions are centred mostly on archiving documents in a more transparent, central and structured way.

41. While the Ombudsman shares the complainant’s concern that 50 relevant documents were identified at the confirmatory stage only, she welcomes that Frontex did conduct a new thorough search at the confirmatory stage. She trusts that with Frontex’s ‘new’ records management policy there no longer will be such difficulties, due to staff changes, in identifying documents that fall within the scope of public access requests.

Conclusion

Based on the inquiry, the Ombudsman closes this case with the following conclusion:

The Ombudsman welcomes the wider partial access that Frontex has now granted to the documents at issue in this complaint. She considers that her solution has been partially accepted.

The complainant and Frontex will be informed of this decision.

Emily O'Reilly
European Ombudsman


Strasbourg, 18/09/2024

 

[1] At that time, the EUAA was called the European Asylum Support Office (EASO).

[2] See: https://edps.europa.eu/sites/default/files/publication/19-11-12_reply_easo_ssm_final_reply_en.pdf.

[3] Ibid.

[4] See: https://edps.europa.eu/system/files_en?file=2023-01/2022-0977_002_redacted.pdf.

[5] See: https://www.europol.europa.eu/about-europol/european-counter-terrorism-centre-ectc/eu-internet-referal-unit-eu-iru.

[6] Available at: https://prd.frontex.europa.eu/wp-content/themes/template/templates/cards/1/dialog.php?card-post-id=2722&document-post-id=9828; https://www.europarl.europa.eu/cmsdata/186840/1-Joint-Europol-Frontex-Action-Plan-2019-original.pdf.

[7] Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52021DC0591.

[8] Ibid.

[9] Ibid.

[10] Ibid.

[11] See Article 86 of Regulation 2019/1896 on the European Border and Coast Guard and repealing Regulations 1052/2013 and 2016/1624; available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019R1896.

[12] Available at: https://prd.frontex.europa.eu/document/management-board-decision-68-2021-adopting-the-rules-on-processing-personal-data-by-the-agency/.

[13] Available at: https://prd.frontex.europa.eu/document/management-board-decision-69-2021-adopting-the-rules-on-processing-operational-personal-data-by-the-agency/.

[14] Available at: https://edps.europa.eu/system/files/2022-06/2022-06-07-supervisory-opinion_on_the_rules_on_processing_personal_data_by_frontex_en.pdf; and at: https://edps.europa.eu/system/files/2022-06/2022-06-07-supervisory-opinion-on_the_rules_of_processing_operational_personal_data_by_frontex_en.pdf.

[15] See: Point 6 of https://edps.europa.eu/system/files/2022-06/2022-06-07-supervisory-opinion_on_the_rules_on_processing_personal_data_by_frontex_en.pdf.

[16] See hearing at the Committee on Civil Liberties, Justice and Home Affairs (LIBE) of 8 November 2022; available at: https://edps.europa.eu/system/files/2022-11/22-11-08_libe-frontex-pedra_en.pdf.

[17] Available at: https://edps.europa.eu/system/files/2023-05/edps_-_23-05-24_audit_report_frontex_executive_summary_en.pdf.

[18] Under Regulation 1049/2001 regarding public access to European Parliament, Council and Commission documents: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32001R1049.

[19] Article 4(1)(a), third indent Regulation 1049/2001.

[20] Article 4(1)(a), first indent Regulation 1049/2001.

[21] Article 4(3) Regulation 1049/2001.

[22] Article 4(2), second indent Regulation 1049/2001.

[23] Article 4(2), third indent Regulation 1049/2001.

[24] Available at: https://www.ombudsman.europa.eu/doc/correspondence/184405.

[25] Available at: https://www.ombudsman.europa.eu/doc/inspection-report/184407.

[26] Available at: https://www.ombudsman.europa.eu/doc/correspondence/184406.

[27] The full text of the Ombudsman’s proposal for a solution is available at: https://www.ombudsman.europa.eu/solution/190769.

[28] Frontex’s reply is available at: https://www.ombudsman.europa.eu/doc/correspondence/190770.

[29] The further disclosed documents are available here: https://prd.frontex.europa.eu/document/european-ombudsman-case-344-2023-pvv/.

[30] Frontex’s reply to the Ombudsman’s proposal for a solution mentions six out of 32. Following a clarification request of the Ombudsman’s Office, Frontex indicated that doc. 24 entitled ‘PAD RE Meeting on OSINT and social media monitoring in SAMD - confirmatory application - partially disclosed’ has also been disclosed further.

[31] Judgment of the General Court of 27 November 2019, Izuzquiza and Semsrott vs Frontex, T-31/18, paragraphs 65-66: https://curia.europa.eu/juris/liste.jsf?num=T-31/18.  

[32] See: documents 2, 3, 4 and 5 identified at the initial stage - not disclosed.

[33] Such as information on Europol’s IRU as published by Europol itself, in the consultation of the EDPS, and in the Commission’s Communication on a renewed EU action plan against migrant smuggling. See, for instance, document 1 identified at confirmatory stage - partially disclosed. This document has been fully disclosed (with out of scope redactions only) after the Ombudsman’s proposal for a solution.

[34] Documents 4 and 18 identified at confirmatory stage - not disclosed.

[35] Judgment of the Court of Justice of 13 July 2017, Saint-Gobain Glass Deutschland v Commission, C-60/15 P, paragraph 82: https://curia.europa.eu/juris/liste.jsf?num=C-60/15&language=EN

[36] Judgment of the General Court of 9 September 2014, MasterCard and Others v Commission, T-516/11, paragraph 67: https://curia.europa.eu/juris/liste.jsf?num=T-516/11&language=EN.

[37] Judgment of the General Court of 7 June 2011, Toland v Parliament, T-471/08, paragraphs 71 and 78: https://curia.europa.eu/juris/liste.jsf?language=en&num=T-471/08.

[38] By way of example, see: document 1 identified at the initial stage - not disclosed; documents 3, 16, 20, and 21 identified at the confirmatory stage - partially disclosed and documents 4, 5, 7, 11 and 18 identified at the confirmatory stage - not disclosed.

[39] Management Board Decision 4/2024 adopting the general rules on the application of the data protection regulation by the Agency, available at: https://prd.frontex.europa.eu/document/management-board-decision-4-2024-adopting-the-general-rules-on-the-application-of-the-data-protection-regulation-by-the-agency/ and Management Board Decision 5/2024 on adopting the rules on processing operational personal data by the Agency, available at: https://prd.frontex.europa.eu/document/management-board-decision-5-2024-on-adopting-the-rules-on-processing-operational-personal-data-by-the-agency/

[40] Judgment of the General Court of 20 September 2016, Pesticide Action Network Europe (PAN Europe) v European Commission, T-51/15, paragraph 30, available at: https://curia.europa.eu/juris/document/document.jsf;jsessionid=04D54E7FC38CA6E9E80970B8A7DD2BDA?text=&docid=183542&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=509387.

[41] See the Ombudsman decision in case 1885/2023/ACB, paragraph 43: https://www.ombudsman.europa.eu/en/decision/en/188984  .

[42] Judgment in case T‑51/15 cited above, paragraph 30 and case-law cited.

[43] Frontex invokes both the protection of the public interest as regards public security and the protection of its decision-making for the remaining redactions in the SMM concept note.

[44] By way of example, see: documents 2, 4, 5, 7, 8 and 18 identified at the confirmatory stage - not disclosed.

[45] Document 8 identified at the confirmatory stage - not disclosed and document 14 identified at the confirmatory stage - not disclosed.

[46] In ClientEarth and PAN Europe v EFSA, the Court of Justice held that the transfer of personal data was necessary to verify doubts about the impartiality of a group of experts. These doubts were not considered to be general and abstract as they were substantiated with a study conducted by an NGO. By analogy, such an overriding public interest a fortiori exists based on the EDPS’s concerns regarding the data protection compliance of Frontex. See: Judgment of the Court of 16 July 2015, ClientEarth and PAN Europe v EFSA, C‑615/13 P, paragraphs 57-60: https://curia.europa.eu/juris/liste.jsf?language=en&num=C-615/13%20P

[47] Judgment of the General Court of 4 May 2012, In’t Veld v Council, T-529/09, paragraphs 90-93: https://curia.europa.eu/juris/liste.jsf?num=T-529/09&language=EN.

[48] Judgment of the Court of First Instance of 7 February 2002, Kuijer v Council, T-211/00, paragraph 57: https://curia.europa.eu/juris/liste.jsf?language=en&num=T-211/00.

[49] Judgment of the General Court of 20 March 2014, Reagens v Commission, T-181/10, paragraphs 161, 162 and 172: https://curia.europa.eu/juris/liste.jsf?num=T-181/10&language=EN.

[50] Judgment of the Court of First Instance of 19 July 1999, Hautala v Council, T-14/98, paragraph 85: https://curia.europa.eu/juris/liste.jsf?language=en&num=T-14/98

[51] Judgment of the General Court of 6 December 2012, Evropaïki Dynamiki v Commission, T-167/10, paragraph 78: https://curia.europa.eu/juris/liste.jsf?num=T-167/10&language=EN; Judgment of the General Court of 5 December 2018, Falcon Technologies v Commission, T-875/16, paragraph 102: https://curia.europa.eu/juris/liste.jsf?num=T-875/16&language=EN.

[52] Documents 2, 3, 4 and 5 identified at the initial stage - not disclosed and document 1 identified at the confirmatory stage - not disclosed.

[53] See the Ombudsman Recommendation in case 1129/2023/OAM on the refusal by the European Border and Coast Guard Agency (Frontex) to provide lists of documents it identifies as falling within the scope of requests for public access to documents; available at: https://www.ombudsman.europa.eu/en/recommendation/en/182124.