- EN English
Report on the meeting of the European Ombudsman inquiry team with representatives of the European Border and Coast Guard Agency (FRONTEX)
Inspection Report - Date Thursday | 27 July 2023
Case 344/2023/PVV - Opened on Tuesday | 28 February 2023 - Decision on Wednesday | 18 September 2024 - Institution concerned European Border and Coast Guard Agency ( Solution partly achieved ) - Country United Kingdom
Complaint submitted
17/02/2023Analysis of the complaint
20/02/2023Inquiry ongoing
28/02/2023Preliminary outcome
30/04/2024Inquiry outcome
18/09/2024
Case title: How the European Border and Coast Guard Agency (Frontex) dealt with a request for public access to documents concerning social media monitoring
Date: Thursday, 27 July 2023
Remote meeting via WebEx
Present
European Border and Coast Guard Agency (Frontex)
Five representatives:
· Inspection Team Leader
· Team Leader of the Business Unit concerned
· Legal Specialist
· Legal Senior Assistant
· Associate Data Protection Officer
European Ombudsman (Directorate of Inquiries)
· Ms Jennifer KING, Legal Expert
· Ms Paulien VAN DE VELDE-VAN RUMST, Inquiries Officer
· Mr Michal KRAJEWSKI, Inquiries Officer
· Ms Maria Eleni KOSMOPOULOU, Inquiries Trainee
Purpose of the meeting
The purpose of the meeting was for the Ombudsman inquiry team to obtain some clarifications on how Frontex handled a public access request concerning:
“- all minutes of meetings and correspondence (incl. annexes) between Frontex and Europol concerning social media monitoring
- all internal documents concerning social media monitoring by Frontex
The request covers the period 1 January 2021 - 27 September 2022”.
Relevant questions had been sent to Frontex in a confidential annex together with the meeting request, in advance of the meeting, on 12 June 2023.
Prior to the meeting, on 24 July 2023, Frontex provided the Ombudsman inquiry team with its written reply to the questions posed in the annex to the meeting request.
Introduction and procedural information
The Ombudsman inquiry team introduced themselves, thanked Frontex’s representatives for meeting with them and set out the purpose of the meeting. They outlined the legal framework that applies to meetings held by the Ombudsman, in particular, that the Ombudsman would not disclose any information identified by Frontex as confidential, neither to the complainant nor to any other person outside the Ombudsman’s Office, without Frontex’s prior consent.[1]
The inquiry team explained that they would draw up a draft report on the meeting to be sent to Frontex to ensure that the contents were factually accurate and complete. The meeting report would then be finalised, included in the file and provided to the complainant. No confidential information would be included in the report or otherwise provided to the complainant or any third party.
Information exchanged
Handling of the public access request and identification of the documents within scope
In reply to a question from the Ombudsman inquiry team about how Frontex had handled the public access request at issue, Frontex’s representatives explained that, at initial stage, the Officer in charge of the public access request contacted the four Units assumed to hold the documents falling within the scope of the request. The Units identified only five documents.
Frontex mentioned that the Social Media Monitoring (SMM) project had changed ownership and that the previous Project Manager had left Frontex sometime before the request was received. As such, it was difficult to locate other documents. It transpired that various documents were stored in the individual email account of that previous Project Manager to which Frontex did not have access unless another Frontex official was either in copy or their addressee.
Frontex’s representatives further clarified that, at confirmatory stage, more actors were involved in the identification of documents and a renewed thorough search was conducted that led to further documents being identified from additional Business Units. These further documents were only identified late in the confirmatory process, taking into account the short deadline for treating public access requests. Several meetings were held between Frontex officials to discuss the sensitivity of the identified documents in order to reply within the deadline of the confirmatory application.
Following a question by the Ombudsman inquiry team as to how Frontex would avoid similar difficulties in the future (when for example a change of ownership of a project or changes in staff occur), Frontex’s representatives noted that they have put a records management policy in place to ensure continuity by storing documents more centrally. They added that there are on-going discussions on how to ensure that all within-scope documents are identified at the initial stage. Those discussions are mostly centred on archiving documents in a more transparent, central and structured way.
Frontex’s representatives also underlined that it is a very rare case that the agency had identified more documents at the confirmatory than at the initial stage. In addition, they stressed that the fact that more documents were identified at confirmatory stage underlines the full review and renewed comprehensive search conducted by Frontex upon receipt of a confirmatory application. They explained that in identifying within-scope documents, they always conduct searches of hard copies as well.
Application of the Public Security exception - art. 4(1)a of Regulation 1049/2001
The Ombudsman inquiry team noted that, in its written reply, Frontex had explained in further detail what aspects of public security it was trying to protect and how the information found in the requested documents could be used by criminal organisations and other actors posing a threat to the public security of the EU and/or Member States. The Ombudsman inquiry team requested clarifications concerning how the aspects mentioned were reflected in certain documents.
Frontex’s representatives referred to social media accounts (e.g. thematic Facebook pages) used by migrants to organise themselves for entering illegally into the EU en mass (e.g. Caravan of Hope, Caravan of Light, etc). Frontex’s representatives explained that these events have a high impact on the security of the EU’s external borders and, therefore, need to be identified in their early stages, and monitored. In this way, the European Commission and the Member States will be alerted by these events and together with Frontex they can plan and implement the appropriate border management measures. For this purpose, Frontex would collect non-personal data regarding these events. Nevertheless, to collect these non-personal data, Frontex would be inherently required to also access (i.e. view without any further processing) the personal data of the users posting the information on social media because the two categories of data are intertwined.
Therefore, the Commission asked Frontex to develop a social media monitoring capability at external borders for the purpose of gathering intelligence to prevent illegal migration and cross-border crime.
Frontex’s representatives added that many criminal organisations are advertising their illegal services on social media platforms (e.g. illegal boat travels to the EU/SAC area); and this not only increases the threat to the security of the EU external borders but also the risk for the migrants who may lose their lives while crossing the sea on board of unseaworthy boats.
Frontex considered that, if more information contained in these specific documents were disclosed, organised criminal groups would have significant insight into the method followed by EU and Member States’ law enforcement actors to tackle criminal and irregular activities. The groups involved in such activities would then in turn change their modus operandi and minimise the use of certain social media platforms. This would set back Frontex's work in monitoring and combatting illegal activity significantly.
Following questions by the Ombudsman inquiry team with regard to the online existence of some of the information contained in the documents, Frontex’s representatives explained that, although the information in one or more of the documents may seem generic, it can give specific insights to someone specialised in this area as to the direction that Frontex would follow for its specific SMM activities. In other words, in case this information became public, someone reasonably qualified in this area could with foreseeable likelihood be able to reach meaningful conclusions on Frontex’s modus operandi. At the request of the inquiry team, Frontex’s representatives explained how such conclusions can be reached and provided concrete examples. In this regard, Frontex’s representatives stressed the need to consider the erga omnes effect of public access.
Frontex further clarified that currently criminal organisations can only piece together unverified third-party information that is available online and, thus, can only speculate on the modus operandi of Frontex. Disclosure of the documents requested would provide those organisations with information validated by Frontex, giving them a key insight into Frontex’s operations. In addition, the documents at issue in this access request would also complement other operational activities by Frontex. As such, it would enable those organisations to build their own risk assessment and intelligence mosaic of Frontex activities based on comprehensive and detailed information contained in Frontex documents that can readily be combined with other publicly available and private sources.
On a more general note, Frontex’s representatives stated that the Agency always takes into account which verified information is available in the public domain, as well as how the information within the documents requested, if disclosed, could be read in conjunction with such publicly available information.
In response to a question from the Ombudsman’s team, Frontex also provided specific examples of how criminal organisations would change their modus operandi upon becoming aware of specific information found in the documents requested. Frontex’s representatives underlined that the effect of disclosing this information depends on the experience, expertise and attention of the members of each criminal organisation. Criminal organisations take into account information that may seem generic for others and adjust their operations accordingly.
In addition, Frontex’s representatives stressed that, when dealing with public access requests, Frontex also makes sure not to disclose documents containing information that, if revealed, could interfere with the systems implemented by Member States and by Europol, and the investigations that are being conducted by them in this context.
The Ombudsman inquiry team then referred to a number of documents which had been heavily redacted and asked whether all of those redactions were necessary. Frontex’s representatives explained that when assessing a public access request it always conducts a balancing exercise between the fundamental right of public access and the need to protect certain information in light of public security considerations. It always performs a case-by-case and document-by-document analysis. Frontex considered that parts of the documents at issue fall under the exceptions of Regulation 1049/2001. If disclosed, those parts not falling under exceptions would not convey any significant information to the applicant. Taking also into account the administrative burden of redacting all the pieces of information falling under the exceptions, in line with established case-law of the CJEU, Frontex decided not to partially disclose them. Frontex’s representatives specified that, in doing so, the Agency followed in particular the jurisprudence that public administrations are equally obliged to adhere to the principles of transparency and to the principle of sound administration.
Application of the ongoing Decision-Making Process exception - art. 4(3) of Regulation 1049/2001
The Ombudsman inquiry team then referred to Frontex’s written reply concerning how it applied the exception related to its ongoing decision-making process. The inquiry team asked for clarifications on the revision of Management Board (MB) Decisions 68 and 69 and on the connection between this revision and Frontex’s SMM plans; and how disclosure of the requested documents would undermine Frontex’s ability to adopt new MB Decisions.
Frontex’s representatives clarified that MB Decisions 68 and 69 establish the legal framework for personal data processing by Frontex. As such, they would determine what form the SMM activities would take. Frontex’s mandate to process personal data derives from the Frontex Regulation.[2]
Frontex’s representatives further explained that Frontex finalised the drafting of the MB Decisions at the end of 2021. In June 2022, the European Data Protection Supervisor (EDPS) adopted two negative Supervisory Opinions on MB Decisions 68 and 69. Even though the EDPS Opinions did not annul the MB decisions, as the EDPS had raised concerns regarding Frontex’s processing of personal data, Frontex started the process of redrafting them. They explained that in October 2022, the EDPS also conducted an audit of Frontex focussing on the collection and processing of personal data which has been finalised. The official report was published on 24 May 2023. That audit report has led to the further redrafting of the MB Decisions. New drafts would be sent to the EDPS during the week of the meeting with the Ombudsman inquiry team.
Due to the redrafting of Frontex’s MB Decisions, the related SMM project was put on hold. Frontex’s representatives explained that disclosure of the documents containing information on the state of the project would inevitably reveal information on how the SMM activities would be conceptualised in the future, if the SMM ever comes to fruition. The non-disclosure was necessary to protect Frontex’s space to think, as recognised by EU jurisprudence, and to take a decision on this sensitive subject.
In relation to a specific document, the Ombudsman inquiry team then asked Frontex to explain what the concrete effects of the disclosure of this document on its ongoing decision-making process would be. More specifically, it asked what the tangible elements that the decision-making process would be undermined were, considering that the decision-making was actually put on hold.[3]
Frontex’s representatives clarified that while the SMM project has been put on hold pending the redrafting of the two MB Decisions, the decision-making process is currently ongoing. Disclosure could significantly undermine the redrafting of the MB Decisions, as it would seriously interfere with Frontex’s space to think as confirmed by and within the meaning of the jurisprudence of the CJEU. Frontex’s representatives emphasised that the exception relating to the protection of the ongoing decision-making process had to be invoked in addition to other exceptions, including the exception for the protection of the public interest as regards public security. They noted that for Frontex’s activities, decision-making is linked often to public security concerns. Frontex’s Associate Data Protection Officer (DPO) stressed that the redrafting of MB Decisions is led by the DPO. At the time of the public access request, the DPO was working on the amendments.
The Associate DPO further clarified that there was no EDPS investigation in the meaning of the Data Protection Regulation into the SMM topic specifically. The Team Leader of the Business Unit concerned stressed again that there was however an investigation within the meaning of Article 4(2) of Regulation 1049/2001 at the time the respective public access decisions were adopted.
Regarding the documents subject to the decision-making process exception, the Ombudsman inquiry team then asked how Frontex had considered whether there was an overriding public interest in their disclosure. The inquiry team referred to the fact that only a few of the documents listed as falling under this exception were considered by Frontex to also be covered by the public security exception.
Frontex’s representatives replied that it always considers whether there is an overriding public interest. However, this depends on the arguments presented by the applicant concerned and in light of the high threshold set in the CJEU jurisprudence, these arguments must usually be dismissed. Frontex’s representatives also added that the key documents concerning SMM were indeed falling under the public security exception, such as the concept note.
According to Frontex, in his confirmatory application, the applicant argued that the need for transparency is high when the decision-making process forms part of a legislative process.[4] However, Frontex’s representatives pointed out that the process at hand is not a legislative one within the meaning of Regulation 1049/2001 as considered by the jurisprudence of the CJEU. In regard to the applicant’s invoking of EU citizens’ interest in being informed about this project and the need for public scrutiny, Frontex’s representatives explained that this is generally not accepted as an overriding public interest in CJEU jurisprudence, especially when phrased in general terms. They further stressed that the settled case law of the CJEU emphasizes that supervising the work of Frontex and other EU actors is entrusted to the respective EU institutions, such as the Commission and the EDPS, and that a personal interest of a member of the public in this regard does not constitute an overriding public interest. Overall, Frontex’s representatives concluded that there is a high threshold for an applicant to establish an overriding public interest in accordance with well-established case-law and maintained that in this case the applicant’s arguments failed to meet the standards laid down by the CJEU.
In reply to the question of the Ombudsman inquiry team about how Frontex considers the release of a document that contains several elements concerning its ongoing decision-making, Frontex’s representatives noted that, in principle, if the release of such document does not seriously undermine an ongoing decision-making process, Frontex grants disclosure. They stressed, however, that this particular decision-making process was very sensitive and that it was the subject of intense interest as evidenced by the widespread media coverage and attempts to unduly influence this procedure. Specifically, Frontex was concerned that the disclosure of the documents at issue would lead to undue influence on the various actors involved in the conception of the new MB Decisions.
The Ombudsman inquiry team asked Frontex’s representatives to explain, in relation to two specific documents, how their disclosure would in actual and specific terms create a serious risk to the decision-making process that is not hypothetical and reasonably foreseeable. Frontex’s representatives explained that disclosure would provide the public with information on the state of the internal drafting process of the MB Decisions and on how Frontex was dealing with the reshaping of the SMM project at a particular point in time. They repeated that they have to protect the state of the negotiations while the SMM project was on hold to ensure that all actors are able to participate in the redrafting within the protected space to think. They added that, in general, the SMM project has been very complex and, as such, it has called for many different considerations.
Application of the ongoing Investigations exception - art. 4(2) of Regulation 1049/2001
Frontex’s representatives explained that Frontex had refused to grant access to certain documents based on the need to protect the purpose of ongoing investigations in conjunction with the need to protect public security and its ongoing internal decision-making process. They stated that all of the exceptions applied to all parts of the documents as it would otherwise be difficult to divide the documents into parts and match them with the corresponding exceptions, especially as often more than one exception was applicable.
Frontex explained that this exception had to be invoked because of the on-going EDPS procedures and other investigations - that is, the EDPS Supervisory Opinions and audit - within the meaning of Regulation 1049/2001 and to ensure that their purpose was not undermined. They clarified that Frontex needs to implement the recommendations it has received from the EDPS as part of its ongoing decision-making process. As a result, the application of all of the exceptions is justified.
Application of the Legal Advice exception - art. 4(2) of Regulation 1049/2001
In relation to a specific document, the Ombudsman inquiry team asked for clarifications on the reasons why Frontex considered it to constitute ‘legal advice’. Frontex’s representatives explained that it did not disclose the document because it had to protect the ability of its Legal and Procurement Unit to provide frank, objective and comprehensive legal advice and to receive such advice from other actors. If the document was disclosed, the future work of the unit and other entities engaged in the drafting would be affected. Moreover, Frontex’s representatives mentioned that the Agency built on the wide notion of legal advice as established by the CJEU: even if much of the information included in the document was publicly available, compiling all of this information can be considered legal advice. The document in question was thus the product of an intellectual endeavour constituting legal advice, it said.
General considerations
The Ombudsman inquiry team asked Frontex’s representatives how Frontex considers granting partial access to documents requested under Regulation 1049/2001. Frontex’s representatives explained that an individual assessment of each document always takes place, the outcome of which is stated to the applicant even if the response provided to the applicant does not specifically explain this assessment for each document identified. Sometimes it is clear what parts of the documents requested can be disclosed and what parts cannot. Frontex’s representatives recalled that, for documents where due to the high number of elements falling under an exception that have to be redacted, a deviation from Article 4(6) of Regulation 1049/2001 has to be considered based on the established CJEU jurisprudence through the balancing of the interests as explained above. In such case, Frontex examines whether the disclosed parts convey meaningful information to the requester whilst also taking account of the administrative burden of redacting such a high number of elements to eventually provide access to redacted documents.
The Ombudsman inquiry team asked on what basis Frontex considered the administrative burden to provide partial access in this case disproportionate and how this had been demonstrated to the complainant. The Ombudsman inquiry team noted that they had been provided with redacted versions of all documents at issue. Frontex’s representatives noted that in accordance with established case-law, the amount of work entailed in considering a request for access depends not only on the number of documents referred to in the request and their volume, but also on their nature, and stated that this had been sufficiently explained and clarified in its confirmatory decision.
Frontex’s representatives accepted that the explanations provided as regards their refusal of full access to the documents only identified at confirmatory stage were more limited. They acknowledged that the complaint to the Ombudsman was akin to a confirmatory application with regard to these documents. They emphasised, however, that this was a particular case and that lessons had been learnt regarding the identification of documents already at initial stage. Concluding, Frontex’s representatives emphasized again in this regard that the thorough search conducted at the confirmatory level and the subsequent identification of more documents was in the interest of the applicant.
The Ombudsman inquiry team asked why Frontex did not provide the applicant with a list or a short description of the documents falling within the scope of the request. In this case, for the non-disclosed documents, the complainant was not even aware of the nature of the documents, their title and date, the number of pages involved, and which exception applied to each document.
Frontex’s representatives stated that it always indicates the number of the identified documents and the reasons for their non-disclosure. However, Frontex’s representatives stated that it will consider the provision of lists to applicants in future public access cases subject to ensuring that the list itself would not undermine the interests intended to be protected. Frontex’s representatives nonetheless recognised the obligation to produce such document lists only when having to invoke a general presumption of confidentiality. They added that providing details as to the number of pages of the documents is not always indicative of the administrative burden involved and emphasized again that both the initial and confirmatory decisions explained the reasons why access to some documents had to be barred in their entirety.
Conclusion of the meeting
The inquiry team thanked Frontex’s representatives for their time and for the explanations provided, and the meeting ended.
Brussels, 27 July 2023
Paulien Van de Velde-Van Rumst Jennifer King
Inquiries Officer Legal Expert
[1] Article 4.8 of the European Ombudsman’s Implementing Provisions.
[2] Chapter IV, Section 2 of Regulation (EU) 2019/1896 of the European Parliament and of the Council of 13 November 2019 on the European Border and Coast Guard and repealing Regulations (EU) No 1052/2013 and (EU) 2016/1624.
[3] In the light of the Court of Justice of the EU’s Pollinis case-law.
[4] In the light of the Court of Justice of the EU’s De Capitani and Pech case-law.