- EN English
Proposal for a solution on how the European Commission dealt with a request for public access to documents concerning surveillance and security systems and equipment at migrant centres in Greece (case 507/2023/PVV)
Solution - Date Wednesday | 15 November 2023
Case 507/2023/PVV - Opened on Thursday | 23 March 2023 - Decision on Friday | 02 August 2024 - Institution concerned European Commission ( Solution achieved ) - Country Greece
Complaint submitted
23/02/2023Analysis of the complaint
16/03/2023Inquiry ongoing
23/03/2023Preliminary outcome
15/11/2023Inquiry outcome
02/08/2024
Made in accordance with Article 2(10) of the Statute of the European Ombudsman[1]
Background to the complaint
1. Multi-Purpose Reception and Identification Centres (MPRICs) are migrant reception centres set up on the Greek islands. The MPRICs are EU-funded and deal with the identification, first reception and pre-removal detention of and for asylum seekers. The European Commission is tasked with ensuring that Greece uses the EU funds covering the MPRICs in compliance with EU law.[2] That includes the surveillance and security systems and equipment that are used in the MPRICs. Such surveillance and security technologies are supported through the Internal Security Fund[3] and the Recovery and Resilience Facility[4].[5]
2. According to the complainant, a journalist, the surveillance and security systems and equipment at issue have been criticised by various organisations and experts. In addition, the Greek Data Protection Authority initiated an investigation into these technologies and concerns have been raised about the way the contract for these systems was awarded by the Greek authorities. The complainant submitted three access to documents requests to the Commission in this context.[6] The second request concerned the ‘Centaur’[7] security system and other surveillance and security systems and equipment at migrant centres in Greece in particular (GESTDEM 2022/4534).
3. More specifically, in August 2022, the complainant requested public access to the following documents, dating from September 2020 to the date of the request:
i. “All documents – including, but not limited to, briefings, notes, papers, non-papers, or reports – created or held by the Task Force Migration Management in DG Migration and Home Affairs (HOME) or exchanged between DG HOME representatives and any other actor (including, but not limited to, other European bodies' officials or Member State representatives) regarding, related to, or mentioning “Centaur” or other surveillance and security systems and equipment at existing and forthcoming migrant reception facilities on Samos, Kos, Leros, Lesbos, and Chios islands in Greece;
ii. All correspondence – including, but not limited to, letters, e-mails, and any attachments – exchanged between [the] Task Force Migration Management [...] and any other actor [on the same topic];
iii. A list of all meetings (including e-meetings) held between the Task Force Migration Management [...] and any other actor [on the same topic];
iv. All correspondence and documents regarding, related to, or mentioning Data Protection Impact Assessments (DPIAs) related to existing and forthcoming migrant reception facilities on Samos, Kos, Leros, Lesbos, and Chios islands in Greece”.
4. The Commission replied in October 2022. It identified eighteen documents as falling within the scope of the request and denied access to all of them. The documents identified at initial stage are correspondence, documents, inquiries, contracts and documentation related to the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA) of the IT systems established by the Greek authorities in the MPRICs.
5. The complainant asked the Commission to review its decision (by making a ‘confirmatory application’) on 31 October 2022. They claimed that the Commission did not identify all relevant documents and that it should have disclosed the documents it did identify. Not having received any acknowledgement of receipt, the complainant contacted the Commission several times and re-sent the confirmatory application twice. On 23 November 2022, the Commission informed the complainant that there had been a clerical error. It registered the confirmatory application with the time limit expiring on 14 December 2022.
6. On 14 December 2022, the Commission extended the time limit to 13 January 2023 as it had “not yet been able to gather all the elements necessary”. On 13 January 2023, the Commission informed the complainant that the extended time limit would not be met. Afterwards, the complainant contacted the Commission several times, asking for an estimated response date. On 16 February 2023, the Commission replied that it was dealing with “a large volume of applications” and that it could not commit to a specific date for a final decision.
7. Dissatisfied with how the Commission handled their request, the complainant turned to the Ombudsman on 23 February 2023.
The inquiry
8. The Ombudsman opened an inquiry into how the Commission handled the complainant’s request for public access.
9. The inquiry initially focused on securing a final decision on the complainant’s access request. As such, the Ombudsman asked the Commission to reply to the complainant as soon as possible and, in any case, by 14 April 2023.
10. The Commission did not meet the deadline set by the Ombudsman. It explained that its assessment was ongoing and that it had launched consultations with the Member State from which the documents at issue originate.
11. Given the persistent delay in replying to the complainant’s confirmatory application, the Ombudsman asked the Commission, in early June 2023, to provide the following:
a) “a list of documents identified at confirmatory stage (that could be shared with the complainant) in case this list differs from the one at initial stage,
b) copies of the documents identified as falling within the scope of the complainant’s request, and
c) any documentation relating to the consultation of the Greek authorities at initial and confirmatory stage, to the extent that it already exists”.
12. The Commission shared a copy of the documents identified at initial stage. It noted that, as the internal assessment at the confirmatory stage was still ongoing, it could not share a list of the documents identified at confirmatory stage, nor the documents themselves. Such transmission would be premature. For the same reason, it provided the Ombudsman inquiry team only with the third party consultations it had conducted at initial stage.
13. The Ombudsman inquiry team inspected the eighteen documents identified at the initial stage.[8]
Arguments presented to the Ombudsman
14. As the documents at issue originate from a Member State, the Commission initiated consultations with the competent national authorities in accordance with Article 4(4) and (5) of Regulation 1049/2001.[9] The Greek Ministry of Migration and Asylum, as the originator of the documents, objected to the documents’ disclosure.
15. Following an examination of the documents and taking into account the opinion of the Greek authorities, the Commission refused access to all documents identified. In its initial decision, it noted that the Greek authorities justified their refusal to grant access based on the following exceptions:
a) Protection of the public interest as regards public security (Article 4(1)(a), first indent of Regulation 1049/2001): specifically, according to the national authorities, the identified documents include “precise plans on the system and thorough details of where the system will be placed and the exact spots in the camps”. Therefore, their disclosure would endanger the lives of those living in the camps.
b) Protection of the commercial interests of Greece (Article 4(2), first indent of Regulation 1049/2001): the national authorities refused disclosure of the contract on the “Centaur” project to protect the methodology and the know-how of the beneficiary of the contract. In case of disclosure, that beneficiary would lose “its competitive advantage on pricing information, planning and overall strategy”.
16. The complainant argued that the Commission invoked the two exceptions under Regulation 1049/2001 in an excessive and disproportionate manner, violating both the spirit and the letter of the Regulation and the relevant case-law. By way of example, they referred to documents 13 and 18, entitled ‘CCTV sign information’ and ‘Information Flyer English’ respectively.
17. In their confirmatory application, the complainant also claimed that the Commission should not simply have accepted the Greek authorities’ reasons for non-disclosure. The complainant specified that the Commission should review the justification for non-disclosure provided by third parties. In particular, in accordance with Regulation 1049/2001 and relevant case-law, the Commission has the “obligation to override Member States’ objections to disclosure” in case of manifestly unfounded justifications. Compliance with this obligation ensures the widest possible access to documents for EU citizens.
18. The complainant also argued that Data Protection and Fundamental Rights Impact Assessments are conducted to ensure that the surveillance and security systems comply with EU data protection and fundamental rights law, and are commonly made publicly available. As such, it is not clear how disclosure (at least partial) of the relevant documents could pose a serious and foreseeable risk to public security.
19. With regards specifically to the Data Protection Impact Assessments (DPIAs), the complainant referred to the European Data Protection Board’s relevant guidelines in their complaint to the Ombudsman. According to these guidelines, controllers should consider publishing at least parts of a DPIA, such as a summary or a conclusion. Such disclosure enhances public trust, accountability and transparency.
20. More generally, the complainant contended that both the national authorities and the Commission failed to establish that the security risks in case of disclosure are not purely hypothetical. They added that the Commission also failed to properly assess the possibility of a partial disclosure of the documents.
21. The complainant stressed that, because the surveillance and security systems at the MPRICs are funded through EU funds, the Commission should grant the widest possible access to the relevant documents. Even more so given the various concerns that have been raised regarding the design and the implementation of these systems by the national authorities.[10]
22. Finally, the complainant claimed to have reasons to believe that the Commission failed to address all aspects of their access request. In particular, they claimed that the Commission only addressed the fourth aspect of the initial request (see above). In support of their claim, they clarified that, upon submitting the confirmatory application, they became aware of the existence of several additional documents falling under their request, such as emails sent by Commission representatives operating within the MPRICs mentioning surveillance systems in the camps. Those documents had already been disclosed by the Commission to colleagues of the complainant in reply to public access requests, however they were not identified in the context of this access request.
The Ombudsman's assessment
23. Under Article 4(5) of Regulation 1049/2001, a Member State may request an EU institution not to disclose a document originating from that Member State without its prior agreement. In accordance with the case law of the Court of Justice of the EU (CJEU), such objection to disclosure is possible only based on the substantive exceptions laid down in Article 4(1) to (3) of the Regulation and only if the Member State concerned gives proper reasons for its position.[11] In the procedure for the adoption of a decision to refuse access, the institution must make sure that those reasons exist and refer to them in the decision on the access request.[12] The institution concerned is not required to carry out an exhaustive assessment of the Member State’s decision to object to disclosure.[13] Rather, it must check whether the explanations given by the Member State appear to it, prima facie, well founded.[14] The obligation for an institution to carry out a specific and individual examination does, in such cases, not apply.[15]
24. That said, Article 4(5) of Regulation 1049/2001 cannot be “interpreted as conferring on the Member State a general and unconditional right of veto, so that it could in a discretionary manner oppose the disclosure of documents originating from it and held by an institution”.[16] Indeed, the “power conferred by that provision on the Member State concerned is delimited by the substantive exceptions set out in Article 4(1) to (3), with the Member State merely being given in this respect a power to take part in the [EU] decision”.[17] Member States thus possess a form of assent rather than a right of veto.[18]
25. In line with the above, the Commission should verify whether the Greek authorities gave proper reasons to object to the disclosure of these documents to protect public security and commercial interests. After inspection of the eighteen documents concerned, the Ombudsman is not convinced that such reasons exist.
1. Documents related to the Data Protection Impact Assessments (DPIAs) and the Fundamental Rights Impact Assessment (FRIA)
26. In her inquiry into how the Commission ensures respect for fundamental rights in EU-funded migration management facilities in Greece, the Ombudsman made, among others, the following suggestion for improvement:
“The Commission should urge the Greek authorities to publish their fundamental rights impact assessment and personal data impact assessment of the surveillance system in the MPRICs. The Commission should include a link to that publication on its own website.”
27. On 29 August 2023, the Commission replied[19] to this suggestion that it “will suggest to the Greek authorities to publish the aforementioned assessments and include a link to the publication on its website following their publication.”
28. To the Ombudsman’s knowledge, the FRIAs and the DPIAs of the surveillance and security systems in the MPRICs have not yet been published.
29. The large majority of the documents at issue are DPIAs conducted for the ‘Centaur’ surveillance system[20], for the drone surveillance system[21], and for the ‘Hyperion’ entry and exit system[22]. In addition, the FRIA conducted for the ‘Centaur’ surveillance system[23] has been identified as falling within the scope of the complainant’s access request. Another document[24] identified contains replies to questions and comments made to the Greek authorities concerning the DPIAs and the FRIA that they conducted for the surveillance and security systems concerned.
30. Granting access to the abovementioned documents would thus be in line with the Ombudsman’s view on proactive transparency regarding surveillance and security systems in the MPRICs, and with the Commission’s commitment to suggest to the Greek authorities to embrace such transparency.
31. The Ombudsman recalls that access to a document can be only refused if the document’s release would specifically and actually undermine the interests that are sought to be protected. The risk of the interests being undermined must be reasonably foreseeable and not purely hypothetical.[25]
32. In this case, the Commission refused access, referring to the objection of the Greek authorities that disclosure of the requested documents related to the DPIAs and the FRIA would undermine the protection of the public interest as regards public security (Article 4(1)(a), first indent of Regulation 1049/2001).
33. While the EU institutions enjoy a wide margin of discretion when deciding on what the protection of the public interest as regards public security calls for in terms of disclosure of documents, they are still required to demonstrate a ‘specific and actual risk’. The review of these documents has however shown that much of the information contained in them appears generic in nature and that it is not readily clear how their disclosure could pose a serious and foreseeable risk to public security.
2. Documents that appear to be public or appear to contain information that is public
34. The review of the documents at issue also revealed that several of the documents identified appear to be public or appear to contain information that is public.
35. For instance, the document entitled ‘Regime on the use of video surveillance systems’[26] provides an overview of Greek, European and international legislation on data protection and the use of video surveillance systems, as well as an overview of the interested supervisory authorities and the relevant case-law. Reference is also made to what DPIAs are, with what methodology based on the General Data Protection Regulation (GDPR) the DPIA was conducted for the ‘Centaur’ surveillance, and what security measures provided by the law can be adopted when processing special categories of personal data. The document thus merely summarises the applicable legislative framework and, as such, it is not readily clear how the document’s disclosure would affect public security.
36. Further documents identified appear to be addressed to migrants arriving or residing in the MPRICs. More specifically, it seems that they are meant to inform migrants of the processing activities concerning their personal data. The document entitled ‘Personal Data Registration Form and Declaration of non-objection to disclosure’[27] for example is a form to be filled in by migrants to consent to the processing of their personal data. The documents entitled ‘CCTV sign template’[28] and ‘CCTV sign information’[29] are aimed at informing and reminding migrants residing in the MPRICs that the site is under video surveillance, as well as providing them with the data controller’s information, the Data Protection Officer’s contact details, and information on their rights as data subjects. Similarly, information flyers in Greek[30] and English[31] contain information on the stages of the reception and identification procedure, and the rights and obligations of camp residents. The security level of the latter two documents is marked ‘ungraded’. As it thus appears that these documents are meant for public dissemination, it is not readily clear how their disclosure could undermine the public interest as regards public security in accordance with Article 4(1)(a), first indent of Regulation 1049/2001.
37. The Commission also denied access to the ‘Data Protection Officer Contract’,[32] relying on the view of the Greek authorities that disclosure would undermine the protection of Greece’s commercial interests (Article 4(2), first indent of Regulation 1049/2001). In particular, the Commission argued that disclosure would affect the protection of the methodology and the know-how of the beneficiary of the contract. As the contract is publicly available on the online platform ‘KIMDIS’[33], the Greek public procurement contracts repository, no further risks for the commercial interests of the DPO concerned would materialise by disclosing this document to the complainant.
38. Finally, the Ombudsman inquiry team also reviewed the documents entitled ‘Privacy Policy’[34] and ‘Template Privacy Policy’[35]. These two documents contain a general description of how the Greek Ministry of Migration and Asylum ensures privacy in its reception facilities. The majority of the information contained in these documents appears generic and already available to the public.
39. In light of the Commission’s reply to OI/3/2002/MHZ and in light of the fact that the explanations given by the Member State originator of the documents appear, prima facie, not well founded for all (parts of) the documents in question, the Ombudsman proposes that the Commission reconsider its decision on this public access request, with a view to disclosing the documents concerned to the widest extent possible.
40. The above assessment is regrettably based on an incomplete file as, at the time of this solution proposal, the third party consultations, which the Commission initiated for the purposes of its confirmatory decision, had not yet been concluded, nor had the Commission adopted an explicit reply at the confirmatory stage. Specifically, the Ombudsman had to base her assessment on the documents that were identified at the initial stage, the third party consultations conducted at the initial stage, and the Commission’s initial decision.
41. The Ombudsman trusts that the Commission will have concluded the third party consultations by the time of its reply to this solution proposal. The Ombudsman would thus like to request that the Commission provide her Office with copies of its decision, along with the documents identified at the confirmatory stage.
42. Moreover, in light of the complainant’s claim that the Commission failed to address all aspects of their request, the Ombudsman trusts that the Commission will have conducted a thorough and detailed search for documents falling within the complainant’s request at the confirmatory stage.
43. Lastly, the Commission is reminded of the Ombudsman’s Special Report in her strategic inquiry concerning the time the European Commission takes to deal with requests for public access to documents.[36]
The proposal for a solution
Based on the above findings, the Ombudsman proposes that the European Commission should:
Reconsider its decision on this public access request, with a view to disclosing the documents concerned to the widest extent possible.
The Commission is invited to inform the Ombudsman by 15 February 2024 of any action it has taken in relation to the above solution proposal. Given the significant delay already incurred in handling the complainant’s public access request, the Ombudsman would however urge the Commission to reply to this proposal as soon as possible.
Emily O'Reilly
European Ombudsman
Strasbourg, 15/11/2023
[1] Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv%3AOJ.L_.2021.253.01.0001.01.ENG&toc=OJ%3AL%3A2021%3A253%3ATOC.
[2] In 2022, the Ombudsman opened an own-initiative inquiry (OI/3/2022/MHZ) on how the European Commission ensures respect for fundamental rights in these new EU-funded migration management facilities in Greece. The Ombudsman made suggestions to address a number of issues identified. Information on the inquiry can be found at: https://www.ombudsman.europa.eu/en/case/en/62000.
[3] More information: https://home-affairs.ec.europa.eu/funding/borders-and-visa-funds/internal-security-fund-borders-and-visa-2014-2020_en and https://home-affairs.ec.europa.eu/funding/internal-security-funds/internal-security-fund-2021-2027_en.
[4] More information: https://commission.europa.eu/business-economy-euro/economic-recovery/recovery-and-resilience-facility_en.
[5] See also the Commission’s reply to a Parliamentary question on this topic: https://www.europarl.europa.eu/doceo/document/E-9-2022-003094-ASW_EN.html#ref2.
[6] GESTDEM 2022/4531 - complaint 380/2023/PVV with the Ombudsman; GESTDEM 2022/4534 - complaint 507/2023/PVV with the Ombudsman and GESTDEM 2022/4621 - complaint 508/2023/PVV with the Ombudsman. Available at: https://www.ombudsman.europa.eu/en/opening-summary/en/167614.
[7] A digital management system for electronic and physical security around and within the facilities, using cameras and motion analysis algorithms (Artificial Intelligence Behavioural Analytics), more information: https://digitalstrategy.gov.gr/project/kentayros.
[8] In its communication with the Ombudsman, the Commission noted that the documents identified at initial stage were not classified under the system for the protection of EU Classified Information (EUCI). The Commission also said that it did not have details on the classification at Greek national level, although the Commission’s initial reply to the complainant mentioned that the Greek authorities noted that the identified documents are classified.
[9] Regulation 1049/2001 regarding public access to European Parliament, Council and Commission documents: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32001R1049.
[10] The complainant noted in their confirmatory application that a) reportedly, the implementation of the surveillance and security systems at MPRICs was carried out without prior recruitment of a Data Protection Officer at the Ministry of Migration and Asylum (MMA); b) the MMA has not clarified whether DPIAs were conducted in the design phase; c) the Greek Data Protection Authority is investigating these systems following a complaint alleging that these systems were designed and initially implemented in violation of basic procedural requirements under EU data protection laws; d) there has been criticism over the implementation of these systems on the grounds of serious risks to the fundamental rights of migrants; and e) there have been serious concerns about the way the contract for the implementation of these systems was awarded.
[11] Judgments of 21 June 2012, IFAW Internationaler Tierschutz-Fonds v Commission, C-135/11 P, paragraph 59, and of 25 September 2014, Spirlea v Commission, T-669/11, paragraph 50: https://curia.europa.eu/juris/document/document.jsf?text=&docid=124191&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=375346 and https://curia.europa.eu/juris/document/document.jsf?text=&docid=157982&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=375454.
[12] Judgments of 21 June 2012, IFAW Internationaler Tierschutz-Fonds v Commission, C‑135/11 P, paragraph 62; of 25 September 2014, Spirlea v Commission, T‑669/11, paragraph 53, and of 8 February 2018, POA v Commission, T‑74/16, paragraph 55 (https://curia.europa.eu/juris/document/document.jsf?text=&docid=199205&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=375567).
[13] Judgments of 21 June 2012, IFAW Internationaler Tierschutz-Fonds v Commission, C‑135/11 P, paragraph 63 and of 25 September 2014, Spirlea v Commission, T‑669/11, paragraph 54.
[14] Judgments of 5 April 2017, France v Commission, T-344/15, paragraph 54 (https://curia.europa.eu/juris/document/document.jsf?text=&docid=189616&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=376000) and of 8 February 2018, POA v Commission, T-74/16, paragraph 57.
[15] Judgments of 25 September 2014, Spirlea v Commission, T-669/11, paragraphs 80 to 84, and of 8 February 2018, POA v Commission, T-74/16, paragraphs 60 and 61.
[16] Judgment of 18 December 2007, Sweden v Commission, C-64/05 P, EU:C:2007:802, paragraph 75: https://curia.europa.eu/juris/document/document.jsf;jsessionid=43BC55AC039CECE614B9B77869B46749?text=&docid=71934&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=374948.
[17] Judgment of 18 December 2007, Sweden v Commission, C-64/05 P, paragraph 76.
[18] Judgment of 18 December 2007, Sweden v Commission, C-64/05 P, paragraph 76.
[19] Available at: https://www.ombudsman.europa.eu/en/doc/correspondence/en/174402.
[20] Documents 2, 3 and 9 identified at initial stage, Document 4 is a synopsis of that DPIA.
[21] Document 10 identified at initial stage.
[22] Document 11 identified at initial stage.
[23] Documents 8 and 14 identified at initial stage.
[24] Document 6 identified at initial stage.
[25] See, for example, judgment of the General Court of 11 July 2018, ClientEarth v Commission, T-644/16, paragraph 22: https://curia.europa.eu/juris/document/document.jsf?text=&docid=203913&pageIndex=0&doclang=EN&mo%20de=lst&dir=&occ=first&part=1&cid=46943.
[26] Document 1 identified at initial stage.
[27] Document 7 identified at initial stage.
[28] Document 12 identified at initial stage.
[29] Document 13 identified at initial stage.
[30] Document 16 identified at initial stage.
[31] Document 17 identified at initial stage.
[32] Document 18 identified at initial stage.
[33] Available in English and Greek at https://www.gov.gr/en/ipiresies/epikheirematike-drasterioteta/elektronikos-phakelos-epikheireses/demosioteta-demosion-sumbaseon-kemdes and https://www.gov.gr/ipiresies/epikheirematike-drasterioteta/elektronikos-phakelos-epikheireses/demosioteta-demosion-sumbaseon-kemdes respectively.
[34] Document 5 identified at initial stage.
[35] Document 15 identified at initial stage.
[36] OI/2/2022/OAM, available at: https://www.ombudsman.europa.eu/en/special-report/en/175425.