Swift, the Belgium-based banking cooperative, has been sharing private data to help U.S. antiterrorism efforts for the past five years, Belgium’s privacy commission concluded Thursday.
The transfer of masses of information gleaned from international financial transactions among individuals and companies to the U.S. Treasury department is in flagrant breach of European data-protection laws, the privacy commission said in a statement issued after a two-month investigation.
Swift, the Society for Worldwide Interbank Financial Telecommunication, handles roughly 11 million financial transactions daily among 7,800 banks and other financial institutions in 200 countries, recording customer names, account numbers and other identifying information.
The sharing of this information with U.S. authorities came to light in newspaper reports in June, sparking an outcry among civil libertarians on both sides of the Atlantic.
“It has to be seen as a gross miscalculation that it has, for years, secretly and systematically transferred massive amounts of personal data for surveillance without effective and clear legal basis and independent controls in line with Belgian and European law,” the commission said in a statement.
Belgian Prime Minister Guy Verhofstadt held a press conference on the commission’s report Thursday, saying that access to information about international data transfers is necessary to track down terrorists, but that gaining access to this information must always be done lawfully.
The prime minister said his government wouldn’t force Swift to stop the data flow to the U.S. Treasury, but he said he would press the European Union to open talks with the United States to get more privacy guarantees from them so that the transfer of financial records could be legally used in terror investigations.
The Belgian privacy commission didn’t impose fines on Swift, as it could have. Instead, it too called for a Europe-wide solution.
“The commission invites the Belgian government to deal with this case at the European level. The European Commission can, for example, find a solution based on the 1995 data-protection directive, that would allow an adequate balance between, on the one hand the struggle against terrorism, and on the other the protection of people’s privacy,” the Belgian privacy commission said.
The European Commission is the executive and regulatory branch of the E.U. European Commission spokesman Friso Roscam Abbing wasn’t immediately available to comment on the findings of the Belgian privacy commission Thursday.
Swift CEO Leonard Schrank said the privacy commission’s report raised important issues about the balance between data privacy and use of financial data for terror probes.
“Swift wholeheartedly supports calls for U.S. and E.U. authorities to work together to develop an improved framework to reconcile data-privacy protections,” Schrank said in a statement.
Data-protection officials from across the European Union met earlier this week to discuss the so-called Swift affair. They will conclude their investigation in November at their next meeting, the European Commission said.
If they too find that European data-protection laws have been violated they could propose that the commission take legal action against Belgium for failing to uphold EU-wide laws.
The Swift affair comes at a time of heightened tension between Europe and the United States over how to balance counterterrorism needs with the need to preserve citizens’ civil liberties. In May the European Court of Justice ruled that an agreement granting American authorities access to passenger data on trans-Aatlantic flights was illegal.
E.U. and U.S. officials are meeting in Washington, D.C., later Thursday. They have until the end of this month to renegotiate the agreement to bring it into line with European law.




