What happened
It was reported that on 2 April 2024 the Hellenic Data Protection Authority issued Decision 13/2024 against the Greek Ministry of Migration and Asylum, and announced it the following day. The authority had opened the investigation itself, on its own initiative. It covered two systems running at Closed Controlled Access Centres and Reception and Identification Centres on Lesvos, Chios, Samos, Leros and Kos. The authority described Centaur as an integrated digital system for managing electronic and physical security, using motion analysis cameras with behavioural analytics, closed circuit television and drones that process image data. It described Hyperion as an integrated entry and exit control system, using readers together with fingerprint authentication, which processes biometric data. The fine came to 175,000 euros. The ministry was given three months to bring its processing into line with the GDPR.
It was reported that the authority found the ministry’s data protection impact assessments for the two systems substantially incomplete and limited in scope, and found a lack of cooperation on the part of the ministry in its capacity as data controller. Computer Weekly reported what that looked like in practice. The documents the ministry submitted were unclear, incomplete, confusing and contradictory, and it would not hand over its supply contracts with two private security companies, citing confidentiality clauses. The same reporting sets out the timeline. The migration minister unveiled a control room already connected to camp systems in September 2021. Ministry officials said in December 2021 that Centaur was operational in several camps. The impact assessments were completed in January 2022, more than three months after the ministry first advertised the programme as active. Neither the authority’s announcement nor the European Data Protection Board’s record of the decision, which lists provisions running from Article 4 to Article 83 of the GDPR together with Article 39 of Law 4624/2019, says which provision each individual finding rests on. The ministry told Computer Weekly that corrective measures had to a large extent already been implemented, that the authority had assessed the evidence incorrectly, and that it intended to assess the possibility of challenging the decision.
What an auditable version would have shown
The finding turned on what the ministry could show about systems already running over people living in its facilities. A record kept as the systems ran answers that. An investigation two years later can only reconstruct it. For Centaur the record would show each time the behavioural analytics raised an alert: what triggered it, how the system classified it, who received it and what they did next. For Hyperion it would show each time a fingerprint was enrolled or checked, the basis for collecting it, where the biometric template is held, how long it is kept, and what happened when a match failed or was disputed. Over time those records turn into figures the ministry does not otherwise have: how many people were processed, how many alerts were raised, how many came to nothing, and how often the biometric check failed the person standing in front of it. The impact assessment could then be written against what the systems were actually doing rather than what they were meant to do.
Where the gap was
It was reported that the authority found the impact assessments substantially incomplete and limited in scope, and that the ministry did not cooperate with it as controller. A ConstraintGate encodes the limits an assessment sets as checks that run before each processing action, so processing outside the assessed scope is refused when it is attempted rather than found years later. A ConductRecord preserves what the system did in each case, in enough detail to answer an authority asking what happened to a named person, or how often a class of alert was raised. The people living in these facilities cannot watch the system work and cannot put questions to it. That leaves accountability resting on the records the operator keeps.
What governance should have looked like
It was reported that the authority gave the ministry three months to bring its processing into line with the GDPR, and that it reached its findings through an investigation it began itself rather than through anything the ministry published. Where a public body runs automated surveillance over a population that cannot leave, good practice is for the impact assessment to be complete and specific before deployment, for the processing to be constrained to what that assessment covers, and for a record of each processing action to exist independently of the people operating the system. On the timeline Computer Weekly sets out, the assessments followed the deployment. The published material describes what the ministry could not show, and it says nothing about what the systems produced during the period under investigation.
Failure Pattern: automated surveillance and biometric systems were put into operation over people living in state accommodation, and the impact assessments required for them were completed late and found substantially incomplete and limited in scope.
Governance Principle: where the state runs automated surveillance over people in its care, the impact assessment should be complete before the system operates, and each processing action should be recorded so that what it actually did can be checked afterwards.
The reference implementation of ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.
Sources
- Ministry of Migration and Asylum receives administrative fine and GDPR compliance order following an own-initiative investigation (Hellenic Data Protection Authority, 3 April 2024)
- Ministry of Migration and Asylum receives administrative fine and GDPR compliance order following an own-initiative investigation by the Greek SA (European Data Protection Board)
- Greek government fined over AI surveillance in refugee camps (Computer Weekly, 9 April 2024)
- Greek Ministry fined over surveillance systems at asylum centres (Balkan Insight, 3 April 2024)