The intelligence services want more power, but time and again show they can’t handle it
The oversight body for the intelligence services concludes in its latest report that the services don't have their data management in order. They're not complying with the law. That's highly problematic, because they collect data not only on so-called targets, but also on millions of ordinary citizens like you and me.
A big shout out to our volunteers for translating our articles into English!
Our data isn't safe with the services
You'd think that the importance of proper data management would be paramount at the intelligence services. But nothing could be further from the truth. The oversight body investigated how the services handle so-called bulk data. These are enormous mountains of data, mostly belonging to people they aren't investigating. Think of your name, phone number, location data, social media data, or email traffic between, say, neighbors or your soccer club.
A few highlights from the report — the full report from the oversight body is available online: bulk datasets are once again being retained for unlawfully long periods. Employees without the proper authorization have access to these mountains of sensitive data. Moreover, bulk datasets are being used for purposes other than intelligence, such as training computer models, which is not permitted. The oversight body also notes that the use of bulk datasets has increased significantly in recent years, further underscoring the urgency of handling them properly.
Because of how the services handle data, our information is less secure elsewhere too
The services obtain this data from government agencies where citizens are required to provide it — think of the Municipal Personal Records Database (BRP), flight data shared with the police, or the vehicle registration database. As a society, we should be able to trust that our data is safe and well protected there. That makes it all the more troubling that this report shows this protection is inadequately safeguarded within the services. Another way the services acquire data is by purchasing it. By not shying away from buying data from hackers who obtained it illegally, they are also financially contributing to the insecurity of our data.
Our data is being used to train AI that keeps an eye on us
Once they have the data, they use it, among other things, to develop computer models. It appears these models are being used to develop AI that can be deployed to collect and analyze even more data — without us having any say in it, and without it being allowed. Finally, the investigation reveals that on multiple occasions employees of the services have gained access to data from a sensitive dataset without being authorized to do so.
Things have been going wrong for a long time
An earlier report from the oversight body, dating back to 2020, already showed that the AIVD and MIVD did not have their data management in order. Data on millions of citizens whom they weren't investigating was being retained for unlawfully long periods. As Bits of Freedom, we filed a complaint — and won, which meant this data had to be deleted immediately. Apparently, no lessons were learned.
This report shows the importance of effective and binding oversight
This report clearly demonstrates why effective, binding oversight is necessary. Only then can citizens and politicians gain insight into what the intelligence services are actually doing in practice, form an opinion about it, and hold them politically accountable.
The Wiv 2017 — the law regulating the work of the intelligence services — is due to be revised soon. This report raises questions that will be front and center in the upcoming amendment. Should oversight be weakened, as the services want, or should it be strengthened instead? Is training AI a sufficient reason to process the private communications of millions of people? Should the services be allowed to buy datasets from hackers who obtained the data illegally? Or collaborate with companies because they aren't bound by the same legislation? And how do you deal with services that break the law time and time again?
Will the new law provide sufficient safeguards to ensure that our data is safe again and that the services stay within the boundaries of the law? Bits of Freedom is deeply concerned. The law will be made public in mid-August, and from that moment everyone will have six weeks to speak up. We certainly will. Will you?