Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Summing Up: EPO Administrative Council Still Asleep at the Wheel

Previous parts:



EPO's council heads



Summary: AC chair Josef Kratochvíl (CZ) and deputy chair Borghildur Erlingsdóttir (IS) seem to be unperturbed by the sell-out of the EPO's "digital sovereignty" taking place on their watch

For quite some time now it has been an open secret that the data protection framework at the EPO is not fit for purpose.



Back in the spring of 2014 the Bavarian Data Protection Commissioner, Dr Thomas Petri, carried out his own independent investigation into the matter following a complaint and he came to the conclusion that "nobody was really in charge".

Together with his colleague the Federal German Data Protection Commissioner, Andrea Vosshoff, Dr Petri raised serious concerns about the state of data protection at the EPO. However, their urgent pleas for reform fell on deaf ears.

"So it's difficult to see how such a manifestly deficient framework which hadn't changed in the meantime could be considered meet the even more stringent standards imposed by GDPR in 2018."When the EU GDPR came into effect in May 2018, Battistelli attempted to pull the wool over the eyes of the EPO's stakeholders and the general public by issuing a self-serving communiqué (warning: epo.org link) proclaiming the EPO's commitment to "ensuring the highest level of data protection" and announcing that "a recent audit report has confirmed a close alignment with the GDPR legal framework".

The only problem here is that Dr Petri, a serious and well-regarded independent expert on data protection law found that the EPO's data protection framework failed to measure up to pre-GDPR standards in 2014.

So it's difficult to see how such a manifestly deficient framework which hadn't changed in the meantime could be considered meet the even more stringent standards imposed by GDPR in 2018.

As a matter of fact, a report commissioned by the EPO staff union SUEPO from external legal experts in 2016 came to the conclusion that the EPO's data protection framework was not compliant with EU data protection standards and was in urgent need of a radical overhaul.

It's worth citing a few passages from that report for the record:

The European Union does, quite rightly, take data protection seriously. Yet the framework at the EPO gives rise to significant cause for concern, which has also been expressed by the national data protection authorities of the main host state – the Federal Republic of Germany.

The Guidelines for the Protection of Personal Data in the European Patent Office (‘EPO DataProtection Guidelines’ or ‘EPO DPG’), which were unilaterally adopted by the President and which entered into force on 1st April 2014. The current EPO DPG appear to fail to meet the standards of both EU data protection law and the national data protection laws of the Contracting States, in particular, the host countries of the EPO. As such, they do not provide a satisfactory framework for safeguarding the data protection rights of data subjects within the Office.

A key component of the EU data protection framework and which is reflected in the national data protection laws of all EU member states is the existence of an independent oversight body; yet this is conspicuously absent at the EPO. Indeed, the deficiencies in the existing system of data protection established by the EPO's Data Protection Guidelines have come to the attention of the national data protection authorities in the host state of the EPO's headquarters (Germany) and have even been the subject of a discussion in the Legal Affairs Committee of the German Federal Parliament (Bundestag).


In the meantime, very little has changed at the EPO apart from the arrival of a new Data Protection Officer via "the talent pipeline from the EUIPO in Alicante” in April 2020 as previously reported by Techrights.

"Unfortunately for all concerned, the Administrative Council appears to have completely abdicated its responsibilities in this regard."When all is said and done, the task of ensuring that the EPO's data protection framework is fit for purpose is a matter of fundamental legal and political significance which lies within the responsibility of the governing body of the organisation, namely the Administrative Council.

This is not something which can be simply delegated to the EPO management to deal with on its own initiative.

Unfortunately for all concerned, the Administrative Council appears to have completely abdicated its responsibilities in this regard.

The Council gives the distinct impression that it is "asleep at the wheel" as the senior management of the EPO proceeds to sell out the organisation's "digital sovereignty" to a US multinational corporation behind its back.

EPO cruise
Once again, the EPO's Administrative Council seems to be asleep at the wheel



Of course the Council has only got itself to blame for the precarious and potentially disastrous situation which has now developed.

After all they were the ones who permitted their sense of judgement to be corrupted by the former Council Chairman Battistelli and agreed to follow his proposal to disband the independent Audit Committee in 2011.

With the benefit of hindsight it is now apparent that, by acting as an accessory to Battistelli's Machiavellian intrigues and acquiescing in the disbandment of the Audit Committee, the Council followed a misguided course of action which has had far-reaching and detrimental effects on the integrity of EPO governance.

It comes as no real surprise to see that - having deprived itself of any genuinely independent source of advice by means of an ignominious act of self-mutilation at the urging of Battistelli - the Council is now unable to react in an robust manner to defend the EPO's "digital sovereignty" and to ensure that the organisation's data protection framework is fit for purpose and truly GDPR-compliant.

These are matters of fundamental importance and legitimate concern not only to EPO staff but also to all other stakeholders, including the general public.

Unfortunately the current Council under the stewardship of its chair, Josef Kratochvíl (Czech Republic), and deputy chair, Borghildur Erlingsdóttir (Iceland), does not appear to appreciate the seriousness of the issues and stake and seems unlikely to take appropriate remedial action unless and until something dramatic happens to jolt it out of its complacent slumber.

Recent Techrights' Posts

Over at Tux Machines...
GNU/Linux news
The Myth of an Aging (or Dying) GNU/Linux Leadership
Self-fulfilling prophecies as a tactic?
 
Links 07/12/2023: More EPO Patents Squashed, More Pfizer COVID-19 Vaccine "Glitches" Found
Links for the day
Still Not 'Canceled'
Ted Ts'o, Jan Kara, Linus Torvalds last month
Google is Googlebombing the Term "Gemini"
Could Google not pick a name that's already "taken"?
Links 06/12/2023: Bitcoin Rebound, China Downgraded by American Firm, Yahoo! Layoffs Again
Links for the day
Shooting the Messenger Using Bribes and Secrecy Bonds
We seem to live in a world where accountability for the rich and well-connected barely exists anymore
Links 06/12/2023: Many More December Layoffs
Links for the day
IRC Proceedings: Tuesday, December 05, 2023
IRC logs for Tuesday, December 05, 2023
PipeWire 1.0: Linux audio comes of age
Once upon a time, serious audio users like musicians and audio engineers had real trouble with Linux
This is How 'Linux' Foundation Presents Linux to the World
Right now it even picks Windows over Linux in some cases
Links 05/12/2023: Microsoft's Chatbot as Health Hazard
Links for the day
There's Nothing "Funny" About Attacking Free Speech and Software Freedom
persistent focus on the principal issues is very important
Professor Eben Moglen Explained How Software Patent Threats Had Changed Around 2014 (Alice Case) and What Would Happen Till 2025
clip aged reasonably well
GNU/Linux Adoption in Africa, a Passageway Towards Freedom From Neo-Colonialism
Digi(tal)-Colonialism and/or Techolonialism are a thing. Can Africa flee the trap?
CNN Contributes to Demolition of the Open Web
Reprinted with permission from Ryan Farmer
Eben Moglen on Encryption and Anonymity
The alternate net we need, and how we can build it ourselves
Yet More Microsofters Inside the Board of Mozilla (Which Has Just Outsourced Firefox Development to Microsoft's Proprietary Prison)
Do you want a browser controlled (and spied on) by such a company?
IRC Proceedings: Monday, December 04, 2023
IRC logs for Monday, December 04, 2023
GNU/Linux Now Exceeds 3.6% Market Share on Desktops/Laptops, According to statCounter
things have changed for Windows in China
Over at Tux Machines...
GNU/Linux news
Links 05/12/2023: Debt Brake in Germany and Layoffs at Condé Nast (Reddit, Wired, Ars Technica and More)
Links for the day