
  • The Hellenic Data Protection Authority fines the Ministry of Migration and Asylum for the “Centaurus” and “Hyperion” systems with the largest penalty ever imposed to a Greek public body

    Two years ago, in February 2022, Homo Digitalis had filed (https://homodigitalis.gr/en/posts/10874) a complaint against the Ministry of Immigration and Asylum for the “#Centaurus” and “#Hyperion” systems deployed in the reception and accommodation facilities for asylum seekers, in cooperation with the civil society organizations Hellenic League for Human Rights and HIAS Greece, as well as the academic Niovi Vavoula.

    Today, the Hellenic Data Protection Authority identified significant GDPR violations in this case by the Ministry of Immigration and Asylum and decided to impose a fine of €175.000 euro – the highest ever imposed against a public body in the country.

    The detailed analysis of the GDPR highlights the significant shortcomings that the Ministry of Immigration and Asylum had fallen into in the context of preparing a comprehensive and coherent Data Protection Impact Assessment, and demonstrates the significant violations of the GDPR that have been identified and relate to a large number of subjects who have a real hardship in being able to exercise their rights.

    Despite the fact that the DPA remains understaffed, with a reduced budget, facing even the the risk of eviction from its premises, it manages to fulfil its mission and maintain citizens’ trust in the Independent Authorities. It remains to be seen how long the DPA will last if the state does not stand by its side.

    Of course, nothing ends here. A high fine does not in itself mean anything. The Ministry of Immigration and Asylum must comply within 3 months with its obligations. However, the decision gives us the strength to continue our actions in the field of border protection in order to protect the rights of vulnerable social groups who are targeted by highly intrusive technologies.

    You can read our press release here: https://homodigitalis.gr/wp-content/uploads/2024/04/PressRelease_%CE%97omoDigitalis_Fine-175.000-euro_Hellenic_Data_Protec

    You can read Decision 13/2024 on the Authority’s website here: https://www.dpa.gr/el/enimerwtiko/prakseisArxis/aytepaggelti-ereyna-gia-tin-anaptyxi-kai-egkatastasi-ton-programmaton


    • Griechenland soll Strafe für Überwachung in Grenzcamps zahlen

      Wie weit darf die EU bei der Überwachung von Asylsuchenden an ihren Grenzen gehen? Griechenland testet das in neuen Lagern auf den Ägäischen Inseln. Nun hat die griechische Datenschutzbehörde dafür eine Strafe verhängt. Bürgerrechtler:innen hoffen auf eine Entscheidung mit Signalwirkung.

      Doppelter „Nato-Sicherheitszaun“ mit Stacheldraht. Kameras, die selbst den Basketballplatz und die Gemeinschaftsräume rund um die Uhr im Blick haben. Drohnen sorgen für Überwachung aus der Luft. Das Lager auf Samos, das die griechische Regierung 2021 mit viel Getöse eröffnet hat, gleicht eher einem Gefängnis als einer Erstaufnahme für Asylsuchende, die gerade in Europa gelandet sind.

      Das Überwachungssystem, das in diesem und vier weiteren Lagern auf den griechischen Inseln für „Sicherheit“ sorgen soll, heißt Centaurus. Die Bilder aus den Sicherheitskameras und Drohnen laufen in einem Kontrollzentrum im Ministerium in Athen zusammen. Bei besonderen Situationen sollen auch Polizeibehörden oder die Feuerwehr direkten Zugang zu den Aufnahmen bekommen. Mit dem System Hyperion wird der Zugang zum Lager kontrolliert: biometrischen Eingangstore, die sich nur mit Fingerabdrücken öffnen lassen.

      Für den Einsatz dieser Technologien ohne vorherige Grundrechtsprüfung hat das Ministerium nun eine Strafe kassiert. Die griechische Datenschutzaufsicht sieht einen Verstoß gegen Datenschutzgesetze in der EU (DSGVO). In einem lang erwarteten Beschluss belegte sie vergangene Woche das Ministerium für Migration und Asyl mit einem Bußgeld von 175.000 Euro.
      Erst eingesetzt, dann Folgen abgeschätzt

      Zwei konkrete Punkte führten laut Datenschutzbehörde zu der Entscheidung: Das Ministerium hat es versäumt, rechtzeitig eine Datenschutz-Folgenabschätzung zu erstellen. Gemeint ist damit eine Bewertung, welche Auswirkungen der Einsatz der Überwachung auf die Grundrechte der betroffenen Personen hat. Es geht um die Asylsuchenden, die in den Lagern festgehalten werden, aber auch Angestellte, Mitarbeitende von NGOs oder Gäste, die das Lager betreten.

      Eine solche Abschätzung hätte bereits vor der Anschaffung und dem Einsatz der Technologien vollständig vorliegen müssen, schreibt die Aufsichtsbehörde in ihrer Entscheidung. Stattdessen ist sie bis heute unvollständig: Ein Verstoß gegen die Artikel 25 und 35 der Datenschutzgrundverordnung, für die die Behörde eine Geldbuße in Höhe von 100.000 Euro verhängt.

      Zusätzlich wirft die Behörde dem Ministerium Intransparenz vor. Dokumente hätten beispielsweise verwirrende und widersprüchliche Angaben enthalten. Verträge mit den Unternehmen, die die Überwachungssysteme betreiben, hätte das Ministerium mit Verweis auf Geheimhaltung gar nicht herausgegeben, und damit auch keine Details zu den Bedingungen, zu denen die Daten verarbeitet werden. Wie diese Systeme mit anderen Datenbanken etwa zur Strafverfolgung verknüpft sind, ob also Aufnahmen und biometrische Daten auch bei der Polizei landen könnten, das wollte das Ministerium ebenfalls nicht mitteilen. Dafür verhängte die Aufsichtsbehörde weitere 75.000 Euro Strafe.
      Ministerium: Systeme noch in der Testphase

      Das Ministerium rechtfertigt sich: Centaurus und Hyperion seien noch nicht vollständig in Betrieb, man befinde sich noch in der Testphase. Die Aufsichtsbehörde habe nicht bedacht, dass „die Verarbeitung personenbezogener Daten nicht bewertet werden konnte, bevor die Systeme in Betrieb genommen wurden“. Hinzu kämen Pflichten zur Geheimhaltung, die sich aus den Verträgen mit den Unternehmen hinter den beiden Systemen ergeben.

      Die Behörde hat das nicht durchgehen lassen: Rein rechtlich mache es keinen Unterschied, ob ein System noch getestet wird oder im Regelbetrieb sei, schriebt sie in ihrer Entscheidung. Die Abschätzung hätte weit vorher, nämlich bereits bei Abschluss der Verträge, vorliegen müssen. Noch dazu würden diese Verstöße eine große Zahl an Menschen betreffen, die sich in einer besonders schutzlosen Lage befänden.

      Abschalten muss das Ministerium die Überwachungssysteme allerdings nicht, sie bleiben in Betrieb. Es muss lediglich binnen drei Monaten den Forderungen nachkommen und fehlende Unterlagen liefern. Das Ministerium kündigt an, die Entscheidung rechtlich überprüfen und möglicherweise anfechten zu wollen.
      Geheimhaltungspflicht keine Ausrede

      „Die Entscheidung ist sehr wichtig, weil sie einen sehr hohen Standard dafür setzt, wann und wie eine Datenschutz-Folgenabschätzung erfolgreich durchgeführt werden muss, sogar vor der Auftragsvergabe“, sagt Eleftherios Helioudakis. Er ist Anwalt bei der griechischen Organisation Homo Digitalis und beschäftigt sich mit den Auswirkungen von Technologien auf Menschenrechte. Eine Beschwerde von Homo Digitalis und weiteren Vereinen aus dem Jahr 2022 hatte die Untersuchung angestoßen.

      Helioudakis sagt, die Entscheidung mache deutlich, dass mangelnde Kommunikation mit der Datenschutzbehörde zu hohen Geldstrafen führen kann. Außerdem sei nun klar: Das Ministerium kann Vertragsklauseln zum Datenschutz nicht aus Gründen der Geheimhaltung vor der Datenschutzbehörde verbergen, denn für deren Untersuchungen ist die Geheimhaltungspflicht aufgehoben – wie es die DSGVO vorsieht. Das Urteil der Behörde beziehe sich zudem erst mal nur auf die Mängel bei der Einführung der Systeme, so der Bürgerrechtler. Es könnten also neue Fälle bei der Datenschutzbehörde anhängig gemacht werden.

      Die Sanktionen sind laut der Hilfsorganisation Hias die höchsten, die die Datenschutzbehörde je gegen den griechischen Staat verhängt hat. In der Summe fallen die Strafzahlungen allerdings gering aus. Sind die Datenschutzregeln der EU wirklich das geeignete Instrument, um die Rechte von Asylsuchenden zu schützen? Eleftherios Helioudakis sagt ja. „Die gesetzlichen Bestimmungen der Datenschutz-Grundverordnung sind Instrumente, mit denen wir die Bestimmungen zum Schutz personenbezogener Daten praktisch durchsetzen können.“ Es gebe keine richtigen und falschen Ansätze. „Wir können die uns zur Verfügung stehenden juristischen Instrumente nutzen, um unsere Strategie zu bündeln und uns gegen übergriffige Praktiken zu wehren.“

      Die Lager auf den Ägäischen Inseln werden vollständig von der EU finanziert und gelten als „Modell“. Nach ihrem Vorbild plant die EU in den kommenden Jahren weitere Lager an ihren Außengrenzen zu errichten. Die Entscheidung der griechischen Datenschutzaufsicht wird von der Kommission vermutlich mit Interesse verfolgt. Sie macht deutlich, unter welchen Voraussetzungen Überwachungstechnologien in diesen Camps eingesetzt werden können.


  • Greek data watchdog to rule on AI systems in refugee camps

    A forthcoming decision on the compliance of surveillance and security systems in Greek refugee camps could set a precedent for how AI and biometric systems are deployed for ‘migration management’ in Europe

    Greece’s data protection watchdog is set to issue a long-awaited decision on the legality of controversial high-tech surveillance and security systems deployed in the country’s refugee camps.

    The Greek Data Protection Authority’s (DPA) decision, expected by the end of the year, concerns in part a new multimillion-euro Artificial Intelligence Behavioural Analytics security system, which has been installed at several recently constructed refugee camps on the Aegean islands.

    The system – dubbed #Centaur and funded through the European Union (EU) – relies on algorithms and surveillance equipment – including cameras, drones, sensors and other hardware installed inside refugee camps – to automatically detect purported threats, alert authorities and keep a log of incidents. Hyperion, another system that relies on biometric fingerprint data to facilitate entry and exit from the refugee camps, is also being examined in the probe.

    Centaur and #Hyperion came under investigation in March 2022, after several Greek civil society organisations and a researcher filed a complaint to the Greek DPA questioning the legality of the programs under Greek and European laws. The Greek DPA’s decision could determine how artificial intelligence (AI) and biometric systems are used within the migration management context in Greece and beyond.

    Although the data watchdog’s decision remains to be seen, a review of dozens of documents obtained through public access to documents requests, on-the-ground reporting from the islands where the systems have been deployed, as well as interviews with Greek officials, camp staff and asylum seekers, suggest the Greek authorities likely sidestepped or botched crucial procedural requirements under the European Union’s (EU) privacy and human rights law during a mad rush to procure and deploy the systems.

    “It is difficult to see how the DPA will not find a breach,” said Niovi Vavoula, a lecturer at Queen Mary University of London, who petitioned the Greek DPA alongside Greek civil society organisations Homo Digitalis, The Hellenic League for Human Rights, and HIAS Greece.

    She said “major shortcomings” identified include the lack of appointment of a data protection officer at the Greek Migration Ministry prior to the launch of its programs.

    Security systems a hallmark of new EU camps

    Centaur and Hyperion are hallmarks of Greece’s newest migrant facilities, also known as Closed Controlled Access Centres (CCACs), which began opening in the eastern Aegean in 2021 with funding and supervision from the European Commission (EC). Greek authorities have lauded the surveillance apparatus at the revamped facilities as a silver-bullet solution to the problems that plagued previous makeshift migrant camps in Greece.

    The Centaur system allows authorities to monitor virtually every inch of the camps’ outdoor areas – and even some indoor spaces – from local command and control centres on the islands, and from a centralised control room in Athens, which Greece’s former migration minister Notis Mitarachi unveiled with much fanfare in September 2021.

    “We’re not monitoring people. We’re trying to prevent something bad from happening,” Anastasios Salis, the migration ministry’s director general of ICT and one of the self-described architects of the Centaur system, told me when I visited the ministry’s centralised control room in Athens in December 2021. “It’s not a prison, okay? It’s something different.”

    Critics have described the new camps as “prison-like” and a “dystopian nightmare”.

    Behind closed doors, the systems have also come under scrutiny by some EU authorities, including its Fundamental Rights Agency (FRA), which expressed concerns following a visit to one of the camps on Samos Island in May 2022.

    In subsequent informal input on Greece’s refugee camp security measures, the FRA said it was “concerned about the necessity and proportionality of some of the measures and their possible impact on fundamental rights of residents” and recommended “less intrusive measures”.

    Asked during the control room tour in 2021 what is being done to ensure the operation of the Centaur system respects privacy laws and the EU’s General Data Protection Regulation (GDPR), Salis responded: “GDPR? I don’t see any personal data recorded.”

    ‘Spectacular #experimentation’

    While other EU countries have experimented with myriad migration management and surveillance systems, Greece’s refugee camp deployments are unique.

    “What we see in Greece is spectacular experimentation of a variety of systems that we might not find in this condensed way in other national contexts,” said Caterina Rodelli, a policy analyst at the digital rights non-profit Access Now.

    She added: “Whereas in other European countries you might find surveillance of migrant people, asylum seekers … Greece has paved the way for having more dense testing environments” within refugee camps – particularly since the creation of its EU-funded and tech-riddled refugee camps.

    The #Samos facility, arguably the EU’s flagship camp, has been advertised as a model and visited by officials from the UK, the US and Morocco. Technology deployments at Greece’s borders have already been replicated in other European countries.

    When compared with other Mediterranean states, Greece has also received disproportionate funding from the EU for its border reinforcement projects.

    In a report published in July, the research outfit Statewatch compared commission funds to Greece between 2014 and 2020 and those projected to be paid between 2021 and 2027, finding that “the funding directed specifically towards borders has skyrocketed from almost €303m to more than €1bn – an increase of 248%”.

    Greece’s Centre for Security Studies, a research and consulting institution overseen by the Greek minister of citizen protection, for example, received €12.8m in EU funds to develop border technologies – the most of any organisation analysed in the report during an eight-year period that ended in 2022.

    Surveillance and security systems at Greek refugee camps are funded through the EU’s Covid recovery fund, known formally as the European Commission’s Recovery and Resilience Facility, as well as the Internal Security Fund.
    Early warnings

    At the heart of the Greek DPA probe are questions about whether Greece has a legal basis for the type of data processing understood to be required in the programs, and whether it followed procedures required under GDPR.

    This includes the need to conduct data protection impact assessments (DPIAs), which demonstrate compliance with the regulation as well as help identify and mitigate various risks associated with personal data processing – a procedure the GDPR stipulates must be carried out far in advance of certain systems being deployed.

    The need to conduct these assessments before technology deployments take place was underscored by the Greek DPA in a letter sent to the Greek migration ministry in March 2022 at the launch of its probe, in which it wrote that “in the case of procurement of surveillance and control systems” impact studies “should be carried out not only before their operation, but also before their procurement”.

    Official warnings for Greece to tread carefully with the use of surveillance in its camps came as early as June 2021 – months before the opening of the first EU-funded camp on Samos Island – when the FRA provided input on the use of surveillance equipment in Greek refugee camps, and the Centaur project specifically.

    In a document reviewed by Computer Weekly, the FRA wrote that the system would need to undergo “a thorough impact assessment” to check its compatibility with fundamental rights, including data protection and privacy safeguards. It also wrote that “the Greek authorities need to provide details on the equipment they are planning to use, its intended purpose and the legal basis for the automated processing of personal data, which to our understanding include sensitive biometric data”.
    A botched process?

    However, according to documents obtained through public record requests, the impact assessments related to the programs were only carried out months after the systems were deployed and operational, while the first assessments were not shared with the commission until late January 2022.

    Subsequent communications between EU and Greek authorities reveal, for the first time, glaring procedural omissions and clumsy efforts by Greek authorities to backpedal into compliance.

    For example, Greece’s initial assessments of the Centaur system covered the use of the CCTV cameras, but not the potentially more sensitive aspects of the project such as the use of motion analysis algorithms and drones, a commission representative wrote to Greek authorities in May 2022. The representative further underscored the importance of assessing “the impact of the whole project on data protection principles and fundamental rights”.

    The commission also informed the Greek authorities that some areas where cameras were understood to have been placed, such as common areas inside accommodation corridors, could be deemed as “sensitive”, and that Greece would need to assess if these deployments would interfere with data protection, privacy and other rights such as non-discrimination or child rights.

    It also requested more details on the personal data categories being processed – suggesting that relevant information on the categories and modalities of processing – such as whether the categories would be inferred by a human or an algorithm-based technology – had been excluded. At the time, Greek officials had reported that only “physical characteristics” would be collected but did not expand further.

    “No explanation is provided on why less intrusive measures cannot be implemented to prevent and detect criminal activities,” the commission wrote, reminding Greece that “all asylum seekers are considered vulnerable data subjects”, according to guidelines endorsed by the European Data Protection Board (EDPB).

    The FRA, in informal input provided after its visit to the Samos camp in May 2022, recommended basic safeguards Greece could take to ensure camp surveillance systems are in full compliance with GDPR. This included placing visible signs to inform camp residents and staff “about the operation of CCTV cameras before entering a monitored area”.

    No such signs were visible in the camp’s entry when Computer Weekly visited the Samos camp in early October this year, despite the presence of several cameras at the camp’s entry.

    Computer Weekly understands that, as of early October, procedural requirements such as impact assessments had not yet been finalised, and that the migration ministry would remain in consultation with the DPA until all the programs were fully GDPR-compliant.

    Responding to Computer Weekly’s questions about the findings of this story, a Greek migration ministry spokesperson said: “[The ministry] is already in open consultation with the Greek DPA for the ‘Centaur’ and ‘Hyperion’ programs since March 2022. The consultation has not yet been completed. Both of these programs have not been fully implemented as several secondary functions are still in the implementation phase while the primary functions (video surveillance through closed circuit television and drone, entry – exit through security turnstiles) of the programs are subject to continuous parameterisation and are in pilot application.

    “The ministry has justified to the Greek DPA as to the necessity of implementing the measure of installing and operating video surveillance systems in the hospitality structures citing the damage that the structures constantly suffer due to vandalism, resulting in substantial damage to state assets … and risking the health of vulnerable groups such as children and their companions.”

    The commission wrote to Computer Weekly that it “do[es] not comment on ongoing investigations carried out by independent data protection authorities” and did not respond to questions on the deployment of the systems.

    Previous reporting by the Greek investigative outlet Solomon has similarly identified potential violations, including that the camp programs were implemented without the Greek ministry of migration and asylum hiring a data protection officer as required under the GDPR.
    Lack of accountability and transparency?

    The commission has said it applies all relevant checks and controls but that it is ultimately up to Greece to ensure refugee camps and their systems are in line with European standards.

    Vavoula, the researcher who was involved in the Greek DPA complaint, said the EU has been “funding … these initiatives without proper oversight”.

    Saskia Bricmont, a Belgian politician and a Member of the European Parliament with the Greens/European Free Alliance, described unsuccessful efforts to obtain more information on the systems deployed at Greece’s camps and borders: “Neither the commission nor the Greek authorities are willing to share information and to be transparent about it. Why? Why do they hide things – or at least give the impression they do?”

    The European Ombudsman recently conducted a probe into how the commission ensures fundamental rights are being respected at Greece’s EU-funded camps. It also asked the commission to weigh in on the surveillance systems and whether it had conducted or reviewed the data protection and fundamental rights impact assessments.

    The commission initially reported that Greece had “completed” assessments “before the full deployment of the surveillance systems”. In a later submission in August, however, the commission changed its wording – writing instead that the Greek authorities have “drawn up” the assessments “before the full deployment” of the tools.

    The commission did not directly respond to Computer Weekly’s query asking it to clarify whether the Greek authorities have “completed” or merely “drawn up” DPIAs, and whether the commission’s understanding of the status of the DPIAs changed between the initial and final submissions to the European ombudsman.

    Eleftherios Chelioudakis, co-founder of the Greek digital rights organisation Homo Digitalis, rejected the suggestion that there are different benchmarks on deployment. “There is no legal distinction between full deployment of a system or partial deployment of a system,” he said. “In both cases, there are personal data processing operations taking place.”

    Chelioudakis added that the Greek DPA holds that even the mere transmission of footage (even if no data is recorded/stored) constitutes personal data processing, and that GDPR rules apply.
    Check… check… is this camera on?

    Greek officials, initially eager to show off the camps’ surveillance apparatus, have grown increasingly tight-lipped on the precise status of the systems.

    When visiting the ministry’s centralised control room at the end of 2021, Computer Weekly’s reporter was told by officials that three camps – on Samos, Kos and Leros islands – were already fully connected to the systems and that the ministry was working “on a very tight timeframe” to connect the more than 30 remaining refugee camps in Greece. During a rare press conference in September 2022, Greece’s then-migration minister, Notis Mitarachi, said Centaur was in use at the three refugee camps on Samos, Kos and Leros.

    In October 2022, Computer Weekly’s reporter was also granted access to the local control room on Samos Island, and confirmed that monitoring systems were set up and operational but not yet in use. A drone has since been deployed and is being used in the Samos camp, according to several eyewitnesses.

    Officials appear to have exercised more caution with Hyperion, the fingerprint entry-exit system. Computer Weekly understands the system is fully set up and functioning at several of the camps – officials proudly demonstrated its functions during the inauguration of the Kos camp – but has not been in use.

    While it’s not yet clear if the more advanced and controversial features of Centaur are in use – or if they ever will be – what is certain is that footage from the cameras installed on several islands is being fed to a centralised control room in Athens.

    In early October, Computer Weekly’s reporter tried to speak with asylum seekers outside the Samos camp, after officials abruptly announced the temporary suspension of journalist access to this and other EU-funded camps. Guards behind the barbed wire fence at the camp’s gate asked the reporter to move out of the sight of cameras – installed at the gate and the camp’s periphery – afraid they would receive a scolding call from the migration ministry in Athens.

    “If they see you in the cameras they will call and ask, ‘Why is there a journalist there?’ And we will have a problem,” one of the guards said. Lawyers and others who work with asylum seekers in the camp say they’ve had similar experiences.

    On several occasions, Computer Weekly’s reporter has asked the Greek authorities to provide proof or early indications that the systems are improving safety for camp residents, staff and local communities. All requests have been denied or ignored.

    Lawyers and non-governmental organisations (NGOs) have also documented dozens of incidents that undermine Greek officials’ claims of increased safety in the tech-riddled camps.
    Unmet promises of increased security

    In September 2022, a peaceful protest by some 40 Samos camp residents who had received negative decisions on their asylum claims escalated into a riot. Staff evacuated the camp and police were called in and arrested several people.

    Lawyers representing those accused of instigating the brawl and throwing rocks at intervening police officers said they were struck by the absence of photographic or video evidence in the case, despite their clients’ request to use the footage to prove their innocence.

    “Even with all these systems, with all the surveillance, with all the cameras … there were no photographs or video, something to show that those arrested were guilty,” said Dimitris Choulis, a lawyer with the Human Rights Legal Project on Samos.

    Asked about the incident, the Samos camp director at the time explained that the system has blind spots and that the cameras do not cover all areas of the camp, a claim contrary to other official statements.

    Choulis’s organisation and the legal NGO I Have Rights have also collected testimonies from roughly a dozen individuals who claim they were victims of police brutality in the Samos CCAC beginning in July 2022.

    According to Nikos Phokas, a resident of Leros Island, which houses one of the EU-funded facilities, while the surveillance system has proven incapable of preventing harm on several occasions, the ability it gives officials in Athens to peer into the camps at any moment has shifted dynamics for camp residents, staff and the surrounding communities. “This is the worst thing about this camp – the terror the surveillance creates for people. Everyone watches their backs because of it.”

    He added the surveillance apparatus and the closed nature of the new camp on Leros has forced some camp employees to operate “under the radar” out of fear of being accused of engaging in any behaviour that may be deemed out-of-line by officials in Athens.

    For example, when clothes were needed following an influx of arrivals last summer, camp employees coordinated privately and drove their personal vehicles to retrieve items from local volunteers.

    “In the past, it was more flexible. But now there’s so much surveillance – Athens is looking directly at what’s happening here,” said Catharina Kahane, who headed the NGO ECHO100PLUS on Leros, but was forced to cut down on services because the closed nature of the camp, along with stricter regulations by the Greek migration ministry, made it nearly impossible for her NGO to provide services to asylum seekers.

    Camp staff in one of the island facilities organised a protest to denounce being subjected to the same monitoring and security checks as asylum seekers.

    Residents of the camps have mixed views on the surveillance. Heba*, a Syrian mother of three who lodged an asylum claim in Samos and was waiting out her application, in early October said the cameras and other security measures provided a sense of safety in the camp.

    “What we need more is water and food,” said Mohammed*, a Palestinian asylum seeker who got to Samos in the midst of a recent surge in arrivals that brought the camp’s population to nearly 200% capacity and has led to “inhumane and degrading conditions” for residents, according to NGOs. He was perplexed by the presence of high-tech equipment in a refugee camp that has nearly daily water cuts.

