Showing posts with label financial intelligence unit. Show all posts
Showing posts with label financial intelligence unit. Show all posts

Monday, November 25, 2024

How my views on financial privacy have evolved over a decade

I began exploring the topic of financial privacy and payment anonymity in the early days of this blog. Over the past decade, my views have shifted significantly—here's how and why.

Rereading my earliest mentions of financial privacy, they now seem a bit... idealistic? extreme? For instance, in my 2014 post entitled Fedcoin, a central-bank issued digital currency, I suggested that the product should be 100% anonymous, like coins and banknotes.

Criminals would undoubtedly exploit unlimited anonymous digital currency, as I acknowledged in a 2018 article entitled Anonymous digital cash. But I figured that the bad guys would find their own ways to transact anyways, say through their own mafia-created payments system, so central banks may as well go forward with anonymous digital currency, the benefits to civil society of unlimited e-cash ultimately outweighing the cost.

I wouldn't support these same ideas today, or would at least modify them, as I'll show further down.

But idealistic and extreme aren't quite the right words. I think that I was right, at least when looking at things from a certain vantage point, but it was still early in my blogging career and I hadn't yet explored other vantage points

To be clear, financial privacy, or the ability to make transactions anonymously or near-anonymously, isn't just something that criminals require. It's crucial for regular folks, too, and in my earlier blog posts I spent a lot of time detailing why this is so. After a cashier dropped my card behind the counter (and potentially skimmed it?), I wrote that cash provides buyers with a "shield from everyone else involved in a transaction" in my 2016 post In praise of anonymous money. And I still agree with that, and to this day always pay with cash when the store I'm at feels a bit sketchy. I worry that this shield will disappear as cash usage continues to decline.

Civil society's need for private transactions isn't just a weird fringe view. In a 2018 entitled Money is privacy, I described the work being done on privacy and payments by Federal Reserve researchers Charles Kahn, James McAndrews, and William Roberds. Licit transactions can unintentionally evolve into a long-term relationship, they write, including clawbacks, extraterritorial rulings, and new forms of product liability. To boot, personal information linked to digital transactions can be stolen in data breaches.
 
According to the three Fed researchers, the ability to transact anonymously converts a potentially thorny transaction into a one-and-done relationship. Licit payments that might have otherwise been deemed too dangerous can proceed, the extra trade making the world better off. (See also my 2020 article Central banks are privacy providers of last resort.)

As for crypto, I've described blockchains as dystopian hellscapes or panopticons, because every single transaction is mapped out for all to see. That makes blockchains just awful places to carry out conventional business. Firms require a degree of secrecy in order to hide their corporate strategies and tactics from competitorsbut the medium doesn't permit secrets. Blockchains need more privacy. (See my 2022 post DeFi needs more secrecy, but not too much secrecy, and the right sort of secrecy). 

So what changed?

Starting in 2018, I focused more on studying fraud, including ransomware, tax evasion, and gift card schemes. I found gift card fraud particularly intriguing: semi-anonymous payment systems linked to Google Play and Apple iTunes have enabled an entire industry of scammers, including IRS and tech support fraudsters, to launder stolen funds. Network operators like Google and Apple, as well as major retailers such as Target and Walmart, quietly profit from all of this fraud. (See Gift Cards: When Good Products Do Bad Things [2021] and In-game virtual items as a form of criminal money [2019].)

Which led me to my next big truth: if privacy is crucial, so is the necessity of criminalizing money laundering.

Money launderers are the financial intermediaries who, knowing full well that a customer's funds are dirty, conduct transactions with them anyways, in a way designed to disguise its source.

The willful laundering of a criminal's money is an extension of the original crime, making a launderer just as morally and ethically culpable as the criminal they are helping. By facilitating the final release of illicit funds, the money launderer enables the crime to fulfill its purpose, completing the damage caused by the initial offense—be it theft, extortion, or human smuggling. This is why the launderer's actions deserve to be criminalized. (See A short and lukewarm defence of anti-money laundering standards from 2021).

The crime of money laundering bears a striking resemblance to the centuries-old crime of fencing—the art of accepting and redistributing stolen property. (See my 2024 post "I didn't launder the cash, your honor. The robot did") In earlier times, thieves were responsible for reselling their stolen goods themselves. However, by the 17th century, this task was often outsourced to specialized intermediaries, or 'fences.' At first, there was no legal term for this crime, but in 1692, England formally criminalized fencing, and deservedly so.

Thinking more about the crime of money laundering led me to become more critical of stablecoins, for instance. From 2014-2018 my articles on stablecoins were mostly neutral or positive, but now my posts focus on the fact that stablecoin issuers, by turning a blind eye to those using their platform, have allowed themselves to become launderers for all types of criminals. (Among others, see my 2019 post From unknown wallet to unknown wallet and my 2023 post Why do sanctioned entities use Tether?)

At this point, you may be able to see my conundrum.    

If, like fencing, money laundering should be criminalized (and indeed it is illegal in most parts of the world), that collides with my prior belief in the importance of financial privacy. After all, the only way for a banker, money transfer agent, or stablecoin issuer to be safe from a money laundering charge is to show that they did a good faith job collecting enough personal information to ensure that they weren't dealing with criminals. And giving up personal information is necessarily privacy-reducing.

One way to resolve my conundrum would have been to pick a side and advocate for it, but I think both sides are important, so I've generally tried to find a compromise. Most of my writing on the topic over the last five or six years has been trying to wrestle with where to draw the line between financial privacy and the crime of money laundering. 

My compromise position has generally advocated a privacy safe harbour for small day-to-day transactions. But anything above a certain monetary ceiling needs to be identified in order to avoid a money laundering charge.

Here are some examples of my often clumsy attempts to balance the two ideals:

Balancing the two ideals rather than taking an either/or approach has led me to adopt a more comparative approach to thinking about financial privacy. I've begun to analyze cross-country differences in the intensity of financial surveillance as conducted by national financial intelligence units. Canada, for instance, has chosen a balancing point that is far more in favor of financial privacy (and accordingly more accepting of money laundering) than the U.S. has, as illustrated in my 2024 post Your finances are being snooped on. Here's how.

So that's where I've landed after ten years of writing about privacy. Hard-core privacy advocates and civil libertarians would probably describe me as a sell-out or a wishy-washy centrist because I'm willing to compromise on financial privacy. Fair enough. But I do wonder how many privacy advocates would go so far as to call for an all-out decriminalization of money laundering. Doing so would maximize privacy, but surely no privacy advocate thinks that bankers who clean money for the mob should by allowed to walk free. We are probably closer than they think.

I look forward to seeing how my opinions evolve over the next ten years, as I'm sure they will. Thoughts or comments?

Thursday, July 11, 2024

Your finances are being snooped on. Here's how


We all have a pretty good idea that our finances are being snooped on, but most of us aren't quite able to articulate how. We know that we're being snooped on by two groups, corporations and the government. This post will focus on how the government surveils our transactions, because democratic governments generally (but certainly not always!) tell us ahead of time what information they will gather, and how the data will be used.

Governments snoop on law abiding citizens' financial data for good reasons  they are trying to trace the money in order to catch bad guys. The government has been given the power to collect this information without having to ask a judge for approval, say by requesting a search warrant. 

I think there is a degree of acceptance among citizens that some amount of warrantless financial snooping is okay, because it reduces crime. But as the intensity of surveillance increases it eventually reaches creepy territory, at which point most of us would prefer the brakes be applied.

Where is this line? I'm a committed comparativist. To get a good sense of how one is snooped on, and whether it has passed over the line to being creepy, one needs a reference point. So in this blog post, I'll compare how two groups of citizens  Americans and Canadians are being surveiled by their respective governments, so that both groups can better understand, by reference to each other, where they stand.

The first section focuses on the inflows of personal financial data from citizens to the government. The second section will focus on the outflows of data from the government to law enforcement.

***How citizens' personal financial data flows into the government***

Both the U.S and Canadian governments collect large amounts of financial data about their citizens. They do so by requiring banks and other financial institutions to record information about their customers and submit reports to the government about their customers' transactions when certain triggers have been met.

First, let's touch on the total amount of data being hoovered up. On this count, Canada far exceeds the U.S. In the 2022-23 reporting period, Canadian financial institutions submitted a total of 36 million reports to the government containing information about Canadians' financial transactions. That's almost one report per Canadian every year. 

Meanwhile, U.S. institutions sent 27.5 million reports to their government about Americans' financial dealings in 2023, a rate of around 0.1 report for every American, which is ten-times less intensive than in Canada. So based purely on the quantity of data collected, Canada seems to be closer to the "it's getting uncomfortable" level than the U.S. (See table below).

What accounts for this big difference in reporting intensity? In short, it's due entirely to cross-border wire transfers. In Canada, every electronic fund transfer leaving or arriving in Canada must be reported by banks to the government if it sums up to $10,000 or more. So if you've sent an $11,500 wire transfer from your Bank of Montreal account to your son or daughter who lives in London or Paris, congratulations, your name is in a Canadian government database. Or if you run a business and have received a $15,000 digital payment from a U.S. company for services rendered, your corporate data is sitting somewhere in an Ottawa government server.

If you're an American making a foreign wire transfer, your information will not get sent to a government database. The U.S. authorities do not require financial institutions to submit personal information on digital cross-border flows. (Mind you, they have been trying for some time to get the ability to collect this data.)

In the 2022-23 financial year, 27 million of these cross-border wire reports were submitted by Canadian banks, accounting for the lion's share of all 36 million reports submitted to the Canadian government that year.

Apart from cross-border transaction reporting, the nature of Canadian and U.S. eavesdropping is broadly similar.

Let's start with cash transaction reports, or CTRs. When a Canadian goes to their bank and deposits $10,000 or more in cash, the bank will generate a report that it sends to the Canadian government. U.S. banks report deposits and withdrawals of $10,000 in cash to the US government.

So if you're selling a used car and the buyer pays you $12,000 in banknotes, and you deposit that to your bank account, you're now in a government database, whether that be in Canada or the U.S.

Canadian banks generated 8 million CTRs in 2022-23 whereas U.S. banks generated 20.8 million in 2023. Pound for pound, Canadian banks submit more cash transaction reports to their government than U.S. banks, around 0.21 per Canadian compared to 0.06 per American. I'm not sure why. The threshold for reporting a cash transaction in Canada is lower in the U.S. (CAD$10,000 is worth around US$7,300) which may explain some of the difference? Dunno.

With CTRs and cross-border wire transfers, the invasiveness is kept relatively low thanks to the objective criteria that triggers a filing. Exceed the $10,000 threshold and at least you know ahead of time that your information is going to be recorded. A law-abiding citizen who is uncomfortable having their finances being collected by the government can choose to avoid sending cross-border payments or dealing in large amounts of cash. But this objectivity doesn't exist with the next type of report: those related to suspicious activities. 

On both sides of the border, financial institutions must submit reports about transactions deemed suspicious to their respective governments. If you've made a transaction that a bank deems to be suspicious, you'll never know that you've landed in a government database. That's because banks are prohibited from notifying their customers that their activity has been snitched on.  

The determination of what qualifies as suspicious involves a fair amount of subjectivity. Canada requires that financial institutions have a reasonable grounds to suspect that a transactions is linked to terrorism or money laundering before reporting it. That means that mere hunch won't cut it  a Canadian banker must be able to articulate a clear reason for suspicion. Mind you, there's no penalty for banks that fail to attach a specific reason to a report, so the reasonable grounds to suspect standard is often ignored. 

We know that many of these hunch-based reports end up in the government's database. Over the years the Office of the Privacy Commissioner of Canada has collected a list of reports that failed to reach the reasonable grounds to suspect standard, including one case in which some individuals were suspected simply because they had Middle Eastern passports:

From the Office of the Privacy Commissioner's 2017 audit of FINTRAC [source]

My reading of the U.S. requirements for reporting a suspicious transaction suggest a looser standard than in Canada. While U.S. bankers are encouraged to provide a specific red flag in their CTRs, the implementing regulations say they can still file a report if they merely "suspect" a transaction to be associated with money laundering or terrorism, which is a lower standard then the requirement to have a "reason to suspect."

In Canada, there is no size threshold for suspicious activity reporting: even a $50 payment can be reported by a bank. By contrast, the U.S. has set a $5,000 threshold before a suspicious action report must be filed. (When suspicious activity reports were first introduced to the U.S. in 1994, the government floated the idea of not including a threshold at all, as Canada would later do in 2001, but retreated because this would impose a "burden of reporting.")

This difference in thresholds suggests Canada should have a much higher intensity of suspicious transaction reporting than the U.S. Not so. Canadian banks generated 560,858 suspicious transaction reports in 2022-23, around 1.4 reports for every 100 Canadians. Compare this to the 4.6 million reports filed by U.S. banks in 2023, which also comes out to 1.4 reports per 100 Americans. So even though bankers in the U.S. are required to ignore small suspicious transactions below $5,000, they more than make up for it by reporting a larger proportion of transactions than Canadian bankers do. I can only guess why, but this may be due to the looser standard for suspicion, discussed above.

There are several other types of transactions that must be reported to the government, including large virtual currency reports in Canada and foreign bank and financial accounts reports (FBAR) in the U.S., but the volume of this sort of reporting isn't as significant as the other types already discussed, so I won't touch on them.

So to briefly sum up, pound for pound a Canadian is more likely to appear in their government's financial database than an American is. This is because Canadian financial institutions collect personal information linked to cross-border wire transfers the U.S. doesn't. The most privacy-invasive reports are suspicious ones. Compared to Canadian banks, U.S. banks are more trigger-happy when it comes to deeming a given transaction as suspicious, but the US$5,000 floor on reporting suspicious transactions somewhat mitigates this eagerness. 

Having dealt with what sorts of data flow in to the government, let's talk about what happens next with the data.    

***How personal financial data flows from the government to law enforcement***

The personal financial data accumulated by the two governments are managed by each nation's respective financial intelligent unit, or FIU. In Canada, this institution is known as the Financial Transactions and Reports Analysis Centre of Canada, or FINTRAC. In the U.S., the body that collects personal financial data is known as the Financial Crime Enforcement Network, or FinCEN.

It's here with the management of harvested financial data that the policies of the two countries really start to diverge.

To begin with, let's start with the length of time that data can be kept. In the U.S., FinCEN holds data indefinitely, so its database is forever growing. Canada allows FINTRAC to keep data for at least ten years and up to fifteen years, but after that FINTRAC must destroy any identifying information if it was not disclosed to law enforcement. Since most of FINTRAC's data is not disclosed, that means large amounts of data fall out of FINTRAC's database every year, and thus the amount of personal information collected grows at a slower rate than FinCEN's data hoard.

The differences between the two countries grows even wider when it comes to the question of who has access to citizens' financial data. In brief, U.S. law enforcement is granted broad access to the raw data whereas Canadian law enforcement's ability to see the data is strictly limited.

472 different U.S. law enforcement agencies at the Federal, state, and local levels have the ability to directly query FinCEN's database of CTRs, suspicious activity reports, and more. This amounts to around 14,000 law enforcement officers who can search through the personal financial data of American citizens. In 2023, these 14,000 users conducted 2.3 million searches using FinCEN's query tool.

FinCEN's data can also be downloaded in bulk form to the in-house servers of eleven different federal agencies, including the FBI, ICE, and the IRS. Bulk access (also known as Agency Integrated Access) means that the FBI, ICE, IRS, and eight other agencies don't need to use FinCEN's query tool. This bulk data can be access by another 35,000 agents. Alas, FinCEN doesn't track how many in-house searches were conducted by these agents in 2023, but I'd guess it's in the tens if not hundreds of millions.

By contrast, Canadian law enforcement agencies do not get direct access to FINTRAC's financial data trove. Instead, FINTRAC employs an internal force of a few hundred data analysts to parse the database for clues that suggest participation in money laundering or terrorist financing. Only when FINTRAC employees have attained a reasonable grounds to suspect that a pattern of transactions has crossed the line can they pass a report on to a Canadian law enforcement body, such as the RCMP or municipal police. This report is known as a financial intelligence disclosure and includes information like the name of the transactor, their address, telephone number, criminal record, and more.

FINTRAC submitted 2,085 of these disclosures to law enforcement in 2022-2023.

So to step back for a moment, tens of thousands of U.S. law enforcement officials conduct tens of millions of searches through Americans' personal financial data to get leads. In Canada, this same database can only be accessed a small number of FinCEN FINTRAC analysts, who selectively push a few thousand reports out to Canadian law enforcement each year. 

That's quite the contrast. Put differently, unlike their U.S. equivalents the RCMP, Sûreté du Québec, Ontario Police Police, and other policy agencies do not have the power to pull personal financial data willy-nilly from the government's database. This means far fewer eyeballs on Canadian financial records. As far as protecting the financial privacy of citizens, the Canadian access model does a better job. The U.S. access model is friendlier to law enforcement and stopping crime.

A disadvantage (or advantage, depending on your tolerance for being watched) of the American system is it allows the 11 agencies with bulk access to create "data cocktails"  personal financial data downloaded from FinCEN spiked with their own data sources  in order to better investigate suspects. For instance, according to a 2009 report from the Government Accountability Office, the FBI incorporates bulk FinCEN suspicious activity reports into its Investigative Data Warehouse along with 50 other data sets from different sources. The IRS's Reveal System, portrayed below, ingests FinCEN reports along with tax data to conduct more complex investigations.

The IRS's Reveal System, which ingests FinCEN CTRs along with other non-FinCEN data [source]

I don't know if the FBI and IRS data cocktails still exist, and in what form, but they certainly give a flavor of what sorts of broad access law enforcement can get to personal financial records in the U.S.

By contrast, Canadian law doesn't allow for U.S.-style data cocktails. An agency like the RCMP can't mix FINTRAC's store of personal financial data with their own bespoke data sources because the RCMP is prohibited from pulling raw CTRs, cross-border wire transfer reports, and suspicious transaction reports out of FINTRAC. Only FINTRAC gets to determine what information gets pushed out to the RCMP.

This firewall isn't accidental. As Horst Intscher, a former director of FINTRAC explains, a degree of privacy protection was purposefully built into FINTRAC's original design: "Because of the very broad range of information that the [Proceeds of Crime (Money Laundering) and Terrorist Financing Act] makes it possible for us to receive from reporting entities, it was determined at the original passage of the legislation that protections had to be built, so it would not be construed that there was a flow-through of massive amounts of personal information directed to law enforcement agencies."

In other words, FINTRAC was designed to prevent the likes of the RCMP from creating an FBI-style Investigative Data Warehouse. 

However, the wall imposed between Canadian law enforcement and FINTRAC does have a degree of porosity, enough to provide law enforcement with an indirect way for pulling data out of FINTRAC. If the RCMP is investigating a suspected money launderer, it can submit information about the suspect to FINTRAC in the form of a voluntary information record. For example, it might say that "Joe Blow and his sister-in-law Martha are the subjects of an investigation for drug trafficking and money laundering, and we just thought you should know that." This new data becomes part of FINTRAC's database, against which FINTRAC's agents will check all other data. If the agents spot a match, and it meets the bar for a "reasonable grounds for suspicion", then they must send the RCMP a disclosure containing the relevant personal financial information.  

In 2022-23 FINTRAC received 2,550 voluntary information records from Canada’s law enforcement and national security agencies (including from members of the public), a large number of these eventually boomeranging back to law enforcement in the form of a disclosure. How many? The head of FINTRAC once claimed that "65% to 70%" of FINTRAC's ultimate disclosures to law enforcement are triggered by voluntary information submitted by law enforcement, which hints at how porous the wall is.

----

That sums up my comparison of the inflows and outflows of personal financial data to the U.S. and Canadian governments. This is just a cursory analysis. There are all sorts of other vectors across which to compare the scope of the two nations' data collection efforts that I haven't explored. I've focused on the factors that I think are the most important.

Readers from other countries may be curious to find out about their own FIUs to determine where they stand relative to Canada and the U.S. If so, leave your findings in the comments. My Australian readers, for instance, may be interested to note that their government collects far more private information than the U.S. and Canada combined. AUSTRAC, the Australian FIU, collected 192 million transaction reports in 2023, an astonishing 7 reports per Australian!  This is because AUSTRAC receives information on all cross-border wires, with no lower threshold.

At the outset of this article I suggested that many of us would tolerate some loss of privacy in order to make it easier for the police to catch criminals. A few of us will accept a large loss. Others will not tolerate even the smallest infringement on privacy. An individual's line in the sand is very much a personal matter. I'm going to leave it to the reader to decide which country (if either) approaches the right balance. Is Canada too lax relative to the U.S.? Does the firewall we've erected between the cops and the trove of financial information give criminals free rein? Or does the U.S. not sufficiently respect privacy? Should the FBI and its sister agencies lose some of their unfettered access to Americans' personal financial data?