citizenship in one territory can make a fresh request in another Member State. Member States currently do not inform each other of rejected applicants, not even of those rejected for posing a security risk. Security and investor residence schemes in the EU In contrast with procedures related to the acquisition of citizenship, some obligations exist under EU law in terms of security checks to be carried out prior to the issuance of visa or a residence permit to foreign investors, in order to ensure they are not a threat for public policy and public security, including of other Member States. Such checks are based on the Schengen acquis and are compulsory for those Member States that are bound by this acquis. In particular, pursuant to Article 25(1) of the Convention implementing the Schengen Agreement, a Member State considering issuing a residence permit must systematically carry out a search in the Schengen Information System (SIS)81. Where a Member State considers issuing a residence permit to a person for whom an alert has been issued for the purposes of refusing entry, it must first consult the Member State issuing the alert and has to take account of its interests. While the study found that in the national laws of the Member States concerned, the check of public policy and public security is generally included as a ground for refusal (or nonrenewal) of the permit, it also identified both a lack of available information and an important level of discretion in the way Member States approach security concerns 82. This has led to some problematic cases, as highlighted also by other reports83. In that context, the Commission has already proposed to upgrade the Visa Information System, which – in conjunction with the proposal for the Interoperability Regulation84 – will introduce mandatory searches in relevant EU and international security databases85 at the external borders for all issued residence permits and long-term visas. Information on residence permit applications, which were refused by a Member State on security grounds, would also be stored and checks can be subsequently made against it. 81 82 83 84 85 The SIS is currently in operation in 26 EU Member States (only Ireland and Cyprus are not yet connected to SIS), though with different access rights, and four Schengen Associated Countries (Switzerland, Norway, Liechtenstein and Iceland). While Bulgaria and Romania are not yet part of the area without internal border checks (the 'Schengen area'), they have had full access to the SIS since August 2018. Croatia, which is also not part of the Schengen area, has still some restrictions regarding its use of Schengen-wide SIS alerts for the purposes of refusing entry into or stay in the Schengen area. The United Kingdom operates the SIS but, as it has chosen not to join the Schengen area, it cannot issue or access Schengen-wide alerts for refusing entry or stay into the Schengen area. Ireland is carrying out preparatory activities to connect to the SIS, but, as is the case for the United Kingdom, it is not part of the Schengen area and it will not be able to issue or access Schengen-wide alerts for refusing entry or stay. Cyprus is not yet connected to the SIS. Security checks relate generally to the background of the applicants and the origin of the funds. Authorities in charge of the management of the investor residence schemes rely on police forces and intelligence services to check the background of the applicants (Bulgaria, Estonia, Spain, Croatia, Cyprus, Hungary, Portugal, Slovakia) and on authorities in charge of health and employment policies and on the competent authorities for the civil status of the applicant. These checks relate mainly to the criminal record of the applicants and the veracity of the document provided by the applicants. See Transparency International, ibid, note 5, p. 37 and Overview Study, ibid, note 4, p. 75. See note 68. Namely in the VIS, SIS, EES, ETIAS, ECRIS, as well as Europol and INTERPOL databases. 13

Select target paragraph3