Showing posts with label data retention. Show all posts
Showing posts with label data retention. Show all posts

Friday, 20 April 2012

Curbing unwholesome desires

Despite her various extracurricular activities - some of which find an outlet on this blog - it cannot be disputed that Matron is first and foremost a lawyer. This means that sometimes, when a particularly complex legal issue comes along, she can't help abusing blogger's privilege for a proper, in-depth legal analysis. So this post comes with the health warning that it is likely to put anyone in deep slumber who isn't similarly freakishly endowed with what Tom Hanks, in the movie Philadelphia, vomit-inducingly called "a love for the law".

Having given those who come out in bumps at this thought the opportunity to google something more interesting, let us have a look at an extremely interesting decision by the EU's Court of Justice that was published yesterday*. The case of Bonnier Audio and others v Perfect Communication Sweden AB concerned claims by several Swedish publishing companies against a Swedish ISP, ePhone, for disclosure of the name and address of ePhone users who were suspected of illegal filesharing. As is common in these cases, the publishers had collected the users’ IP addresses by monitoring activity on certain filesharing sites and required ePhone to disclose the users’ identity so that they could bring infringement proceedings against them. In the UK, such claims for information disclosure would be made through a legal instrument called a Norwich Pharmacal Order, in Sweden, this is permitted on the basis of section 53(c) of the Swedish Copyright Law.

In reality, in many cases, ISPs will willingly hand over the data once a court order is made as they have nothing to gain from opposing it other than incurring unnecessary legal costs. However, in this case, ePhone challenged the order on grounds arising under the 2006 Data Retention Directive.

ePhone argued that the Directive specifically prohibits the disclosure of retained communications data (because that is what this information is) to anyone for purposes other than the prevention, detection, investigation and prosecution of serious crime. In particular, Article 4 of the Data Retention Directive requires member states to ensure that data retained in accordance with the Directive are provided only to the competent national authorities (mainly security and law enforcement agencies) in specific cases and in accordance with national law.

However, this defence was ultimately unsuccessful and instead, the Swedish court of first instance granted the publishers’ application. Both, ePhone and the publishers appealed the case at various stages in the proceedings until the Swedish Supreme Court decided to make a reference to the ECJ. In particular it asked the ECJ for guidance on two questions:

1. Does the Data Retention Directive preclude the application of a national provision (in this case section 53(c)) under which ISPs may be ordered to disclose communiations data about their users to rightsholders for the purpose of IP enforcement?

2. Does it matter that the member state in question has not yet implemented the Data Retention Directive?

In brief, the ECJ ruled that (a) the Data Retention Directive (2006/24/EC) does not prevent member states from enacting such laws and that (b) it was irrelevant to the main proceedings that Sweden had not yet transposed the Data Retention Directive.

On first reading, Matron was extremely disappointed by this decision, which seemed a step back after rather encouraging recent rulings on ISPs’ role in the monitoring and filtering of online activity, for example in SABAM v Netlog. On second reading, Matron began to wonder whether the court could in fact have decided in any other way. But on third and most recent reading, questions are beginning to crop up, of which Matron wondered whether they should have been answered, even if they weren’t asked.

Lets tackle it step by step:

1. The thing that can be ascertained most clearly is that the ECJ is not going to depart from its 2008 decision in Promusicae any time soon. In that case, it had ruled that while Community law does not require member states to oblige internet service providers to disclose details of suspected file-sharers to enable a copyright owner to bring civil proceedings, it does also not prevent them from doing so, provided that the law in question allows the national courts to strike a fair balance between the IP rights of rightsholders and the privacy rights of individuals. In the Bonnier case, the ECJ examined the Swedish law and found that section 53(3) fulfilled the Promusicae requirements.

2. The ECJ’s ruling that the Data Retention Directive would not have precluded member states from adopting section 53(c) (or from permitting rightsholders to use it to obtain communications data from ISPs) even if the Directive had been implemented in Sweden was probably – technically – also correct. Even the Advocate General, who in his own opinion on the Bonnier case has taken a much wider view of the issues in question, had come to that conclusion. The Data Retention Directive clearly only envisaged disclosure of communications data to public authorities so that it could be argued, as the ECJ did, that the disclosure to private entities does not come within its remit.

3. This means that the ECJ’s ruling, at least in this respect, cannot be blamed on the quality of its interpretation of the law, but on the quality of the law itself. Maybe, just maybe, lawmakers should have asked themselves whether or not a provision should have been included in the Data Retention Directive that would have limited access to the retained data to access by law enforcement agencies solely for the purposes of law enforcement. But the truth, of course, is that campaigners DID in fact ask for such a provision at the time, but that they were widely ignored, with the then UK Home Secretary, Charles Clarke, admitting openly in Parliament that he saw no reason why such data, once retained, should not be available to rightsholders for IP enforcement purposes. Going forward this means that member states are still free to adopt similar laws – mainly on the basis of Article 8 of the 2004 IP Enforcement Directive – without having to fear that the ECJ will use the Data Retention Directive to strike them down.

4. The question the ECJ has not answered is whether this means that the ECJ has now given card blanche to rightsholders to make applications for the disclosure of any kind of data held by ISPs, including data that are in existence solely because the ISP is required to retain them by EU or national laws (rather than because they need them for their own business purposes). This is a question of “landgrabs” where the mere existence of a data pool generates unwholesome desires in third parties, who would enthusiastically like to get their mittens on that data, if only they could find a legal way to do so. This is a point that has exercised Matron for several years now and where she has come to the firm conclusion that the only way to protect personal data from those “landgrabs” is by making sure that the data pools do not come into existence at in the first place. In her opinion, any arguments – including arguments put forward by members of the tech community – that data protection law should only concern itself with regulating the use of personal data and not its collection, fall at that initial hurdle. "Build it and they will come", as they say, and anyone who argues otherwise is highly likely to be unpleasantly surprised a few years down the line.

5. So how should the ECJ have addressed this question in the context of Bonnier and has it really made such a fist of it? Well, yes and no. And yes again. At first glance, the court does not seem consider at all the purpose for which the requested data was initially retained as a factor in its decision on whether or not member states should have the right to grant rightsholders access to that data. This could suggest that it does not care and that the right it has granted to member states is wide-ranging.

6. On the other hand, as the German civil society organisation AK Vorrat points out on its blog (in German), the ECJ has made it clear in its decision, that it “is starting from the premiss that the data at issue in the main proceedings have been retained in accordance with national legislation, in compliance with the conditions laid down in Article 15(1) of Directive 2002/58”, and that “this is a matter which it is for the national court to ascertain”.

7. This list is enumerative, meaning that any national laws granting rightsholders access to communications data must comply not only with the conditions laid down in Article 15(1) of the E-Privacy Directive (which includes the right to derogate from the general requirement to erase communications data when they are no longer required by ISPs for their own business purpose – this is the derogation on which the Data Retention Directive was based), they must also comply with other national laws! And EU member states must, of course, have national laws in place that implement the 1995 Data Protection Directive. In order to determine whether national laws that allow rightsholders access to retained communications data comply with the EU legal framework, we must therefore examine whether those laws comply with the provisions of the Data Protection Directive.

8. The way Matron sees it, a core principle of the Data Protection Directive is that the processing of personal data is only permitted for “specified, explicit and legitimate purposes” and that it must not be “further processed” in a way “incompatible with the original purpose” (Article 6(1)(b), Data Protection Directive). This “purpose restriction principle” applies to all forms of processing except where the further processing is for “historical, statistical or scientific purposes”. Member states are only permitted to impose restrictions on this general rule in very limited cases when such a restriction constitutes a “necessary measures to safeguard” an important public interest (national security, defence and public security, to name but a few, see Article 13, Data Protection Directive). The protection and enforcement of IP rights is specifically not included in that list of public interests, so it is difficult to see how a member state can justify adopting a law that allows the “further processing” by ISPs or rightsholders of data for IP enforcement purposes, when that data was originally collected by ISPs for purposes of billing and traffic management.

9. Some may argue that Article 7(c) of the Data Protection Directive permits a data controller to process data if such processing is necessary for "compliance with a legal obligation to which the controller is subject". This, they say, leaves the door open for member states to adopt all kinds of laws that legitimise “futher processing”. However, as the Article 29 Working Party has pointed out on several occasions, ontologically, Article 7 is merely setting out the conditions on which the first data protection principle (to process data fairly and lawfully, see Article 6(1)(a), Data Protection Directive) is met. That principle and the purpose restriction principle contained in Article 6(1)(b) stand side by side. One does not override the other. A legal obligation referred to in Article 7(c) should therefore merely legitimise the first instance of processing, i.e. the collection of the communications data by the ISP, but not any “further processing” by him or any third party.

10. This is an unpopular interpretation of Articles 6 and 7, and indeed the recently proposed Data Protection Regulation that is designed to replace the Data Protection Directive includes a provision that would permit member states to legitimise “further processing” through national laws (see Article 5(4) of that draft Regulation). However, it is almost impossible to say at this stage whether Article 5(4), which would effectively remove the purpose restriction principle from the EU data protection framework, will make it into the final version of the Regulation given that it is strenuously opposed by the EDPS, the Article 29 Working Party and many privacy advocates. In addition, for the time being courts would still have to decide cases on the basis of existing law.

11. On an objective reading of the Data Protection Directive, it therefore seems to Matron that any member state trying to adopt a law that mandates the disclosure (i.e. further processing) for the purpose of IP enforcement of communications data initially collected for billing purposes would fail to implement the Data Protection Directive correctly and would (or at least should) have to expect a legal challenge before the ECJ on that basis.

12. As for the question of whether the ECJ should have made this clear, well, in the court’s defence, this wasn’t the question the national court had asked. Already, it is obvious from the decision that the ECJ had to do a certain amount of reinterpretation of the original reference to get to the heart of the question that, in its view, the national court actually wanted to have answered. Maybe the judges felt that there was only so much they could do in this context – particularly in light of the fact that the court already receives a fair amount of stick for allegedly answering questions it isn’t asked. Judges are political animal too, after all.

13. However - and this is where the Advocate General’s opinion is much more useful than the ECJ’s decision – the court could probably have made it clearer that the national courts will have to consider the framework put in place by the Data Protection Directive when deciding whether or not section 53(c) is compatible with EU law. This is a massive oversight and may very well lead to the Swedish courts skirting this issue entirely when the case comes back to them for review. If that happens, it is impossible to say how long we would have to wait for another suitable case that would allow the ECJ to clarify the situation.

One can only hope that ePhone’s lawyers will make sure that this doesn’t happen.







* It should be stressed that this is Matron's reading of the decision and than she actively welcomes dissent on this. The judgement is a complicated piece and more may need to be said.

Jedi Knights 1 : 2 Empire

Fellow privacy advocates may agree that it was a funny old day yesterday for our lot. As the saying goes, things tend to come along in threes , and yesterday this is exactly what happened.

SfS2012

To start with the good stuff, Matron spent the afternoon at the excellent “Scrambling for Safety” conference hosted by the LSE and organised by the Open Rights Group, fipr and Privacy International to kick-start a nationwide campaign against the UK government’s latest surveillance brainchild, the Communications Capabilities Development Programme. And an excellent conference it was too despite that fact that much of the preaching was done to a very receptive choir. This was not the organisers’ fault – Matron was reliably informed that enourmous energies had been expended trying to get people from different backgrounds and with different views to speak on the subject.

But when even a senior cop (Sir Chris Fox QPM, first President of the Association of Chief Police Officer) condemns the proposals as unworkable and unnecessary, when the guys from the Home Office prefer to pull up the draw bridge, and when the Labour Party (possibly acutely aware of the embarrassing fact that the proposals are a carbon copy of the Interception Modernisation Programme they themselves proposed in 2009) fails to respond to the invitation, who else is there to speak out on behalf of a project that could cost the country billions, violate the fundamental rights of millions of citizens and have no beneficial effect whatsever? The people who are likely to make a mint from flogging the technology – first to the UK, then to other “benevolent” regimes? Well, yeah, now there’s a conversation that is likely to happen in the spirit of openness and full and frank disclosure. Not!

But leaving that aside, Matron has nothing to add to her own recent post on the CCDP and fellow blogger Paul Bernal has already expertly summarised the SfS2012 conference. The conference was the start of a campaign that, Matron still feels, at a political level in the UK is ultimately winnable. So please concerned people of all ages and political pursuasions, join the fight, support one of the groups mentioned above by giving your time, expertise or even just money and help prevent this from happening.

Come fly with me (well, maybe not…)

The second thing that happened yesterday was less enjoyable. Matron is speaking, of course, about the European Parliament's decision to approve the international agreement between the EU and the US on the collection and transfer to the US Department for Homeland Security of the passenger names records of all citizens boarding a plane to the US from an EU member state. This agreement has been controversial for years and much more information than Matron could ever provide in this short space can be found on the website of European Digital Rights (EDRi). However, a few words on the procedural aspects of this decision.

Matron can’t say that the result of the EP’s vote has come as a surprise to her. With regard to matters of privacy and surveillance a pattern has been emerging here for some time where the EP – seemingly more concerned about its own role in the legislative process than the issues at stake – makes an almighty fuss about privacy and safeguards and the impossibility of it all until someone lets it onto the playing field to kick the ball around for a bit, after which it quietly returns to the bench with a content smile and lets those who really run the show get on with it.

Of course, this damning judgement does not apply to ALL MEPs, and Matron must particularly commend the work of , and the stance taken by, Sophie In’t Veld (ALDE, NL), who was the rapporteur for the LIBE committee which had recommended that the agreement should be rejected and who reportedly withdrew her name from the report after the vote.

However, the EP’s role in these matters is becoming almost as much of a trigger for privacy campaigners’ frustration as the inevitable outcomes of the various legislative proposals, almost all of which promote what Bruce Schneier calls the false dichotomy of privacy v security. MEPs should therefore ask themselves whether they are doing their own reputation any favours in the long run, if they never grasp the opportunity to stand up – and be seen to stand up – against the whimseys of their political paymasters.

The EP’s powers in the legislative process were increased in the Lisbon Treaty specifically with the aim of ensuring democratic controll and accountabilty. It is currently quite blantantly not fulfilling that role in many, many cases.

Bonnier Audio v Perfect Communication Sweden AB

Speaking of EU institutions that “could do better”: before she swanned off to her conference yesterday, Matron had the dubitable pleasure of having to write up the ECJ’s decision in Bonnier Audio v Sweden.

This decision was expected to provide some clarity on whether IP rightsholders should be allowed to demand the disclosure from ISPs of data identifying those ISPs' users for the purpose of bringing claims for illegal filesharing against those users. The best (and briefest) answer to this question may very well be that the ECJ - unhelpfully - has left many questions unanswered. However, Matron has made a stab at a fuller account of the judgement in a separate post for those with a masochistic interest in the lengthy and complicated analysis of ECJ judgements.

The end is nigh?

So what to make of this day? Is there a clear direction discernible of whither we are headed in the area of information privacy? Is it all doom and gloom? Is the end of civilisation as we know it imminent?

Well, the best one can probably say for all these developments is that they show that legislators, law enforcement agencies, security services, rightsholders and online providers are not allowed to ride roughshot over individuals' rights without there being at least a great deal of opposition, albeit that this opposition comes from a fairly small number of people. However, as SfS panellist, David Davies MP pointed out during his panel yesterday, that small number of people is endowed with a disproportionate amount of skill, knowledge and expertise as well as the willingness to put it to good use. We are also quite stubborn.

So maybe things are not as bad as they sometimes feel and maybe that move to the Outer Hebrides can be put off for a little while longer. As any good lawyer would say, it all depends. On a bad day, the temptation to do nothing and watch reruns of the Big Bang Theory instead is amost irrisistable. On a good day, Matron tries to remember the words of her favourite philospher, Albus Dumbledore, when asked whether opposition to Lord Voldemort would necessarily be in vain:

"[W]hile you may only have delayed his return to power, it will merely take someone else who is prepared to fight what seems a losing battle next time – and if he is delayed again, and again, why, he may never return to power."

And on that note, good night and good luck, fellow conspirators!

Tuesday, 17 April 2012

Back to the future?

One of the “joys” of getting older is the realisation that nothing is ever really new and that almost everything that happens is bound to come round again in your lifetime. The contribution of networked technology to this time-honoured process seems to be the speed with which, these days, history repeats itself. At the same time when the average person’s memory and attention span seems to be contracting due to the overload of information to which we are all exposed, fashions - of the clothing and political type - seem to be coming full circle more quickly than ever before.

While Matron could go on about the way in which our current government seems to be obsessed with re-enacting the 80s (Royal Wedding, check; riots in the streets, check; sending visible "goodwill" in the form of aircraft carriers to small islands near South America, check), or about the horror she feels when mint green dungarees are staring her in the face from the pages of the Observer off a Sunday morning, her most recent deja vu actually stems from something closer to her own heart. Namely, the outrage caused a few weeks ago by the governments “new” proposals for extending the police and security service’ powers to carry out surveillance of electronic communications.

Snappily dubbed the Communications Capabilities Development Programme (CCDP), it proposes – in a nutshell – the expansion of existing requirements for the retention of, and access to, communications data to data generated by social media services and others. As well informed observers and privacy obsessives of any kind quickly noted, there are uncanny similarities between this project and Labour’s doomed “Interception Modernisation Programme” which had to be dumped in 2009 in the face of mounting opposition, mounting costs and an increased understanding even by politicians that the technical difficulties that developers would have to overcome would not be would not be conquered any time soon. However, what the security services want, the security services eventually get, so Matron knows very few people who were really surprised when this particular ball was fetched from its hiding place in the long grass and kicked back into play.

As those who know Matron in the flesh are aware, when stories like these break, she tends to express a desire to move to a wood cabin in the Outer Hebrides, armed only with a sawn-off shotgun and a box full of beans. It was therefore not without a certain irony that the sofa in the holiday cottage where she watched the news reports about the CCDP had a view of the Western Isles. Alas, holidays end, and it’s still bl**dy cold up there in Northern Scotland, so until it warms up a bit, Matron has opted for adding her two cents’ worth.

There is very little to be said about the CCDP that has not already been said on ORG’s most excellent wiki on the subject. Others, like Paul Bernal, have analysed the likely attitudes of the UK political parties to renewed endeavours to push through this massive expansion of surveillance. Within a UK context, both sides are busy preparing for yet another big fight and the sound of sharpening knives on Matron’s Twitter feed is almost palpable.

Matron has no idea whether this (Coalition) government stands any realistic chance of getting a law adopted that managed to defeat the previous government while it had a substantial majority. She has to admit that she is not quite so pessimistic about this as Paul Bernal, who thinks that all three parties have good reasons to vote this through. Agreed, it will take a good hard fight to prevent it, long nights spent burning the midnight oil, hours of fruitless discussions and the likely disillusionment of yet another generation of campaigners for a free and open internet. However, the crux of the matter lies in the level of attention that this proposal currently attracts. And on that count, at least, the opponents have a slight advantage as tech and law journalists seem to choose to give this matter prominence. This may even be one of the increasingly rare cases where good journalism (rather than the kind that works off the press release) prevails.

However, what if we win this? Then what? Will that stop the government – and more importantly the security services – from craving the “precious”? Will it heck. And this is where Matron thinks that we could all do with revisiting history in an attempt to prevent its repeat. In particular, the CCDP should by no means be seen solely as a UK legislative project but should be put in context of developments currently going on at European level.

Connecting the dots

As many readers will be aware, the UK government is not the only actor currently on stage pensively staring at a skull. The DG Home of the European Commission is at this very moment engaged in an impact assessment of whether or not changes should be made to the EU Data Retention Directive and what, if any, those changes should be.

The Directive was pushed through the EU legislative process – almost as an emergency measure – in late 2005 on the basis of shortcuts, backroom deals and a blatant disregard for both popular opinion and fundamental human rights. Since then, the Directive and the national laws trying to implement it have encountered numerous hurdles in the form of constitutional court judgements questioning their compatibility with the right to privacy, national parliaments refusing to transpose all or part of the Directive and a more or less obstructive tech industry. What was meant to be adopted as a harmonising measure has led to some of the most fractured legal environment ever and one that is now actively threatening to impact on the online industry.

Matron has commented on these developments several times already, but with the CCDP now on the horizon, more needs to be said:

Timing

First, the timing of the publication of the CCDP proposals (the official "official announcement" is still expected for the Queen's Speech in May) is unlikely to be a coincidence. If, as rumour still has it, the EU Commission is going to adopt a proposal for a revised Data Retention Directive as early as September of this year, the CCDP could, and should, be seen as the UK both drawing a line in the sand early and setting out their shopping list.

As many others will remember, last time round, the Labour government - having already legislated for wide-ranging access provisions in the Regulation of Investigatory Powers Act 2000 - battled to get a mandatory communications data retention requirement adopted in the UK against considerable resistance by ISPs, the Lords and the media for almost four years before they quietly policy-laundered the whole shebang in Brussels.

The advantages of this approach are clear: the British media is notoriously focused on what is going on in Westminster and almost pathologically averse to reporting anything that happens in Brussels unless it is about something like the bad Europeans dictating the shape of “our” bananas. This may therefore well happen again.

Choice of options

Secondly, the Commission has allegedly already commissioned a study as part of its impact assessment for a revised DR Directive. Among the options said to be under consideration for a revised Directive is the option of "expanding the collection of communications data". This does not bode well. Although most of us will be hoping that the review will give effect to the various constitutional court decisions across the EU that criticised the current Directive, it is always dangerous to untie a legislative bundle. Stuff happens!

This makes it even more important that we finally get an ECJ decision on the Irish High Court reference which raises the human rights implications of the existing DR laws. Fortunately, it seems as if the High Court has now finally come out of its hiatus and made the reference in January. But given the ECJ timetable, this may yet be too late.

Political will and power

Thirdly, the hard core of opposition to the DR Directive, both within and outwith the political classes, currently comes from Germany, which is also - as we are frequently reminded - the EU's biggest economy and the member state (bar possibly Austria) with the biggest privacy chip on their shoulder. It is therefore likely that the German position on this – in the European Parliament and the Council – will be of the utmost importance when this is going to be decided.

Much of the political resistance rests on the shoulders of Justice Minister Leutheuser-Schnarrenberger, a declared opponent of DR who was one of the claimants in the by now famous German constitutional court challenge before her party joined the German coalition government, but who, to her credit, has continued to man the barricades after she was appointed to her current job. Alas, she is a Liberal Democrat MP and although Matron has not lived in the country for years, from what her German friends tell her, the German Lib Dem's chances of getting enough votes to even get back into the Bundestag come the next German election (October 2013) are as slim, if not slimmer, as those of their British counterparts. Word on the street has it, they may even go the way of the dodo.

While one should never pay too much homage to the power of one single person to change the ways of the world, one should also not underestimate the problems their absence can cause. Once Leutheuser-Schnarrenberger is gone, German political resistance to DR is likely mellow considerably. There is, of course, that constitutional court decision, but that will not protect us against the collection of new traffic data, it will merely provide an upper limit for retention periods and access safeguards - in Germany, not the UK!

Timing revisited

Similarly, if the speed with which the last DR Directive was pushed through is anything to go by, the final discussions/negotiations of a revised Directive may actually coincide with both the looming end of Commissioner Malstroem's period in office and the next European Parliament elections (summer/autumn 2014).

That is never a good thing as it tends to lead to "fire sales" in the corridors of power in Brussels. We've seen this with the Telecoms Package (where, oddly enough, it worked partly in our favour) and Commission employees Matron spoke to in Brussels in January already voiced this as a concern with regard to the new Data Protection Regulation which may face a similar challenge. So this is something that we need to bear in mind from a campaigning point of view.

Overall, it is therefore most important to remember that regardless of any political wrangling that we will have to go through in the UK (and it goes without saying that we should oppose this harebrained threat to civil liberty strenuously), we should bear in mind that with a reasonably vigilant British press, the House of Lords, loud-mouthed voters and stubborn, cost-averse ISPs, the government's chances of getting anything substantial past the UK Parliament are infinitely slimmer than their chances of "outsourcing" this to the EU in what may well turn out to be a parallel legislative process.

What is more, from a political point of view, the latter is a win-win. If loose here, but are successful in Brussels, they can then come back to Westminster with hangdog eyes and say, "So sorry, chaps, but we have to implement this now, Brussels told us so".

This may make Matron sound like a cynical and disillusioned old hag, but her guess would be that there is a plan to this effect somewhere in a drawer in Whitehall, even if it is marked "Plan B". The Home Office and the security services are used to playing the long game. The fact that those involved in the pushback will be roughly the same people (at civil society level) who are also going to be engaged in fighting on several other fronts (including trying to get a decent version of the Data Protection Regulation adopted) at roughly the same time, is not helping matters either. Most human brains only have so much capacity.

So nipping this in the bud over here would be great, but it won't be enough. We need more brains, we need a wider horizon and we need to build alliances in the EU on this and quickly. For that we need individuals in the UK (including lawyers, techies, journalists, campaigners) willing to spend some time and to get their head around rather complicated technologies, legal frameworks, lobbying strategies and political tactics.

On Thursday, 19 April, the good folks at Privacy International, ORG, fipr and the LSE are organising a workshop called “Scrambling for Safety” where many of these issues will be discussed. The line-up is stellar and the need to cooperate is clear. If you are at all interested in becoming involved please register here or follow it on Twitter (#sfs2012).

Matron may even see you there.

Thursday, 15 July 2010

An opening salvo?

After many weeks of joyful distractions, Matron just spent a few days concentrating on the day job and, among other things, dutifully worked her way through the EU Working Party’s Report on the implementation of the Data Retention Directive. At the risk of teaching grandmothers to suck the proverbial eggs, that is the small innocuous piece of EU legislation that requires EU member states to impose an obligation on its telco providers and ISPs to retain all data relating to the telephone call made and e-mails sent by us, the Great Unwashed. Sender, addressee, time of transmission, location of transmission – you get the picture. As will the law enforcement authorities and selected others who may access that data. The full picture. Of all of us.

While the WP’s report does not include the comprehensive condemnation of the Directive that many were hoping for, it makes for interesting reading. Of course, the easy explanation for the lack of condemnation may possibly be that there was nothing to condemn as yet. According to the report, only a few member states did provide the requested information regarding the number of requests submitted to providers, the cases where the requested information was provided and those where the provider was unable to make available the requested data. Nor is data available about the time elapsed between the date on which the data were stored and the date on which the authorities requested transmission of said data. As the WP rightly points out, this lack of information makes it somewhat difficult to evaluate a) whether the prescribed retention periods are realistic and b) whether the mandatory retention of traffic data is actually necessary to combat crime and terrorism. In an ideal world both of these questions should obviously have been asked before the Directive was adopted, but when did evidence-based policy making last get in the way of a good lobbying campaign (the British DEAct debacle is a point in case)?

The fact that the questions are asked only now, when the Commission is seriously considering either revoking or at least substantially amending the Directive, may make for some amusing debates. Matron wonders in whose favour this lack of information will be interpreted. Will member states pipe up that it is far too early to even consider a revocation, given that we do not yet know, whether the sodding thing worked in the first place? Or will the Commission - as it should properly do - remind law enforcement authorities that the burden of proof of showing that retention is necessary is on them. No statistics, no further retention? That would be the day.

But while we wait for this issue to resolved, here’s a short summary of what Matron considers to be the highlights of today’s report:

1. Very interestingly, the WP interprets the DR Directive as a derogation from the general requirement on providers to erase all traffic data when it is no longer required for billing purposes. It takes this to mean that the list of data to be retained under Article 5 of the Directive is exhaustive and that member states must not require ISPs to retain any additional data categories not mentioned in the Directive. This is likely to come as a bit of a shock to those member states which, like the UK, have shown an interest in using domestic law to impose retention requirements for traffic data generated by users of social networking services and search engines. Of course, things have changed even in the UK and we live in an entirely new political environment now. But Matron seems to remember the write up of a meeting of a parliamentary committee circa 2008 where laws of that nature were demanded by a number of Tory MPs and peers. Despite the coalitions promise that it “will end the storage of internet and email records without good reason”, it all depends – as better minds than Matron’s have already pointed out – on how you define “good reason”.

2. Although, the DR Directive gives member states a choice to impose retention periods from 6 to 24 months, 78% of member states actually require the retention for 12 months or longer. The WP seems quite concerned about the discrepancies in retention periods between the different member states as this impacts on the principle whereby EU citizens “can enjoy throughout the European Union the same level of protection”. It also means that the costs to be borne by providers can differ considerably from country to country which, in turn, may affect competition. Matron is sure that this fact was pointed out to the law makers when the Directive was first adopted but, of course, she may be wrong here.

The interesting question arising from all this is this: if the WP favours a harmonised (i.e. applying in all member states), single (applying to all data categories) and shorter retention term and given that the German Constitutional Court has already quite categorically stated that it deems anything above six months to be unconstitutional under German law, is this the best indication yet that we are heading for a harmonised 6 months retention period? Not ideal, but definitely “bird-in-the-hand” material.

Scarily, the WP also found that there were some serious violations of existing laws by the provider. First, it found that in some cases data is actually stored for longer periods than those set forth in the DR directive. In some cases data was retained for as long as 36 months, and in one case the storage period was found to amount to 10 years. Secondly, the WP found that one EU member state (which was not named) actually used DR Directive to retain the content of SMS messages to which the security services were then given access. Matron can only hope that infringement procedures will be commenced against that member state forthwith.

3. It seems that the security measures taken by individual providers vary wildly with bigger providers generally found to employ higher security measures. No surprise there, given the cost of putting in place such measure, but it’s nice to see that conclusion in black and white nonetheless.

4. The extent to which, and the way in which, access is granted to law enforcement and other public authorities also seems to vary. So much so that the WP calls for inclusion of provisions in a revised Directive that would regulate the modalities of access. Among other things, it recommends that:

a) data should only be accessed by duly authorised staff

b) strong access control to the retained data should be maintained; and

c) detailed tracking of accesses and processing operations by way of log retention, via logs recording at least user identity, access time, file acceded should be carried out.

Another announcement from the Department of the Bleedin' Obvious then but - in the WP’s defence - it has always advocated that access to retained data should be addressed in the same legal instrument as retention. But on this, as on many other issues, opponents were outmanoeuvred during what is still the shortest EU legislative procedure on record. Which plays no small part in the current problems those opponents have in persuading a court – any court – to accept the Directive and its implementing laws for judicial review to establish once and for all its human rights credentials. Maybe, just maybe, the EU institutions will see sense when negotiations of the Directive are opened up once again. And maybe the porcupine flying squad will presently take off at the back of Matron’s garden.

5. We all felt it on some level of inner consciousness, but now we know for sure: the definition of what constitutes “serious crime” (for the prevention of which data may be retained) is different in each member state. Which means that different member states have taken different approaches to the purposes for which retained data may be accessed (unless, of course, you live in the UK or in Germany, both of which have dispensed with the “serious” bit altogether – albeit that Germany was told “nonononono” by its Constitutional Court. No such luck in Britain). The WP recommends that, at the very least, each member state should have an exhaustive list of crimes that it considers to be “serious” and that, at best, this list should be harmonised at European level.

6. The WP thinks that the decision of whether or not law enforcement authorities should be given access to retained data should be up to judicial authorities. It seems a reasonable demand, but, of course, it would generally exclude all those members of the executive (like ministers, police superintendents, senior officers and duty managers) that are currently persons designated to request access to traffic data under the UK Regulation of Investigatory Powers (Communications Data) Order 2010. So what are the chances of this finding its way into a revised Directive? Who knows.

Overall, Matron can't help thinking that the WP’s report reads like a giant exercise in “I told you so”. Will it be enough? Do we have the right narrative this time round? Matron isn't sure. But it’s a start. An opening salvo. Next!

Wednesday, 18 February 2009

Data retention and the incredible duplicity of events

You wait for ages for an irrational and totally see-through official position on data retention and then two come along at once. Following hot on the heels of last week's ECJ decision on the validity of the Data Retention Directive, the Home Office has now published its response to the consultation on the transposition of the Directive into English law. And what a response it is!

Matron isn't quite sure what to commend them on first. That they managed to gloss over the extension of the retention period for internet data from currently six months (under the Voluntary Industry Code) to 12 months, blatantly ignoring the point made by a number of respondents (including the SCL and Liberty) that they have yet to present a business case for any retention of communications data?

That they managed to find and quote the one sentence in a highly critical submission by Liberty that acknowledges that "communications data records can prove a valuable crime detection and prevention tool” (in its submission, Liberty then goes on to say, that the recently reported use of communications data by local authorities for the purpose of enforcing laws against flytipping and benefit fraud hardly fall within the definition of serious crime and terrorism)?

But the most worrying part of the response has to be the government's refusal to even engage with the argument that the retention of internet data for 12 months may very well be disproportionate under Article 8 of the European Convention on Human Rights.

As a general rule, Matron loves to be right as much as the next know-it-all, but in some cases she really doesn't. And the fact that the Home Office - less than a week after the ECJ made a similar point - also seems to suggest that the retention of communications data is somehow separate from access to the data so retained is one of those cases.

But first things first. Let us first look at the changes to the draft Regulations that the Home Office wishes to introduce as a result of the consultation:

Application of the Regulations
Because the UK government has agreed to reimburse CSPs for the costs they incur in implementing the Directive, it has long tried to keep those costs to a minimum by avoiding duplicate storage of data. In practice, this is difficult as many CSPs are using networks operated by other CSPs so that communications data are often held by both the upstream and the downstream provider. In the original draft Regulations the government therefore proposed that they should not apply to a CSP to the extent that the data concerned are already retained by another UK CSP. However, CSPs were very unhappy with this provision as they feared it would create both uncertainty and market distortion. They also argued that third parties interested in accessing retained data (for example, copyright owners) might bring actions for breach of statutory duty against those CSPs ostensibly not required to retain data under the Regulations.

The revised Regulations published by the Home Office last week provide that they will only apply to a CSP if the Secretary of State issues a notice to that CSP requiring it to retain data. No statutory duty to retain data will exist on the part of the CSP in the absence of such a notice. At the same time, under revised regulation 10(2), the Secretary of State must issue such a notice to a CSP unless the data to which the Regulations apply are retained in the UK in accordance with the Regulations by another CSP. In the words of President Truman: "the buck stops with the Home Secretary". Meaning that even if the Home Office gets it wrong, it is now likely that third parties who feel aggrieved that a particular CSP has not retained communications data will probably have to bring an action against the UK government under the Francovich principles rather than have a case against the individual CSP. Directives do not have direct effect and from a CSPs point of view, their statutory duty is what English law says it is. So, that's good news. Or is it?

Well, it depends on whether or not you generally agree with the right of third parties to access data retained for crime prevention and anti-terrorism purposes for their own commercial purposes in the first place. Quite a few respondents raised this issue in their submission. It seems that the CSPs are mainly concern that this may net them lots of Norwhich Pharmacal orders from the already prolific film and music industry. But those of us, who feel that the use of CSP data for the purpose of enforcing copyright has already gone far enough, the Home Office's response to this issue is worrying indeed. It merely states that the Home Office is working with the Ministry of Justice and the Interception of Communications Commissioner to provide guidance for the courts on how these cases should be handled, and that, separately, the government intends to provide more effective remedies for rights holders. So, unsurprisingly, the government is still refusng to consider other solutions to the problem of filesharing and illegal downloads.

Data to be retained
Many ISPs have pointed out that the majority of communications data to be retained relates to unsolicited marketing e-mails ("spam") that is filtered by CSPs and that in most cases is never delivered to the intended recipient. Excluding that data from the retention requirement (along the lines of the Directive's exclusion of data relating to unconnected telephone calls) could save the government millions of £££ but did common sense prevail? Did it heck!

Statistics
Coming back to the mystery of the missing business case, the government was caught with a small amount of egg on its face, when it had to admit that the orginal draft Regulations had omitted a requirement of the Directive that statistics relating to the time elapsed between the date on which the data were retained and the date on which a lawful request for data was made should be collected. That sort of data is obviously essential for establishing whether or not a retention period of 12 months is actually necessary and, hence, proportionate under Art. 8 ECHR (other views that have been mooted include the suggestion that the police only needs a retention period of 12 months because it is so unorganised that it will need at least six months to actually make the request and that long retention periods are really there to cover incompetence and inefficieny. Matron prudently reserves judgment on that).

Apparently, the omission was an "oversight" and the necessary requirement has now been inserted in draft regulation 9, but as they say, just because you're paranoid, doesn't mean they're not after you.

Human rights considerations
But returning to the above mentioned duplicity of events, most notably of all the Home Office has indeed managed to dismiss any suggestions that the retention provisions may actually be disproportionate under Art. 8 ECHR, reasoning that respondents who made those suggestions largely focused on the proportionality of access to the retained data rather than its retention. However, access, the Home Office argues, is governed by RIPA not the Regulations, so arguments relating to disproportionality should be made in a RIPA context. Wait a minute! Isn't that what the ECJ just said?

It is, of course, complete baloney, particularly when you look at the recent judment by the European Court of Human Rights in S. and Marper v United Kingdom, where the court decided that the blanket and indiscriminate retention of DNA records by the UK government, regardless of whether the data subject was convicted of an offence after collection, failed to strike a fair balance between the competing public and private interests. The court concluded that the UK government had overstepped any acceptable margin of appreciation in this regard and it could be argued that similar considerations should apply in relation to the retention of personal data of millions of innocent individuals.

But leaving that aside for the moment, Matron continues to be worried about strategy. If both the UK government and the ECJ are trying to separate the retention of data from access to that data, it may really be time to take note. As Matron suggested before, data retention opponents, particularly in the UK, should start to seriously plan for a fight on two fronts, namely they should think about lodging actions for judicial review of both the Regulations (once they are in force) and the access provisions under RIPA.

Tuesday, 10 February 2009

When Irish eyes are smiling - NOT

The waiting is over and the ECJ has finally delivered its decision on the validity of the Data Retention Directive. Unsurprisingly, it followed the Advocate General's opinion earlier last year and held that the Directive was adopted on the correct legal basis. While this is a short term bummer - member states will still have to implement the Directive by the 15 March 2009 deadline - Matron can't help thinking that in the long term this was the correct approach. Beware the turncoats among the Directive's opponents who lobbied for the involvement of the European Parliament back in September 2005 when it looked like the only way to prevent the worst from happening and who were now hoping that the Irish government would be successful (notwithstanding that it is a stout data retention supporter) for the very same reason. Hard cases make bad law, as they say, and a confirmation of the Irish position may very well have opened a Pandorra's Box more viscious than we would currently be able to foresee.

Yes, it is true that adopting harmonised European provisions under the third pillar requires unanimity in the European which is difficult to achieve. Difficult but not impossible and the proposers of the original Framework Decision on the subject (including Ireland and the UK) had made some headway in that regard back in September 2005 when both the European Parliament started to kick off. Also - and this is probably more important in the short term - in the absence of harmonising EU law, every member state would have been able to adopt its own data retention laws. That would have been great news for human rights organisations in places like Austria, whose government has long opposed data retention on principle, and Germany, where the Constitutional Court may very well have put a stop to it. But in places like Ireland, Italy and, not least, the UK we may well have ended up with laws which require providers to retain more types of data for longer than the maximum of 24 months allowed under the directive. Furthermore, much of the Council decisions come about as a result of horse-trading behind closed doors. At least, the involvement of the European Parliament guarantees some sort of political transparency, even though - as in this case - this will not always protect us from undesirable outcomes. So right on, ECJ, you did well.

But what does it all mean for individuals' right to privacy? Well, the bad news is that ISPs and telecommunication providers will now initially have to retain communications data for between 6 and 24 months. The technology and the infrastructure for this will have to be set up, costed and funded. And we know how it goes - once that infrastructure is in place, both the state and the providers will most probably manage to find a use for it even of the Directive is eventually binned. A frightening thought!

However, the ECJ has not yet examined the question of the Directive's compatibility with fundamental human rights, in particular with the right to privacy under Article 8 of the European Convention of Human Rights (ECHR). Indeed, it has very clearly stated that the action brought by Ireland - and consequently its own decision - relates solely to the choice of legal basis and not to any possible infringement of fundamental rights arising from interference with the exercise of the right to privacy by the Directive. That, in a way, is a good thing, because it leaves the door open for a future challenge by data retention opponents who hope to be able to prove that blanket data retention is wildly disproportionate to the objective the Directive is set to achieve. Judicial or constitutional reviews relating to the compatibility with the right to privacy of national laws implementing the Directive are already pending in a number of member states including Germany and Ireland. The relevant courts may now refer any of those cases to the ECJ for preliminary ruling. The German Constitutional Court - bound as it is by its own "Solange II" principles (that it will not review the compatibility of EC legislation with the German Constitution as long as ("solange") the European Communities, and in particular the judicature of the ECJ, secure the protection of fundamental rights) - are the most likely suspect for such a reference. The Court has repeatedly postponed its own decision in the pending case - likely because of the impending ECJ ruling.

But the ECJ also made another interesting point: namely, it emphasised that the Directive merely relates to activities of communication service providers (the retention of communications data) and not to the activities of public and law enforcement authorities (access to the retained data). While factually correct, this could suggest that when the ECJ eventually receives a reference from a national court, it may limit its own jurisdiction to a review of the question whether the mere retention of data infringes fundamental rights rather than taking a "big-picture-view" of the matter and taking into account the effect that law enforcement's access to that data will have on those rights. It could argue that the mere retention of data does not infringe individual rights provided that access to that data is limited and subject to sufficient safeguards. As the access provisions and safeguards are currently contained in national law (here in the UK, access is governed by Part I Chapter II of the Regulation of Investigatory Powers Act 2000 (RIPA) and a host of secondary regulation), the ECJ could rule itself out completely as a competent court to review the matter from that point of view leaving it instead to national courts to decide.

On the one hand, this could mean that data retention will come to be seen as be a beautiful example for a judicial game of "pass-the-parcel" where data retention provisions are quietly implemented all across Europe while the courts are sorting out their own compentency between themselves. On the other hand, such an approach by the ECJ could open up an opportunity for opponents provided they grasp it quickly and strongly enough.

Data retention opponents should now also consider the judicial review of national access provisions by the national courts as well as, ultimately, by the European Court of Human Rights in Strasbourg. To a varying extent, all EU member states are also signatories to the ECHR which means that their national laws are subject to that Court's jurisdiction once all national judicial remedies have been exhausted. In a UK context this could mean, that even if the ECJ, in a future action referred to it, determines that



  • data retention alone is not enough to infringe people's fundamental rights
  • it is not competent to review the access provisions that may be so infringing,
the access provisions under RIPA could be attacked separately.

Like many others, lawyers advising data retention opponents have so far been puzzeld by the fact that the demarcation line between the jurisdiction of the ECJ and the ECtHR has never been clearly defined. Ever since the ECJ, in the case of Internationale Handelsgesellschaft v. Einfuhr und Vorratsstelle Getreide, confirmed that it would protect fundamental rights as general principles of EU law, the scene was set for a clash between the two courts, albeit that to date this clash has never materialised. It was thought, that data retention could have been the case, where this might finally happen.

However, unless the European Council adopts harmonised provisions on access to retained data which would bring the matter squarely within the ECJ's jurisdiction (probably unlikely, given how difficult it was to achieve consensus even on the retention of the data), civil rights organisations across the EU should now probably review their strategies and start planning for a two-pronged attack:


  1. Continue the judicial review of national laws implementing the Data Retention Directive with a view to a reference to the ECJ. Cross your fingers and hope.
  2. At the same time commence separate actions for judicial review of the related national access provisions arguing that they violate Art. 8 ECHR and that it would be inappropriate to refer those cases to the ECJ for preliminary decision, as they do not concern EU laws. If the national courts decide that those provisions do indeed violate Art. 8 ECHR, then - depending on the constitutional procedures of the relevant country - the provisions will either be void immediately or be declared "incompatible with human rights" leaving the legislator to amend the law. If the national court finds that access to retained data does not breach Art. 8 ECHR, the path to Strasbourg is clear. And it light of the court's most recent decision in the area of privacy and state surveillance, Matron can't help feeling that the chances of success in that court would be much better than before the ECJ.

However, even if a challenge before the ECtHR was successful, the problem of data retention may remain. Would the ECtHR assume jurisdiction on the retention provisions given that they are subject to review by the ECJ? If not, would national legislators, the European Institutions and/or the ECJ revise their position on data retention, if the ECtHR decided that access to the retained data breaches individuals' human rights? Data retention is expensive. National governments will (hopefully) not want to bear those cost or impose them on businesses operating from their territory if they cannot then access the data retained. An ECtHR decision condemning the right to access could therefore be a roundabout way to make them change their mind. But it's tricky. So "as long as" we don't know how best to tackle this we should probably tackle it any which way we can.