Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, 20 August 2013

Living in an age of confusion: David Miranda and the concept of "lawfulness"


Like many privacy advocates who followed Edward Snowden's revelations about the activities of the US National Security Agency and the UK's GCHQ, matron was shocked by the news that David Miranda, the partner of Guardian journalist Glen Greenwald, who had worked with Snowden was detained for nine hours at London's Heathrow Airport on a flight back from Berlin to Brazil. Having read David Allen Green's excellent analysis of the legality of the detention under the Terrorism Act 2000, Matron, like many of the commenters on his Jack of Kent blog, nevertheless has to disagree with his conclusions.

He argues, probably correctly, that if it cannot be established that the police detained Miranda (under Schedule 7 of the 2000 Act) specifically for the purpose of determining whether he appears to be a terrorist, then the detention itself and all subsequent actions of the police (like the confiscation of his laptop, etc.) were unlawful. Reading the Act, there is very little to argue with that analysis, were it not for the fact that his conclusions inevitably seem to be based on the assumption that it would/should have been obvious to the police that Miranda was NOT a terrorist. Any kind of awareness or subjective view on the part of the detaining officer that there was nothing that Miranda could possibly have done that would fall within the definition of terrorism would immediately turn his detention from a lawful exercise of police power into an unlawful "fishing expedition". But this means that it is the definition of “terrorist” or “terrorism” and the policeman's interpretation of it wherein lies the proverbial rub.

The conjugation of power: I am, you are, he/she/it is a terrorist


As DAG explains, “terrorist” is defined in section 40(1)(b) of the Act as  “a person who…is or has been concerned in the commission, preparation or instigation of acts of terrorism”. So what, you may rightfully ask, constitutes “acts of terrorism”?

To answer THAT question, we have to look at section 1(2) of the Act, which includes a helpful little list. Some of the actions mentioned (for example, actions involving “serious violence against a person”, “serious damage to property” or actions “designed seriously to interfere with or seriously to disrupt an electronic system”) are - on the basis of the facts as we know them – indeed unlikely to apply to Miranda. The police coulda/woulda/shoulda  known that when they detained him. However, with a bit of paranoid imagination of the kind that our security services are so good at incubating in their staff, one could possibly argue that the actions in sub-sections (c) (actions that "endanger a person’s life") or (d) (actions that "create a serious risk to the health or safety of the public or a section of the public") could be engaged. Given the projected self image of the security services and their craving for absolute secrecy, is it really so far fetched that they might genuinely believe that the publication of details about their activities is likely to lead to both? 

That being so, anyone involved in that publication or helping someone involved in that publication (for example, by carrying copies of documents that may themselves disclose information about their activities) could then arguably be considered to fall within the definition of “terrorist”. So, the real problem in the Miranda case may not be that the police has acted "unlawfully" in detaining him, but that the powers under which they detained him are now so wide that, in practice, they may very well allow the detention of just about anyone. Which, in turn, raises the question whether a country that prides itself on being a liberal, democratic state should have granted the police those powers in the first place.

There’s lawful and there’s … lawful


What this shows, once again, is the clear stretch of water that divides our understanding of what is "lawful" (i.e. compatible with primary laws adopted by a country’s Parliament) from what is "constitutional" (i.e. whether those primary laws themselves are compatible with commonly accepted fundamental rights principles).

On the basis of current laws a good many things - some of which we may object to - can be "lawful". Indeed - abusing for a moment Matron’s Kraut privilege of invoking Godwin's law at her discretion - much was "lawful" in Nazi Germany.  Much is “lawful” now in the many totalitarian systems all over the world that we Westerners love to criticise.

But many of the laws that make certain actions "lawful" are themselves unlawful - in the sense of them being “unconstitutional” - because they violate one or more of the fundamental rights on which our entire constitutional system and our own perception of ourselves as a civilized society are based. Which means, in essence, that - all things being equal - those laws should never have been adopted by the Parliaments of democratic nations that pride themselves in adhering to the rule of law.

But as we all know, good governments do bad things (not that Matron would want to suggest for a moment that the UK has had a "good government" for some time now, but that’s a whole different bunch of blog posts). We need to remember that, in the immortal words of Matron's very own hero, Albus Dumbledore, "the world isn't divided into good people and death eaters". So while the fact that sometimes an unconstitutional law is adopted and enforced is extremely regrettable, all this shows in the first instance is that one (ONE, but not ALL) of the safeguards (or, in US speak, “checks and balances”) that we have put in place for our protection from the actions of an overbearing state have failed. Fortunately, there are usually other safeguards, or at least there should be. So it is important to see what happens next.

How to change bad laws


Generally, when a law is somewhat questionable, there are two ways to go about changing it: we can challenge it in the courts or we can get Parliament to change it through political action. Experience has shown that it is usually wise to take a two-pronged approach on these things rather than focus on one or the other. So with regard to the political campaign surrounding the Schedule 7 powers Matron would like nothing more than to see every privacy group, human rights organisation, regulator and anyone else who has a stake in this (which pretty much means everybody) to get to grips with the legal aspects of this case (and the legal issues it raises), to raise awareness and to make it impossible for our current shower of career politicians NOT to do something about this.

At the same time, Matron genuinely hopes that David Miranda will challenge his detention in the courts so that a judicial review of the extremely wide powers contained in the Act can determine whether or not they are indeed “necessary in a democratic society” (that element of necessity being the threshold which laws that interfere with the right to privacy have to meet in order to be “constitutional”, see Article 8(2) of the European Convention on Human Rights). This will take time, maybe a lot of time, and although it is easy to get disillusioned by this, we shouldn’t be. The mills of the law may grind exceedingly slowly (and too slow for many of us), but they should not be underestimated in bringing about real change over time, not just in terms of direct change to the law itself but also to the public's perception of what should (ethically) be allowed in a free country and what shouldn’t.

Constant vigilance


What we need to look out for, however, is our continued ability to challenge laws in this way and that is an area where the UK has an abysmal record. Unlike Germany, where a multitude of stakeholders (including regional governments, political parties and individual citizens) have the right directly to challenge the constitutionality of a primary law if they are affected by it, in the UK, the right to judicial review is extremely limited. The doctrine of "Parliamentary Sovereignty", which forms the cornerstone of the UK's constitutional settlement, does not allow for the judicial review of primary legislation (although some limits to that claim were introduced by the Human Rights Act 2000). Instead, a court will usually review the compatibility of primary laws with fundamental rights only when it judicially reviews the compatibility of an executive measure or of secondary legislation with an Act of Parliament. This makes it nigh on impossible to have some laws reviewed in the UK as we have seen, for example, with regard to the legislation implementing the EU’s Data Retention Directive.  Despite the fact that implementing national laws (and in some cases the Directive itself) were declared unconstitutional in several EU member states, in the UK we haven’t even been able to bring a case to court.

What is more, what little right to judicial review we currently possess is under continuous attack from the government on several fronts. In some areas, like planning law, the government has recently halved the period claimants have to make an application from three months to six weeks. In other areas, the government has restricted legal aid for judicial review cases. Taken by themselves, those changes are small and relatively innocuous, but cumulatively they may eventually lead to the erosion of due process and whatever limited powers UK courts have in providing a measure of oversight with regard to Parliament’s activities. Viewed in this way, it is no surprise that the court with the most wide-ranging oversight powers, the European Court of Human Rights in Strasbourg, is so universally loathed by at least one half of the current government, that the latter has engaged in a long-term campaign to discredit both the Court and the Convention it enforces ever since the previous Labour government briefly exercised the courage of its former convictions by adopting the Human Rights Act in 2000.

So what HAS Miranda’s detention taught us about this country? Well, a good many unpleasant things many of us knew already  - namely that our laws include powers that, if used to their full extent, would most probably enable flagrant breaches of human rights - and some things we hoped we would never have to learn in our lifetime - that the bodies we have entrusted with protecting our rights and liberties will indeed use those powers to their full extent even if that results in the inevitable destruction of said rights and liberties. For those of us who had still hoped that some remnants of morality would ensure that “they wouldn’t do that”, the Miranda case - like the grounding of Morales plane in Austria in July - comes as a wake-up call. 

It also proves once and for all the futility of arguing (as many defending the NSA actions have done) that we should concentrate on what public bodies are actually doing now rather than questioning – as lawyers and as citizens - what existing laws could permit them to do if the political climate allows. It is the most intrusive uses of the powers granted by those laws from which our legal system must defend us, not their most benevolent interpretation. 

And above all, some words written more than half a century ago, still ring true today with a terrible clarity:

"We must not confuse dissent from disloyalty. We must remember always, that accusation is not proof, and that conviction depends upon evidence and due process of law. We will not walk in fear, one of another, we will not be driven by fear into an age of unreason. If we dig deep into our history and our doctrine, we will remember we are not descended from fearful men. Not from men who feared to write, to speak, to associate, and to defend causes that were, for the moment, unpopular. This is no time for men [...] to keep silent or for those who approve. We can deny our heritage and our history but we cannot escape responsibility for the result. There is no way for a citizen of the republic to abdicate his responsibilities. As a nation we have come into our full inheritance at a tender age. We proclaim ourselves, as indeed we are, the defenders of freedom wherever it still exists in the world. But we cannot defend freedom abroad by deserting it at home. [...] Cassius was right: the fault, dear Brutus, is not in our stars, but in ourselves."

Edward R. Murrow

Good night and good luck!

Friday, 20 April 2012

Jedi Knights 1 : 2 Empire

Fellow privacy advocates may agree that it was a funny old day yesterday for our lot. As the saying goes, things tend to come along in threes , and yesterday this is exactly what happened.

SfS2012

To start with the good stuff, Matron spent the afternoon at the excellent “Scrambling for Safety” conference hosted by the LSE and organised by the Open Rights Group, fipr and Privacy International to kick-start a nationwide campaign against the UK government’s latest surveillance brainchild, the Communications Capabilities Development Programme. And an excellent conference it was too despite that fact that much of the preaching was done to a very receptive choir. This was not the organisers’ fault – Matron was reliably informed that enourmous energies had been expended trying to get people from different backgrounds and with different views to speak on the subject.

But when even a senior cop (Sir Chris Fox QPM, first President of the Association of Chief Police Officer) condemns the proposals as unworkable and unnecessary, when the guys from the Home Office prefer to pull up the draw bridge, and when the Labour Party (possibly acutely aware of the embarrassing fact that the proposals are a carbon copy of the Interception Modernisation Programme they themselves proposed in 2009) fails to respond to the invitation, who else is there to speak out on behalf of a project that could cost the country billions, violate the fundamental rights of millions of citizens and have no beneficial effect whatsever? The people who are likely to make a mint from flogging the technology – first to the UK, then to other “benevolent” regimes? Well, yeah, now there’s a conversation that is likely to happen in the spirit of openness and full and frank disclosure. Not!

But leaving that aside, Matron has nothing to add to her own recent post on the CCDP and fellow blogger Paul Bernal has already expertly summarised the SfS2012 conference. The conference was the start of a campaign that, Matron still feels, at a political level in the UK is ultimately winnable. So please concerned people of all ages and political pursuasions, join the fight, support one of the groups mentioned above by giving your time, expertise or even just money and help prevent this from happening.

Come fly with me (well, maybe not…)

The second thing that happened yesterday was less enjoyable. Matron is speaking, of course, about the European Parliament's decision to approve the international agreement between the EU and the US on the collection and transfer to the US Department for Homeland Security of the passenger names records of all citizens boarding a plane to the US from an EU member state. This agreement has been controversial for years and much more information than Matron could ever provide in this short space can be found on the website of European Digital Rights (EDRi). However, a few words on the procedural aspects of this decision.

Matron can’t say that the result of the EP’s vote has come as a surprise to her. With regard to matters of privacy and surveillance a pattern has been emerging here for some time where the EP – seemingly more concerned about its own role in the legislative process than the issues at stake – makes an almighty fuss about privacy and safeguards and the impossibility of it all until someone lets it onto the playing field to kick the ball around for a bit, after which it quietly returns to the bench with a content smile and lets those who really run the show get on with it.

Of course, this damning judgement does not apply to ALL MEPs, and Matron must particularly commend the work of , and the stance taken by, Sophie In’t Veld (ALDE, NL), who was the rapporteur for the LIBE committee which had recommended that the agreement should be rejected and who reportedly withdrew her name from the report after the vote.

However, the EP’s role in these matters is becoming almost as much of a trigger for privacy campaigners’ frustration as the inevitable outcomes of the various legislative proposals, almost all of which promote what Bruce Schneier calls the false dichotomy of privacy v security. MEPs should therefore ask themselves whether they are doing their own reputation any favours in the long run, if they never grasp the opportunity to stand up – and be seen to stand up – against the whimseys of their political paymasters.

The EP’s powers in the legislative process were increased in the Lisbon Treaty specifically with the aim of ensuring democratic controll and accountabilty. It is currently quite blantantly not fulfilling that role in many, many cases.

Bonnier Audio v Perfect Communication Sweden AB

Speaking of EU institutions that “could do better”: before she swanned off to her conference yesterday, Matron had the dubitable pleasure of having to write up the ECJ’s decision in Bonnier Audio v Sweden.

This decision was expected to provide some clarity on whether IP rightsholders should be allowed to demand the disclosure from ISPs of data identifying those ISPs' users for the purpose of bringing claims for illegal filesharing against those users. The best (and briefest) answer to this question may very well be that the ECJ - unhelpfully - has left many questions unanswered. However, Matron has made a stab at a fuller account of the judgement in a separate post for those with a masochistic interest in the lengthy and complicated analysis of ECJ judgements.

The end is nigh?

So what to make of this day? Is there a clear direction discernible of whither we are headed in the area of information privacy? Is it all doom and gloom? Is the end of civilisation as we know it imminent?

Well, the best one can probably say for all these developments is that they show that legislators, law enforcement agencies, security services, rightsholders and online providers are not allowed to ride roughshot over individuals' rights without there being at least a great deal of opposition, albeit that this opposition comes from a fairly small number of people. However, as SfS panellist, David Davies MP pointed out during his panel yesterday, that small number of people is endowed with a disproportionate amount of skill, knowledge and expertise as well as the willingness to put it to good use. We are also quite stubborn.

So maybe things are not as bad as they sometimes feel and maybe that move to the Outer Hebrides can be put off for a little while longer. As any good lawyer would say, it all depends. On a bad day, the temptation to do nothing and watch reruns of the Big Bang Theory instead is amost irrisistable. On a good day, Matron tries to remember the words of her favourite philospher, Albus Dumbledore, when asked whether opposition to Lord Voldemort would necessarily be in vain:

"[W]hile you may only have delayed his return to power, it will merely take someone else who is prepared to fight what seems a losing battle next time – and if he is delayed again, and again, why, he may never return to power."

And on that note, good night and good luck, fellow conspirators!

Thursday, 15 July 2010

An opening salvo?

After many weeks of joyful distractions, Matron just spent a few days concentrating on the day job and, among other things, dutifully worked her way through the EU Working Party’s Report on the implementation of the Data Retention Directive. At the risk of teaching grandmothers to suck the proverbial eggs, that is the small innocuous piece of EU legislation that requires EU member states to impose an obligation on its telco providers and ISPs to retain all data relating to the telephone call made and e-mails sent by us, the Great Unwashed. Sender, addressee, time of transmission, location of transmission – you get the picture. As will the law enforcement authorities and selected others who may access that data. The full picture. Of all of us.

While the WP’s report does not include the comprehensive condemnation of the Directive that many were hoping for, it makes for interesting reading. Of course, the easy explanation for the lack of condemnation may possibly be that there was nothing to condemn as yet. According to the report, only a few member states did provide the requested information regarding the number of requests submitted to providers, the cases where the requested information was provided and those where the provider was unable to make available the requested data. Nor is data available about the time elapsed between the date on which the data were stored and the date on which the authorities requested transmission of said data. As the WP rightly points out, this lack of information makes it somewhat difficult to evaluate a) whether the prescribed retention periods are realistic and b) whether the mandatory retention of traffic data is actually necessary to combat crime and terrorism. In an ideal world both of these questions should obviously have been asked before the Directive was adopted, but when did evidence-based policy making last get in the way of a good lobbying campaign (the British DEAct debacle is a point in case)?

The fact that the questions are asked only now, when the Commission is seriously considering either revoking or at least substantially amending the Directive, may make for some amusing debates. Matron wonders in whose favour this lack of information will be interpreted. Will member states pipe up that it is far too early to even consider a revocation, given that we do not yet know, whether the sodding thing worked in the first place? Or will the Commission - as it should properly do - remind law enforcement authorities that the burden of proof of showing that retention is necessary is on them. No statistics, no further retention? That would be the day.

But while we wait for this issue to resolved, here’s a short summary of what Matron considers to be the highlights of today’s report:

1. Very interestingly, the WP interprets the DR Directive as a derogation from the general requirement on providers to erase all traffic data when it is no longer required for billing purposes. It takes this to mean that the list of data to be retained under Article 5 of the Directive is exhaustive and that member states must not require ISPs to retain any additional data categories not mentioned in the Directive. This is likely to come as a bit of a shock to those member states which, like the UK, have shown an interest in using domestic law to impose retention requirements for traffic data generated by users of social networking services and search engines. Of course, things have changed even in the UK and we live in an entirely new political environment now. But Matron seems to remember the write up of a meeting of a parliamentary committee circa 2008 where laws of that nature were demanded by a number of Tory MPs and peers. Despite the coalitions promise that it “will end the storage of internet and email records without good reason”, it all depends – as better minds than Matron’s have already pointed out – on how you define “good reason”.

2. Although, the DR Directive gives member states a choice to impose retention periods from 6 to 24 months, 78% of member states actually require the retention for 12 months or longer. The WP seems quite concerned about the discrepancies in retention periods between the different member states as this impacts on the principle whereby EU citizens “can enjoy throughout the European Union the same level of protection”. It also means that the costs to be borne by providers can differ considerably from country to country which, in turn, may affect competition. Matron is sure that this fact was pointed out to the law makers when the Directive was first adopted but, of course, she may be wrong here.

The interesting question arising from all this is this: if the WP favours a harmonised (i.e. applying in all member states), single (applying to all data categories) and shorter retention term and given that the German Constitutional Court has already quite categorically stated that it deems anything above six months to be unconstitutional under German law, is this the best indication yet that we are heading for a harmonised 6 months retention period? Not ideal, but definitely “bird-in-the-hand” material.

Scarily, the WP also found that there were some serious violations of existing laws by the provider. First, it found that in some cases data is actually stored for longer periods than those set forth in the DR directive. In some cases data was retained for as long as 36 months, and in one case the storage period was found to amount to 10 years. Secondly, the WP found that one EU member state (which was not named) actually used DR Directive to retain the content of SMS messages to which the security services were then given access. Matron can only hope that infringement procedures will be commenced against that member state forthwith.

3. It seems that the security measures taken by individual providers vary wildly with bigger providers generally found to employ higher security measures. No surprise there, given the cost of putting in place such measure, but it’s nice to see that conclusion in black and white nonetheless.

4. The extent to which, and the way in which, access is granted to law enforcement and other public authorities also seems to vary. So much so that the WP calls for inclusion of provisions in a revised Directive that would regulate the modalities of access. Among other things, it recommends that:

a) data should only be accessed by duly authorised staff

b) strong access control to the retained data should be maintained; and

c) detailed tracking of accesses and processing operations by way of log retention, via logs recording at least user identity, access time, file acceded should be carried out.

Another announcement from the Department of the Bleedin' Obvious then but - in the WP’s defence - it has always advocated that access to retained data should be addressed in the same legal instrument as retention. But on this, as on many other issues, opponents were outmanoeuvred during what is still the shortest EU legislative procedure on record. Which plays no small part in the current problems those opponents have in persuading a court – any court – to accept the Directive and its implementing laws for judicial review to establish once and for all its human rights credentials. Maybe, just maybe, the EU institutions will see sense when negotiations of the Directive are opened up once again. And maybe the porcupine flying squad will presently take off at the back of Matron’s garden.

5. We all felt it on some level of inner consciousness, but now we know for sure: the definition of what constitutes “serious crime” (for the prevention of which data may be retained) is different in each member state. Which means that different member states have taken different approaches to the purposes for which retained data may be accessed (unless, of course, you live in the UK or in Germany, both of which have dispensed with the “serious” bit altogether – albeit that Germany was told “nonononono” by its Constitutional Court. No such luck in Britain). The WP recommends that, at the very least, each member state should have an exhaustive list of crimes that it considers to be “serious” and that, at best, this list should be harmonised at European level.

6. The WP thinks that the decision of whether or not law enforcement authorities should be given access to retained data should be up to judicial authorities. It seems a reasonable demand, but, of course, it would generally exclude all those members of the executive (like ministers, police superintendents, senior officers and duty managers) that are currently persons designated to request access to traffic data under the UK Regulation of Investigatory Powers (Communications Data) Order 2010. So what are the chances of this finding its way into a revised Directive? Who knows.

Overall, Matron can't help thinking that the WP’s report reads like a giant exercise in “I told you so”. Will it be enough? Do we have the right narrative this time round? Matron isn't sure. But it’s a start. An opening salvo. Next!

Saturday, 26 June 2010

Notes from under a virtual stone

With the inevitability of English summer rain the footballing scenario that Matron most feared has come to pass. On Sunday, England will once more play Germany in the World Cup and for Matron this means that the time has arrived where it is prudent for members of her national persuasion to hide under a stone. Despite manifold assurances by her English chums that not everyone will be filled with feelings of hostility towards her breed (though, bless you all for saying it and keep’em coming) those of us who have lived here for a while know that this is no time to be an out and proud Kraut in these parts (and if anyone could tell Beckenbauer to shut up, that would also help).

However, while dwelling on the good fortunes (or not) of the 11 “Lions” is bound to be the water cooler moment of choice until at least Monday, the yearning to hide under a stone actually reminded Matron that this is a concept she has mentally employed for some time in another context, namely her online existence. Those of her readers who paid attention (all three of them then) will have noted that Matron blogs under a pseudonym and that her blogger profile includes exactly zero information about her real life persona. She has taken the same approach to her Twitter existence where she has so far admitted a total of two followers – both of them known to her in real life - to her otherwise strictly private account. In other word, she lurks.

Now, the question of online anonymity (or pseudonimity) is an interesting one. Does it serve a purpose or is it a hindrance to fame, fortune and lucrative consultancy contracts? Should all online activity be open, transparent and accountable or is there something to be said for reticence and inscrutability? Matron wonders and ponders and has done so for some time. While many of her academic friends have made names for themselves as bloggers and Twitter power users (and encouraged her to do likewise), she has chosen to remain shrouded in obscurity - largely out of a nagging feeling of unease about what this particular “coming out” would mean for her. So what is the problem? Well, as far as she can tell there are several:
  1. As Daniel Solove pointed out in his excellent book “The Future of Reputation”, all online information is ubiquitous and permanent. Once it’s out there, it cannot be recalled nor can access to it be properly limited. With powerful search engines and information aggregators working to their own rules and algorithms, individuals no longer have any control over the way in which information about them is presented to the inquisitive onlooker, how it is prioritised and what it will be used for. This means that there is a real risk that a false or distorted picture is painted of an individual which is then accessible to an audience of millions, and based on which others (like employers or potential dating partners) will make value judgements. We all do it, and yet, Matron asks herself, is there not a moral question in there somewhere that needs to be answered. At what point does our ability to freely access information about other people make us incapable of judging them in an unbiased fashion, particularly if someone’s online persona is not actually representative of the person that they really are. When does “googling someone” turn into a human rights violation, for example because our accumulated prejudice means we don’t grant them equal treatment? Matron can’t help thinking that until rules or social mores are established that limit the way in which and the purposes for which information available online is used, any attempt to minimise the information available about oneself online seems a sane approach.
  2. Blogging under a pseudonym creates a feeling of relative freedom. The blogger may work in a position where his or her opinions would not be well received or they may actually enjoy being someone completely different online. A pseudonym makes this possible. It also encourages playfulness. Using her pseudonym, Matron can try out ideas that she may not always be ready to discuss online under her real name yet. It allows her to have a full and frank exchange of opinion with others that often help her clarify specific issues in her mind which she then addresses in her academic writing. But what about accountability, some may ask. Shouldn’t people who sound off on things have the courage of their convictions and don’t others, when they engage in discourse with them, have a right to know who they are talking to? Matron would answer “what does it matter?”. If the discussion is on a specific topic, why is it important who the discussants are? As long as both stick to acceptable standards of human interaction, arguments can be made, examined and countered without one person necessarily knowing who the other person is. Of course, the identity of the speaker may weigh either in favour (if they are a known expert) or against (if they are a renowned crank) the argument they are making. But doesn’t this knowledge also (again) lead to bias and prejudice? Don’t we sometimes find that the best ideas come from people from whom we did not expect them? Should we not be able to examine a statement on its merits, rather have our judgement clouded because we know it was made by a particular person? But what if people hide behind their pseudonym while distributing hate speech or false or defamatory statements? Well, this is where the difference between a pseudonym and full anonymity comes into play. Matron is fully aware that if she made, say, a defamatory statement, the person so defamed would probably have a right to find out her identity from the online provider whose service she used. Matron has not made up a fake identity for this blog and she does (she thinks) support a level of online traceability rather than a right to full anonymity. The reasons for this are simple: while the bloggosphere and the Twitterverse are relatively new developments, the right to free speech (and its limitations) are established legal concepts in the offline world. There are very few offline scenarios, where speech, in order to be free, would have to be made anonymously. In most contexts, the speaker would be, if not immediately identified, then identifiable and the right to participate in public discourse is, in most cases, subject to an understanding that commonly accepted norms (whether legal or social) will be in place which enable the detection and prevention of the kind of speech that is not covered by the human right. (Advocating a traceability requirement does, of course, only work if the relevant statement is made within a liberal democratic context. Citizen journalists operating in countries with autocratic or totalitarian governments will hardly be able to do their job properly, if they are traceable.)
  3. Social media have managed to blur the distinction in the heads of many users of what is public and what is private space. As the recent furore around Facebook’s privacy settings shows, providers have created platforms that feel intimate, yet are often accessible by many more people than the individual is aware of. It seems that most users have not yet found a way to deal with the resulting confusion when sharing information about themselves and others. Twitter is a point in case. Unbeaten as a modern form of news feed cum commentary tool, many people have started to use their open tweets rather than the direct messaging function for direct communication with other users. This means that – with a few extra clicks - the “conversation” between those two users can be followed by all their followers, of whom there may be hundreds if not thousands. Are we always aware when we’re doing it? Heck, no! Do we care? Well, in some cases we may. In some cases, we probably should, particularly if we don’t at all times personally know all of our followers. Members of social networking sites also distribute far more and far more intimate information about themselves and others than they would ever be willing to share offline. At this point, we still seem to lack social norms equivalent to those in the offline realms that govern the sharing of information about each other. Matron believes that we do not yet have an internal censor that tells us that certain information “is not for the internet” or social sanctions enforced by our friends if we violate an unwritten code of online conduct (she may be wrong here and, particularly younger, people may well feel that they are well on their way to such norms. If that ewere the case, Matron would be happy to receive examples). Nor do we have a proper understanding of just how widely the information we disclose about others is being distributed or the speed with which that can be done. A pseudonym that is only known by people we know and trust ( and that is respected by them, see below) enables us to protect ourselves against the worst effects of compulsory over-sharing until the necessary social norms have developed and are properly enforced. Gossip about something that happened to “X” remains gossip about the event rather than the individual.
  4. A pseudonym provides limited protection from trolls. Of which there are many in the online world. Indeed, it seems to Matron that one of the bigger problems with the regulation and governance of online social spaces is that – despite all the attempts at netiquette - there is as yet no common understanding regarding the social norms with which individuals should comply. Things are commonly said on online discussion boards that would never be said, if the people involved were making those statements face-to-face (by the same token, we wouldn’t send a double-glazing sales man round to a friend’s house, but we give him their e-mail address for the chance to win a competition). What is the reason for that? Well, Matron would hazard a guess that the online medium removes us from the immediate vicinity of the other person. We do not have the unmediated experience of witnessing the effect our actions have on them first hand. Naturally, unqualified comments can be made even if the blogger’s real identity is unknown. But a pseudonym is at least likely to deter those who play the person rather than the ball.
A pseudonym does, of course, only work if it is effective. And herein, as they say, lies the rub. With every piece of information that Matron discloses about herself - her nationality, her gender, her profession and her whereabouts at any given time - she makes it easier for those who know her in “real” life (and any halfway talented private eye, where they to make it their business to look for her) to identify her as the person behind the blog. She expects that, over time, the anonymity that the pseudonym provides will simply melt away and with it some of its protection. However, Matron is not actually too worried that friends, colleagues and even passing acquaintances may know who she is. Many do already and include references to her pseudonym in their online conversations. What Matron – admittedly very subjectively - is concerned about is the transition of that knowledge from (wo)man to machine, that is the creation of an online link between her real name and her pseudonym which would make it possible for the search engines and information brokers mentioned above to incorporate anything she says in this blog into the profile they create for her real life identity. This will only be possible if one of the people in the know makes that connection public or if the provider of the blogging platform makes Matron’s personal information accessible for that purpose. Should either her friends or her service provider be permitted to do this? Matron thinks not. Some people like to blog openly and benefit from the reputation they build, some prefer to remain anonymous and enjoy the freedom and the feeling of safety this gives them. It’s about choice and it’s about control. It’s about what the Germans call informational self-determination. They protect in their Constitution and we over here enjoy some protection through existing data protection laws. However, what we also need is an equivalent social norm that requires each of us to respect the other’s choice. We do it offline, because there'd be hell to be pay from our friends if we didn't. By and large social pressures keep us in line. We need to work on an online version of that subtle control mechanism.

For as long as powers imbalances exist between different individuals, individuals and companies and individuals and the state, most of us will prefer to keep some information about ourselves private or within the domain of a few trusted individuals. Everybody has something to hide. Information about ourselves and others is not something with which we do, or should should, part unthinkingly. In our networked society we are now all data controllers so the responsibility falls on all of us. Within the realms of free speech, press freedom and the public interest we must begin the discussion of how to establish and enforce online social norms that respect individual's freedom to choose their own level of openness. If we don't, we may at some stage feel like the England goal keeper as he watched that ball slowly finding its way into his own goal.

Wednesday, 11 March 2009

Google calling - again!

And while we're on the subject of Google, the BBC reported today that Google has become the latest provider to serve up behaviour-based advertising. Under its Adsense program, Google will serve ads based on the content of the sites users view. It will associate their browsers with certain "interest categories" based on behavioural data collected through a cookie it places in users' browsers. Cookies will be placed in the browsers of all Google and You Tube users from today unless the user opts-out. Advertisers will be able to start serving ads using the new system from April.

The move follows the publication of guidelines on behavioural advertising by the Internet Advertising Bureau which are supposed to ensure that such advertising does not breach individuals' right to privacy (see last week's report by Out-Law). Google as well as Microsoft Advertising, Yahoo! SARL and Phorm have all committed to following them. However, the guidelines have already been criticised by the good people at the Open Rights Group for the opt-out approach and the cookie technology.

"Any ‘opt out’ would be stored by a cookie. So each time a user deletes their cookies, or changes browser or machine, they have to opt out. This makes opting out a repeated procedure, such that which would make all but the most stubborn user simply give their consent. This is not how consent should work, and a system that ‘pesters’ users into opting in is in our view an illegitimate attempt to substitute acquiescence for consent, whereas nothing but consent is acceptable."

There have been lots of discussions about whether most users would prefer targeted advertising to the current "random" kind. The prospect of making - as Lilian Edwards called it at last year's GikIII conference - "every ad a wanted ad" seems tempting, but at what cost? Matron is fairly relaxed about being served with relevant advertising when using the internet. But she baulks at the mass of data that Google will collect in the process, the other purposes for which that data may be used and the people who might want to use it. If the data security breaches of the last two years have taught us anything, it is that the only way to prevent the abuse of large databases is to prevent those databases from being established in the first place.

On that note, this is how you opt-out of the Google Adsense cookie.