Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Wednesday, 26 October 2011

Newzbin2 - the order

The High Court has just handed down its order in "Newzbin2".

For those not following the story so far goes like this: newzbin (whose site I will not link to for obvious reasons) describe themselves as a "Hand edited, searchable archive of Usenet binary content from the creators of the NZB Format." USENET is of course the grandparent of most peer-to-peer file sharing networks. People were sharing copyright material via USENET even when I started using the internet over 20 years ago. Newzbin do not host any of the material (which is available via USENET) but their site undoubtedly makes it much easier to find copyright infringing material to be downloaded. Unsurprisingly, many large copyright owners do not like it.

Last year, a group of Hollywood studios persuaded Mr Justice Kitchen that Newzbin were guilty of copyright infringement in three different ways (1) their actions amounted to "authorisation" of copyright infringement; (2) they were also joint infringers with or procurers of the infringement of their subscribers; (3) even though they did not host any of the movies complained about they "made them available to the public" which is an act protected by copyright. The case Twentieth Century Fox v Newzbin [2010] EWHC 608 (Ch) makes interesting reading as it explores just how far a website may (or in that case may not) go without infringing copyright.

Newzbin's reaction was to be expected: their operation moved outside the jurisdiction of the UK courts. Undeterred (one hopes they were sufficiently web-savvy to have anticipated the move) the studios applied to the High Court for an injunction against BT to force BT to block access to Newzbin to its (ISP) customers. The studios made use a statutory power given to the High Court to make injunctions of this kind under section 97A of the Copyright Designs and Patents Act 1988.

At the end of July, Mr Justice Arnold agreed to grant the injunction (Twentieth Century Fox v British Telecommunications [2011] EWHC 1981 (Ch) ). Lillian Edwards wrote a very neat analysis of the decision on the day it appeared. As she explains, Newzbin was an unusually good case for an injunction, not least because there had already been a decision of the High Court finding that the site was involved in copyright infringement. Other cases may be more difficult for rights holders to argue. It will depend.

Mr Justice Arnold postponed deciding on the exact form of the injunction — that is exactly what BT should be ordered to do — until he had heard further submissions from the parties. His decision on the form of order was what was handed down today.

A huge simplifying factor is that BT are already running a system known as Cleanfeed which is used to filter out material on the Internet Watch Foundation's list of suspect IP addresses and blacklisted URL's. This meant the order could require BT to add IP addresses and URL's supplied by the studios to its Cleanfeed list.

Cleanfeed is not used with all BT ISP products. In particular it is not used for what is effectively wholesale supply of internet connectivity, nor to particular customers in certain cases — one example being the police who, one imagines, absolutely do wish to be able to access illegal material for investigatory purposes. The order applies "In respect of its customers to whose internet service the system known as Cleanfeed is applied whether optionally or otherwise". Read literally that would appear to mean that customers who have Cleanfeed as an option but have opted out would still have to be filtered by BT. It is unclear to me whether that is what the judge intends.

The order makes it clear that BT is not required to carry out deep packet inspection. BT need simply rely on the IP addresses and URL's reported to it by the studios, but this, in my view, leads to the most serious defect in the order: it relies entirely on the good faith and judgment of the studios. There is no sanction for mis-reporting of websites. Since there is no requirement to publish the list of sites supplied to BT or to notify site owners that they have been placed on the list, it may be difficult to ensure that the studios act fairly and properly.

BT did try to obtain what is known as a cross-undertaking or an indemnity from the studios which would have compensated BT for any loss it suffered as a result of any mistakes made by the studios. The judge rejected that request on the basis that, as he decided, BT could not be liable for damages (eg by being sued by its customers) because it was acting under a court order. That will no doubt be a useful decision for ISP's and web service providers in other situations, but it did mean there was no basis for imposing any sanction on the studios for supplying incorrect sites in its list.

There was some argument as to how precisely the list should be described. In order to ensure that it would be difficult to circumvent the order, the judge decided that the order would apply to not only the newzbin website itself but also to "any other IP address or URL whose sole or predominant purpose is to enable or facilitate access to the Newzbin2 website". Here we see one of the weaknesses of section 97A. It gives the High Court the power to grant an injunction but it fails completely to say what kind of an injunction that might be. In particular it does not say that the injunction should be restricted to preventing access to sites where copyright is being infringed (like Newzbin). I am therefore concerned about whether the combination of the wording of the order and lack of sanction on studios may cause problems at a later date.

The other significant issue was costs. While costs (which lawyers get very excited about) may not seem as interesting as arguments about what should be blocked and how, costs are often as expensive to a party as the consequences of losing (or winning) a claim. Costs are a big deal. One positive outcome of the decision is that BT was entitled to be paid its legal costs for the first part of the claim up to 16 December 2010 - in other words the costs that would have to be incurred to obtain a court order. In the future ISP's can be reasonably confident that they can demand a court order before instituting website blocking and not expect to have to pay the costs of that order. The judge found that BT should pay the costs of the contested part of the proceedings, but that each party would bear its own costs for the decision about the final order.

In conclusion, I have two points to make: first, it is now clear that copyright owners are perfectly able to obtain quite favourable court orders to block websites, so that there was really no need for the Digital Economy Act 2010 to introduce more website blocking provisions when the existing ones (in section 97A) had not been properly tried out. Second, other cases may not work out the same way as this one. For example TalkTalk do not run Cleanfeed. One expects that the argument (and subsequent order) in a case against TalkTalk might be a little different for that reason. We will see.

Tuesday, 17 May 2011

Restraining cookies: the new privacy rules

On 26th May 2011, a new law — the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 — comes into force which will change fundamentally the legal regime governing cookies and other similar locally stored data. As I will explain, the legal change is a big deal, but the practical effect may, at least in the short term, be small.

The Information Commissioner has published some useful practical guidelines (alas only as a PDF). They are not definitive (so they may not protect you in the unlikely event someone tries to sue you for damages caused by a breach of the regulations) but since the Information Commissioner (or his office at least) has the primary role in enforcing the regulations, complying with his guidelines will go a long way to avoiding any possible legal repercussions. If you have a short attention span and wish to read only one thing about the new cookie law then I'd advise you go there (see you another time and thanks for visiting).

The new rules apply to storing (or accessing information stored) on a public network user's computer. That includes not only cookies and "flash cookies" but any other information that might be stored on a local computer, for example they would certainly apply to the iPhone's storage of location data. For brevity I'll talk about cookies, storing cookies but all that follows applies much wider than that.

Overview

The amended regulation 6 will forbid anyone from storing cookies unless one of the following applies:

  • the user has given their prior, informed, consent (an opt out is no good)
  • it is for the sole purpose of "carrying out the transmission of a communication"
  • it is strictly necessary for the provision of an information society service that was requested by the user

In practice this means that, except in very limited circumstances, prior explicit permission will need to be given by a user before using cookies. The limited circumstances might include situations where the illusion of a session (http being stateless) is needed in order to provide the user with the service they want, for example via a "shopping cart".

Tracking what a user does (eg with a tool like google analytics) or supplying additional services they might want (eg "other users also bought...") would not be for a service "requested by the user" and so would need consent.

Consent may be given by the user explicitly setting their browser to accept cookies. At the moment most browsers will, by default, accept cookies and so it is not, at present, realistic to rely on a user's browser settings to gain the necessary consent. Browser technology may change to make such a reliance tenable and I expect there to be some pressure in that direction.

Clauses in a website's terms and conditions which do not have to be explicitly accepted by a user (for example because they are linked to at the bottom of a page) are, in my view, also not going to be any good.

One small consolation to online service providers is that the ICO has said that in the early stages of this new law all he will look for is a plan to get things right, rather than expect 100% compliance from 26th May. That isn't an excuse to be complacent, but does give some breathing space.

Detail

The origin of the new law is in an amendment to the directive on privacy and electronic communications (directive 2002/58/EC). There doesn't appear to be a consolidated version in html format online, but for the purposes of this post all we care about is replace article 5(3) which was added by directive and reads:

3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.

One one analysis it is not the web server (and thus the operator of the server) who stores or gains access to cookies on a user's machine, rather the server returns a "Set-Cookie" response which a web browser has no obligation to honour. It is also the web browser that transmits the value of a cookie back to the web server.

The directive is not intended to be understood in so narrow a sense. Only a small minority of web users understand how http works. The majority will not realise that information is being stored by their web browser on someone else's behalf. It is clearly the risks associated with this lack of knowledge that the directive aims to address. Recital 24 says:

(24) Terminal equipment of users of electronic communications networks and any information stored on such equipment are part of the private sphere of the users requiring protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms. So-called spyware, web bugs, hidden identifiers and other similar devices can enter the user's terminal without their knowledge in order to gain access to information, to store hidden information or to trace the activities of the user and may seriously intrude upon the privacy of these users. The use of such devices should be allowed only for legitimate purposes, with the knowledge of the users concerned.

Recital 25 makes it clear that "cookies" are one such device. It concedes that they can be legitimate and useful but that any use must be with informed consent.

Article 5(3) is very broad in its application. It catches storage on any "terminal equipment" (so mobile devices as well as traditional PC's) and is not restricted to the web or web browsers. The terminal equipment need only belong to a "user" which is defined in article 2(a) as anyone using the network for private or business purposes. So it does not seem to be possible to agree with a subscriber to (say) an ISP or mobile phone service in advance that they consent to the storage of cookies etc on any terminal equipment using their connection if others might use it with different equipment.

The only obvious restrictions to 5(3) are:

  • It only applies to services available over public communication networks and so does not apply to (i) private network services or (ii) to gaining access to a computer without using a network at all.
  • Unsurprisingly, member states are allowed to create their own exceptions where necessary for the purposes of public security, defence and the prevention of crime. Just such an exception was made by the UK in regulation 28 .

Who is responsible? For example, at present I publish this blog using google's blogger service. If google choose (say) to track those reading my blog using cookies without my asking them to, what then? In my view it is the service provider (in this case google) that is carrying out the unlawful activity rather than I, although if I have expressly asked them to do so, then we may both be responsible. If, on the other hand, my blog was made available on a "dumber" hosting service - for example if I installed my own wordpress isntance on a server on which I had shell access and I decided to use cookies, then it would be I, not the provider of my shell access account, who would have to take care of the legalities.

There are two ways that a user (or subscriber)'s rights may be enforced. First by the information commissioner in much the same way as data protection obligations are enforced. Second, regulation 30 permits an individual who has suffered damages as a result of a breach (who might not be the user or subscriber whose equipment was accessed) to bring a claim for damages against the person who committed the breach. There is a defence of reasonable care against such a claim.

So, where cookies are used to illicitly track an individual's preferences and sold to advertisers to allow advertising to be targeted, there is unlikely to be any actual damage and enforcement would have to be by the information commissioner. By contrast, where the use of cookies results in someone's bank details being obtained by a third party (entirely possible with some of the more poorly written systems out there) there may well be financial loss and a right of action. In practice I don't expect to see very many claims, interesting though they would be.

Update

An anonymous commenter asks about other forms of content stored by a web browser. A web browser will almost always store the http response(s) to any request. Some of the information contained in that response may be sent back to the server. A simple example being the value of any fields set in an HTML form, but there are many other, in some cases very sophisticated, mechanisms for doing the same thing. Even the URL in an href attribute can be used to store information — as those with long web memories will recall, one of the earliest example applications using HTML created a noughts and crosses game doing just that.

I suspect that the courts will read the directive as applying only to data stored on a user's computer that can (in principle) be later retrieved by the person storing it or by some other third party. It seems to me that the directive is intended at that kind of mischief which arises where someone or some people track what a user does and keep secret information about them that they can use for their own purposes. Of course there are still risks if information is stored without your knowledge even if it is accessible only to the user of the computer, so the courts may decide to read the directive more widely than that.

Most of these forms of storage will be lawful because they are strictly necessary to provide the service sought by the user. HTML stored by the browser which is displayed to the user is a necessary part of browsing any web page. Ditto where form fields are used for any kind of web transaction such as logging in or purchasing a product. The service can't be supplied without some local state being maintained one way or another. The user will expect it to be so.

On the other hand, keeping a complicated session key that tracks (or allows the tracking) of the user's behaviour without forming part of the functionality the user wanted, would, in my view, fall foul of the directive and need express consent. The fact that cookies aren't used is irrelevant.

Wednesday, 21 April 2010

ACTA is out

A draft (in PDF form) of ACTA, the Anti-Counterfeiting Trade Agreement, has been released by the European Commission. This is the first time any of us have been allowed "officially" to see a draft of the treaty as hitherto negotiations have been conducted in secret. As governments often remind us — if you have done nothing wrong you have nothing to hide — why the secrecy?

Inspired by leaked versions, the treaty has excited much opposition. For example from La Quadrature du Net, the EFF and many others. Michael Geist gives a very thorough analysis on his blog site for those inclined to dig deeper.

If you read the draft you will see that it is marked up with numerous possibilities, indicating differences of opinion between the national delegations. The draft coyly avoids telling us which those delegations might be, but a recently leaked draft may give a clue. I am fairly confident that an analysis of the various parties positions can be crowd-sourced so that we all know where to apply pressure.

This multiple choice nature of the draft makes it hard to analyse whether it is really good or bad or indeed what effect it will have at all. This is particularly so where there are two possible drafts: one stating what parties to the treaty "may" do (which means they need not) or "must" do (which means they certainly will). For example Article 2.2(2) on damages.

I leave a thorough analysis to others who have rather more time than I do, but a couple of points strike me as being of particular interest to the digital/internet environment:

Damages

The normal rule in English civil proceedings is that the damages are compensatory and intend to put you back in the position you would have been if the defendant had done no wrong (or not breached a contract or whatever). In some circumstances a claimant might be able to force a defendant to disgorge any gain they have made without a good lawful reason, or even to pay over any profits they have made as a result of their actions.

In the world of intellectual property this limitation does not operate. Many jurisdictions allow more compensation on top. For example s97(2) of the Copyright Designs and Patents Act 1988, a court may award "such additional damages as the justice of the case may require", having particular regard not only to any benefit gained by the defendant but also to the "flagrancy" of the infringement. In the United States 17 USC 504 allows a copyright owner, where they have registered their copyright, to elect to receive "statutory damages" rather than actual damages and profits, at a minimum of $750 (but up to $30,000) per work infringed. The ludicrous effect of such damages is well known.

ACTA's proposed article 2.2(2) proves that the parties may or shall (which to be later determined) maintain a system of pre-established damages much like that of the US, as well as presumptions for determining the amount of damages. Such a presumption might be that the damages suffered for copying N works each of which would have made (if sold) a profit of p would be Np. Such a sum would almost always be more (probably much more) than the actual loss. There may (or shall) also be a provision for "additional damages".

It is quite possible that rights industries could make more money this way than they would if there were no infringement which would be a surprising outcome in any other field of law.

Criminal liability

Copyright infringement may be a criminal offence in the UK in essentially two circumstances: first where it is done in the course of business and second where it is done "to such an extent as to affect prejudicially the owner of the copyright" (I am simplifying this somewhat). Article 2.14 of ACTA suggests there should be criminal liability for infringement on a commercial scale, which is defined to include "significant wilful". I am unclear on what "wilful" means (perhaps readers can help) but that looks to me to increase the range of criminal liability.

Online infringement

The headline part of ACTA for me ought to be section 4 which concerns enforcement "in the digital environment". With the passage of the Digital Economy Act 2010 it may be we have seen the last of new attempts to legislate in this field in the UK for a few years. It may be that ACTA makes little difference to us except to provide the government of the day with political cover to push things a little further.

Article 2.18 requires that parties make available enforcement procedures that include "expeditious remedies to prevent infringement and remedies which constitute a deterrent to further infringement". So to protect and deter. The detail that results from this general requirement could be almost anything because the draft includes two main options, and many sub-options, that range from a less intrusive system of copyright control than we have in the UK to a system that goes much further. I find it difficult to give any kind of useful summary — if such a thing is even possible.

There are options to protect intermediate service providers though these may be predicated on the provider either taking proactive steps to prevent infringement (but not including monitoring) or responding properly to requests to block/take-down material or both. There are also provisions that may require legal protection of effective technological measures, though to what extent they will go further than those already imposed on us is unclear.

Conclusion

There's an awful lot more in there. I look forward to reading a wider analysis and to seeing what response the various campaigning organisations now adopt. Overall the treaty seems to be a mixture of unnecessary repetition of existing treaty arrangements (such as TRIPS or WCT) and overly draconian provisions. In my view the best outcome would be for the treaty to be abandoned, but I realise that is unlikely, so it might be time to focus more on the detail.

Tuesday, 7 April 2009

Data retention and open wifi

The Data Retention (EC Directive) Regulations 2009 came into force yesterday (6 April 2009). A frequently asked question is: "I run an open wifi network will I have to log user's data?"

Do I need to retain data?

At first sight you would appear to be quite safe because the regulations do not apply to everyone. Check out regulation 10(1):

10.—(1) These Regulations do not apply to a public communications provider unless the provider is given a notice in writing by the Secretary of State in accordance with this regulation.

So until you get that letter from the Secretary of State (or some nice minion working on her behalf) you need to do nothing. But hang on, the Secretary of State would appear to have given herself a rather bigger job than anticipated, still in regulation 10:

(2) The Secretary of State must give a written notice to a public communications provider under paragraph (1) unless the communications data concerned are retained in the United Kingdom in accordance with these Regulations by another public communications provider.

So she must give that notice. Notice in passing that there's no particular penalty on her for failing to do so, so the only way to make her would be to bring proceedings for judicial review. An unlikely eventuality.

But am I really a public communications provider?

Well the law on data retention is meant to be a paper chase for lawyers. "public communications provider" is defined in regulation 2(e):

(e) “public communications provider” means—

(i) a provider of a public electronic communications network, or

(ii) a provider of a public electronic communications service;

and “public electronic communications network” and “public electronic communications service” have the meaning given in section 151 of the Communications Act 2003

So, turning to s.151 of the Communications Act 2003 we find that

“public electronic communications network” means an electronic communications network provided wholly or mainly for the purpose of making electronic communications services available to members of the public;

If you noticed that the s.151 also has a definition of what a "public communications provider" is and that its not quite the same as in the regulations. Well spotted. You will not find transparency or consistency here.

So it looks from s.151 very much like an open wifi, or a wifi supplied to customers in a cafe or other site is a "public communications provider". The Secretary of State will be busy.

But hang on, does that mean I have to get ID from customers?

Well, if I'm right and if the Secretary of State did decide to comply with her statutory duty would that not make life really quite hard for (say) an internet cafe that does not check the identity of its customers?

Some comfort can be found in regulation 3:

  1. These Regulations apply to communications data if, or to the extent that, the data are generated or processed in the United Kingdom by public communications providers in the process of supplying the communications services concerned.

Notice that the regulations only apply to data that has been generated or processed. There's no obligation to create any data you don't already have.

That is just as well, if you check out the schedule to the regulations you will see that some of the data that is covered by the regulations doesn't seem to quite fit with the operation of many cybercafes etc that I know.

But that won't quite work as an answer. Some of the cybercafe's kit probably does at least process data mentioned in paragraph 13(1) of the schedule.

(a) The date and time of the log-in to and log-off from the internet access service, based on a specified time zone,

So it appears that if the regulations mean what they appear to say and an open wifi provider gets a regulation 10 notification they are going to have to keep 12 months' of data which would be a real pain. I promise not to tell the Secretary of State where you live.