Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Sunday, 17 June 2012

The Communications Data Bill (first look)

On Thursday the government announced the Communications Data Bill. The official copy is available as CM8359 but the open rights group have made it available in in an easier to read format. The bill has attracted a lot of interest, so I thought it would be useful if I posted an explanation of what it does and does not do. Bills of this kind benefit from (or suffer, depending on your point of view) considerable amendment while passing through Parliament, so the end product may be very different.

The bill replaces two existing pieces of legislation: chapter I, part II of the Regulation of Investigatory Powers Act 2000 (RIPA) and part 11 of the Anti-terrorism, Crime and Security Act 2001 (ATCSA). For some what will be of interest will be the ways in which the bill changes that existing law, but for others that law is already controversial, so they may see debates on the bill as a chance to re-visit the state we are in.

Communications data

Chapter I, part II of RIPA is all about allowing public bodies to obtain "communications data". The bill and RIPA use essentially identical definitions of communications data (RIPA s22(4) Bill cl.2(9)), which the bill helpfully divides into three parts:

  • traffic data - which includes the identity and location of the communication's end-points and the individuals (if any) sending and receiving it;
  • use data - information which is not traffic data about the use made of a telecommunications service or in connection with the use of a telecommunications service or system;
  • subscriber data - any other information obtained by the provider of a telecommunications system about the people to whom it is provided

But, in both cases, not the content of any communications. Traffic data may include the contents of a communication, in so far as it is "traffic data" but "use data" may not.

The definition is very broad. In RIPA terms a "telecommunications service" is:

any service that consists in the provision of access to, and of facilities for making use of, any telecommunication system (whether or not one provided by the person providing the service)

A "telecommunications system" is:

a system (including the apparatus comprised in it) that exists (whether wholly or partly in the United Kingdom or elsewhere) for the purpose of facilitating the transmission of communications by any means involving the use of electrical or electro-magnetic energy

This definition clearly includes radios and televisions; telephones and mobile telephones and routers. It almost certainly includes mail servers. I am less sure about a server which has multiple roles - since it might be difficult to say that it "exists .. for the purpose", but anyone running a server which acted as a mail transfer agent or on which ran a mail user agent (eg gmail) would surely be running a telecommunications service​ even if the server itself was not a telecommunications system​.

This means that subscriber information and usage patterns of facebook, gmail and so on are already within the scope of RIPA. The bill uses almost identical definitions for telecommunications services and systems, which suggests that exactly the same sets of data will be in scope.

Obtaining communications data

The RIPA regime for obtaining communications data has essentially two parts:

  • authorisations - given by a "designated person" to other members of their organisation or suitably associated organisations (eg collaborating police forces), who are then "authorised officeers". The effect of an authorisation is to make lawful, including removing any civil liability, anything an authorised officer does while obtaining communications data under their authorisation.
  • notices - given by a "designated person" to postal or telecommunications operators, requiring them to obtain (if they are able to) and disclose communications data

Authorisations and notices last up to a month but may be renewed.

The bill has a broadly similar structure with, as far as I can tell, a few changes:

First, an authorisation (given by a designated person) may authorise an authorised officer to give notice to telecommunications operators (cl 9(3)(d)) in contrast to RIPA where it is the designated person who may give notices (s21(4)). In other words the power to force telecommunications operators to obtain and cough up communications data appears to be delegated further down the tree. I do not know enough about how RIPA is operated within police forces to know whether this will make any practical difference.

The second change is more significant. In RIPA a "telecommunications operator" is someone who "provides a postal or telecommunications service" (s25(1)). The definition in the bill (cl 28(1)) extends "operator" to include not only those providing a service but to any person who "controls or provides a telecommunication system".

In theory that means that anyone who owns a mobile telephone (or radio or television) is a "telecommunications operator", so that, in theory, the government could order us all  to keep records of who watches any television we control. While any government doing so would look extremely stupid - and find themselves out of office very fast - the increase in reach has other more usable implications. For instance it extends to manufacturers of communications equipment, who might usefully be asked to install hardware or software to make interception easier. It will be much harder to say that particular data is out of scope.

Retaining data​

The power to obtain communications data from communications operators is only of any use if there is data to obtain. At present the main provision for requiring retention of communications data is the data retention directive. This is directed at "providers of publicly available electronic communications services or of a public communications network" (article 3) who are defined (in the framework directive) in relation to services consisting of the transmission of signals over networks. In particular the obligation does not apply to those (like gmail and facebook) who provide "information society services".

Part 11 of ATCSA, which I mentioned earlier, did give the government a power to pass secondary legislation requiring communications providers (as defined in RIPA) to retain communications data, but only for national security purposes. The power had a sunset clause which meant that if, after two years, the government had not exercised the power it would lapse which it did on December 14 2003.

The bill will change all that. Drastically. Clause 1(1) of the bill states:

(1) The Secretary of State may by order—

(a) ensure that communications data is available to be obtained from telecommunications operators by relevant public authorities in accordance with Part 2, or

(b) otherwise facilitate the availability of communications data to be so obtained from telecommunications operators.

Other than that, there are no restrictions on what the order may do. All the limitations are procedural (consultation, laying before Parliament). This means that the government may do pretty much anything that is at least rationally connected to ensuring that communications data is available. If there was any doubt about this, the rest of clause 1 spells out just how wide the power is, for instance:

  • requirements ("you must") or restrictions ("you must not") may be imposed on anyone;
  • the Secretary of State may be given a power to impose requirements and restrictions on anyone by notice
  • those requirements may include forcing the use of particular software, equipment or algorithms
  • any requirements may be aimed at a different communication provider's data (eg an out of UK mail provider that does not wish to help the UK government might be targeted by asking ISP's to monitor usage of the site)
  • telecommunications operators can be made to contract out compliance with the government or with private firms, including "on a commercial basis", eg the government could nominate a private contractor that would store data on behalf of ISP's and force ISP's to hire them to do so commercially.

It seems to me that clause 1 is just too wide. It allows far too many things. There are essentially no restraints to stop a determined government doing what it wants. The requirement for Parliamentary approval (for instance) is in practice of little weight. Secondary legislation is almost never refused by Parliament and there is no mechanism for amendment to an order that has been laid before the house.

Filtering

Clause 14 (and following) referring to "filtering arrangements" seems to have caught many people's eyes. The explanatory notes suggest that the government intends to run a great big "Request Filter" which will collate communications data from many different sources and also act as a useful front end for designated officers, for example to work out what questions to ask, what sort of results will be obtained and to extract the communications data required.

As a part of the legal analysis I'm not sure that the provisions concerning "filtering arrangements" are particularly interesting. They make it clear that the Secretary of State can run a system like the "Request Filter", but they don't give the government any more powers to obtain data - those are all to be found in clause 1. Clause 14 etc may be there to ensure that no-one challenges the creation of a Request Filter on the grounds that it is beyond the powers (​ultra vires​) of the Secretary of State's office to maintain it.

But the filtering arrangements are interesting in that they give us a clue of one of the things the government has in mind.

Conclusion

In short the bill is all about increasing the amount of communications data that the authorities can get hold of. It does this in two principle ways: (1) by giving an essentially unlimited power to the government to order anyone to do anything rationally connected with that aim (and presumably proportionate and human rights compliant - though that may result in much time-consuming litigation); and (2) by widening the scope of people who can be asked to give up communications data to anyone who controls any communications equipment - in practice almost everyone old enough to own a mobile telephone.

There are a few other bits and pieces in the bill I have not mentioned, for example a requirement for local authority officers to obtain judicial approval for authorisations and a certain amount of tidying up.

It is almost impossible to have a sane debate about this sort of law because, as always, the government are likely to say "but we will only use our powers for good". What is more the bill, if passed, won't do anything particularly bad itself​ that badness is merely a potential badness that allows for misuse of the power at a later date. Again governments will swear on their mothers' that they will only pass just and sensible secondary legislation.

I hope this short post will inform the debate.

Thursday, 20 October 2011

Can we force facebook to give us its "like" database?

Jim Killock of the Open Rights Group pointed me at an interesting response made by facebook to an Irish student named Max's subject access request under Irish data protection legislation which forms a part of the Europe versus facebook campaign.

The particular point that interests me is that, concerns facebook's tracking of all pages visited which show a "like" button - a practice that can be really intrusive. Although Max did obtain a considerable quantity of information, facebook did not release to him their list of "like" tracked data.

In their response facebook say:

Section 4(12) of the Acts carves out an exception to subject access requests where the disclosures in response would adversely affect trade secrets or intellectual property. We have not provided any information to you which is a trade secret or intellectual property of Facebook Ireland Limited or its licensors.

Unfortunately for facebook, that isn't quite what the relevant Irish legislation appears to say (health warning: I am not an Irish lawyer). What section 4(12) of the Irish Data Protection Act 1988 says, according to a consolidated version of the statute, is:

(12) Subsection (1)(a)(iv) of this section is not to be regarded as requiring the provision of information as to the logic involved in the taking of a decision if and to the extent only that  such provision would adversely affect trade secrets or intellectual property (in particular any  copyright protecting computer software).

Note the phrase "information as to the logic involved in the taking of a decision". What this is all about is that section 4 gives data subject several different rights. One right (in section 4(1)(iii)(I)) is to be supplied with a copy of "the information constituting any personal data of which that individual is the data subject" - a simple right to information. Another, and different right, can be found in section 4(1)(iv) which applies to automatic decision making by the data controller. Here the data subject has a right to be informed of the "logic involve in the processing". Obviously that's quite a different right since it is essentially a right to know about algorithms rather than data.

Quite clearly section 4(12) is a restriction on the right under 4(1)(iv) to know about the logic of automatic decision making and not a restriction on the right of information simplicter. Nice try facebook, but I can't see that working.

Our own legislation is very slightly different. We also have a right (in section 7(1)(d) of the Data Protection Act 1998 to be informed about the logic involved in automatic decision making, but the restriction on that right is limited to trade secrets. Section 8(5) says:

Section 7(1)(d) is not to be regarded as requiring the provision of information as to the logic involved in any decision-taking if, and to the extent that, the information constitutes a trade secret.
So that any UK national involved in the Europe v facebook campaign has a much stronger argument.

In any case, at best facebook can claim a database right over the contents of the list of pages visited by Max that they have collected using the "like" button. The database right is a creature of European law (directive 96/9/EC). Recital 48 of the directive states that "the provisions of this Directive are without prejudice to data protection legislation", which seems to me to argue that data protection law ought to trump database right. If you think about it, the contrary would be an impossible situation. Personal data will often be protected by database rights. If you could use database rights to avoid subject access requests they would be of far less use.

Tuesday, 17 May 2011

Restraining cookies: the new privacy rules

On 26th May 2011, a new law — the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 — comes into force which will change fundamentally the legal regime governing cookies and other similar locally stored data. As I will explain, the legal change is a big deal, but the practical effect may, at least in the short term, be small.

The Information Commissioner has published some useful practical guidelines (alas only as a PDF). They are not definitive (so they may not protect you in the unlikely event someone tries to sue you for damages caused by a breach of the regulations) but since the Information Commissioner (or his office at least) has the primary role in enforcing the regulations, complying with his guidelines will go a long way to avoiding any possible legal repercussions. If you have a short attention span and wish to read only one thing about the new cookie law then I'd advise you go there (see you another time and thanks for visiting).

The new rules apply to storing (or accessing information stored) on a public network user's computer. That includes not only cookies and "flash cookies" but any other information that might be stored on a local computer, for example they would certainly apply to the iPhone's storage of location data. For brevity I'll talk about cookies, storing cookies but all that follows applies much wider than that.

Overview

The amended regulation 6 will forbid anyone from storing cookies unless one of the following applies:

  • the user has given their prior, informed, consent (an opt out is no good)
  • it is for the sole purpose of "carrying out the transmission of a communication"
  • it is strictly necessary for the provision of an information society service that was requested by the user

In practice this means that, except in very limited circumstances, prior explicit permission will need to be given by a user before using cookies. The limited circumstances might include situations where the illusion of a session (http being stateless) is needed in order to provide the user with the service they want, for example via a "shopping cart".

Tracking what a user does (eg with a tool like google analytics) or supplying additional services they might want (eg "other users also bought...") would not be for a service "requested by the user" and so would need consent.

Consent may be given by the user explicitly setting their browser to accept cookies. At the moment most browsers will, by default, accept cookies and so it is not, at present, realistic to rely on a user's browser settings to gain the necessary consent. Browser technology may change to make such a reliance tenable and I expect there to be some pressure in that direction.

Clauses in a website's terms and conditions which do not have to be explicitly accepted by a user (for example because they are linked to at the bottom of a page) are, in my view, also not going to be any good.

One small consolation to online service providers is that the ICO has said that in the early stages of this new law all he will look for is a plan to get things right, rather than expect 100% compliance from 26th May. That isn't an excuse to be complacent, but does give some breathing space.

Detail

The origin of the new law is in an amendment to the directive on privacy and electronic communications (directive 2002/58/EC). There doesn't appear to be a consolidated version in html format online, but for the purposes of this post all we care about is replace article 5(3) which was added by directive and reads:

3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.

One one analysis it is not the web server (and thus the operator of the server) who stores or gains access to cookies on a user's machine, rather the server returns a "Set-Cookie" response which a web browser has no obligation to honour. It is also the web browser that transmits the value of a cookie back to the web server.

The directive is not intended to be understood in so narrow a sense. Only a small minority of web users understand how http works. The majority will not realise that information is being stored by their web browser on someone else's behalf. It is clearly the risks associated with this lack of knowledge that the directive aims to address. Recital 24 says:

(24) Terminal equipment of users of electronic communications networks and any information stored on such equipment are part of the private sphere of the users requiring protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms. So-called spyware, web bugs, hidden identifiers and other similar devices can enter the user's terminal without their knowledge in order to gain access to information, to store hidden information or to trace the activities of the user and may seriously intrude upon the privacy of these users. The use of such devices should be allowed only for legitimate purposes, with the knowledge of the users concerned.

Recital 25 makes it clear that "cookies" are one such device. It concedes that they can be legitimate and useful but that any use must be with informed consent.

Article 5(3) is very broad in its application. It catches storage on any "terminal equipment" (so mobile devices as well as traditional PC's) and is not restricted to the web or web browsers. The terminal equipment need only belong to a "user" which is defined in article 2(a) as anyone using the network for private or business purposes. So it does not seem to be possible to agree with a subscriber to (say) an ISP or mobile phone service in advance that they consent to the storage of cookies etc on any terminal equipment using their connection if others might use it with different equipment.

The only obvious restrictions to 5(3) are:

  • It only applies to services available over public communication networks and so does not apply to (i) private network services or (ii) to gaining access to a computer without using a network at all.
  • Unsurprisingly, member states are allowed to create their own exceptions where necessary for the purposes of public security, defence and the prevention of crime. Just such an exception was made by the UK in regulation 28 .

Who is responsible? For example, at present I publish this blog using google's blogger service. If google choose (say) to track those reading my blog using cookies without my asking them to, what then? In my view it is the service provider (in this case google) that is carrying out the unlawful activity rather than I, although if I have expressly asked them to do so, then we may both be responsible. If, on the other hand, my blog was made available on a "dumber" hosting service - for example if I installed my own wordpress isntance on a server on which I had shell access and I decided to use cookies, then it would be I, not the provider of my shell access account, who would have to take care of the legalities.

There are two ways that a user (or subscriber)'s rights may be enforced. First by the information commissioner in much the same way as data protection obligations are enforced. Second, regulation 30 permits an individual who has suffered damages as a result of a breach (who might not be the user or subscriber whose equipment was accessed) to bring a claim for damages against the person who committed the breach. There is a defence of reasonable care against such a claim.

So, where cookies are used to illicitly track an individual's preferences and sold to advertisers to allow advertising to be targeted, there is unlikely to be any actual damage and enforcement would have to be by the information commissioner. By contrast, where the use of cookies results in someone's bank details being obtained by a third party (entirely possible with some of the more poorly written systems out there) there may well be financial loss and a right of action. In practice I don't expect to see very many claims, interesting though they would be.

Update

An anonymous commenter asks about other forms of content stored by a web browser. A web browser will almost always store the http response(s) to any request. Some of the information contained in that response may be sent back to the server. A simple example being the value of any fields set in an HTML form, but there are many other, in some cases very sophisticated, mechanisms for doing the same thing. Even the URL in an href attribute can be used to store information — as those with long web memories will recall, one of the earliest example applications using HTML created a noughts and crosses game doing just that.

I suspect that the courts will read the directive as applying only to data stored on a user's computer that can (in principle) be later retrieved by the person storing it or by some other third party. It seems to me that the directive is intended at that kind of mischief which arises where someone or some people track what a user does and keep secret information about them that they can use for their own purposes. Of course there are still risks if information is stored without your knowledge even if it is accessible only to the user of the computer, so the courts may decide to read the directive more widely than that.

Most of these forms of storage will be lawful because they are strictly necessary to provide the service sought by the user. HTML stored by the browser which is displayed to the user is a necessary part of browsing any web page. Ditto where form fields are used for any kind of web transaction such as logging in or purchasing a product. The service can't be supplied without some local state being maintained one way or another. The user will expect it to be so.

On the other hand, keeping a complicated session key that tracks (or allows the tracking) of the user's behaviour without forming part of the functionality the user wanted, would, in my view, fall foul of the directive and need express consent. The fact that cookies aren't used is irrelevant.